Author Topic: CCleaner Malware Incident  (Read 11454 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
CCleaner Malware Incident
« on: September 18, 2017, 10:53:22 PM »
CCleaner Malware Incident - What You Need to Know and How to Remove

What happened?

An unknown threat group compromised the CCleaner infrastructure.

The attacker added malware to the 32-bit versions of CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191.

The files were available for download between August 15 and September 12.

Who is affected?

Everybody who downloaded and installed the affected versions in that timespan.

Avast estimates the number of affected machines at 2.27 million.

https://www.bleepingcomputer.com/how-to/security/ccleaner-malware-incident-what-you-need-to-know-and-how-to-remove/

REDACTED

  • Guest
Re: CCleaner Malware Incident
« Reply #1 on: September 18, 2017, 10:57:25 PM »
Good luck getting some answers out of Avast and Piriform. They are trying to downplay this, by not delivering adequate information. Every shred of good reputation CCleaner had, is gone now and Avast' reputation has been hurt even more, and the more Avast and Piriform holds back information, the bigger the hole they are digging for them self.


Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: CCleaner Malware Incident
« Reply #2 on: September 18, 2017, 11:10:26 PM »
Eh, people dramatizing it again. And I'm not saying this because I've been working with avast! for a long time, I'm saying it because it can happen to ANY company if it gets target attacked. And this was the case here. Blaming it on avast! which just purchased Piriform is just the lamest thing ever. If anything, they should be applauded for finding out themselves. If avast! didn't buy Piriform, it could have been going on for months before someone noticed it. And like I've said, it could have happened to any company. Piriform isn't specialized in security, so, things are more likely to go wrong with such company than with avast! itself. And we've seen hacks happened to security firms before, including avast! (usually to 3rd party stuff under their control).

The information is there, but I guess some people expect avast! to go back in time and change the course of history somehow...
Visit my webpage Angry Sheep Blog

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: CCleaner Malware Incident
« Reply #3 on: September 18, 2017, 11:15:24 PM »
If at first you don't succeed, then skydiving's not for you.

Offline EmoHobo

  • Sr. Member
  • ****
  • Posts: 339
Re: CCleaner Malware Incident
« Reply #4 on: September 19, 2017, 11:54:05 AM »
So I've always used the 64-bit version, I'm fine, right?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: CCleaner Malware Incident
« Reply #5 on: September 19, 2017, 11:56:52 AM »
So I've always used the 64-bit version, I'm fine, right?
Yep.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline EmoHobo

  • Sr. Member
  • ****
  • Posts: 339
Re: CCleaner Malware Incident
« Reply #6 on: September 19, 2017, 12:12:04 PM »
So I've always used the 64-bit version, I'm fine, right?
Yep.
I don't see the regedit change either for the added item.

I also set it to automatically launch the 64bit version since I have both installed.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: CCleaner Malware Incident
« Reply #7 on: September 19, 2017, 12:44:55 PM »
Hi EmoHobo,

Well I was not affected either, according to the registry read out.

But know that 20% of the data breaches in the "Murica's" today stem from cyberattacks threatening your data and privacy.
Nothing new when folks admit that privacy does not exist any longer there and all your data are for the grab (to render the new digital gold that is in data), when not showing you ads one is javascript mining monero inside your browser with or without your consent.

That is how far as how it has got, and in the case of the alleged CCleaner breach the malware injected into #CCleaner has shared code with several tools used by one of the APT groups from the #Axiom APT 'umbrella', an umbrella for dynamic API hackers by the so-called Lazarus group cybercriminal malware factory. They were active amongs other things from Asia and were fought in a common initiative known as  Operation Blockbuster Security Coalition.

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline EmoHobo

  • Sr. Member
  • ****
  • Posts: 339
Re: CCleaner Malware Incident
« Reply #8 on: September 19, 2017, 12:59:36 PM »
and what does all that mean polonus?  For a regular person like me. Does it mean my data is probably already out there just floating around like some kind of floating gold mine of personal data?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: CCleaner Malware Incident
« Reply #9 on: September 19, 2017, 01:02:29 PM »
See Reply #5.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: CCleaner Malware Incident
« Reply #10 on: September 19, 2017, 05:10:17 PM »
If at first you don't succeed, then skydiving's not for you.

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CCleaner Malware Incident
« Reply #11 on: September 19, 2017, 05:26:48 PM »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: CCleaner Malware Incident
« Reply #12 on: September 19, 2017, 06:50:16 PM »
More info here: https://blog.avast.com/update-to-the-ccleaner-5.33.1612-security-incident
Pls don't add Ccleaner to AVAST.It is a request.  :)

Why would they when there is already avast cleanup (free or paid) and even if they did, what is to stop you doing a custom install and deselecting it as you can with other components.

Presumably those that are already using ccleaner wouldn't get it again.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: CCleaner Malware Incident
« Reply #13 on: September 19, 2017, 07:27:17 PM »
This entire thread is in the wrong forum.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48550
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: CCleaner Malware Incident
« Reply #14 on: September 19, 2017, 11:52:15 PM »
Who cares which forum it's in. It's still the Avast forum and Ccleaner is now an Avast product.
@ Be Secure,
Ccleaner is it's own program.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet