Live data from Hacker News

Malware identified in CCleaner 5.33

blog.talosintelligence.com

201–210 of 229 posts

Re: Malware identified in CCleaner 5.33

#201

It's also worth noting that the default installer for CCleaner automatically installs Chrome and sets it as the default browser with no notification in the default process. Unless you click "More..." from one of the screens, then it tells you. At least it was like this two weeks ago. Had to uninstall bundleware Chrome again from multiple family members' PCs.

FYI, BleachBit is a (FLOSS) alternative to ccleaner, that works pretty well.

Re: Malware identified in CCleaner 5.33

#202

Earlier quoted context omitted.

The culprit was the non-free AV. Gone are the days of simple passive signature scanners. Now they all sink their claws deeply into the OS intercepting filesystem operations, network packets, and any other privileged activity. Performance be damned.

Gone are the days of simple passive signature scanners. Now they all sink their claws deeply into the OS intercepting filesystem operations, network packets, and any other privileged activity. Well, things have been like that for a long time already. E.g. Thunderbyte used an ISA card in the early 90ies to insert itself before and outside the operating system [1]. Old anti-virus programs also used Terminate and Stay R…

On the note of ISA cards, i once helped install a card on some school computers that inserted itself before the OS loaded and split the HDD in half. This so that on certain conditions a clean version of the OS etc could be loaded from the half that was hidden during normal use.

Re: Malware identified in CCleaner 5.33

#203
post #193

Earlier quoted context omitted.

Google pays companies to do new installs of Chrome. They're supposed to make it explicit, but Google doesn't really police it. It's usually via 'dark patterns' as it is with most free Windows antivirus apps where it shows a small indication at the bottom of the screen on a window that's about something else. For example, Avast sneaks it in as part of an automatic update on the Continue window: https://i.imgur.com/NIZ…

"Don't be evil" Even if it is explicit the idea is to have it enabled by default so people accidentally install it and then hopefully start using it. Which browser dominates should be based on its quality not how much money you spend on it :/

Having chrome installed by whatever [dark] pattern is at least putting it on an even footing with the platform's default browser - for those who would never proactively change their browser, this at least is closer to such a browser meritocracy.

Re: Malware identified in CCleaner 5.33

#204
post #43

Earlier quoted context omitted.

Malwarebytes is great. However, what if it was their installer that was attacked in such fashion? Trusting old memories of what's good or not can be dangerous. I remember getting caught out once by CoreTemp which suddenly packed a load of dung in its default installer. :(

For apps it supports, Ninite is a good way to avoid that kind of thing, although it may not have stopped the CCleaner issue. They package their installer with extraneous bundles removed.

I hope Ninite reads this and pulls them off their list of installers. It should be automatically removed from end users by Ninite as a direct response to this.

Re: Malware identified in CCleaner 5.33

#205
post #193

Earlier quoted context omitted.

"Don't be evil" Even if it is explicit the idea is to have it enabled by default so people accidentally install it and then hopefully start using it. Which browser dominates should be based on its quality not how much money you spend on it :/

Having chrome installed by whatever [dark] pattern is at least putting it on an even footing with the platform's default browser - for those who would never proactively change their browser, this at least is closer to such a browser meritocracy.

What about putting it on an even footing with Firefox, because currently that's its biggest competitor.

The thing is with Firefox that if it's on your computer is most likely because you installed it yourself.

Re: Malware identified in CCleaner 5.33

#206
post #193

Earlier quoted context omitted.

"Don't be evil" Even if it is explicit the idea is to have it enabled by default so people accidentally install it and then hopefully start using it. Which browser dominates should be based on its quality not how much money you spend on it :/

Having chrome installed by whatever [dark] pattern is at least putting it on an even footing with the platform's default browser - for those who would never proactively change their browser, this at least is closer to such a browser meritocracy.

Every one of my family members I have to uninstall it for is already running a fully-up-to-date copy of Firefox. The question is usually "why does the web look different?" or "why does Firefox have a rainbow ball now?".

Re: Malware identified in CCleaner 5.33

#207

It's also worth noting that the default installer for CCleaner automatically installs Chrome and sets it as the default browser with no notification in the default process. Unless you click "More..." from one of the screens, then it tells you. At least it was like this two weeks ago. Had to uninstall bundleware Chrome again from multiple family members' PCs.

FYI, BleachBit is a (FLOSS) alternative to ccleaner, that works pretty well.

That's why I package it for our PortableApps.com users! https://portableapps.com/apps/utilities/bleachbit_portable

Re: Malware identified in CCleaner 5.33

#208
post #185

Earlier quoted context omitted.

Categorically disregarding the use of automated maintainence tools under the guise of "lazy vs real techies" seems short sited, arrogant, and regressive.

It may be more expensive but hand-crafted, artisanal system administration is well worth it. The difference between it and cheap, factory produced system administration is night and day. Also, it's Local and Made In The USA so you are helping people around you in the greatest nation on earth rather than poor people in another country.

If being some sort of sysadmin craftsman gets you up in the morning, all the power to you. But for many others, "good enough" really is good enough.

Re: Malware identified in CCleaner 5.33

#209

It's also worth noting that the default installer for CCleaner automatically installs Chrome and sets it as the default browser with no notification in the default process. Unless you click "More..." from one of the screens, then it tells you. At least it was like this two weeks ago. Had to uninstall bundleware Chrome again from multiple family members' PCs.

The VLC authors also report that Google tried to pay them quite huge amounts to include Chrome as well: https://www.youtube.com/watch?v=jWx1P93nS0c&t=48s

With Google’s recent actions, this makes Chrome literally into malware that your system’s AV should automatically detect and remove. If a significant amount of users gets the software without intending to, the install was malicious, and should be removed.

Re: Malware identified in CCleaner 5.33

#210

Earlier quoted context omitted.

hi-dpi is in a sad state right now. Fortunatly, there is good support for hidpi in wayland, and as things migrate that way it will get better. As for running windows apps....how much time do you want to waste? The only windows stuff I really run is games, and the way I do that is by running windows in a VM with the graphics card direct assigned. It works really well, and is super neat, but it was a huge pain in the a…

Exciting to hear about HighDPI support in Wayland. I had to switch back to windows after getting a 4k display because it's basically unusable for a 3 monitor setup on Ubuntu (1 4k + 2 1080s). We'll see in a month :)

If you give it another shot, make sure you are running Xwayland and that you aren't manually setting the scaling factor. In the current version, it will guess a scaling factor based on the DPI of each display, but if you manually set it it will be applied globally and you will be right back where you are now.
Post reply on HN