[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y ] [Home]
4chanarchives logo
So apparently a website that i frequent often (news related,
Images are sometimes not shown due to bandwidth/network limitations. Refreshing the page usually helps.

You are currently reading a thread in /g/ - Technology

Thread replies: 22
Thread images: 4
File: what.jpg (20 KB, 400x265) Image search: [Google]
what.jpg
20 KB, 400x265
So apparently a website that i frequent often (news related, called 20 minutes) got "attacked" and a malware called Gozi (a trojan) was spead through a flash vulnerability (as usual, it's always fucking flash).

How do i know i'm infected, and if it's the case will a standard format get rid of it ?
>>
h-hello
>>
How 2 google

https://storify.com/bbddst/instructions-to-completely-remove-gozi-trojan-hors

ask in /wsr/ or /sqt/ next time.
>>
>>53930591
>https://storify.com/bbddst/instructions-to-completely-remove-gozi-trojan-hors

I did Google it, of course, and read through 6 pages of content and description of that specific Trojan but ive found nothing ending in .exe in %UserProfile%\, or any strange process running.

I think i'm becoming paranoiac because of these fucking retards that can't protect their website correctly. I will clean format.
>>
Gopferteckel, me holt sich sini news au ned bi 20minute.
>>
>>53930633
What ?
>>
>>53930633
Speaking nazi outta nowhere
>>
>>53930451
Option 1: netstat and look for unknown foreign connections

Option 2: Wireshark; view traffic going to foreign connections you don't know anything about; look out especially for DNS providers(i.e duckdns, No-IP, etc)

Option 3: Process hacker; look for any suspicious software installed that has a callback address
>>
>>53930648
Kek
>>
>>53930651
Thanks. If anything comes positive out of these inspections i suppose the logical next step would be format right ?
>>
>>53930752
Not really
Most trojans install a file to make sure there is a constant re-connection

If you DO find something; save what you found, turn off wifi, and look through your /tmp folders. Look specifically at the file extensions
>>
>>53930451
>using Flash
You deserve it.
>>
File: laughing.png (353 KB, 613x495) Image search: [Google]
laughing.png
353 KB, 613x495
>>53930821
kekd
>>
>>53930821
This right here, nigger
>>
>>53930821
I don't use Flash. In fact, i never saw a single flash element on that specific website.

I'm giving up. I've found nothing manually, and even then my knowledge is limited. That being said based on what i saw on the Gozi virus it shouldn't be able to replicate, therefore a format should be enough.
>>
File: confused.png (316 KB, 604x344) Image search: [Google]
confused.png
316 KB, 604x344
>>53930837
>needing to format because of a trojan

That's like saying you need to evacuate a city because some faggot's oven is on fire
>>
>>53930854
Yeah. Big deal. I have virtually nothing to back-up, everything remotely important is on cloud, and nowadays a clean format is done in five to ten minutes flat.
>>
>>53930868
The only PLAUSIBLE excuse for a format would be a rootkit
>>
Everyone knows spaniards are incompetent when it comes to tech
>>
File: 1460093537634.gif (75 KB, 268x198) Image search: [Google]
1460093537634.gif
75 KB, 268x198
>>53930868
> on the cloud
>>
>>53930837
Classic person that uses AV. I'd try common sense first.
>>
>>53930451
>20 minutes
you should kill yourself
Thread replies: 22
Thread images: 4

banner
banner
[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y] [Home]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
If a post contains personal/copyrighted/illegal content you can contact me at [email protected] with that post and thread number and it will be removed as soon as possible.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com, send takedown notices to them.
This is a 4chan archive - all of the content originated from them. If you need IP information for a Poster - you need to contact them. This website shows only archived content.