Slashdot Mirror


US Reigns As Most Bot-Infected Country

Trailrunner7 writes "The US has by far the highest number of bot-infected computers of any country in the world, with nearly four times as many infected PCs as the country in second place, Brazil, according to a new report by Microsoft. The quarterly report on malicious software and Internet attacks shows that while some of the major botnets have been curtailed in recent months, the networks of infected PCs still represent a huge threat."

91 of 121 comments (clear)

  1. Microsoft Did the Report? by DarkKnightRadick · · Score: 1, Interesting

    I'm sure they failed to mention the OS with which most infected computers are running. :p

    --
    "There is a way that seems right to a man, but its end is the way of death." Proverbs 16:25 (NKJV)
    1. Re:Microsoft Did the Report? by DarkKnightRadick · · Score: 4, Informative

      I take that back. Not only do they report which OS, but claim their count by how many computers their malicious software tool has cleaned. lol

      --
      "There is a way that seems right to a man, but its end is the way of death." Proverbs 16:25 (NKJV)
    2. Re:Microsoft Did the Report? by shadowbearer · · Score: 3, Interesting

        Which is only a small fraction of the real infections out there. I've cleaned thousands of infected computers since MS introduced that tool, and I've yet to see one which the tool dealt with adequately.

        (Don't bother to say "Yeah, but if it dealt with it, you wouldn't see the computer!" If they really believed that tool was effective, then Microsoft wouldn't include the warning "you don't appear to have an antivirus solution installed" in their security center warning, now, would they?)

      SB

      --
      It's old. The more humans I meet, the more I like my cats. At least they are honest.
    3. Re:Microsoft Did the Report? by DarkKnightRadick · · Score: 1

      No kidding. And every last one of them, I'd imagine, is running some form of Windows. It's actually quite scary. The fact that MS can spin this good for themselves and people buy it? Even scarier.

      --
      "There is a way that seems right to a man, but its end is the way of death." Proverbs 16:25 (NKJV)
    4. Re:Microsoft Did the Report? by shadowbearer · · Score: 1

        I think it's more intended as an emergency tool to clean up widespread overnight threats, like Blaster, or for dangerous infections like keyloggers.

        Come on, now. Microsoft surely has the resources to write the best antivirus/anti-rootkit/anti-malware solutions for their own code.

        At the very least they could work with the community to close the holes they already have, and to develop better solutions to detection and mitigation.

        They rarely do (I know some will say that they do. If so, then why are there so many free and much more effective antivirus solutions offered by third parties? Why are there so many free and effective rootkit removal tools available - that actually WORK? I could go on and on... )

        The Emperor has no clothes.

      SB

      --
      It's old. The more humans I meet, the more I like my cats. At least they are honest.
    5. Re:Microsoft Did the Report? by BrokenHalo · · Score: 1

      Which is only a small fraction of the real infections out there.

      Indeed. But what the submission doesn't mention is that while the US may indeed have four times the number of bots of its nearest "rival", it also very likely has four times as many computers in total. In other words, a fairly pointless non-statistic.

    6. Re:Microsoft Did the Report? by shadowbearer · · Score: 1

      but because the AV industry is terrible at writing software,

        Oh, an astroturfer. What fun ;=)

        The solutions I use are what have proven to me to work in the field.

        Neither Defender nor the Microsoft Security Essentials do. I go with what works; what fixes the problems for my customers. That is how I make a living. My customers don't care to pay high dollars for to fix their problems; they aren't "business" accounts.

        Microsoft is in the best position to develop an anti-virus product for Windows due to their close knowledge.

        Jeez, I think I said that. Then perhaps they should fix their own operating system; or, at the least, provide solutions for customers who buy their operating system to do so, at no charge - they sold a product, then support it.

        Since they have not, it has fallen on third party vendors and outside technicians to do it for them.

        My sincere apologies if I refuse to bleed for them.

      SB

      --
      It's old. The more humans I meet, the more I like my cats. At least they are honest.
    7. Re:Microsoft Did the Report? by shadowbearer · · Score: 1

        All statistics are pointless; because the numbers depend on who compiles them. Which is a small part of what I was trying to point out. ;-)

      SB

      --
      It's old. The more humans I meet, the more I like my cats. At least they are honest.
    8. Re:Microsoft Did the Report? by CrossChris · · Score: 1

      Come on, now. Microsoft surely has the resources to write the best antivirus/anti-rootkit/anti-malware solutions for their own code.

      Nope. MS don't even understand the internals of their own NT kernel. There is no hope whatsoever of MS making "their" code secure - it just can't be done. Their only hope is to ditch all their products and start again - probably with a BSD or Linux core - and forget compatibility with their existing codebase.

      Game over, Microsoft.

    9. Re:Microsoft Did the Report? by shadowbearer · · Score: 1

        Then don't post AC.

      SB

      --
      It's old. The more humans I meet, the more I like my cats. At least they are honest.
    10. Re:Microsoft Did the Report? by Eskarel · · Score: 2, Interesting

      MSE is free, available on every OS back to XP and as from my personal experience and research actually works. They're certainly far better than any other free AV solution available and I've seen it pick up stuff which broke Norton, all without requiring an extra core just to run your AV program.

      Not sure what the heck you mean about business accounts or high dollars since the app is free.

    11. Re:Microsoft Did the Report? by shadowbearer · · Score: 1

        I strongly disagree with you about it being better than external AV solutions; I haven't seen that it can fix much at all. I see numerous computers with it installed that are just plain hosed.

        As to the latter I am referring to the high cost of Microsoft tech support for the average home user. Last I checked it was 2 free incidents then $35 PER INCIDENT.

      SB

      --
      It's old. The more humans I meet, the more I like my cats. At least they are honest.
    12. Re:Microsoft Did the Report? by Eskarel · · Score: 1

      What does how much it costs to call Microsoft have to do with their AV? I also never said it was perfect, it won't stop an idiot who runs stuff they shouldn't, but all the other free options are worse, the pay ones are no better, and it doesn't kill your CPU running it.

      You don't have to be some sort of elite product to be the best AV solution, you just need to find problems some of the time and use less resources than the malware.

    13. Re:Microsoft Did the Report? by mcgrew · · Score: 1

      Subscribers get 400, which I found out a while ago when I tried to friend three people who friended me and couldn't friend them and mentioned it in my journal. One of them bought me a subscription! So now I have almost 300 friends, the same number of fans, no foes and almost 30 people who freak out when they see one of my posts.

      If you have a lot of foes, make the least bad ones neutral to free up space for friending.

    14. Re:Microsoft Did the Report? by BrokenHalo · · Score: 1

      If you have a lot of foes, make the least bad ones neutral to free up space for friending.

      If you have any foes at all, maybe you should get out more. Over the last decade or so, I've come across posters with whom I disagree completely enough to nudge me to rank them as a foe, only to find a few months later that they are talking complete sense on another topic.

      There's no reason why this forum has to be adversarial, and it would probably be better without this friend/foe claptrap.

    15. Re:Microsoft Did the Report? by mcgrew · · Score: 1

      I agree about the foes (I have none), but friending someone does have advantages, such as being notified when someone with interesting journals posts a new one. I friend fans out of simple courtesy.

      At one time I figured that the few foeing me were probably trolls, until I looked up a few of them and found that they were all good, contributing members. It's a mystery to me except one guy; there was a subthread where I mentioned that I stayed away from married woman but considered any unmarried woman fair game. A (I thought) pleasant conversation ensued, and he foed me the next day.

  2. ALL RIGHT !! USA NUMBER 1 USA! USA! USA! USA! by Anonymous Coward · · Score: 5, Funny

    Eat that China. You suck!

  3. I read the TFA by OzPeter · · Score: 3, Insightful

    But after a short glance I still couldn't see if this is a "per computer" basis for the country or simply a "total pwned" basis.

    --
    I am Slashdot. Are you Slashdot as well?
    1. Re:I read the TFA by Unoriginal+Nick · · Score: 5, Informative

      The US is most in absolute numbers. In rate per 1000, Turkey has the highest rate.

    2. Re:I read the TFA by T+Murphy · · Score: 5, Informative
      The actual Microsoft report has a map that is far more informative than the article itself. As expected, Brazil has a higher infection rate than the US, with the US only leading by gross number of infections. Of course, this data is just number of infections detected and cleaned- it isn't necessarily a complete survey. From the site where the map is given:

      Figure 15 [the map] shows the infection rates in locations around the world using a metric called computers cleaned per thousand, or CCM, which represents the number of reported computers cleaned for every 1,000 executions of the MSRT.

      The actual site is here if you want to get straight to the information (link is also given in the article).

    3. Re:I read the TFA by orient · · Score: 1

      The map is missing a continent! (Antarctica)

      --
      Laudele lor desigur m-ar mahni peste masura.
    4. Re:I read the TFA by war4peace · · Score: 1

      You know what's insightful on that map? You see white spots. And then map those over real countries. Bang! There's North Korea, the most internet-free, Microsoft-free, infection-free country in the world! Also Sudan and Iran. Interesting...

      --
      ...gis sdrawkcab (usually not responding to ACs; don't bother posting as AC)
    5. Re:I read the TFA by John+Hasler · · Score: 1

      Seems more likely that those places are simply free of licensed copies of Microsoft Windows.

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
    6. Re:I read the TFA by Will.Woodhull · · Score: 1

      It needs to be noted that Brazil has a much higher rate of use of Linux than the USA. It is certainly high enough to skew these statistics and might be high enough that, if it were taken into account, would cause Brazil to fall out of worst place.

      Of course there is the notoriously difficult problem of assessing how many persons are using Linux, so there is probably no way to estimate the penetration of malware in all computers in use.

      --
      Will
    7. Re:I read the TFA by socsoc · · Score: 1

      Obviously the machines there must use OS X or nix.

    8. Re:I read the TFA by socsoc · · Score: 1

      You had a good point and then went way off on a tangent.

    9. Re:I read the TFA by hedwards · · Score: 1

      Numbers that haven't been normalized are terribly uninformative. I'm sure that per 1000 isn't the best way of doing it, however it's a lot more useful than going with the gross number. Especially since the US is the 3rd largest nation by population behind India and China with Indonesia right behind us.

      It would be almost impossible for us to ever be behind a nation like Switzerland which is substantially smaller than us, regardless of policies in place. Given that we've probably got more computers infected than they have computers period.

    10. Re:I read the TFA by c0lo · · Score: 1

      From the point of view of a site under DDoS originated from a botnet, I don't think the "relative percentage of zombies to the total number of computers in a certain country" matters too much - a pwned computer is a pwned computer no matter if it is "one in two" or "one in 1000".

      --
      Questions raise, answers kill. Raise questions to stay alive.
    11. Re:I read the TFA by Jaime2 · · Score: 1

      But how much juice does this topic really have? If somebody doesn't get us off on an interesting tangent, this thread will become nothing but a series of "Windoze" and tounge-in-cheek "Go USA" jokes.

    12. Re:I read the TFA by ralphdaugherty · · Score: 1

            There's the point about licensed copies of Windows involved made elsewhere in the thread, but besides the absolute count vs. rate point, the impression given is that a large number of bot activity emanate from US computers compared to other countries.

            There is other bot activity such as generating email or probing networks to infect other computers that I don't see, but I can tell you it isn't forum board spamming coming in large numbers from US computers. It comes from former USSR, China, and Brazil in quite predominant numbers.

            But then again, we're back to the legal/illegal copies of Windows and what appears to be Microsoft counting large numbers of legal copies of Windows in the US compared to other countries.

            I've seen this reported about relatively large numbers of US bots repeatedly and I just don't see that in my web logs over last eight years. Actually the honey pot IP address collectors would be much more accurate sources of this data in my opinion. This particular source and method from Microsoft is, in the words of several posters here, next to worthless.

            If the honey pot collectors are also saying that relatively large numbers of bot type activity is coming from US IP addresses compared to other countries such as former USSR and China, then I would have a hard time understanding it. I would have to look at the data, because I haven't seen that in my experience.

        rd

    13. Re:I read the TFA by lxs · · Score: 1

      Yeah but bonus points for using a car analogy.

    14. Re:I read the TFA by ginbot462 · · Score: 1

      I notice viruses don't cross over into Canada. The border guard is doing a great job not allowing export of a military grade infections. That, or the mounties and socialized medicine are doing great jobs at protecting computers.

      And that is amazing since MS is so prevalent in Canada.

      http://www.cbc.ca/health/story/2008/09/18/f-multiple-sclerosis.html

      --
      Atlas Shrugged : Thematic Story :: Battlefield Earth : Organized Religion
  4. I Blame WindowBUYTIXNOW4SALE by WillAffleckUW · · Score: 2, Funny

    I blame Window#BUY TIX NOW 4 SALE only $19,99 in America dollar! Extra fine speci4l sauce extra.

    You give gold, please.

    --
    -- Tigger warning: This post may contain tiggers! --
  5. Scraping the bottom here by oldhack · · Score: 1

    At least throw in some off-the-wall super-twisted headline. How's a post like this supposed to generate views and comments other than tired old rants like this?

    --
    Fuck systemd. Fuck Redhat. Fuck Soylent, too. Wait, scratch the last one.
  6. Quick Question by Monkeedude1212 · · Score: 5, Insightful

    How many computers total are in the US compared to other countries of the world?

    Simple counts don't cut it in the real world of statistics.

    I bet 100% of Canadian computers could be infected and we still might not beat out the US. Considering the Population of California alone is greater than our national population (or at least it was last time I checked).

    1. Re:Quick Question by tacarat · · Score: 4, Insightful

      Real statistics don't cut it in the world of headlines.

      --
      "Common sense will be the death of us all"
    2. Re:Quick Question by Anonymous Coward · · Score: 2, Insightful

      I bet 100% of Canadian computers could be infected and we still might not beat out the US

      Why didn't that sentence confuse you?

    3. Re:Quick Question by aliddell · · Score: 1

      You might want to reread OP and think about what you just said. There might be some very basic between-the-lines, but I bet a good solid second glance would clear it all up for you.

      --
      What do you think, sirs?
    4. Re:Quick Question by martin-boundary · · Score: 5, Insightful

      Simple counts don't cut it in the real world of statistics.

      Huh? It entirely depends on what the statistics are being used for. Simple counts are useful when the amount of activity is proportional to the population size.

      For example, with a botnet, it's the absolute number of bots that matters, because the bots in a botnet are interchangeable (it doesn't matter where they're located, or what processor they're running, etc).

      So if you're going to propose botnet solutions on a per country basis, then you want to know which country has the greatest number of active bots, not the country which has the greatest percentage of infectected computers.

    5. Re:Quick Question by Anonymous Coward · · Score: 1, Funny

      Having a problem with complex thoughts expressed in two sentences, are we?

    6. Re:Quick Question by c6gunner · · Score: 1

      So if you're going to propose botnet solutions on a per country basis, then you want to know which country has the greatest number of active bots, not the country which has the greatest percentage of infectected computers.

      Um, no. That only works if your "solution" is to sever the affected country from access to the internet. Otherwise you still care more about percentages, because as the percentage level decreases your efforts to combat the problem quickly run afoul of the diminishing returns.

    7. Re:Quick Question by SkeeZerD · · Score: 1

      Isn't Canada just another state? I thought canadians were just americans trapped under the maple leaf.

    8. Re:Quick Question by hedwards · · Score: 1

      I'm not sure that's true. In China they don't pay for licensed copies of Windows. It's been so bad that MS has had to introduce a cut cost version for the Chinese market. Makes me wonder why on Earth we have to pay the full cost when other nations get the same product for basically nothing.

      For years before he stopped being CEO, Bill Gates was obsessed with getting the Chinese to pay for Windows.

    9. Re:Quick Question by c0lo · · Score: 1

      How many computers total are in the US compared to other countries of the world?

      If your site is under attack from a botnet, do you care much if a zombie is Canadian or in US?

      --
      Questions raise, answers kill. Raise questions to stay alive.
    10. Re:Quick Question by cbiltcliffe · · Score: 1

      How many computers total are in the US compared to other countries of the world?

      If your site is under attack from a botnet, do you care much if a zombie is Canadian or in US?

      Well, I much prefer the overly polite Canadian zombies, myself....

      --
      "City hall" in German is "Rathaus" Kinda explains a few things......
  7. Cyber Defense by Anonymous Coward · · Score: 1, Funny

    Our Federal Department of Cyber Defense is as effective as tepid jello against spammers and spambots.

    1. Re:Cyber Defense by ThePawArmy · · Score: 2, Funny

      Hmmm tepid jello....

    2. Re:Cyber Defense by couchslug · · Score: 1

      "Now *there's* a fetish!"

      And he's not alone...

      --
      "This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
    3. Re:Cyber Defense by hedwards · · Score: 1

      Well, at least he's not fucking the pie. We can easily get more Jello, but god damn it, that pie was for dessert.

    4. Re:Cyber Defense by LordAzuzu · · Score: 1

      Jerking, already? ;)

  8. True measure by __aagmrb7289 · · Score: 4, Insightful

    This report is not a good measure of anything. It only counts botnets cleaned by Microsoft's program, and it doesn't talk about infections per capita. It measures nothing, and is pretty close to useless. Yay. Okay, that's not totally fair - there is useful information in it. But the article has very little of that information, and the summary has none of it. Now, yay.

    1. Re:True measure by Arrogant-Bastard · · Score: 2, Insightful

      Absolutely true -- any estimate of total botnet populations that isn't in excess of 100 million can safely be disregarded as the product of either (a) poor methodology or (b) creative public relations.

      Moreover, since these statistics are allegedly based on the number supposedly cleaned up, they've severely biased toward "systems which happen to have the appropriate cleanup tool installed AND which happen to have malware that the cleanup tool knows about". Given that the bad guys have copies of the cleanup tool as well, it's certain that they've undertaken significant engineering effort to craft their malware to avoid it.

      The only things we really know about bots at this point are (a) they're already epidemic (b) there are more every day (c) no effective countermeasure exists (d) botnet disruption does not remediate bots (e) botnet C&C mechanisms are improving continuously and (f) we are approaching the point in time where any Windows system, chosen randomly, will have a 50-50 chance of being a bot.

    2. Re:True measure by doesnothingwell · · Score: 1

      ...the article has very little of that information, and the summary has none of it.

      The first rule of Slashdot.

      --
      They can have my command prompt when they pry it from my cold dead fingers.
    3. Re:True measure by __aagmrb7289 · · Score: 1

      Hear hear! Well said sir!

  9. this by buddyglass · · Score: 3, Interesting

    Exactly. Here are Microsoft's statistics after computer prevalence is taken into account. Quote from that page:

    Among locations with more than 200,000 executions of the MSRT in 2Q10, Turkey had the highest infection rate, with 36.6 computers cleaned for every 1,000 MSRT executions (CCM 36.6). Following Turkey were Spain (35.7), Korea (34.4), Taiwan (33.5), and Brazil (25.8). All have been among the locations with the highest infection rates for several periods.

    Locations with the lowest infection rates include Belarus (1.3), Bangladesh (1.5), Sri Lanka (1.8), Tunisia (1.8), and Morocco (1.9).

    Given the very low infection rate of most of Africa, though, something tells me Microsoft's "CCM" metric may not perfectly reflect real infection rates.

    1. Re:this by Anonymous Coward · · Score: 1, Interesting

      1) The highest country had only a 3.66% detected infection rate. I think this really shows how ineffective the malware removal tool is. Judging by the non IT run computers that I come in contact with, approximately 100% are filled to the brim with toolbars, random processes, and odd start up programs. 2) Africa's number is only so low because you can't cure AIDS.

    2. Re:this by tlhIngan · · Score: 1

      The highest country had only a 3.66% detected infection rate. I think this really shows how ineffective the malware removal tool is. Judging by the non IT run computers that I come in contact with, approximately 100% are filled to the brim with toolbars, random processes, and odd start up programs.

      Except, it isn't.

      MSRT (Malicious Software Removal Tool) is NOT an antimalware/antispyware/antivirus solution (Microsoft's version of that is called Microsoft Security Essentials). MSRT is a small tool run once every Patch Tuesday to remove what Microsoft deems extremely bad.

      It does not remove anything else other than the few bad things it's looking for - you can compare antivirus scanners and the like against how many they catch (10s of thousands), and MSRT really targets under 100 or so per month - the ones that seem to cause the most crashes and the like that come in via the crash reporter. It's a very targeted antimalware tool, and has been credited with crippling botnets in the past when come Patch Tuesday, vast swaths of computers suddenly have the botnet removed quite ungracefully.

      MSRT predates MSE (and OneCare) and was used as a way to get rid of particular pieces of malware for a few years now. It's limited because it's free and comes automatically (if you have updates enabled), so Microsoft has been very careful with MSRT to not trample on anti-virus sellers by not making it run all the time (it runs at most once a month) and not having a comprehensive antivirus database (it only targets the few Microsoft deem worthy). It's also why you have to install MSE yourself - it will never be bundled with Windows (anti-trust).

  10. Numbers... by citoxE · · Score: 3, Insightful

    The reason more Americans are infected is because of the sheer amount of computers we have. As others have noted, it's really the percentage per 1000 that are infected that really count. I would bet that most people nowadays have more than one PC in their home, so the statistics are skewed if no one is playing by the same rules.

    1. Re:Numbers... by Tanktalus · · Score: 1

      How about those of us running multiple VM's on a single box? I'm sure that skew is being ignored, too :-P

    2. Re:Numbers... by Anonymous Coward · · Score: 2, Funny

      percentage per 1000

      Idiot

  11. IT staff by NetNed · · Score: 2, Interesting

    Could it be from the down playing of hiring a proper IT staff that actually knows what they are doing, or paying a professional that knows how to properly remove and repair things? Sure most reading this know to run scans of up to date tools to remove infections on PC's, but in my experience most put up with it till performance is to the point of crippling the PC or network. Then a outside IT is called in and sometimes is treated like they are somehow to blame for the issues they are experiencing and try and use that as an excuse for not hiring a real IT person that actually knows what security is about. Of course this is for smaller sized business, but I have seen things as stupid as this in larger sized companies that think they are really saving something by having a secretary or high school kid run their network.

    1. Re:IT staff by david.emery · · Score: 3, Informative

      It's clear from my experience that you need a competent IT staff to run a network of Microsoft machines.

      It's also clear from my experience that a reasonably intelligent group of Mac users do NOT need the same level of help. That's not to say they never need "professional experience," rather to point out that a single trained Mac IT support person takes care of a LOT more installations than a trained Windows IT support person. In the company I used to work for, I think that number was about 25-1; there were 2 Mac people supporting an installed Mac user base of several hundred in a department of, I don't know, 25-50 maybe for a Windows installed base of several thousand. Now some of those people did servers, routers, etc, and not just desktops.

      Running a server, whether Windows, Mac OS X Server or Linux, requires a deeper level of training, experience and time investment.

    2. Re:IT staff by sirsnork · · Score: 1

      So, let me get the striaght...

      It takes 2 people to take care of about 200 Macs, and ~30-35 people to take care of 2000 Windows machines, of which some are servers, and you admit some of those take care or network/firewall/routers etc. To me that looks like your desktop support people are almost exactly equally distributed between Mac and Windows, about 1/100 with the rest of the Windows guys running the servers and the network.

      Honestly I'd say those numbers are pretty good overall from a machine per tech point of view.

      I deal with both Windows and Mac's and unless you have insane automation and reporting (which is pretty much impossible in a mixed environment) thats about the numbers you have to run. Mac's are no easier to manage in large numbers than Windows machines. both give you tools to manage them and both can be screwed up just as easily by the user. The only real problem with Windows boxes is when apps that aren't written well require an admin account to run

      --

      Normal people worry me!
  12. US Reigns As Most Bot-Infected Country on Web by BudAaron · · Score: 2, Insightful

    So can someone explain why this is news? Sounds more like it reflects the number of computers in the country!

    1. Re:US Reigns As Most Bot-Infected Country on Web by ColdWetDog · · Score: 5, Funny

      So can someone explain why this is news? Sounds more like it reflects the number of computers in the country!

      Look, as an American, it feels good to be the bestest at something for a change. We're desperate, we'll take anything.

      --
      Faster! Faster! Faster would be better!
  13. In other news by MintOreo · · Score: 1

    China gave birth to 4 times as many babies as the US in 2010, so obviously they just love making tons of babies over there.

  14. Re:We're Number 1!!! by hairyfeet · · Score: 3, Insightful

    You know, you trolls are starting to piss me off. You know here in the USA we got TONS of other races yet all you say is "nigger nigger nigger" and "spic spic spic" and that is....well it just ain't fair! I mean sure, you throw in the occasional Jew, but what about us Micks? I haven't heard a decent Irish insult in ages! And where is the Italian and Native American jokes? This used to be a site with top notch trolls, trolls that really went that extra mile. THREE PAGE ass rape trolls written in the style of a Harlequin romance, or HUGE vulgar ASCII layouts that took real artistic ability. Now you just say "nigger" and think you have written a quality troll, it is just sad I tell ya. I'm sure the great trolls are hanging their heads under their bridges in shame.

    As for TFA, before we get all those lame "ban windblowz LOL!" lame bits, as a PC repair guy that actually has to deal with these on a day to day basis? The OS is fine, has been since XP Sp2 as a matter of fact, it is the dumb as shit users that ruin everything! I don't know how many times I tell them "don't just download and run random shit from the Internet" or "Don't go opening email attachments or clicking links sent to you by people you don't even know" but do they listen? hell no! At least with Vista and 7 the new security features help somewhat to protect the OS from the PEBKAC, but I can tell you the two biggest sources of infection are 1.-people purposely installing malware because it came with some "free app" they wanted or a web page said "ZOMG! you got teh Viruzz" even though they have a working AV (which I swear I have seen them turn off because some app they are trying to install told them to) and 2.- Adobe Reader bullshit.

    Linux or any other FLOSS would NOT magically fix that kind of stupid my friends, Lord I wish it would but it simply won't. These same folks if you stuck them on Linux would happily pass their root password to any and every app without a second thought, they simply don't give ANY thought at all. You'd think I'd be happy about this, but it makes me feel like the cave painter in "History of the World: Part 1" who has his masterpiece pissed on. I get enough work from referrals I'm actually very happy when someone follow basic best practices and doesn't need to bring me their machine all the time. But as TFA shows, for every 1 of those there are 10,000 that would give you their password for a cookie. it is just fricking sad man, just fricking sad.

    --
    ACs don't waste your time replying, your posts are never seen by me.
  15. Why can't we fix this? by Pathway · · Score: 1

    Forgive my ignorance on the subject matter, but why can't we fix this?

    Is it because the infected machines have no anti-virus or anti-malware? Would a free AV program installed on the maxhine fix the problem on an individual machine?

    Is it because it is too hard for most AV programs to detect a Bot?

    Is it because there are too many older computers that don't have a supported AV solution?

    Could a free AV check on the most popular homepages (google.com, yahoo.com, live.com, etc) inform users that they are potentially compromised? This would only check to see if an up to date AV program was installed, not a full AV check...

    Is it something else all together? Do we even know?

    Thanks for helping me understand the problem.

    --Pathway

    1. Re:Why can't we fix this? by hedwards · · Score: 1

      The main reason is that we just have more boxes than any other country. But beyond that it's primarily and issue of ignorance in the people using the machines. Our users aren't the worst in that respect, but they could use a lot more education. I've personally not ever had any trouble, but then again, I run anti-malware protection and a sandbox and I'm mindful of where I go play.

    2. Re:Why can't we fix this? by shutdown+-p+now · · Score: 1

      The problem isn't cleaning up the malware, the problem is preventing it from getting back there shortly afterwards. No anti-malware tool will help if the OS permits applications to run outside the sandbox - even if it asks for user permission to do so, casual users will happily click on "yes" the requisite amount of times to see the promised boobs (or whatever). The only true fix is iOS-style walled garden where the OS does not let the user make security decisions at all (and hence make mistakes about them), so be careful what you're asking for.

  16. National Reformat Day by The+Living+Fractal · · Score: 1

    Seriously, this should be a holiday or something... when everyone reformats and goes back to a clean install. Good bye botnets, at least for quite a while...Too bad, as a species, we don't seem capable of this kind of synchronization.

    --
    I do not respond to cowards. Especially anonymous ones.
    1. Re:National Reformat Day by Merls+the+Sneaky · · Score: 3, Insightful

      Too bad, as a species, we don't seem capable of this kind of synchronization.

      Actually as a species we are quite capable of synchronisation, the problem is people only synchronise of trivial bullshit EG: sporting events.

    2. Re:National Reformat Day by hedwards · · Score: 1

      Humans are predominantly a herd animal. Most people want to do whatever other people are doing and it's really scary once you start to notice it. One of my friends used to volunteer for campaigns and one thing she'd be responsible for at times was starting the applause. Which meant being doing the first three or four claps that started everybody else clapping.

      I wasn't there, but I have observed the phenomenon myself and I don't think that there's any way of looking at it which isn't terrifying.

    3. Re:National Reformat Day by southpolesammy · · Score: 1

      All work and no play makes Jack a dull boy....

      Seriously /.'ers, there are people out there that don't consider computer maintenance as a fun thing to do. I know, it's blasphemy, but variety is the spice of life.

      --
      Rule #1 -- Politics always trumps technology.
    4. Re:National Reformat Day by The+Living+Fractal · · Score: 1

      Yes, did my statement "this kind" not attempt to say that?

      --
      I do not respond to cowards. Especially anonymous ones.
  17. Any figures on Mac or Linux botnets? by jbeach · · Score: 1

    Not flamebaiting, just actively curious.

    --
    The Invisible Hand of the Free Market is what punches workers in the nuts.
  18. Wrong headline, wrong RTFA by Anonymous Coward · · Score: 3, Funny

    Sorry to disappoint the USA #1 fans, but it should have read: The U.S. has by far the highest number of bot-infected computers of any country in the world, with nearly four times as many infected PCs as the country in second place, Brazil, according to a new report by Microsoft, until Microsoft's malicious software removal tool cleaned up said computers so those stats are no longer valid.

  19. Re:At the risk of sounding like an asshole... by aiht · · Score: 1

    No, because they're actually counting number of infections cleaned.
    They also give it as a percentage of the number of executions, but that would go down if a country had more executions of the tool.
    Also, the tool runs itself once a month. Is there any way to run it manually?

  20. Re:ALL RIGHT !! USA NUMBER 1 USA! USA! USA! USA! by clarkkent09 · · Score: 1

    Not so fast. Looks like the main sources of data are MS security tools like Windows Defender, MSRT, Microsoft Security Essentials etc which are available only if you have a licenced copy of Windows. As far as I know there is no such thing as a legal copy of Windows in China.

    --
    Negative moral value of force outweighs the positive value of good intentions.
  21. F*cking Bots, How Do They Work? by hoggoth · · Score: 1

    I am so sick of my mother's computer getting owned. Lay off the warez and porn sites ma.

    What the hell can I do so she'll stop calling me for tech support when her computer starts acting like Robin Williams on crack every other week?

    --
    - For the complete works of Shakespeare: cat /dev/random (may take some time)
    1. Re:F*cking Bots, How Do They Work? by cbiltcliffe · · Score: 2, Funny

      What the hell can I do so she'll stop calling me for tech support when her computer starts acting like Robin Williams on crack every other week?

      Next time you show up to fix it, act like Robin Williams on crack.

      --
      "City hall" in German is "Rathaus" Kinda explains a few things......
    2. Re:F*cking Bots, How Do They Work? by s_p_oneil · · Score: 1

      Here are a few options:

      1) Don't give her an admin account. If she's using XP or higher, give her a "guest" account. She won't be able to install anything, but that's a good thing the next time she clicks on a trojan or visits a web site that tries to silently install something. She'll still get viruses, but if they can't break out of her user folder, they can be cleaned off by simply logging on as the administrator and renaming her user folder (so you can move her documents and favorites to the new user folder after it's created). This won't stop every virus, but it has worked perfectly so far with my wife's PC. I even gave her the admin password so she can install things when she needs to, but she doesn't know how to actually log in as the admin.

      2) Windows Home Server. If you have the extra machine and disk space, it can back up your entire hard drive and track changes daily. If you get a virus, you can roll the entire system back to any previous date. I have a co-worker who set this up at home and for some of his relatives, and he swears by it.

  22. Re:We're Number 1!!! by Anonymous Coward · · Score: 2, Funny

    I haven't heard a decent Irish insult in ages!.

    I'll speak more slowly then.

  23. wth /. wth. by The+Hatchet · · Score: 1

    COMMON GUYS! This is a website that is *supposed* to consist primarily of intelligent people and nobody asked the important question, or pointed out the moronic flaw!

    Of course the US will have the highest absolute number of infected computers, we have the highest number of computers period! This is only relevant if we have the highest PERCENTAGE of infected computers. if 10% of our computers are infected and 100% of canada's computers are infected, we still probably have a lot more infected computers than canada, despite better upkeep.

    That being said, I don't doubt that we also have the highest percentage of infected computers, I am just flabbergasted something so incredibly stupid and meaningless would be posted to slashdot when any moron that passed middle school math class should know why this article is totally meaningless, but simply by switching from descriptions in absolute terms to description in percent infected terms, the article would all of a sudden actually show that americans suck with computers or are targeted more frequently. Right now all it is saying is that we have more infected computers than anybody else. Well that's fine and dandy, I suppose you are going to tell me that China has more cases of the flu than the US does too? I mean, sure they have several times more people than us, so even if they had double the flu cases they would still be healthier per capita than us. You just need to say they have twice as many flu cases per population than the US, and it suddenly becomes a glaring scar on their image instead of a meaningless rant about irrelevant bullshit.

    And really, i am always the guy attacking people who inject excess sense into a conversation gone terribly astray, but this doesn't even have a baseline of sense to which an excess can be added.

    Also, most of the posts are just pointless nerd culture which speaks nothing of intelligence simply that you watched star trek instead of football. Really the both of you are the same unless you can say something important and they can't. And when you lose the ability to say something important, like a per capita comparison of issues between cultures instead of ranting about how your country has more penises just because it has a higher number of total men, then you are no longer any more intelligent than even the dumbest jock. What is nerd culture worth if you are not being nerdy but totally retarded, ranting about pointless bullshit like how hot your quarterback/sci-fi character is?

    --
    Where is the mod rating for "scary"? Also, ...
  24. Makes sense by Rysc · · Score: 1

    There are a lot of privately owned Windows boxes in the USA that have fast internet connections and excessive amounts of CPU and RAM. This combination is surely juicier than the kind of specs and connections and (importantly) volume you can get in most other places. I would be shocked if first-world countries with large tech sectors were not the biggest source of compromised computers.

    --
    I want my Cowboyneal
  25. Re:ALL RIGHT !! USA NUMBER 1 USA! USA! USA! USA! by DarkXale · · Score: 1

    Unless you apply the wrong update.

  26. Re:Be thankful: They keep YOU working... by hairyfeet · · Score: 1

    Actually I try my damnedest to make sure they WON'T come back. Why would I do that and cost myself business? Simple. I've found that by making the machine as "idiot proof" as possible my business more than quadruples thanks to referrals. people just love to help their friends and family, and when you make their PC a joy to use they are quick to interject when they hear someone having a PC problem "oh you should just take it where I took mine! It runs great now and is hassle free!" I used to have long arguments with my former boss over this, who was of the "busted boxes bring more business" mindset, and where is he now? He retired and his shop closed down.

    So there are those of us who are quite happy to see a person only once, because we know we'll be working on their (insert sis, cousin, brother, uncle)'s machine soon enough. Through the right combo of free programs I've managed to cut down the infections among my customers by a good 70-80%, and I try to have as much of the PC maintenance process automated as I possibly can. Defrag, registry and shortcut cleaning, Windows updates, etc. Sadly I haven't found a tool to automate the third party programs yet, the closest I've found is FileHippo Update Checker, but that requires manual download and install after it scans. But by automating the process as much as possible (as I tell my customers "I do the hard stuff so you never have to") I make their PCs as close as I possibly can a "flip the switch and go" appliance, and they are happy to send their family and friends to me as a result. It also builds quite the customer loyalty, and with 2 other shops in town I still had a pile of new machines to work on when I came back from vacation because many wouldn't allow anyone else to touch their PC.

    And as for repair guys writing the bugs? Not happening unless there are a LOT of pissed of repair guys in Eastern Europe, because watching the boards and looking at traffic on infected machine that is where ultimately many of the bots are being controlled. No most of the bots are being used to push fake penis pills, not push towards getting the PC fixed. If it was repair guy they wouldn't try to make the infections so hard to detect, as that makes it less likely they'll take it in to get fixed. A scary scenario was described to me by a friend in the state crime lab last time I was in the capital a few months back and we had lunch though. He said more CP scumbags are starting to learn bots so they can hide and sell their CP scum without having it on their personal machines. He predicted in a couple of years that many of their traces of CP will end up coming back to some grandma's PC that got infected with a backdoor and a couple of hidden CP folders encrypted on the drive. Nasty huh? I'm just glad the worst I've ever seen on a client's machine was one girl who I swear had dildos big enough she should have had a gun rack for the things LOL!

    --
    ACs don't waste your time replying, your posts are never seen by me.
  27. Re:We're Number 1!!! by mcgrew · · Score: 2, Funny

    what about us Micks? I haven't heard a decent Irish insult in ages!

    Ok, here you go...

    How many Irishmen does it take to screw in a lightbulb? Three. One to hold the bulb and two to drink until the room spins.

    What's a seven course meal for an Irishman? A six pack and a potato.

    If you go into a bar and hear a British accent, how do you tell if he's English, Scotch, or Irish? You wait until a fly lands in his beer. An Englishman will make a face and politely order another beer. A Scotsman will make a face, pull the fly out and keep drinking. An Irishman will pull the fly out and scream "SPIT IT OUT YOU LITTLE BASTARD!!!!"

    BTW, one of my anscestors was born in Blarney Castle. I wonder if the troll you responded to was black, or Hispanic?

  28. Re:I think you misunderstood my point, but... by hairyfeet · · Score: 1

    Hi! I just read your article, good read and follows many of the best practices I try to drum home to customers. As for CP? It is child pornography. I am friends with a buddy that runs a task force at the state crime lab. He keeps trying to recruit me because I'm good at rooting out data....but HELL NO! There ain't enough brain bleach in the world to get that crap out of your head! Like I told him "there is no way in hell I could sit calmly in that box while staring at the scum who I know for a fact was messing with his kid because I saw the pictures". No way. But he says they are already beginning to see when they trace down a source of CP instead of the source or a lead to it some poor Joe that got infected by a bug and now has a backdoor CP server running on his box via bot. Nasty.

    And sure, I'd believe some playing with them for fun, just to see how they work. For years I ran a honeypot just to see what nasties the old thing would pick up and to learn which tools did the best on cleaning it. I just meant that other than a few that are assholes (which there is ALWAYS at least one asshole in ANY job, ever notice?) that most guys are honest Joes. The PHBs on the other hand can be real jerks. The "more infections is good" attitude is seen too much at places like Worst Buy, which when I worked a shop near a Worst Buy we spent half our time cleaning up their messes. NO patches, autoupdates turned OFF, just real shitty work. Now they charge for applying iPhone updates and for "optimization" which is just removing the crapware with a script! Nice guys that bunch.

    As for doing it right? I'm an old southerner and was raised to take pride in my work and to do an honest day's work for an honest day's pay. I'm never gonna make the money a worst buy does but then again I'm not trying to push granny into a quad core either. I'd rather sleep well and know my machines will be purring like a kitten than be a douche. You're right that some customers never learn. I got a good example "Mr Brown" who is a hell of a nice guy, but know just enough to be dangerous. I'm sure you've met the type. He'll be bringing his PC over tomorrow because he decided to "clean the programs and registry for a speed boost" and borked the sound. Sigh, and of course Mr. Brown didn't bother making a restore point beforehand. But on the flip side I met a sweet gal online when I helped her through getting her pictures back after a nasty bug. We have been together for nearly 2 years now and we switch off spending weekends at each others places. This weekend she is taking time off to spend the whole week. So being a nice guy DOES pay off now and then ;-)

    And I agree on the tools, including LiveCDs and Process Explorer, although I personally prefer Comodo over AVG as it uses less resources. Another good one if you can find a download on the net is "the computer repair toolkit V2" which a bunch of FOSSies had a fit because they were actually sharing FOSS tools instead of forcing them to go to a dozen different websites (WTF?) but it is easy to update it to the latest and is a hell of a tool to have. Just drop it on a $5 4Gb flash stick and you have the tools to fix most of the major "uh ohs" like TCP/IP stack problems as well as the usual bug removal. Has all the tools for checking networks as well as being easy to add your own stuff to. Give it a try as it is a great Swiss Army Knife to carry around on your keychain. I also use Spywarebalster to automate updating the HOSTS file, as I've found that is easier to teach folks than how to manually update HOSTS or go get a new one when new nasties come out. Like I said the only bitch is I can't find a way to automate third party programs. I've found Ninite works great on initial installs, but you really have to do updates yourself. Maybe after Xmas I'll buy a subscription to Ninite and see about setting up a local server using a Ninite front end where I can just point the customers towards it and use Task Scheduler to check every week

    --
    ACs don't waste your time replying, your posts are never seen by me.
  29. Re:ALL RIGHT !! USA NUMBER 1 USA! USA! USA! USA! by sharkbiter · · Score: 1

    slmgr -rearm

  30. keep using Windows... by perles · · Score: 1

    This is the best Microsoft achievement. Keep running Windows ...