Live data from Hacker News

Malware identified in CCleaner 5.33

blog.talosintelligence.com

21–30 of 229 posts

Re: Malware identified in CCleaner 5.33

#22
So it was only the 32-bit executable that was affected?

By default CCleaner installs both the 32-bit and 64-bit versions, however on 64-bit systems it only runs the 64-bit executable and points every shortcut it makes to the 64-bit executable.

On one of my affected systems that appears to have had 5.33 installed, I noticed no registry keys that appear to be created and that system never ran the 32-bit executable.

Would it be safe to assume it's not affected and simply uninstalling CCleaner 5.33 is enough?

Piriform seems to suggest that only some useless system information was ever released by the compromised version. The general worry is that it wasn't just that information, but also other more important things like account logins and such.

Re: Malware identified in CCleaner 5.33

#23
As a kid, the only OS I was aware of was Windows. Once, my computer was infected to the point where it was almost unusable. A more experienced friend suggested a non-free antivirus and the CCleaner. After a lot of effort, I could get my machine back to working, but it became so slow that it led me to discover Linux. Now, on a Windows 10 machine, I’ve nothing but Defender, and since the aforementioned experience I’ve never had to use any other antivirus, a ‘junk’ cleaner, etc. Once bitten, twice shy :)

Edit: I hated investing in anti-stuff.

Re: Malware identified in CCleaner 5.33

#25

Just Wow. I am happy now that I haven't updated my installation of ccleaner for over a year and so I am safe.

I'm happy I'm not using Windows XP so I don't need this crapware anymore because Windows10 runs fast w/o it.

Well, if you're about to use Malwarebytes / Rogue Killer / ZHP Cleaner, you will win hours by cleaning all these temporary files before a scan.

Re: Malware identified in CCleaner 5.33

#26

As a kid, the only OS I was aware of was Windows. Once, my computer was infected to the point where it was almost unusable. A more experienced friend suggested a non-free antivirus and the CCleaner. After a lot of effort, I could get my machine back to working, but it became so slow that it led me to discover Linux. Now, on a Windows 10 machine, I’ve nothing but Defender, and since the aforementioned experience I’ve…

I rescued my neighbor's Mac from an adware invasion using Malwarebytes so I I would argue that not all these tools are created equal.

Re: Malware identified in CCleaner 5.33

#27

As a kid, the only OS I was aware of was Windows. Once, my computer was infected to the point where it was almost unusable. A more experienced friend suggested a non-free antivirus and the CCleaner. After a lot of effort, I could get my machine back to working, but it became so slow that it led me to discover Linux. Now, on a Windows 10 machine, I’ve nothing but Defender, and since the aforementioned experience I’ve…

Years ago I used to use CCleaner and their disk defragmentor tool. Now I too am on Windows 10 and use neither, still it's sad to see this sort of thing happen to what I remember being decent free software.

Re: Malware identified in CCleaner 5.33

#28
post #22

So it was only the 32-bit executable that was affected? By default CCleaner installs both the 32-bit and 64-bit versions, however on 64-bit systems it only runs the 64-bit executable and points every shortcut it makes to the 64-bit executable. On one of my affected systems that appears to have had 5.33 installed, I noticed no registry keys that appear to be created and that system never ran the 32-bit executable. Wou…

> Would it be safe to assume it's not affected

Well, it would be many things, but it wouldn't be "safe". Not a tinfoiler, just a pedant :) I could go with "reasonable".

Re: Malware identified in CCleaner 5.33

#29

There has been a number of cases of installers from trusted developers being infected lately. (For example Transmission being infected twice...) On our side (developers) we need to be careful with this idea that "we will know" when something is wrong and be more careful when deploying software. It would also be nice if some form of tool could be used to test a binary to make sure it only contains what it should conta…

I'm not sure how exactly these infections work, but one method would be to infect the developers' PCs. In which case you essentially can't trust anything. You'd need some kind of byzantine fault tolerance (mandatory multi-person code review?) to be sure nothing like this ever happens What makes this scary is that, as far as I know, pretty much no software has that kind of security, and there are several pieces of wid…

You can enable AppLocker and have explicit control on what executes and what not by creating rules. I know quite a few companies that enforce its use in their employees' PCs.
Post reply on HN