Con-ficker botnet.

    First. not sure if this is the correct forum but its the closest i saw.

    Yes we know its out there. yes we know there is a patch. Yes we know what to do when something is infected..

    question is. I have a large area network here of many comptuers. is there any way to detect this botnet within the network insted of packet inspection? doing packet filtering on this network. live filtering of every packet would cost a few thousand and is not in the works yet.

    any other ideas on how this can be done??????
    random ideas are good to play with here. as im just part of a team here working on some things with it.......
