CCleaner trojan\backdoor

4wd

Getting the picture
Joined
Dec 16, 2012
Messages
1,674
Reaction score
2,203
Points
113
My Satellite Setup
5 W, 9-13-19-28 E
My Location
Bergen, Norway \ Alpes Maritimes, France

Topper

Amo Amas Amant Admin
Staff member
Joined
Nov 18, 2004
Messages
23,991
Reaction score
4,014
Points
113
Age
69
My Satellite Setup
Has gone to a good home elsewhere
My Location
Blackburn, Lancashire
Yes I spotted this yesterday evening whilst setting up my replacement workstation in the study, I have finally retired the XP model. I also use CCleaner on a regular basis, I had that version on my laptop but my lappy is locked down tight so it seems to be unaffected however I am just running a full scan with Avast at the moment.
 

Topper

Amo Amas Amant Admin
Staff member
Joined
Nov 18, 2004
Messages
23,991
Reaction score
4,014
Points
113
Age
69
My Satellite Setup
Has gone to a good home elsewhere
My Location
Blackburn, Lancashire
Ok well it has recognised the download as a threat which is good so have set it to deep scan prior to booting. It could be a long job
 

jeallen01

Specialist Contributor
Joined
Oct 12, 2003
Messages
6,674
Reaction score
2,630
Points
113
My Satellite Setup
See Signature
My Location
Somewhere in England (possibly?)!
4wd

Many Thanks for the alert - I think my previous version was 5.33 installed on 2 Sept, but Kaspersky prompted me to install the latest version this morning and it's now 5.34.6207.
Nevertheless, will run deep scans with Kaspersky & Malwarebytes to see if anything nasty has been left behind!

BTW: here is a snapshot of the list of apps and malware found when Virus Total scanned ccsetup533.exe, and the Virus Total page is here
 

Attachments

  • Virus Total Scan of CCset 5.33, 2017-09-19.JPG
    Virus Total Scan of CCset 5.33, 2017-09-19.JPG
    92.5 KB · Views: 11
Last edited:

jeallen01

Specialist Contributor
Joined
Oct 12, 2003
Messages
6,674
Reaction score
2,630
Points
113
My Satellite Setup
See Signature
My Location
Somewhere in England (possibly?)!
BTW2: do you think the problem might have been the site from which 5.33 was downloaded, if it were not the original Piriform site?

Update: this page on howtogeek tells how you can look in the Registry and find out if you had the infected version on your m/c at sometime, and says that
"If that version is before version 5.33.6162, then you are not affected, and you should manually download the latest version now. If that version is 5.34 or later, your current version isn’t affected, but if you updated CCleaner in between August 15th and September 12th, and are on a 32-bit system, you may still have been affected. (If you’re comfortable going into the registry, you can open Registry Editor and navigate to HKLM\SOFTWARE\Piriform and see if there is a key labeled Agomo:MUID . If that key exists, it means you had the infected software on your system at one point in time.)"

- just checked the Registry on my main laptop (it's 64 bit, so should be OK anyway) and there's no sign of Agomo:MUID !
 
Last edited:

Topper

Amo Amas Amant Admin
Staff member
Joined
Nov 18, 2004
Messages
23,991
Reaction score
4,014
Points
113
Age
69
My Satellite Setup
Has gone to a good home elsewhere
My Location
Blackburn, Lancashire
BTW: here is a snapshot of the list of apps and malware found when Virus Total scanned ccsetup533.exe, and the Virus Total page is here
Can I just correct you, I believe the posted pic is a list of the av engines that could and could not find the trojan, 40 did but a lot more did not
 

jeallen01

Specialist Contributor
Joined
Oct 12, 2003
Messages
6,674
Reaction score
2,630
Points
113
My Satellite Setup
See Signature
My Location
Somewhere in England (possibly?)!
Topper

Maybe you are correct, and I misinterpreted the page info.
 

jeallen01

Specialist Contributor
Joined
Oct 12, 2003
Messages
6,674
Reaction score
2,630
Points
113
My Satellite Setup
See Signature
My Location
Somewhere in England (possibly?)!
Update
Did two full scans:
- Malwarebytes found nothing,
- Kaspersky found and deleted the downloaded setup file ("ccsetup533.exe//CCleaner.exe") for version 5.33

So looks like the latest and updated Malwarebytes Free did not, but Kaspersky did, find the malware files shown here on the Virus Total website page
upload_2017-9-19_22-16-5.png
 

Terryl

Specialist Contributor
Joined
Apr 14, 2011
Messages
3,288
Reaction score
1,941
Points
113
Age
82
My Satellite Setup
OpenBox X5 on a 1 meter motorized dish.
And now a 10 foot "C" band dish.

Custom built PC
My Location
Deep in the Boonies in the central Sierra Nevada mountains of California.
My paid version of Malwarebytes found it on one of my 32 bit PC's and dumped it.
 

jeallen01

Specialist Contributor
Joined
Oct 12, 2003
Messages
6,674
Reaction score
2,630
Points
113
My Satellite Setup
See Signature
My Location
Somewhere in England (possibly?)!
My paid version of Malwarebytes found it on one of my 32 bit PC's and dumped it.
Was it found "automatically" during the download, or only when you initiated a scan (as I did with Kaspersky)?
 

Terryl

Specialist Contributor
Joined
Apr 14, 2011
Messages
3,288
Reaction score
1,941
Points
113
Age
82
My Satellite Setup
OpenBox X5 on a 1 meter motorized dish.
And now a 10 foot "C" band dish.

Custom built PC
My Location
Deep in the Boonies in the central Sierra Nevada mountains of California.
It scanned the computer at a pre-set time, (2 AM) it found it automatically, I don't use that PC that much so it waited till I logged on and I saw the warning.
 

Topper

Amo Amas Amant Admin
Staff member
Joined
Nov 18, 2004
Messages
23,991
Reaction score
4,014
Points
113
Age
69
My Satellite Setup
Has gone to a good home elsewhere
My Location
Blackburn, Lancashire
Yes Avast missed it in the download but picked it up when I initiated a full scan....poor
 

dig deep

Prince of Birthdays
Staff member
Joined
Sep 28, 2005
Messages
8,972
Reaction score
424
Points
83
My Satellite Setup
Dream7020 and AZ Elite and a few DM800
My Location
Sweden
Used it for many years but always downloaded from official homepage
 

4wd

Getting the picture
Joined
Dec 16, 2012
Messages
1,674
Reaction score
2,203
Points
113
My Satellite Setup
5 W, 9-13-19-28 E
My Location
Bergen, Norway \ Alpes Maritimes, France
but always downloaded from official homepage

What makes this case so special is that it's the official download server that got infected, owned and run by an established and well reputated antivirus company, ridiculous situation of not detecting their 'own' virus and allowing millions of downloads before realizing.
 

Topper

Amo Amas Amant Admin
Staff member
Joined
Nov 18, 2004
Messages
23,991
Reaction score
4,014
Points
113
Age
69
My Satellite Setup
Has gone to a good home elsewhere
My Location
Blackburn, Lancashire
Yes I spotted this yesterday evening whilst setting up my replacement workstation in the study, I have finally retired the XP model. I also use CCleaner on a regular basis, I had that version on my laptop but my lappy is locked down tight so it seems to be unaffected however I am just running a full scan with Avast at the moment.
To correct my earlier statement my lappie uses the 64bit version which was supposed to be unaffected, yet the file containing a trojan was found in my downloads directory
 

jeallen01

Specialist Contributor
Joined
Oct 12, 2003
Messages
6,674
Reaction score
2,630
Points
113
My Satellite Setup
See Signature
My Location
Somewhere in England (possibly?)!
To correct my earlier statement my lappie uses the 64bit version which was supposed to be unaffected, yet the file containing a trojan was found in my downloads directory
Actually it was a similar situation here, but the file in question was "Saved as" in a sub-folder in the Ccleaner folder when I downloaded it - I suspect that the same setup file was used for both 32 & 64 bit O/S but was only "activated" when installed on the former.

More info on what appears to have happened is on the Tom's Hardware site here
 

Topper

Amo Amas Amant Admin
Staff member
Joined
Nov 18, 2004
Messages
23,991
Reaction score
4,014
Points
113
Age
69
My Satellite Setup
Has gone to a good home elsewhere
My Location
Blackburn, Lancashire
Yep a lot of unhappy bunnies in the world who will never trust either Avast or CCleaner again, perhaps it was a disgruntled employee who lost his/her job when Avast took over, also seems odd that the certification was correct
 

Channel Hopper

Suffering fools, so you don't have to.
Staff member
Joined
Jan 1, 2000
Messages
35,596
Reaction score
8,576
Points
113
Age
59
Website
www.sat-elite.uk
My Satellite Setup
A little less analogue, and a lot more crap.
My Location
UK
At the end of last week I found that ccleaner had already released 5.34, if so, why would 5.33 still be promoted as current?
 

jeallen01

Specialist Contributor
Joined
Oct 12, 2003
Messages
6,674
Reaction score
2,630
Points
113
My Satellite Setup
See Signature
My Location
Somewhere in England (possibly?)!
At the end of last week I found that ccleaner had already released 5.34, if so, why would 5.33 still be promoted as current?
CH:
From what I read, 5.33 is still "current" for those people who are using the free version which has to be updated manually - and so theirs won't update unless they manually trigger it, whereas those with paid-for subscriptions will get it automatically. Also, for PCs running a 32 bit OS, 5.33 appears to leave a Trojan entry in the Registry which 5.34 does not then seem to remove - see Post #5 above.
 

PaulR

Dazed and Confused Admin
Staff member
Joined
Jun 28, 2003
Messages
18,024
Reaction score
4,046
Points
113
My Satellite Setup
-----------See sig-----------
My Location
Wirral, NW UK and Vaucluse, France.
Phew! Glad I'm 64 bit.
 
Top