CCleaner: A Vast Number of Machines at Risk

Page 6 of 14 FirstFirst ... 45678 ... LastLast

  1. Posts : 18,432
    Windows 11 Pro
       #50

    Bwahaha! AVAST distributing malware.... I'll just stick with MS provided Defender for now.
      My Computer


  2. Posts : 1,097
    Windows 10 Home x64 Version 1809 (OS Build 17763.437)
       #51

    NavyLCDR said:
    ... AVAST distributing malware....
    I knew I couldn't be the only one to see the irony in this.
      My Computer


  3. Posts : 1,811
    W7 Ultimate SP1 (64 bit), LM 19.2 MATE (64 bit), W10 Home 1703 (64 bit), W10 Pro 1703 (64 bit) VM
       #52

    Registry Key is irrelevant


    Josey Wales said:
    No one is 100% safe, if you want to be pull your Ethernet plug and play solitaire all day.:)
    Old games (like the ones I have) don't require 24/7 Internet access either. :)

    It seems the installer I downloaded is clean.
    Regedit can't find "Agomo" on any of my PCs or VMs (XP, W7 & W10 - 32 bit or 64 bit).

    Update
    It looks like the Registry Key is irrelevant!

    MBAM just detected something on my main PC ("funnily enough" Avast detected nothing).

    CCleaner: A Vast Number of Machines at Risk-mbam-ccleaner-malware.png
    Last edited by lehnerus2000; 18 Sep 2017 at 20:19. Reason: Update
      My Computer


  4. Posts : 14,903
    Windows 10 Pro
       #53

    lehnerus2000 said:
    Old games (like the ones I have) don't require 24/7 Internet access either. :)

    It seems the installer I downloaded is clean.
    Regedit can't find "Agomo" on any of my PCs or VMs (XP, W7 & W10 - 32 bit or 64 bit).

    Update
    It looks like the Registry Key is irrelevant!

    MBAM just detected something on my main PC ("funnily enough" Avast detected nothing).

    CCleaner: A Vast Number of Machines at Risk-mbam-ccleaner-malware.png
    The registry keys are relevant, Mbam detected the malicious code that begin everything.
    The first stage of the payloader loads a dll into memory and executes the dll that contains all important functionality including the registry part.
      My Computers


  5. Posts : 5,452
    Windows 11 Home
       #54

    OldMike65 said:
    Think some of you folks are getting carried away on this......Never removed mine, and I have no issues, no threats, nothing....everything checks out just fine.
    Indeed, all this malware does, that it collects some system info, pretty much every software does that.

    Secondly, taking control over remote devices using cloud version, every remote software is deceptible to this, TeamViewer had been hacked and had its installer altered a few times, so that is to be expected from cloud.

    First of all, the bottom line is: to the best of our knowledge, no harm was done to any CCleaner users as the threat was removed before it had a chance to fully activate.
    This is really not about downplaying the issue. This is a statement based on a pretty thorough analysis, partially shared below and partially still embargoed because of the ongoing investigation.

    Now, some facts:
    - Avast acquired a company (Piriform) which was in the process of being hacked. We have good evidence that the attack started at least several weeks before the acquisition.
    - Immediately after we first learned about something wrong with the CCleaner product (which was on September 12, i.e. 6 days ago) we started working on it and have been working on it around the clock since then.
    - The #1 priority for us was to protect the CCleaner customers and minimize the actual customer impact of the incident.
    - For that reason, we first focused on fully understanding the malicious code and disconnecting the bad actors from their ability to control the backdoor, i.e. taking down the CnC servers.
    - The CnC server was taken down on September 15, three days after we first learned about the incident. Given how difficult these things tend to be, we consider this a very good result and I don't see how we could have done it any better. (By that time, the secondary CnC servers (the DGA domains) were already sinkholed as well, so that technically cut the attackers off their ability to control the backdoor).
    CCleaner and installing avast with out permission...
      My Computer


  6. Posts : 516
    Windows 10 Enterprise
       #55

    Update to the CCleaner 5.33.6162 Security Incident September 19

    Thanks TairikuOkami for the link.

    It is quite obvious that the fake news syndrome is spreading fast and in every facet of life.

    Hackers trying to infiltrate software is not new in any sense. I have trusted CCleaner for years and it seams that Avast also saw a great product in acquiring it. Unfortunately just as if your Equifax info were stolen by hackers, you'd have to read up to find out if you feel secure about your info.

    This info from Avast is quite clear.
      My Computer


  7. Posts : 7,254
    Windows 10 Pro 64-bit
    Thread Starter
       #56

    lehnerus2000 said:
    Old games (like the ones I have) don't require 24/7 Internet access either. :)

    It seems the installer I downloaded is clean.
    Regedit can't find "Agomo" on any of my PCs or VMs (XP, W7 & W10 - 32 bit or 64 bit).

    Update
    It looks like the Registry Key is irrelevant!

    MBAM just detected something on my main PC ("funnily enough" Avast detected nothing).

    CCleaner: A Vast Number of Machines at Risk-mbam-ccleaner-malware.png
    Did you do a full or quick scan with MBM?
      My Computers


  8. Posts : 5,452
    Windows 11 Home
       #57

    Official news release: Update to the CCleaner 5.33.6162 Security Incident

    Zardoc said:
    This info from Avast is quite clear.
    Unfortunately the damage is done, not just to Piriform, but to Avast as well, long term.
      My Computer


  9. Posts : 516
    Windows 10 Enterprise
       #58

    TairikuOkami said:
    Official news release: Update to the CCleaner 5.33.6162 Security Incident


    Unfortunately the damage is done, not just to Piriform, but to Avast as well, long term.
    I agree.

    My two cents, I don't like Avast security software, I'm more of a NOD guy but that's my choice. Wouldn't be surprised that anti virus software gets hacked.

    Still gonna use CCleaner until it probably gets bloated like PGP, Acronis and others that got taken over. Hope not...
      My Computer


  10. Posts : 63
    W7
       #59

    I'm on Win10 64 bit and CCleaner 64 bit, However I was on the hacked version and updated to the "Safe" version before any of the hacked news came out.

    So I checked HKLM\SOFTWARE\Piriform\ and the only subfolder is ccleaner no Agomo of any type, and scanned with Malwarebytes and WinDefender and nothing came up. Does this mean I'm in the clear or should I be looking at anything else?
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 22:17.
Find Us




Windows 10 Forums