SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Do you use CCleaner?
Go
New
Find
Notify
Tools
Reply
  
Do you use CCleaner? Login/Join 
probably a good thing
I don't have a cut
posted
I received this at work. I don't use CCleaner myself though.

quote:
FYI if you use CCleaner at home or otherwise.

CCleaner distribution servers were infected with malware payload.

http://blog.talosintelligence....ributes-malware.html
 
Posts: 3383 | Location: Tampa, FL | Registered: February 09, 2002Reply With QuoteReport This Post
Member
posted Hide Post
I've used CCLeaner almost religiously for decades on all may computers.
No observed problems, but I will be on the lookout.


"Crom is strong! If I die, I have to go before him, and he will ask me, 'What is the riddle of steel?' If I don't know it, he will cast me out of Valhalla and laugh at me."
 
Posts: 6641 | Registered: September 10, 2007Reply With QuoteReport This Post
Fighting the good fight
Picture of RogueJSK
posted Hide Post
Wow. Hacking anti-malware software to reconfigure it to distribute malware. Sneaky.

I do use CCleaner on occasion. Luckily, it appears that this issue only applies to folks who used version 5.33 from August 15, 2017 through September 12, 2017. I have not used CCleaner in probably 6 months or so.
 
Posts: 32509 | Location: Northwest Arkansas | Registered: January 06, 2008Reply With QuoteReport This Post
Member
posted Hide Post
Damn. I use CCleaner everyday.

Double Damn that Piriform was recently bought by Avast.




 
Posts: 4981 | Location: Arkansas | Registered: September 04, 2008Reply With QuoteReport This Post
quarter MOA visionary
Picture of smschulz
posted Hide Post
quote:
Luckily, it appears that this issue only applies to folks who used version 5.33 from August 15, 2017 through September 12, 2017.

Yeah, hopefully that is all it is.
 
Posts: 22909 | Location: Houston, TX | Registered: June 11, 2006Reply With QuoteReport This Post
wishing we
were congress
posted Hide Post
problem verified by Piriform

https://www.piriform.com/news/...32-bit-windows-users

Security Notification for CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 for 32-bit Windows users


I use CCleaner but on a 64 bit system
 
Posts: 19576 | Registered: July 21, 2002Reply With QuoteReport This Post
Member
Picture of SIG 229R
posted Hide Post
Seeing this tells me in no uncertain terms "uninstall" immediately if not sooner. I have enough problems with out adding any more.


SigP229R
Harry Callahan "A man has got to know his limitations".
Teddy Roosevelt "Talk soft carry a big stick"
I Cor10: 13 "1611KJV"
 
Posts: 6066 | Registered: March 04, 2007Reply With QuoteReport This Post
Fighting the good fight
Picture of RogueJSK
posted Hide Post
quote:
Originally posted by sdy:
Security Notification for CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 for 32-bit Windows users


I use CCleaner but on a 64 bit system


Oh, good. Mine's 64 bit too.
 
Posts: 32509 | Location: Northwest Arkansas | Registered: January 06, 2008Reply With QuoteReport This Post
Member
posted Hide Post
Fwiw, 64-bit here and Malwarebytes caught the Trojan.

Immunet confirms it's cleaned.


***************************
Knowing more by accident than on purpose.
 
Posts: 14186 | Location: Tampa, Florida | Registered: December 12, 2003Reply With QuoteReport This Post
Member
posted Hide Post
I am also using Malwarebytes, so maybe that saved me.


"Crom is strong! If I die, I have to go before him, and he will ask me, 'What is the riddle of steel?' If I don't know it, he will cast me out of Valhalla and laugh at me."
 
Posts: 6641 | Registered: September 10, 2007Reply With QuoteReport This Post
Member
posted Hide Post
Give it a scan, Crom. Just in case.

I'm using the free version and the scan caught it.

Heck, I'm scanning it again!


***************************
Knowing more by accident than on purpose.
 
Posts: 14186 | Location: Tampa, Florida | Registered: December 12, 2003Reply With QuoteReport This Post
Chip away the stone
Picture of rusbro
posted Hide Post
Wow. I use Ccleaner only a handful of times a year, and I happened to use the exact version (5.33.6162) on 9/11 on two important machines, to free space on C drives. Fortunately they're 64 bit. I'm surprised 64 bit machines were apparently not impacted.

My registries look fine, no attempted connections to the mentioned IPs in our firewall, no file hash match.
 
Posts: 11597 | Registered: August 22, 2008Reply With QuoteReport This Post
Chip away the stone
Picture of rusbro
posted Hide Post
quote:
Originally posted by jehzsa:
Give it a scan, Crom. Just in case.

I'm using the free version and the scan caught it.

Heck, I'm scanning it again!


Oh my. I will run MBAM and Immunet this evening.
 
Posts: 11597 | Registered: August 22, 2008Reply With QuoteReport This Post
wishing we
were congress
posted Hide Post
just to be sure I checked my Registry Key

I am clean

details:

https://www.bleepingcomputer.c...w-and-how-to-remove/
 
Posts: 19576 | Registered: July 21, 2002Reply With QuoteReport This Post
Member
posted Hide Post
Re-scanned using Malwarebytes and Immunet. Came clear. Also checked the Registry Key. Nothing there.

I recall that when Malwarebytes was going through the Registry the Floxif/trojan threat was detected. Yes, like watching paint dry.

Again, don't assume that 64-bits are not infected. Mine was.


***************************
Knowing more by accident than on purpose.
 
Posts: 14186 | Location: Tampa, Florida | Registered: December 12, 2003Reply With QuoteReport This Post
The 2nd guarantees the 1st
Picture of fiasconva
posted Hide Post
My thread was locked but I downloaded latest version of Malware and ran a scan too. Nothing there. Whew!



"Even if the world were perfect it wouldn't be." ... Yogi Berra
 
Posts: 1866 | Location: York County, VA | Registered: August 25, 2007Reply With QuoteReport This Post
For real?
Picture of Chowser
posted Hide Post
Crap. I will have to check the computers at work when I go back. Thankfully all my home stuff haa been 64bit for awhilw.



Not minority enough!
 
Posts: 8020 | Location: Cleveland, OH | Registered: August 09, 2007Reply With QuoteReport This Post
Chip away the stone
Picture of rusbro
posted Hide Post
Malwarebytes identified the CCleaner installer itself (in the trash bin), and a file in the Google Chrome cache on my two 64-machines, but no actual infection.
 
Posts: 11597 | Registered: August 22, 2008Reply With QuoteReport This Post
  Powered by Social Strata  
 

SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Do you use CCleaner?

© SIGforum 2024