CCleaner v5

Discussion in 'other software & services' started by anon, Nov 25, 2014.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    I never actually monitored it's network traffic but after some of the last updates CCleaner is launching much longer if it's blocked by FW. This is my experience whether I use Windows FW or 3rd party (ESET, Kaspersky - IDK if they use their own filtering engine or MS' built-in).
    It seems to me that if CCleaner is starting slowly this is a good indication that it couldn't established network connections the way it tried to do.
     
  2. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Hadn't used EAM Network lockdown button before - good idea - but @stapp don't you mean the other way round, click to 'On', then 'Off' again (it is 'Off' by default)?
     
  3. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,069
    Location:
    UK
    You got me there paulderdash !! Too much green tea this morning.:D
    (By the way, when you turn the network lockdown on, EAM definition updates are programmed to be the only thing allowed through)
     
  4. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,005
    +1 (Windows FW)
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I believe it's done by using svchost.exe to bypass the firewall, I don't know why M$ has made this possible. SpyShelter gives me an alert about "Inter-process communication", never really knew that this was a security risk until it was mentioned in the WFC thread, about Adobe Reader X using the exact same method. This leads me to the conclusion that these type of apps can't be fully trusted.
     
  6. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    I somehow doubt it. CCleaner doesn't install service and AFAIK doesn't use svchost. When using ESET I get prompts for outbound request for svchost on per-service basis and create rules for specific service and not whole svchost executable. So CCleaner should abuse some system service that is allowed to connect out , but I really really doubt that this is happening.
     
  7. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    FW limitation mentioned here.
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I'm not an expert on this topic, but the way I understand it, is that these apps don't need to launch svchost.exe or need to install a service in order to use this firewall bypassing method. It seems that they can simply communicate with the already running instance of svchost.exe via interprocess communications, that's why SpyShelter alerts me about this.

    The problem is that lots of legitimate apps use IPC for all kinds of stuff, so it's difficult to say if it's used in a malicious way. So you either trust some app or not. However, I do notice that when you block CCleaner and Adobe Reader X from IPC, they still function correctly. It's also weird that I never saw this technique being mentioned on sites like Matousec back in the days.

    https://docs.microsoft.com/en-us/windows/win32/ipc/interprocess-communications
     
  9. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,069
    Location:
    UK
  10. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    The CCleaner link is temporarily unreachable from Italy.

    Immagine.jpg

    No problem with a Proxy:

    Immagine1.jpg

    Changing DNS (Quad9 ----> Clean Browsing DNS ) does not solve the problem.

     
    Last edited: Jun 23, 2020
  11. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    No problem here in Australia (using my ISP's DNS).
     
  12. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,069
    Location:
    UK
  13. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    I discovered the "problem".
    I had put Adric's rules into the Hosts file and then I forgot about it.
    This rule obviously prevents you from reaching the website:


    Code:
    0.0.0.0 www.ccleaner.com
     
  14. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    Sorry about that. I wanted a clean LiveTcpUdp log.:D You can still download directly without being blocked, which is all I needed.
     
  15. zmechys

    zmechys Registered Member

    Joined:
    Dec 29, 2012
    Posts:
    1,155
    Location:
    usa

    I have a very annoying issue with that CCleaner update.
    For years and years, I've been using CCleaner and have never encountered that kind of problem.
    After starting my computer/s, I would open CCleaner and leave it in my taskbar.
    Now, that newest update Ccleaner, SLOWS DOWN my computers!
    I cannot leave it minimized like I've done it for YEARS!
     
  16. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    same here with the portable i've been testing (the latest release).
     
  17. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    :);)
     
  18. guest

    guest Guest

    Answered: 31 popular online questions about CCleaner
    July 23, 2020
    https://www.ccleaner.com/news/blog/2020/07/23/31-popular-ccleaner-questions
     
  19. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
  20. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
  21. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    You should therefore remove the deletion of the ".sqlite-shm" and ".sqlite-wal" files from the rule "Internet Cache". It is also not necessary that these files are deleted by the rule "Internet Cache" ...
    I suppose only Avast / Piriform can do that, else 'Internet Cache' would have to be unticked which makes CCleaner a bit pointless.

    Wonder of Wise Disk Cleaner does same. :doubt:
     
  22. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    PrivaZer doesn't cause any problems here. Not sure about WDC though.
     
  23. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I have included:
    C:\Users\nnnn\AppData\RoamingFirefox\Profiles\*\*.sqlite, sqlite.shm and sqlite.wal in Options>Exclude?

    I had similar before, but for favicons only (must have been in the distant past) ... but as the man says in the Community link, 'places' uses that path / string as well - as does' webappstore', 'cookies' ...
     
  24. guest

    guest Guest

    Microsoft now detects CCleaner as a Potentially Unwanted Application
    July 29, 2020
    https://www.bleepingcomputer.com/ne...leaner-as-a-potentially-unwanted-application/
    PUA:Win32/CCleaner
     
  25. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.