CCleaner silently compromised, contains backdoor/maleware

Collapse

Recommended Videos

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • LambertandHam
    All Star
    • Jul 2010
    • 8008

    #1

    CCleaner silently compromised, contains backdoor/maleware

    Huge news if you use CCleaner like me. The program has been silently compromised for at least a month to add in a backdoor. I deleted the portable version from my computer, am currently scanning and might do a full restart/restore.


    Piriform this morning warned customers that the Windows 32-bit edition of version 5.33.6162 of CCleaner, and version 1.07.3191 of CCleaner Cloud, were "illegally modified before it was released to the public". This was used to infect PCs with a backdoor that can run code from the attacker's remote IP address.

    The tainted versions of CCleaner and CCleaner Cloud were released on August 15 and August 24, respectively.

    link
    Steam

    PSN: BigGreenZaku

  • Gotmadskillzson
    Live your life
    • Apr 2008
    • 23429

    #2
    Re: CCleaner silently compromised, contains backdoor/maleware

    I'm not running 32 bit Windows so I'm not worried about it.

    Comment

    • countryboy
      Growing pains
      • Sep 2003
      • 52708

      #3
      Re: CCleaner silently compromised, contains backdoor/maleware

      Never used it.
      I can't shave with my eyes closed, meaning each day I have to look at myself in the mirror and respect who I see.

      I miss the old days of Operation Sports :(


      Louisville Cardinals/St.Louis Cardinals

      Comment

      • LambertandHam
        All Star
        • Jul 2010
        • 8008

        #4
        Re: CCleaner silently compromised, contains backdoor/maleware

        Originally posted by Gotmadskillzson
        I'm not running 32 bit Windows so I'm not worried about it.
        Still worth a check and an update just to be sure. Thankfully nothing found on my PC after scans, although I was using the portable version.
        Steam

        PSN: BigGreenZaku

        Comment

        • daflyboys
          Banned
          • May 2003
          • 18238

          #5
          Re: CCleaner silently compromised, contains backdoor/maleware

          Originally posted by countryboy
          Never used it.
          It's an excellent registry cleaner. Good for cleaning junk files too. Highly recommend... well, the non-virus version.

          Comment

          • p_rushing
            Hall Of Fame
            • Feb 2004
            • 14514

            #6
            Re: CCleaner silently compromised, contains backdoor/maleware

            Originally posted by LambertandHam
            Still worth a check and an update just to be sure. Thankfully nothing found on my PC after scans, although I was using the portable version.
            The scan wouldn't have found anything, it was so buried it even passed as safe.

            From a security aspect, there wasn't any real risk. The rogue installer was only on 1 server and then reached out to 1 server to collect the data. That server was shut down quickly, so there was no where for the data to go. The data also was just hardware, OS, etc info, so it would be hard to do too much with it. It also only affected 1 version, so unless you update immediately, you might not even have installed it.

            Comment

            • DieHardYankee26
              BING BONG
              • Feb 2008
              • 10178

              #7
              Re: CCleaner silently compromised, contains backdoor/maleware

              Windows Defender caught it for me, I'm running 64 bit so i guess it didn't actually run but it was still there.

              A registry cleaner gets bought out by an anti virus company and spreads malware to its users. Who watches the watchmen I guess.
              Last edited by DieHardYankee26; 09-19-2017, 07:56 AM.
              Originally posted by G Perico
              If I ain't got it, then I gotta take it
              I can't hide who I am, baby I'm a gangster
              In the Rolls Royce, steppin' on a mink rug
              The clique just a gang of bosses that linked up

              Comment

              • slickdtc
                Grayscale
                • Aug 2004
                • 17125

                #8
                CCleaner silently compromised, contains backdoor/maleware

                Originally posted by DieHardYankee26
                A registry cleaner gets bought out by an anti virus company and spreads malware to its users. Who watches the watchmen I guess.


                Strange isn't it?

                I was going to make a joke here about how I use Avast and it is Russian-based (which I was mistaken about, it's Czech-based), which just seems sketchy. When I went to fact check myself, I found out who the anti-virus company was that bought CCleaner (Piriform) -- Avast. D'Oh!
                NHL - Philadelphia Flyers
                NFL - Buffalo Bills
                MLB - Cincinnati Reds


                Originally posted by Money99
                And how does one levy a check that will result in only a slight concussion? Do they set their shoulder-pads to 'stun'?

                Comment

                • SuperBowlNachos
                  All Star
                  • Jul 2004
                  • 10218

                  #9
                  Re: CCleaner silently compromised, contains backdoor/maleware

                  They were recently bought out by Avast. Expect it to seriously go downhill and also start giving you a pop up every day.

                  Comment

                  • AlexWilliams20
                    Rookie
                    • Jul 2020
                    • 6

                    #10
                    Re: CCleaner silently compromised, contains backdoor/maleware

                    Is this a problem on a 32 bit Windows? As much as I know it may cause issues on a 64 bit Windows, but I'd better check. As much as I know CCleaner was considered the best registry cleaner and the most used among users all over the world, so I don't think it might be compromised. Maybe this is just a strategy of the competition to discredit it or something like this, but from what I've seen online a lot of people still use this and have no issues. I'll still check this, but these are just my thoughts about this.

                    Comment

                    Working...