Current Events > CCleaner Compromised to Distribute Malware for Almost a Month

Topic List
Page List: 1
luigi13579
09/18/17 8:01:28 AM
#1:


https://www.bleepingcomputer.com/news/security/ccleaner-compromised-to-distribute-malware-for-almost-a-month/

Version 5.33 of the CCleaner app offered for download between August 15 and September 12 was modified to include the Floxif malware, according to a report published by Cisco Talos a few minutes ago.

Floxif is a malware downloader that gathers information about infected systems and sends it back to its C&C server. The malware also had the ability to download and run other binaries, but at the time of writing, there is no evidence that Floxif downloaded additional second-stage payloads on infected hosts.

The malware collected information such as computer name, a list of installed software, a list of running processes, MAC addresses for the first three network interfaces, and unique IDs to identify each computer in part. Researchers noted that the malware only ran on 32-bit systems. The malware also quit execution if the user was not using an administrator account.


Ouch. Thankfully it was only on 32-bit systems. I haven't used the software in years myself.

It's kinda scary how updates can be hijacked to distribute malware. Usually updating is a defense against attacks, but not always.

Also, interesting that Avast acquired the company that makes it beforehand...
... Copied to Clipboard!
pinky0926
09/18/17 8:02:59 AM
#2:


Ouch. Thankfully it was only on 32-bit systems. I haven't used the software in years myself.

*Breathes out*
---
CE's Resident Scotsman.
http://i.imgur.com/ILz2ZbV.jpg
... Copied to Clipboard!
ChromaticAngel
09/18/17 8:03:36 AM
#3:


You shouldn't be using CCleaner anyway.
---
... Copied to Clipboard!
pinky0926
09/18/17 8:04:23 AM
#4:


ChromaticAngel posted...
You shouldn't be using CCleaner anyway.


Why not? If there's a lightweight cleanup tool you'd recommend I'm all ears.
---
CE's Resident Scotsman.
http://i.imgur.com/ILz2ZbV.jpg
... Copied to Clipboard!
#5
Post #5 was unavailable or deleted.
pinky0926
09/18/17 8:05:38 AM
#6:


Spooking posted...
I still have version 4.

Can't believe CCleaner would stoop this low. Nobody can be trusted nowadays.


The biggest betrayal was when malwarebytes became unforgivable bloatware.
---
CE's Resident Scotsman.
http://i.imgur.com/ILz2ZbV.jpg
... Copied to Clipboard!
ChromaticAngel
09/18/17 8:06:05 AM
#7:


pinky0926 posted...
ChromaticAngel posted...
You shouldn't be using CCleaner anyway.


Why not? If there's a lightweight cleanup tool you'd recommend I'm all ears.


You shouldn't run it because you shouldn't run automated cleanup tools in the first place so my recommendation for the thing to replace CCleaner is "nothing"
---
... Copied to Clipboard!
Looked gf
09/18/17 8:07:03 AM
#8:


Avast is ass I bet they wanted you to use Avast pro to clean up their own malware
---
... Copied to Clipboard!
pinky0926
09/18/17 8:07:34 AM
#9:


ChromaticAngel posted...
pinky0926 posted...
ChromaticAngel posted...
You shouldn't be using CCleaner anyway.


Why not? If there's a lightweight cleanup tool you'd recommend I'm all ears.


You shouldn't run it because you shouldn't run automated cleanup tools in the first place so my recommendation for the thing to replace CCleaner is "nothing"


but why....

I'm not saying you're wrong. I just don't know why I need all those gigs of cached temporary files.
---
CE's Resident Scotsman.
http://i.imgur.com/ILz2ZbV.jpg
... Copied to Clipboard!
Rexdragon125
09/18/17 8:08:40 AM
#10:


ChromaticAngel posted...
pinky0926 posted...
ChromaticAngel posted...
You shouldn't be using CCleaner anyway.


Why not? If there's a lightweight cleanup tool you'd recommend I'm all ears.


You shouldn't run it because you shouldn't run automated cleanup tools in the first place so my recommendation for the thing to replace CCleaner is "nothing"

Yup. Registry cleaners are snake oil. EDIT: Use the built in Disk Cleanup tool instead.
... Copied to Clipboard!
Vyrulisse
09/18/17 8:11:07 AM
#11:


ChromaticAngel posted...
pinky0926 posted...
ChromaticAngel posted...
You shouldn't be using CCleaner anyway.


Why not? If there's a lightweight cleanup tool you'd recommend I'm all ears.


You shouldn't run it because you shouldn't run automated cleanup tools in the first place so my recommendation for the thing to replace CCleaner is "nothing"

It's a great tool if you know what you're doing. Don't understand your hatred of it. *Shrug* It works nicely for me.

I'm glad I was slow to update though, seems the latest release version is fixed. Sucks for Avast, it appears some of their other offerings were infected as well.
---
... Copied to Clipboard!
ChromaticAngel
09/18/17 8:12:16 AM
#12:


pinky0926 posted...
but why....

I'm not saying you're wrong. I just don't know why I need all those gigs of cached temporary files.


the majority of temporary files most people have are generated by their browsers. You can clean out most of them just by going to your browsers menu and saying "delete temporary files"

Temp folders that are targeted by CCleaner are also high privileged areas that other applications use as staging areas to perform updates or store configuration data that need to be written to (as you generally cannot write to the program files folder directly itself without clicking the admin rights popup). CCleaner doesn't know what's safe to delete and what isn't and assumes everything in temp folders is garbage however, this is not the case.

It will also delete registry keys that it thinks aren't being used anymore but you should never do that.

You could just untick a bunch of options before you run CCleaner but chances are you'll end up having to untick so much shit you're better off doing as I said just opening up your browser settings and saying "delete temp files"
---
... Copied to Clipboard!
pinky0926
09/18/17 8:20:13 AM
#13:


Interesting, cheers.
---
CE's Resident Scotsman.
http://i.imgur.com/ILz2ZbV.jpg
... Copied to Clipboard!
#14
Post #14 was unavailable or deleted.
tripZ504
09/18/17 8:48:47 AM
#15:


Its not a bad malware compared to others. Most if not all cleaners and antivirus software collects that type of data.

Good tools but you are better off manually doing it.
... Copied to Clipboard!
Rika_Furude
09/18/17 8:51:27 AM
#16:


... Copied to Clipboard!
FL81
09/19/17 3:07:23 AM
#17:


Nvidia used to spam my hard drive with gigabytes of old drivers, think they fixed that though

As for an alternative, BleachBit is probably your best bet
https://www.bleachbit.org/
---
... Copied to Clipboard!
Sami1000
09/19/17 3:13:45 AM
#18:


Good i didn't update it in long time.
---
Can't think any good sig
... Copied to Clipboard!
Johnny_Nutcase
09/19/17 3:19:06 AM
#19:


ChromaticAngel posted...
pinky0926 posted...
but why....

I'm not saying you're wrong. I just don't know why I need all those gigs of cached temporary files.


the majority of temporary files most people have are generated by their browsers. You can clean out most of them just by going to your browsers menu and saying "delete temporary files"

Temp folders that are targeted by CCleaner are also high privileged areas that other applications use as staging areas to perform updates or store configuration data that need to be written to (as you generally cannot write to the program files folder directly itself without clicking the admin rights popup). CCleaner doesn't know what's safe to delete and what isn't and assumes everything in temp folders is garbage however, this is not the case.

It will also delete registry keys that it thinks aren't being used anymore but you should never do that.

You could just untick a bunch of options before you run CCleaner but chances are you'll end up having to untick so much shit you're better off doing as I said just opening up your browser settings and saying "delete temp files"


This is actually 100% correct. If you do use CCleaner NEVER use the registry cleaner above all else.
---
I've learned that life is one crushing defeat after another... until you just wish Flanders was dead. - Homer Simpson
... Copied to Clipboard!
Topic List
Page List: 1