GB HOMEPAGE

Malware Hits PC Cleanup Tool CCleaner

Posted By: Donald

Malware Hits PC Cleanup Tool CCleaner - 09/19/17 02:15 AM

Malware Hits PC Cleanup Tool CCleaner

Malware Hits PC Cleanup Tool CCleaner
Posted By: Jenny100

Re: Malware Hits PC Cleanup Tool CCleaner - 09/19/17 03:48 AM


Or from ***Reuters***
Originally Posted By: Reuters
A version of CCleaner downloaded in August and September included remote administration tools that tried to connect to several unregistered web pages, presumably to download additional unauthorized programs, security researchers at Cisco’s Talos unit said.

Originally Posted By: Reuters
In a blog post, Piriform confirmed that two programs released in August were compromised. It advised users of CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 to download new versions.

So if you have version 5.33.6162 of CCleaner, uninstall it and run antivirus or an antimalware program like Malware Bytes. You'd only have gotten it if you downloaded in August or early September. Piriform has a new version up for download now.

Originally Posted By: Reuters
Piriform said that Avast, its new parent company, had uncovered the attacks on Sept. 12. A new, uncompromised version of CCleaner was released the same day and a clean version of CCleaner Cloud was released on Sept. 15, it said.

Originally Posted By: Reuters
CCleaner does not update automatically, so those who installed the problematic version will need to delete it and install a fresh version, he said.

He also recommended running an antivirus scan.

Williams said that Talos detected the issue at an early stage, when the hackers appeared to be collecting information from infected machines, rather than forcing them to install new programs.
Posted By: Uncle Reg

Re: Malware Hits PC Cleanup Tool CCleaner - 09/19/17 05:24 AM


According to How-To Geek it was only the 32 bit version of 5.33.6162 that was affected. Read about it here.

If you have 64 bit Windows, CCleaner installs its 64 bit version. Right-click on the CCleaner shortcut and select Properties. If it says "C:\Program Files\CCleaner\CCleaner64.exe", then you have the 64 bit version.
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/19/17 06:18 AM

When I tried to update to V5.34, my AV said it caught a trojan. Will check into this more tomorrow.
Posted By: Mad

Re: Malware Hits PC Cleanup Tool CCleaner - 09/19/17 10:32 AM

I already have version 5.34 and there's been no sign of any malware or virus.

[I run Win7 Enterprise 64-bit.]
Posted By: Winfrey

Re: Malware Hits PC Cleanup Tool CCleaner - 09/19/17 10:59 PM

I'm not updating till this is figured out...
Posted By: Jenny100

Re: Malware Hits PC Cleanup Tool CCleaner - 09/19/17 11:49 PM

Originally Posted By: Winfrey
I'm not updating till this is figured out...

What version do you have?
If you have an earlier version than version 5.33 you are fine.
If you have version 5.33 you should get rid of it.
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/19/17 11:57 PM

Yes... what Jenny said. Get v.5.34 ASAP. The problem is NOT getting it. I kept being sent to File Hippo when I tried to update through the application. So I went to the Piriform website and downloaded 5.34 from there with no problems. No alerts from Defender about the trojan.
Posted By: Winfrey

Re: Malware Hits PC Cleanup Tool CCleaner - 09/20/17 03:01 AM

Downloaded 5.34 :-)
Posted By: JKEerie

Re: Malware Hits PC Cleanup Tool CCleaner - 09/20/17 09:33 PM

My Webroot antivirus caught the Trojan in CCLeaner. At first I thought it was a false positive, but it was pretty adamant. I went online and found the article and updated right away to 5.34. BTW...I have 64 bit and the virus was there.

CCleaner updates so much, I usually skip a few. Guess I got unlucky on the one I chose. smirk
Posted By: Mad

Re: Malware Hits PC Cleanup Tool CCleaner - 09/21/17 08:09 PM

How odd that you got it, JKEerie !!

I have Win7 64-bit and have used every CCleaner update without any problems whatsoever ....

EDIT :

Just received an "auto" download for CCleaner to version 5.35 !! So maybe 5.34 had a problem woozy
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/21/17 10:02 PM

My Windows Defender picked it up right away too. Mad, if you used a version before 5.34 to clean your computer and your anti-virus didn't pick it up, you were mostly likely a victim and wouldn't know it.
Posted By: Winfrey

Re: Malware Hits PC Cleanup Tool CCleaner - 09/22/17 12:09 AM

Even if your version was like 5.28
Posted By: JKEerie

Re: Malware Hits PC Cleanup Tool CCleaner - 09/22/17 05:56 AM

Hi Mad! Apparently, some 64 bit systems were potentially impacted via a secondary payload. Fortunately, that How to Geek article showed a way to look into your registry to see if you were potentially infected. I did so and don't have the key indicator.

Between this and the Equifax debacle, I'm feeling less and less secure these days! confused
Posted By: Mad

Re: Malware Hits PC Cleanup Tool CCleaner - 09/22/17 07:31 AM

Well I run Norton scans on a regular basis and throw in a Malwarebytes quite often also and neither have sounded any alarms.

I'll get my Son in Law to do a registry check for anything offensive but I'm pretty sure my machine is clean yes
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/22/17 03:26 PM

This particular malware didn't install any malicious programs or spyware on your computer - it collected information and then got out. The registry check is a good idea. I did it and was relieve to find I didn't have it either because I'm pretty sure I ran the previous version about a month ago.

Info about the registry entry to look for. https://www.ghacks.net/2017/09/21/ccleaner-malware-second-payload-discovered/


JK, the Equifax debacle is bad enough, but how they handled it just makes me furious.
Posted By: Jenny100

Re: Malware Hits PC Cleanup Tool CCleaner - 09/22/17 04:16 PM

Originally Posted By: Winfrey
Even if your version was like 5.28

No, only version 5.33 was infected.
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/22/17 05:27 PM

Yes, only 5.33 as Jenny said. Sorry, I missed that post.
Posted By: JKEerie

Re: Malware Hits PC Cleanup Tool CCleaner - 09/22/17 05:47 PM

I agree with you there, Drac, regarding Equifax. I ended up with the notification that my info was compromised, so I froze my credit. I already had alerts on as part of my ID theft protection through AARP. Still...we're supposed to be able to trust companies, banks, software providers, etc to have adequate security measures in place to keep us "safe." I don't think that is possible anymore and we all need to be very vigilant.
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/22/17 07:08 PM

Yup... Reading through the timeline of this breach is just mind-boggling. The hackers were wandering around in their system for months before they found it.
Posted By: Creeping_Doom

Re: Malware Hits PC Cleanup Tool CCleaner - 09/23/17 02:50 AM

Originally Posted By: Draclvr
This particular malware didn't install any malicious programs or spyware on your computer - it collected information and then got out. The registry check is a good idea. I did it and was relieve to find I didn't have it either because I'm pretty sure I ran the previous version about a month ago.

Info about the registry entry to look for. https://www.ghacks.net/2017/09/21/ccleaner-malware-second-payload-discovered/


JK, the Equifax debacle is bad enough, but how they handled it just makes me furious.


Wouldn't be at all surprised if Equifax is basically history after this mess . By the way Drac , just in case you had not known , Avast purchased Piriform some time ago , so , Ccleaner is an Avast tool now .
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/23/17 04:01 AM

Yes, I know about Piriform being purchased by Avast - was very disappointed to hear it.
Posted By: Jenny100

Re: Malware Hits PC Cleanup Tool CCleaner - 09/23/17 05:10 PM

There are now reports that the CCleaner breach was part of a targeted attack.
https://www.wired.com/story/ccleaner-malware-targeted-tech-firms/

Some people believe that reformatting and restoring from a backup is the only way to be sure there isn't a lingering infection. Here's what Cisco's Talos Intelligence posted about it.
http://blog.talosintelligence.com/2017/09/ccleaner-c2-concern.html

Quote:
These new findings raise our level of concern about these events, as elements of our research point towards a possible unknown, sophisticated actor. These findings also support and reinforce our previous recommendation that those impacted by this supply chain attack should not simply remove the affected version of CCleaner or update to the latest version, but should restore from backups or reimage systems to ensure that they completely remove not only the backdoored version of CCleaner but also any other malware that may be resident on the system.

and discussions at slashdot, including why 32-bit computers were targeted (more apt to be old business machines).
https://it.slashdot.org/story/17/09/21/1...ific-tech-firms

I don't plan on recommending CCleaner anymore, unless they already have an old version they downloaded months ago and none of the improvements listed in the version history apply to them.
https://www.piriform.com/ccleaner/version-history

I didn't realize Avast had bought Piriform (on July 2017 according to Wikipedia), though that alone wouldn't make me avoid CCleaner. I can't find any info on how CCleaner v5.33 was infected. If it was an inside job by an employee, it could happen again.

+_+_+_+_+_+_+_+_+

Equifax hired a music major as chief security officer
http://www.marketwatch.com/story/equifax...icer-2017-09-15

Equifax set up a website that was supposed to tell you if you were "potentially" affected at
https://www.equifaxsecurity2017.com
However people have reported getting conflicting results -- sometimes it says yes, sometimes no for the same individual. It's been suggested this site is just a way to get people to enroll in their credit monitoring service, which may be "free" at the moment but will start charging later, attempting to profit after the breach.
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/23/17 07:40 PM

Very troubling news about CCleaner...

Signing up for the Equifax free credit monitoring also includes signing away your rights to joining a class action lawsuit in the future. They are REALLY getting slammed for that.
Posted By: Mad

Re: Malware Hits PC Cleanup Tool CCleaner - 09/24/17 04:38 PM

Originally Posted By: Draclvr
My Windows Defender picked it up right away too. Mad, if you used a version before 5.34 to clean your computer and your anti-virus didn't pick it up, you were mostly likely a victim and wouldn't know it.


Being an ignoramus, Draclvr rolleyes

Is Windows Defender used on other Windows versions than Win10 ??
Posted By: Marian

Re: Malware Hits PC Cleanup Tool CCleaner - 09/24/17 04:46 PM

I think Windows Defender started with Vista - and supports every operating system since. It's on my Windows 7 computer.
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/24/17 05:42 PM

Windows Defender on versions previous to Windows 8 was more of an anti-spam program. Starting with Windows 8, it was a full-fledged anti-virus program, albeit not a very good one. It replaced the old Microsoft Security Essentials. It has slowly been improved greatly, but I'm not sure where it stands with the paid anti-virus programs now. It used to rank towards the middle or lower. I really like using it with Malwarebytes Pro.
Posted By: Mad

Re: Malware Hits PC Cleanup Tool CCleaner - 09/24/17 06:07 PM

Thanks for that info, Marian and Draclvr smile

EDIT :

My Son in Law kindly checked the registry on my Win7 machine for me, and, as we both fully expected, there were no aliens present !! laugh

I have every confidence in my "Norton and Malwarebytes" security combination yes
Posted By: Mad

Re: Malware Hits PC Cleanup Tool CCleaner - 09/25/17 09:34 PM

Well reading through this thread again, no one actually seems to have suffered a successful attack thumbsup
Posted By: Draclvr

Re: Malware Hits PC Cleanup Tool CCleaner - 09/25/17 10:43 PM

So far, so good anyway! That's always good news!
© 2024 GameBoomers Community