Security Notification for CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 for 32-bit Windows users

Discussion in 'other security issues & news' started by stapp, Sep 18, 2017.

  1. Theblackstar

    Theblackstar Registered Member

    Joined:
    Mar 27, 2016
    Posts:
    36
    Location:
    Italia
    A screenshot with details (data column), please?
     
  2. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,099
    Location:
    UK
    Vik from Avast said..

    https://forum.avast.com/index.php?topic=208612.msg1421249#msg1421249
     
  3. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,099
    Location:
    UK
    https://blog.avast.com/update-to-th...alposts_us&utm_source=twitter&utm_medium=post

     
  4. PEllis

    PEllis Guest

    I remember I installed CCleaner recently for temporary use. I did scan with RogueKiller Anti-Malware free and it only detected unrelated PUPs. So I should be all good?

    Edit: Nevermind, I saw the posts above.
     
  5. Theblackstar

    Theblackstar Registered Member

    Joined:
    Mar 27, 2016
    Posts:
    36
    Location:
    Italia
  6. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,008
  7. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    They had to release new version before they took down CnC infrastructure so they couldn't make it public ATM. At least I understand it that way from their announcement.
     
  8. mekelek

    mekelek Registered Member

    Joined:
    May 5, 2017
    Posts:
    518
    Location:
    Hungary
    i would do a NPE scan just for the sake of being sure, NPE can find a lot of weird nasty ****.
     
  9. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    I hope that they are right and that they have enough data to be sure of it.
     
  10. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    If you mean Norton Power Eraser - Major PASS! Way to dangerous! Can and has removed important Windows files resulting in a non-booting paperweight.
     
  11. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Lol, aand potentially with a backdoor on it too :D
     
  12. mekelek

    mekelek Registered Member

    Joined:
    May 5, 2017
    Posts:
    518
    Location:
    Hungary
    nobody said you should blindly delete everything NPE flags dangerous, but it's good to see maybe something you missed...
     
  13. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Mmm, maybe something YOU missed. I won't use it, period! I've seen the results = a completely crippled machine. No thanks.
     
  14. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
  15. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    Yes, that's all. If you've updated to the new version of CCleaner, you don't have to do anything. When you update, the malicious version of CCleaner get replaced with a clean version.
     
  16. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,064
    Location:
    Texas
    Avast opens up about CCleaner hack and outlines how it will protect users

     
  17. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen
    Better solution would be to restore a system image previous the infected CCleaner version. Well.... but do we have the assurance that all previous CCleaner version weren't infected ?
     
  18. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Yes and other software from Piriform can be questioned also. As long as they don't find out how this happened everything is possible.
     
  19. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I have Windows x64 and (now) CCleaner 5.34 - and up-to-date CCleaner Cloud(!) - and do not have the HKLM\SOFTWARE\Piriform\Agomo key.

    But MB3 scan now picks up the following threats:

    Registry Key: 1
    Trojan.Floxif.Trace, HKLM\SOFTWARE\WOW6432NODE\PIRIFORM\AGOMO

    Registry Value: 1
    Trojan.Floxif.Trace, HKLM\SOFTWARE\WOW6432NODE\PIRIFORM\AGOMO|TCID


    But these appear to be related to CCleaner Cloud (previously Agomo) account, because after quarantining these, I had to re-sign in to my account, so I suspect these may be FPs.

    I may now remove CCleaner Cloud, but I quite like how it informs one of all installs e.g. silent Microsoft OneNote updates. But given recent events here, I am now wary of data sent out.
     
    Last edited: Sep 19, 2017
  20. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Thinking that if you would otherwise still want to use CC Cleaner you should copy and paste your post on The MB Forums (maybe try False Positives) before you jump ship.

    https://forums.malwarebytes.com/forum/40-malwarebytes-for-home-support/
     
  21. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    On my Windows 8.1 x64/Windows 10 x64 machine I don't see these reg keys even I run multiple times the floxified version in the past days.
     
  22. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    I'll wait for Piriform/Avast researchers for more infos. Thanks.
     
  23. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    But you probably do not have CCleaner Cloud (initially called Agomo) installed, which I think is responsible for those keys.
     
  24. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    AFAIK it affected 32 bit only.
     
  25. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Nope, backdoored CCleaner.exe created those keys (also). I've tested it in VM with regular 5.33 desktop installation.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.