Paul D
Member
Posts: 106
Former World Start Member: Yes
World Start Name: Paul D
|
Post by Paul D on Sept 18, 2017 11:59:23 GMT -5
uk.finance.yahoo.com/news/hackers-compromised-ccleaner-free-software-avasts-piriform-says-084009922--finance.htmlSAN FRANCISCO (Reuters) - Hackers broke into British company Piriform's free software for optimising computer performance last month potentially allowing them to control the devices of more than two million users, the company and independent researchers said on Monday. The malicious program was slipped into legitimate software called CCleaner, which is downloaded for personal computers and Android phones as often as five million times a week. It cleans up junk programs and advertising cookies to speed up devices. CCleaner is the main product made by London's Piriform, which was bought in July by Prague-based Avast, one of the world’s largest computer security vendors. At the time of the acquisition, the company said 130 million people used CCleaner... In a blog post, Piriform confirmed that two programs released in August were compromised. It advised users of CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 to download new versions. A spokeswoman said that 2.27 million users had downloaded the August version of CCleaner while only 5,000 users had installed the compromised version of CCleaner Cloud. Note that the current version (5.34.6207) is OK
|
|
|
Post by jholland1964 on Sept 18, 2017 13:00:38 GMT -5
Thanks for the heads up Paul. I have the latest version so all is good and I had not updated it all summer so I was running a version from early June. Thanks!
|
|
|
Post by sheila on Sept 18, 2017 18:44:49 GMT -5
Thank you, Paul. "Big Toe" gave a reminder that there was an update - which I did. I guess I am safe. Thanks again.
Sheila
|
|
sozo777
Member
Posts: 110
Former World Start Member: Yes
World Start Name: ralphie
|
Post by sozo777 on Sept 19, 2017 9:22:48 GMT -5
Thank YOU Paul! I did a MWBytes scan and it found the Trojan.Floxif via CCleaner I am assuming. MWBytes quarantined this, but is it sufficient in the complete removal other than also installing an updated version from 5.33? I'm wondering if this may have been what caused the AVIRA Blue Screen SYSTEM_SERVICE_EXCEPTION Error we attempted to repair with JHolland? (see screenshot) Advise please. Best, Raphael Attachments:
|
|
|
Post by bigbarney on Sept 21, 2017 5:46:44 GMT -5
I got exactly the same thing after updating CCleaner.
|
|
|
Post by jholland1964 on Sept 21, 2017 8:09:24 GMT -5
I got exactly the same thing after updating CCleaner. I am finding your post very confusing. You got this infection with the brand new version just released? ? The compromised version, v5.33.6162, was released in August and according to their information that version is no longer even available for download on their web site at all. Where did you get your new version?? The ONLY place to get the program is directly from piriform. They have released two new versions since this hacking happened, first one was v. 5.34.6207 and the newest version v. 5.35.6210 just released, it was thought both were clean Since you just found the infection with the new install then you need to report this to Piriform because that indicates their problems are not over.
|
|
sozo777
Member
Posts: 110
Former World Start Member: Yes
World Start Name: ralphie
|
Post by sozo777 on Sept 21, 2017 9:28:06 GMT -5
FWIW I received a warning window from Avira last night running version v. 5.34.6207 and I updated to this version from Filehippo 15.0.31.27 just released and i haven't detected anything further. filehippo.com/download_avira I did send this along to Avira - virus@avira.com Attachments:
|
|
|
Post by budgall on Sept 21, 2017 18:46:13 GMT -5
Software should only be downloaded from the developers web site if possible to lessen the chance of also downloading unwanted programs.
I thought you gave up on Avira per a prior thread
|
|
sozo777
Member
Posts: 110
Former World Start Member: Yes
World Start Name: ralphie
|
Post by sozo777 on Sept 21, 2017 20:15:38 GMT -5
Software should only be downloaded from the developers web site if possible to lessen the chance of also downloading unwanted programs. I thought you gave up on Avira per a prior thread Thank You! it's on a different computer..the prior was a HP desktop that had the Blue Screen Error and Avira issues. I have MSE on the desktop now. I was wondering if this trojan might have been what caused the Avira issue? I say that because I'm nearly certain I had the version that was suspect..Which Judy said there were two updated versions since then cause apparently there were still some issues and Piriform had more work to do.`
|
|
|
Post by budgall on Sept 21, 2017 21:47:34 GMT -5
Software should only be downloaded from the developers web site if possible to lessen the chance of also downloading unwanted programs. I thought you gave up on Avira per a prior thread Thank You! it's on a different computer..the prior was a HP desktop that had the Blue Screen Error and Avira issues. I have MSE on the desktop now. I was wondering if this trojan might have been what caused the Avira issue? I say that because I'm nearly certain I had the version that was suspect..Which Judy said there were two updated versions since then cause apparently there were still some issues and Piriform had more work to do.` It might have been, but I don't think we will ever know for sure.
|
|
|
Post by bigbarney on Sept 22, 2017 3:26:53 GMT -5
I got exactly the same thing after updating CCleaner. I am finding your post very confusing. You got this infection with the brand new version just released? ? The compromised version, v5.33.6162, was released in August and according to their information that version is no longer even available for download on their web site at all. Where did you get your new version?? The ONLY place to get the program is directly from piriform. They have released two new versions since this hacking happened, first one was v. 5.34.6207 and the newest version v. 5.35.6210 just released, it was thought both were clean Since you just found the infection with the new install then you need to report this to Piriform because that indicates their problems are not over. I updated CCleaner to version 5.35.6210 from within itself and then ran MBAM.The infection could have been there before I updated CCleaner.
|
|
|
Post by jholland1964 on Sept 22, 2017 7:44:09 GMT -5
I updated CCleaner to version 5.35.6210 from within itself and then ran MBAM.The infection could have been there before I updated CCleaner. Thanks for that information. The removed item came from your Downloads folder and shows that it was the CC_Set Up file. Since it came from the Downloads folder I would feel very comfortable saying that it was the set-up file for compromised version, v5.33.6162 and NOT v. 5.34.6207 or v. 5.35.6210. According to all I have read your original install of v. 5.34.6207 definitely would have removed the installed compromised v5.33.6162 and the Trojan but the downloaded set up file would have remained in the downloads folder until deleted by you or removed by something like MBA-M. The set up file had to have been opened and run in order to have infected the computer. So that shows that the two versions released AFTER that compromised version are good as have been noted in all articles that followed following the finding of the original problem. I have found NO mentions anywhere of the two new versions having problems. The v. 5.34.6207 release absolutely DID fix the compromised version and also had very normal added fixes for Browser Cleaning: Firefox: Internet History cleaning rule no longer removes Favicon content. General: Minor GUI improvements. Minor bug fixes. The release of v. 5.35.6210 was done only because All builds signed with new Digital Signatures. No other changes were done or needed. BOTH the newly released versions since the hack are 100% Clean. This happening to you is one of the main reasons that I never keep the downloaded install/set up files for any programs. Once I have installed them I delete that downloaded install file. If I need to uninstall a program for some reason and install a new copy I Always go to the home page of the program and download I brand new copy of the install/set up file. You actually could have mistakenly used that old file and installed the Trojan onto your computer. Dump the install files once you have used them.
|
|
|
Post by jholland1964 on Sept 22, 2017 20:33:21 GMT -5
|
|
bigtoe
Member
Posts: 111
Former World Start Member: Yes
World Start Name: BigToe
|
Post by bigtoe on Sept 22, 2017 21:55:59 GMT -5
Not to beat a dead horse, but another history/accounting on the CCleaner situation that is believed to be an “insider” or “saboteur” action ... Ask Bob Rankin vigilance reminder
|
|