New
#50
Bwahaha! AVAST distributing malware.... I'll just stick with MS provided Defender for now.
Bwahaha! AVAST distributing malware.... I'll just stick with MS provided Defender for now.
Old games (like the ones I have) don't require 24/7 Internet access either. :)
It seems the installer I downloaded is clean.
Regedit can't find "Agomo" on any of my PCs or VMs (XP, W7 & W10 - 32 bit or 64 bit).
Update
It looks like the Registry Key is irrelevant!
MBAM just detected something on my main PC ("funnily enough" Avast detected nothing).
Last edited by lehnerus2000; 18 Sep 2017 at 20:19. Reason: Update
Indeed, all this malware does, that it collects some system info, pretty much every software does that.
Secondly, taking control over remote devices using cloud version, every remote software is deceptible to this, TeamViewer had been hacked and had its installer altered a few times, so that is to be expected from cloud.
CCleaner and installing avast with out permission...First of all, the bottom line is: to the best of our knowledge, no harm was done to any CCleaner users as the threat was removed before it had a chance to fully activate.
This is really not about downplaying the issue. This is a statement based on a pretty thorough analysis, partially shared below and partially still embargoed because of the ongoing investigation.
Now, some facts:
- Avast acquired a company (Piriform) which was in the process of being hacked. We have good evidence that the attack started at least several weeks before the acquisition.
- Immediately after we first learned about something wrong with the CCleaner product (which was on September 12, i.e. 6 days ago) we started working on it and have been working on it around the clock since then.
- The #1 priority for us was to protect the CCleaner customers and minimize the actual customer impact of the incident.
- For that reason, we first focused on fully understanding the malicious code and disconnecting the bad actors from their ability to control the backdoor, i.e. taking down the CnC servers.
- The CnC server was taken down on September 15, three days after we first learned about the incident. Given how difficult these things tend to be, we consider this a very good result and I don't see how we could have done it any better. (By that time, the secondary CnC servers (the DGA domains) were already sinkholed as well, so that technically cut the attackers off their ability to control the backdoor).
Update to the CCleaner 5.33.6162 Security Incident September 19
Thanks TairikuOkami for the link.
It is quite obvious that the fake news syndrome is spreading fast and in every facet of life.
Hackers trying to infiltrate software is not new in any sense. I have trusted CCleaner for years and it seams that Avast also saw a great product in acquiring it. Unfortunately just as if your Equifax info were stolen by hackers, you'd have to read up to find out if you feel secure about your info.
This info from Avast is quite clear.
Official news release: Update to the CCleaner 5.33.6162 Security Incident
Unfortunately the damage is done, not just to Piriform, but to Avast as well, long term.
I agree.
My two cents, I don't like Avast security software, I'm more of a NOD guy but that's my choice. Wouldn't be surprised that anti virus software gets hacked.
Still gonna use CCleaner until it probably gets bloated like PGP, Acronis and others that got taken over. Hope not...![]()
I'm on Win10 64 bit and CCleaner 64 bit, However I was on the hacked version and updated to the "Safe" version before any of the hacked news came out.
So I checked HKLM\SOFTWARE\Piriform\ and the only subfolder is ccleaner no Agomo of any type, and scanned with Malwarebytes and WinDefender and nothing came up. Does this mean I'm in the clear or should I be looking at anything else?