Live data from Hacker News

Malware identified in CCleaner 5.33

blog.talosintelligence.com

221–229 of 229 posts

Re: Malware identified in CCleaner 5.33

#222
post #22

So it was only the 32-bit executable that was affected? By default CCleaner installs both the 32-bit and 64-bit versions, however on 64-bit systems it only runs the 64-bit executable and points every shortcut it makes to the 64-bit executable. On one of my affected systems that appears to have had 5.33 installed, I noticed no registry keys that appear to be created and that system never ran the 32-bit executable. Wou…

I believe that it was just the 64-bit version. See their twitter reply:

https://twitter.com/piriform/status/910098222051446784

'The 64-bit version of CCleaner v5.33.6162 was not affected but we encourage all users to update to the latest version, 5.24.'

Re: Malware identified in CCleaner 5.33

#224

Earlier quoted context omitted.

On the note of ISA cards, i once helped install a card on some school computers that inserted itself before the OS loaded and split the HDD in half. This so that on certain conditions a clean version of the OS etc could be loaded from the half that was hidden during normal use.

DeepFreeze? I thought it was all software.

Do not recall the brand, i just helped install them and set up the initial install of OS and software.

Re: Malware identified in CCleaner 5.33

#226
post #140

Earlier quoted context omitted.

The Intel integrated graphic card of my laptop does handle 3 screens fine and I dont need to mess with drivers, everything works well out of the box. I would actually advise against NVIDIA cards unless you need powerful graphic processing or to do GPU computation.

Cool. Didn't know laptops existed with 3 monitor ports. Which model laptop are you using, and would you recommend it for programming? :)

Ahhh, doing some Googling shows it's from add-on peripherals and/or docking stations. eg:

http://www.dell.com/support/article/uk/en/ukbsdt1/sln115952/...

Re: Malware identified in CCleaner 5.33

#227
Wow that's crazy, I was on the toilet just this morning running CCleaner on my phone as I do weekly and the thought momentarily crossed my mind that I shouldn't trust CCleaner on my phone (I limit my use of apps as much as I can) but my next immediate thought was, "Nah, this is Piriform we're talking about, they're one of the few free software developers I can probably trust to never inject malware into their products."

I mean, I guess that's still true since the build was compomised by an outside party, but it's still just an interesting moment of synchronicity.

Re: Malware identified in CCleaner 5.33

#228

Earlier quoted context omitted.

Don't go down that rabbit hole. Linux is not for desktop despite many years of efforts. Even the distro with the greatest focus on UI (elementaryOS) looks like a toy. That Linux is hugely successful everywhere EXCEPT in the desktop should tell us something. Just my honest opinion after 15 years of continuous use in university and work. XKCD still relevant today: https://xkcd.com/456/

> XKCD still relevant today and I wish this to be true for any *nix system. The ability to venture down the rabbit as far as you want, without black-boxes. I think a lot of us sit here today because of that privilege.

It absolutely has its place. That place just isn't the mainstream desktop consumer.

Re: Malware identified in CCleaner 5.33

#229

Earlier quoted context omitted.

For apps it supports, Ninite is a good way to avoid that kind of thing, although it may not have stopped the CCleaner issue. They package their installer with extraneous bundles removed.

I hope Ninite reads this and pulls them off their list of installers. It should be automatically removed from end users by Ninite as a direct response to this.

Well, it's not on the list currently, so either they never had it or they did indeed remove it.
Post reply on HN