18 ms·
Malware identified in CCleaner 5.33
- bobsoap 9y ago"CCleanup" appears to be a wordplay on "cleaning up CCleaner", but it's confusing and unnecessary. Even though the original article is named that way, I propose changing the thread title to the proper, well-known application name, CCleaner.
- nekopa 9y agoAlso "A vast" - a play on Avast.
- user5994461 9y agoInstaller neither on your system. They do more harm than good.
- pbhjpbhj 9y agoAny proof?
- lightedman 9y agohttps://www.google.com/search?q=ccleaner+broke+my+computer&ie=utf-8&oe=utf-8 https://www.google.com/search?q=ccleaner+broke+my+computer&i... Two seconds to type four words into the search bar.
- pbhjpbhj 9y agoThat doesn't prove the parents contention which was "they do more harm than good". They presumably have something they've based that opinion on other than the existence of problems with a particular app - if you don't have anything substantive to add then please keep your "lm[f]gtfy, lolz" type comments to yourself, thanks.
- user5994461 9y agoThe opinion is based on the broken computers and applications that happen after running CCleaner. That software basically go through your computer and delete a ton of things that it considers useless. Have you ever seen the defaults settings? For instance, it used to delete the history, cache and settings from all major browsers.
- kronos29296 9y agoJust Wow. I am happy now that I haven't updated my installation of ccleaner for over a year and so I am safe.
- agumonkey 9y agoMe too, good that their update isn't convenient.. for once. Still at 5.31. Gotta check other computers though, and smartphones.
- romanovcode 9y agoI'm happy I'm not using Windows XP so I don't need this crapware anymore because Windows10 runs fast w/o it.
- fbouynot 9y agoWell, if you're about to use Malwarebytes / Rogue Killer / ZHP Cleaner, you will win hours by cleaning all these temporary files before a scan.
- lightedman 9y agoI never needed this kind of software while running Windows XP. Protip: Quit installing more than you need.
- jccalhoun 9y agoI still run it occasionally on my windows 10 laptop which has a small ssd for the main drive.
- vels 9y agoWhat can be done on machines that have a new install of CCleaner - Is there a patch available ? Also does this effect the Mac OSX version of CCleaner or just the windows version ?
- csydas 9y agoEdit: Updating with their release blogpost instead, as it's clearer: Release Post: http://www.piriform.com/news/release-announcements/2017/9/18/security-notification-for-ccleaner-v5336162-and-ccleaner-cloud-v1073191-for-32-bit-windows-users http://www.piriform.com/news/release-announcements/2017/9/18... Affected Versions: >This compromise only affected customers with the 32-bit version of the v5.33.6162 of CCleaner and the v1.07.3191 of CCleaner Cloud. No other Piriform or CCleaner products were affected. We encourage all users of the 32-bit version of CCleaner v5.33.6162 to download v5.34 here: download. We apologize and are taking extra measures to ensure this does not happen again. macOS seems fine, it looks like it was their 32bit Windows/Cloud offerings: http://www.piriform.com/news/blog/2017/9/18/security-notification-for-ccleaner-v5336162-and-ccleaner-cloud-v1073191-for-32-bit-windows-users http://www.piriform.com/news/blog/2017/9/18/security-notific... >Before delving into the technical details, let me say that the threat has now been resolved in the sense that the rogue server is down, other potential servers are out of the control of the attacker, and we’re moving all existing CCleaner v5.33.6162 users to the latest version. Users of CCleaner Cloud version 1.07.3191 have received an automatic update. In other words, to the best of our knowledge, we were able to disarm the threat before it was able to do any harm. So if you have a Windows copy, look for a patch I guess. Seems like it's not just fixed, but the rogue server taken down.
- ameyv 9y agoUninstalling CCleaner and formatting now.
- deleted 9y ago[deleted]
- dan1234 9y agoNot much point in uninstalling if you're going to format anyway.
- RationPhantoms 9y agoIt's the software equivalent of a double tap.
- princekolt 9y agoThere has been a number of cases of installers from trusted developers being infected lately. (For example Transmission being infected twice...) On our side (developers) we need to be careful with this idea that "we will know" when something is wrong and be more careful when deploying software. It would also be nice if some form of tool could be used to test a binary to make sure it only contains what it should contain (sort of a whitelist of symbol names compared to the source files, idk...) I'm sure something along these lines probably exists for some different purpose.
- westoque 9y agoBinary analysis for each software you install might be too cumbersome for most developers. I suggest you use something like "Little Snitch" for mac which warns you when software makes inside/outside connections. It might not be the best, but it's definitely something that works to mitigate some hacks.
- princekolt 9y agoThing is, you can't even trust little snitch these days[1] :( At least a binary check after compilation+signing (by the developer) should improve security a little bit. [1]: https://objective-see.com/blog/blog_0x21.html https://objective-see.com/blog/blog_0x21.html
- corv 9y agoI like to compliment Little Snitch with XFence (formerly known as Little Flocker). You can think of it as a firewall for your filesystem and devices.
- danieldk 9y agoI use Little Snitch too. I had a Little Flocker license, but the rules were quite painful to maintain. Especially if you are also using the Terminal and command-line apps.
- mollusk 9y ago>Transmission being infected twice Could you please elaborate? I only recall one instance of compromised Transmission installer.
- deleted 9y ago[deleted]
- jcims 9y agoIncredible write-up.
- tekni5 9y agoSo it was only the 32-bit executable that was affected? By default CCleaner installs both the 32-bit and 64-bit versions, however on 64-bit systems it only runs the 64-bit executable and points every shortcut it makes to the 64-bit executable. On one of my affected systems that appears to have had 5.33 installed, I noticed no registry keys that appear to be created and that system never ran the 32-bit executable. Would it be safe to assume it's not affected and simply uninstalling CCleaner 5.33 is enough? Piriform seems to suggest that only some useless system information was ever released by the compromised version. The general worry is that it wasn't just that information, but also other more important things like account logins and such.
- nothrabannosir 9y ago> Would it be safe to assume it's not affected Well, it would be many things, but it wouldn't be "safe". Not a tinfoiler, just a pedant :) I could go with "reasonable".
- giancarlostoro 9y agoAccording to: https://news.ycombinator.com/item?id=15274517 https://news.ycombinator.com/item?id=15274517 This blog post from Piriform has more details: http://www.piriform.com/news/release-announcements/2017/9/18/security-notification-for-ccleaner-v5336162-and-ccleaner-cloud-v1073191-for-32-bit-windows-users http://www.piriform.com/news/release-announcements/2017/9/18... Basically they believe it was only the 32-bit installer that was compromised.
- r1ch 9y agoI wish there was more technical information, even the advisory is unclear here. The CCleaner installer is always 32 bit for compatibility - it installs both 32 bit and 64 bit program binaries. On 64 bit systems, the default shortcuts are to the 64 bit binary. So was the 32 bit installer compromised, or only the 32 bit binary? The original advisory makes references to the installer which is quite confusing. Tried to figure it out myself but I assume the loader has VM detection techniques as I wasn't able to infect a VM.
- 9y ago
- happy-go-lucky 9y agoAs a kid, the only OS I was aware of was Windows. Once, my computer was infected to the point where it was almost unusable. A more experienced friend suggested a non-free antivirus and the CCleaner. After a lot of effort, I could get my machine back to working, but it became so slow that it led me to discover Linux. Now, on a Windows 10 machine, I’ve nothing but Defender, and since the aforementioned experience I’ve never had to use any other antivirus, a ‘junk’ cleaner, etc. Once bitten, twice shy :) Edit: I hated investing in anti-stuff.
- exhilaration 9y agoI rescued my neighbor's Mac from an adware invasion using Malwarebytes so I I would argue that not all these tools are created equal.
- sundvor 9y agoMalwarebytes is great. However, what if it was their installer that was attacked in such fashion? Trusting old memories of what's good or not can be dangerous. I remember getting caught out once by CoreTemp which suddenly packed a load of dung in its default installer. :(
- kbutler 9y agoSourceforge revolutionizes open source by providing free hosting for projects! [later] Sourceforge - You will never find a more wretched hive of scum and villainy. [still later] Sourceforge is respectable again! (hopefully?)
- kevin_thibedeau 9y ago> Sourceforge is respectable again! (hopefully?) When pigs fly. I cringe every time I encounter a project hosted on SF and have to play their stupid find the download link game.
- 9y ago
- thrillgore 9y agoOnce again, my bad habit of never upgrading in a timely manner has saved me a particular breed of egg on my face.
- CharlesDodgson 9y agoI really liked the style of this article, it explained things that are very technical in a way that someone with moderate knowledge of the concepts can grasp. Hats off to the author!
- deleted 9y ago[deleted]
- Jdam 9y ago"CCleaner is an application that allows users to perform routine maintenance on their systems." It's 2017, how is this still a thing?
- pmlnr 9y agoI don't understand the question. Maintenance will always be a thing, carried out by humans, cron, or the os itself doesn't really matter.
- avenius 9y agoI think he's referring to the fact that you need a third-party application to perform maintenance, rather than have the functionality supplied in the OS.
- pbhjpbhj 9y agoWhy doesn't MS Windows do the maintenance - CCleaner does things like clean up ancient cache files, remove Windows update files, remove registry entries for software that's no longer installed. That sort of maintenance seems like it's the result of poor design in an OS that has the hood welded shut. I actually used ccleaner on Win 10 recently, an MS update had associated loads of files with TWINUI which wasn't installed making things like viewing images impossible. Ccleaner found of the order of thousands of stale entries, removed them and made a backup. It also let me simply check and disable startup programs - I don't think Win 10 has a way to do that in the user UI?
- madshiva 9y agoCCleaner like Avast never make the job for me, I have always told people to stop using it.. but user need proof. Even with ton of subject "I have removed X with CCleaner and now I.."
- WorldMaker 9y agoWhile the malware-ification of Avast has been a relatively slow process, [1] I have never trusted CCleaner, and I also groan when I see friends/family still using CCleaner after all the times I've helped them get out of jams CCleaner caused. Anecdotally, I've seen CCleaner delete way too many false positives in the Registry, breaking applications, (and people have never heeded it's warning to properly backup the Registry), and worse entirely corrupt Registry Hives, breaking Windows. The Hive database format of the Windows Registry was built to be read-mostly/write-rarely and doesn't survive well to active surgery, especially not "I run CCleaner once a week with all the options checked". Like I said, I've seen it corrupt entire Hives from too regular operation. I'm also of the opinion that some of that "Windows slowdown" that these users complain of is a snowball impact of too much Registry surgery leaving sadly deteriorated/badly optimized for reading Hives behind, but that's mostly a hypothesis I have not scientifically proven. [1] I kind of forgive people still running Avast out of habit from bad old XP days (not everyone got on the Microsoft Security Essentials train as fast as they could, and that was as much a marketing/awareness problem), though as knowledge that Windows Defender exists spreads there are increasingly fewer excuses to still run Avast.
- NiveaGeForce 9y agoIndeed, I explained some of the issues with cleaners here. https://news.ycombinator.com/item?id=15277316 https://news.ycombinator.com/item?id=15277316
- lunorian 9y agoDoes anyone know whether the macOS Version was infected?
- ballenf 9y agoOthers have stated only 32-bit Windows installer was comprimised. So, no, macOS version was not infected.
- hourislate 9y agoWas reading a copy of Maximum PC a while back and they suggested Privazer http://privazer.com/ http://privazer.com/ . I've installed it on a couple of machines and it seems to do a pretty thorough job in cleaning the system. The CCleaner infection was for win32 machines and from what I understand upgrading to the next version (v5.34) fixes the problem.
- legulere 9y agoWith all these malware problems I look forward to more heavily sandboxed operating systems based on capabilities. Maybe Fuchsia will be that operating system, if it does not turn out to be a google spyware hell.
- jackpot51 9y agoI hope I can make Redox be that operating system.
- emodendroket 9y agoI think you're just going to see more stuff become a Web app. Sandboxing doesn't make much sense with a system utility like this.
- jerheinze 9y agoI think what you're looking for is Qubes OS https://qubes-os.org https://qubes-os.org
- jmkni 9y agoIsn't that what Microsoft are attempting with the Windows Store? IIRC Windows Store apps don't run in the same way as regular Windows applications, they run in a sandbox.
- CapacitorSet 9y agoSo... SELinux?
- jasonmaydie 9y agoBundled installers are the worst thing about the old way windows software was distributed.
- WorldMaker 9y agoI think it is just about time for all apps to be distributed only by APPX package; now that the Project Centennial bridge has been available for several Windows builds, and what with the Anniversary Update making sideloading on by default, and the UX Upgrades for sideloading in the AU and Creators Update (and now with all of that several months to a year old). Office itself is in Preview on the Windows Store, and when that comes out of Preview, other developers are especially going to be on notice to get applications into APPX packages, if not the Store, because for most applications if Office can do it, so can you.
- AJ007 9y agoJust wait until everyone finds out that Avast sells your raw traffic data to marketers and who knows else... (Google Jumpshot)
- ballenf 9y agoFound this post from 2015 for anyone else curious for details: https://malwaretips.com/threads/avast-and-jumpshot.46539/ https://malwaretips.com/threads/avast-and-jumpshot.46539/
- AdmiralAsshat 9y agoMy Windows 7 machine still has a nightly scheduled cronjob to run ccleaner in headless mode. I mostly used it to automatically securely wipe anything I put into the Recycle Bin. Fortunately I don't think I've updated the program in 2-3 years, so it probably doesn't have any malware in it, but still, rather scary to think that was used to be a daily program for me is now infected. Which reminds me, I probably need to call my dad and anyone else I installed that for...
- Tanya_Romanova 9y agothat's rotten news you guys. if ccleaner goes bad, then eset nod 32 will soon do too?:((((
- quaffapint 9y agoThey also have a portable version, which is what I always use, so you don't have the installer issue (of course the main exe could be compromised, but that's not the case here).
- cJ0th 9y agoWhat's the easiest way to find out whether a computer is infected?
- TravelTechGuy 9y agoQuestion: I get my CCLeaner installers through Chocolatey, so it always installs the 64 bit version. Obviously, this gave me quite a scare, so I downloaded and ran both MalwareBytes and Immunet - both came up negative. I checked my registry for the keys mentioned in the article, and found none of them. Can I assume I'm "safe" (well, one never is, but relatively speaking), or should I revert my system to an August image?
- iza 9y agoApparently only the 32 bit installer was compromised.
- makkesk8 9y agogood thing I refuse to update, still on 5.25 :D
- OscarTheGrinch 9y agoMy new app: CCleanerCleaner will clear everything up in a jiffy.
- Zeklandia 9y agoI guess we know how Equifax got hacked.
- JohnTHaller 9y agoIt's also worth noting that the default installer for CCleaner automatically installs Chrome and sets it as the default browser with no notification in the default process. Unless you click "More..." from one of the screens, then it tells you. At least it was like this two weeks ago. Had to uninstall bundleware Chrome again from multiple family members' PCs.
- happy-go-lucky 9y agoSo, they fucked it. Thank you!
- happy-go-lucky 9y ago> the default installer for CCleaner automatically installs Chrome and sets it as the default browser Why is that is my question.
- JohnTHaller 9y agoGoogle pays companies to do new installs of Chrome. They're supposed to make it explicit, but Google doesn't really police it. It's usually via 'dark patterns' as it is with most free Windows antivirus apps where it shows a small indication at the bottom of the screen on a window that's about something else. For example, Avast sneaks it in as part of an automatic update on the Continue window: https://i.imgur.com/NIZk9Pd.jpg https://i.imgur.com/NIZk9Pd.jpg
- happy-go-lucky 9y agoPal, you know you're revealing the selves of both MS and Google!
- takeda 9y ago"Don't be evil" Even if it is explicit the idea is to have it enabled by default so people accidentally install it and then hopefully start using it. Which browser dominates should be based on its quality not how much money you spend on it :/
- kakarot 9y agoWow that's crazy, I was on the toilet just this morning running CCleaner on my phone as I do weekly and the thought momentarily crossed my mind that I shouldn't trust CCleaner on my phone (I limit my use of apps as much as I can) but my next immediate thought was, "Nah, this is Piriform we're talking about, they're one of the few free software developers I can probably trust to never inject malware into their products." I mean, I guess that's still true since the build was compomised by an outside party, but it's still just an interesting moment of synchronicity.