Windows 10: CCleaner: A Vast Number of Machines at Risk

Discus and support CCleaner: A Vast Number of Machines at Risk in Windows 10 News to solve the problem; Official news release: Update to the CCleaner 5.33.6162 Security Incident Unfortunately the damage is done, not just to Piriform, but to Avast as... Discussion in 'Windows 10 News' started by swarfega, Sep 17, 2017.

  1. Zardoc Win User

    CCleaner: A Vast Number of Machines at Risk


    I agree.

    My two cents, I don't like Avast security software, I'm more of a NOD guy but that's my choice. Wouldn't be surprised that anti virus software gets hacked.

    Still gonna use CCleaner until it probably gets bloated like PGP, Acronis and others that got taken over. Hope not... *Wink
     
    Zardoc, Sep 18, 2017
    #61
  2. Karizma Win User

    I'm on Win10 64 bit and CCleaner 64 bit, However I was on the hacked version and updated to the "Safe" version before any of the hacked news came out.

    So I checked HKLM\SOFTWARE\Piriform\ and the only subfolder is ccleaner no Agomo of any type, and scanned with Malwarebytes and WinDefender and nothing came up. Does this mean I'm in the clear or should I be looking at anything else?
     
    Karizma, Sep 18, 2017
    #62
  3. swarfega Win User
    You were clear from the start since you used the 64-bit version of ccleaner, it was only the 32-bit that was affected.
     
    swarfega, Sep 18, 2017
    #63
  4. swarfega Win User

    CCleaner: A Vast Number of Machines at Risk

    I moved away from Avast recently, I felt it was too bloated and intrusive.
     
    swarfega, Sep 18, 2017
    #64
  5. DerDonc Win User
    MBAM found and removed the same "Trojan.Floxif" object on my laptop. Further scans found nothing else. Registry seems to be in good shape.
    Edit: I had to manually search the .exe so MBAM could find it.
     
    DerDonc, Sep 18, 2017
    #65
  6. yu gnomi Win User
    props to Talos Intelligence Group for coming up with a suitably clever headline for their blog post.

    I use the portable versions of piriform softs, and actually delete the 32 bit executables because I never use them. I don't think I was ever in any danger from this, but I scanned with MBAM anyhow - nothing bad was found.
     
    yu gnomi, Sep 18, 2017
    #66
  7. D4ni3l Win User
    I did some experiment on a virtual machine with v5.33
    At least, it is now detected by Windows Defender Antivirus & MalwareBytes


    CCleaner: A Vast Number of Machines at Risk [​IMG]



    CCleaner: A Vast Number of Machines at Risk [​IMG]


    Code: Category: Backdoor Description: This program provides remote access to the computer it is installed on. Recommended action: Remove this software immediately. Items: taskscheduler:C:\Windows\System32\Tasks\CCleanerSkipUAC file:C:\Program Files\CCleaner\CCleaner.exe file:C:\Windows\System32\Tasks\CCleanerSkipUAC regkey:HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53F0D184-E624-492B-9E46-099A892E7B7B} regkey:HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC Get more information about this item online.[/quote]

    CCleaner: A Vast Number of Machines at Risk [​IMG]



    CCleaner: A Vast Number of Machines at Risk [​IMG]


    This confirm that the malware is only detected in the 32bits version (in CCleaner.exe only but not CCleaner64.exe)
     
    D4ni3l, Sep 18, 2017
    #67
  8. dalchina New Member

    CCleaner: A Vast Number of Machines at Risk

    dalchina, Sep 18, 2017
    #68
  9. Last night I went to update my wife's really old free version of CC and the website gave her computer an AVAST scan which I wasn't that pleased about. Later her AV indicated that when it did so it dropped two adware type infections on the machine. Think I'll be leaving ex- Piriform/AVAST products permanently.
     
    Fisher Mann, Sep 18, 2017
    #69
  10. DavidE Win User
  11. Josey Wales, Sep 18, 2017
    #71
  12. JohnBurns Win User
    In another forum I use, most users seem to be jumping ship of CC. Does anyone in here think this is really necessary at this point if you are using 64bit? I have used CC for so long, I guess i am to complacent in my thinking of it, maybe, but right now I think I will continue to use it. Using Windows Defender, MBAM (with rootkit scans, regular HitmanPro and regular EEK scans will hopefully keep me aware if a problem presents itself. Fingers crossed.
     
    JohnBurns, Sep 18, 2017
    #72
  13. Sky Ranch Win User

    CCleaner: A Vast Number of Machines at Risk

    Sounds like Avast is initiating damage control and now in conflict with Cisco Talos in regards to who was first to identify and analyze the behavior of the malicious code. It was Cisco Talos to registry the suspected domains.

    Always thought Avast used shady business tactics in promoting their products.
     
    Sky Ranch, Sep 18, 2017
    #73
  14. OldMike65 Win User
    1st off let me say this, its entirely up to the user if they want to remove CCleaner. That is there choice. *Smile
    I have been running CCleaner for years the Pro version. I had no infections, no issues. I have no intention of removing my registered version.
    On another note, I've also read that installing the latest update for CCleaner 5.34 and CCleaner Cloud 1.07.3214 that it removes the Floxif malware, which I didn't know till recently. So even if a user didn't use a program like MB to remove the malware, latest CCleaner update does this automatically.

    Again its up to every individual user to decide what they feel is best for them.
     
    OldMike65, Sep 18, 2017
    #74
  15. AndreyT Win User
    For people who use such software as CCleaner, or any other "cleaners" or "optimizers", on their Windows machines this particular issue should not be an issue at all: one virus more, one virus less - it makes no difference. Who cares?
     
    AndreyT, Sep 18, 2017
    #75
Thema:

CCleaner: A Vast Number of Machines at Risk

Loading...
  1. CCleaner: A Vast Number of Machines at Risk - Similar Threads - CCleaner Vast Number

  2. A Vast Range of Errors

    in Windows 10 Gaming
    A Vast Range of Errors: Hello,for clarification, these are my PC specs:Ryzen 5 3600 not OC CPU,MSI B450m PRO-VDH Max MBO,MSI Ventus 2x RTX 3060 Ti GPU,Corsair Vengeance 2x8GB 3200MHz DDR4 RAM,Corsair RM650 PSU,WD Green 240GB SSD Boot drive+ 2TB Seagate Barracuda.My issues started around a month ago,...
  3. A Vast Range of Errors

    in Windows 10 Software and Apps
    A Vast Range of Errors: Hello,for clarification, these are my PC specs:Ryzen 5 3600 not OC CPU,MSI B450m PRO-VDH Max MBO,MSI Ventus 2x RTX 3060 Ti GPU,Corsair Vengeance 2x8GB 3200MHz DDR4 RAM,Corsair RM650 PSU,WD Green 240GB SSD Boot drive+ 2TB Seagate Barracuda.My issues started around a month ago,...
  4. A Vast Range of Errors

    in Windows 10 BSOD Crashes and Debugging
    A Vast Range of Errors: Hello,for clarification, these are my PC specs:Ryzen 5 3600 not OC CPU,MSI B450m PRO-VDH Max MBO,MSI Ventus 2x RTX 3060 Ti GPU,Corsair Vengeance 2x8GB 3200MHz DDR4 RAM,Corsair RM650 PSU,WD Green 240GB SSD Boot drive+ 2TB Seagate Barracuda.My issues started around a month ago,...
  5. 1-8O8-8OO-0937 Ccleaner Customer Care Ccleaner Customer Service Phone Number

    in Windows 10 Gaming
    1-8O8-8OO-0937 Ccleaner Customer Care Ccleaner Customer Service Phone Number: ccleaner customer service number comes with numerous features such as a calendar, contact manager, task manager, note-taking, journal, web browsing, and email application. Out of all these features, ccleaner is mainly considered for its email application. Whether you want...
  6. 1-8O8-8OO-0937 Ccleaner Customer Care Ccleaner Customer Service Phone Number

    in Windows 10 Software and Apps
    1-8O8-8OO-0937 Ccleaner Customer Care Ccleaner Customer Service Phone Number: ccleaner customer service number comes with numerous features such as a calendar, contact manager, task manager, note-taking, journal, web browsing, and email application. Out of all these features, ccleaner is mainly considered for its email application. Whether you want...
  7. get machine serial number

    in Windows 10 Gaming
    get machine serial number: Windows 10, desktop system. We replaced a desktop unit over the weekend. Now we need to transfer the accounting software and for that we need the serial number of the machine we replaced. I right clicked start > left clicked Run > typed 'wmic bios get serialnumber' into the...
  8. get machine serial number

    in Windows 10 Software and Apps
    get machine serial number: Windows 10, desktop system. We replaced a desktop unit over the weekend. Now we need to transfer the accounting software and for that we need the serial number of the machine we replaced. I right clicked start > left clicked Run > typed 'wmic bios get serialnumber' into the...
  9. get machine serial number

    in Windows 10 Customization
    get machine serial number: Windows 10, desktop system. We replaced a desktop unit over the weekend. Now we need to transfer the accounting software and for that we need the serial number of the machine we replaced. I right clicked start > left clicked Run > typed 'wmic bios get serialnumber' into the...
  10. Ccleaner

    in Windows 10 Software and Apps
    Ccleaner: Each time I log into my user profile, Ccleaner asks for permissions to run. How can I stop this? Note: I could probably go to Google and research this problem, but I always like to hear something from this forum as I trust you guys and your solutions as they always...