Live data from Hacker News

Malware identified in CCleaner 5.33

blog.talosintelligence.com

91–100 of 229 posts

Re: Malware identified in CCleaner 5.33

#91
post #82

Earlier quoted context omitted.

Sourceforge revolutionizes open source by providing free hosting for projects! [later] Sourceforge - You will never find a more wretched hive of scum and villainy. [still later] Sourceforge is respectable again! (hopefully?)

> Sourceforge is respectable again! (hopefully?) When pigs fly. I cringe every time I encounter a project hosted on SF and have to play their stupid find the download link game.

Uh have you been there recently? Like in the past year? The company is under new management, and cleaned up their act and download pages a lot. Sourceforge is headed in a better direction again.

Re: Malware identified in CCleaner 5.33

#93
post #33

"CCleaner is an application that allows users to perform routine maintenance on their systems ." It's 2017, how is this still a thing?

> Given the presence of this compilation artifact as well as the fact that the binary was digitally signed using a valid certificate issued to the software developer, it is likely that an external attacker compromised a portion of their development or build environment and leveraged that access to insert malware into the CCleaner build that was released and hosted by the organization.

Did you read the article? It can happen to any company. It just so happens they targeted a very popular downloaded application. Who knows what other software installers have been compromised.

Re: Malware identified in CCleaner 5.33

#94

As a kid, the only OS I was aware of was Windows. Once, my computer was infected to the point where it was almost unusable. A more experienced friend suggested a non-free antivirus and the CCleaner. After a lot of effort, I could get my machine back to working, but it became so slow that it led me to discover Linux. Now, on a Windows 10 machine, I’ve nothing but Defender, and since the aforementioned experience I’ve…

The culprit was the non-free AV. Gone are the days of simple passive signature scanners. Now they all sink their claws deeply into the OS intercepting filesystem operations, network packets, and any other privileged activity. Performance be damned.

> The culprit was the non-free AV.

Yes it was. After using it a couple years, when I decided to get it off my system, it was far from easy. It simply didn't go. Because of the trouble it was giving me, I thought I had no choice but to renew my subscription. It was at this point I started looking for an OS alternative.

Re: Malware identified in CCleaner 5.33

#95

As a kid, the only OS I was aware of was Windows. Once, my computer was infected to the point where it was almost unusable. A more experienced friend suggested a non-free antivirus and the CCleaner. After a lot of effort, I could get my machine back to working, but it became so slow that it led me to discover Linux. Now, on a Windows 10 machine, I’ve nothing but Defender, and since the aforementioned experience I’ve…

Feels like you've vaccinated you brain and developed antibodies of security-conscious computer usage patterns.

[deleted]

Re: Malware identified in CCleaner 5.33

#96

With all these malware problems I look forward to more heavily sandboxed operating systems based on capabilities. Maybe Fuchsia will be that operating system, if it does not turn out to be a google spyware hell.

I think what you're looking for is Qubes OS https://qubes-os.org

Re: Malware identified in CCleaner 5.33

#97

Earlier quoted context omitted.

> Sourceforge is respectable again! (hopefully?) When pigs fly. I cringe every time I encounter a project hosted on SF and have to play their stupid find the download link game.

Uh have you been there recently? Like in the past year? The company is under new management, and cleaned up their act and download pages a lot. Sourceforge is headed in a better direction again.

Yet while SourceForge improved, Slashdot became a clone of HN's front page and is a cesspool of horrid editing staff, now.

So take that as you will. That tells me that SourceForge is probably bound to degrade some time soon.

Re: Malware identified in CCleaner 5.33

#98

Earlier quoted context omitted.

I’m not a gamer. Also, I can’t recommend using or not using Defender. For aimless browsing I use my Linux box, and one of my favorite browser extensions is uBlock Origin. Nowadays I don’t have to carry flash drives or other storage devices and never plug in things that belong to others :)

Do you never run software you haven't written/audited?

I do, but I try to see if it's from a trustworthy source.

Re: Malware identified in CCleaner 5.33

#99
post #22

So it was only the 32-bit executable that was affected? By default CCleaner installs both the 32-bit and 64-bit versions, however on 64-bit systems it only runs the 64-bit executable and points every shortcut it makes to the 64-bit executable. On one of my affected systems that appears to have had 5.33 installed, I noticed no registry keys that appear to be created and that system never ran the 32-bit executable. Wou…

"By default CCleaner installs both the 32-bit and 64-bit versions"

So the default for CCleaner, which is supposed to get rid of old system bloat and cruft, is to be bloaty and crufty, and install versions of itself the system does not need or can not use?

Re: Malware identified in CCleaner 5.33

#100

With all these malware problems I look forward to more heavily sandboxed operating systems based on capabilities. Maybe Fuchsia will be that operating system, if it does not turn out to be a google spyware hell.

Isn't that what Microsoft are attempting with the Windows Store?

IIRC Windows Store apps don't run in the same way as regular Windows applications, they run in a sandbox.

Post reply on HN