SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics > PC Hardware/Software forum
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 09-18-17, 10:23 AM   #1
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 40,510
Downloads: 9
Uploads: 0


Nuke Warning: CCleaner is malware-infested

http://blog.talosintelligence.com/20...s-malware.html

http://www.piriform.com/news/blog/20...-windows-users

My cold-hearted advise if you are affected: system reinstall. A system that got compromised, must still be considered to be compromised after any "cleanings", "repairs", or whatever. The only way to deal with a bug and be certain, is to nuke the whole system from orbit.

Note that Talos (first link) disagrees with Piri (second link) on the ammount of damage done. Talos says it potentially could be an immense number of users, Piri says the threat was tackled before it could do damage. Of cpourse, Piri has its own reputation to protect here, Talos is a neutral third party.

I believe I understood it like this: a completely infested version of CCleaner was spread via a manipulated servers of theirs, and so the malware must have reached millions and millionsn of users, see the link for affected version and date. The malware scanned the infested systems, extracted data and downloaded additional malware, which was probbaöly the intended "warhead" to detonate. But if Piri is right, then this malware never got activated, they switched off the rogue server fast. Which means that affected people have downloaded-for-sure, but non-activated malware on their machines now. Their systems probably got scanned and data was extracted. The additonal downloaded malware, the warhead, is still there.

Well, believing is not knowing. So expect the worst. Nuke it. From orbit.

P.S. Note that the critical version of CCleaner was distributed for almost a full month. Thats damn many systems affected.
__________________
If you feel nuts, consult an expert.

Last edited by Skybird; 09-18-17 at 11:08 AM.
Skybird is offline   Reply With Quote
Old 09-18-17, 11:04 AM   #2
THEBERBSTER
Growing Old Disgracefully
 
THEBERBSTER's Avatar
 
Join Date: Dec 2012
Location: Dibden Purlieu - Southampton
Posts: 9,605
Downloads: 1123
Uploads: 0


Default

I have used CCleaner everyday for many years without any problems and also have recommended it many times here on Subsim.
Like any application on your system it is open to attack.
While this may sound alarming those at CCleaner have rectified the problem without any serious incidents having taken place.
I am running the later 6207 version but is quite likely that at some point I also have used the 6162 corrupted version.
While anti virus may give protection it is better to back it up with a specific malware/spyware program installed.

I would suggest installing this free program which was recommended and installed by my computer shop.
It will identify any threats which you can quarintine.
https://www.malwarebytes.com/mwb-download/
Peter

Last edited by THEBERBSTER; 09-18-17 at 12:46 PM.
THEBERBSTER is offline   Reply With Quote
Old 09-18-17, 12:07 PM   #3
aanker
Pacific Thunder
 
aanker's Avatar
 
Join Date: Apr 2004
Location: Yellow Sea
Posts: 1,896
Downloads: 236
Uploads: 14


Default

I have used Ccleaner Pro for years too. I noticed that 6207 was released fast on the heels of the previous version.

Thanks for the link Peter, and thanks for the alert Skybird.
aanker is offline   Reply With Quote
Old 09-18-17, 03:42 PM   #4
propbeanie
CTD - it's not just a job
 
propbeanie's Avatar
 
Join Date: May 2016
Location: One hour from Music City USA!
Posts: 9,749
Downloads: 440
Uploads: 2


Default

My gosh. This is getting old, having to search through all of my computers and look for issues with a program that I've trusted and used for years... I did just recently download a newer version of it, but I do not remember which box it was... I know what I'm doing tonight... Thanks Skybird and THEBERBSTER...
__________________

"...and bollocks to the naysayer/s" - Jimbuna
propbeanie is offline   Reply With Quote
Old 09-18-17, 04:16 PM   #5
mapuc
Fleet Admiral
 
Join Date: Sep 2003
Location: Denmark
Posts: 17,905
Downloads: 37
Uploads: 0


Default

Earlier today I got the information from a computer page on FB-It was said, from my memory-It's only those who have a 32-bit computer system

and they should reinstall Windows.

People asked on 64-bit system and was told that they haven't heard anything about this type of system.

I don't have this CC-cleaner.

Markus
mapuc is offline   Reply With Quote
Old 09-18-17, 04:25 PM   #6
THEBERBSTER
Growing Old Disgracefully
 
THEBERBSTER's Avatar
 
Join Date: Dec 2012
Location: Dibden Purlieu - Southampton
Posts: 9,605
Downloads: 1123
Uploads: 0


Default

Hi Mapuc
I have a 64 bit system and Malwarebytes picked up and quarantined Ccleaner malware when I ran it.
Peter
THEBERBSTER is offline   Reply With Quote
Old 09-18-17, 04:27 PM   #7
STEED
Lucky Jack
 
Join Date: Jan 2006
Location: Down Town UK
Posts: 27,695
Downloads: 89
Uploads: 48


Default

Looks like my laptop is in the clear.

V5.155513(64bit)

But my desktop has

V5.33.6162(64bit) Same version number that is infected but the artical states (32bit) so have I got it or not?

UPDATE

I have rolled back my system to July 31st and Removed that version of Ccleaner off my desktop.

Malwarebytes Anti rootkit. ALL CLEAR

Malwarebytes custom scan and threat scan. ALL CLEAR

Avast smart scan. ALL CLEAR

Avast rootkits full scan. ALL CLEAR
__________________
Dr Who rest in peace 1963-2017.

To borrow Davros saying...I NAME YOU CHIBNALL THE DESTROYER OF DR WHO YOU KILLED IT!

Last edited by STEED; 09-18-17 at 08:02 PM.
STEED is offline   Reply With Quote
Old 09-18-17, 05:51 PM   #8
aanker
Pacific Thunder
 
aanker's Avatar
 
Join Date: Apr 2004
Location: Yellow Sea
Posts: 1,896
Downloads: 236
Uploads: 14


Default

I don't think you need to worry now. To be safe, update to the latest release.

From: https://www.askwoody.com/
Quote:
CCleaner back door / botnet infection updates

Bottom line: If you installed CCleaner any time after Aug. 15, you need to install the latest version.

Avast bought Piriform (and CCleaner) in July. The malware was inserted into the installer in August. The botnet Command center was taken down in September.

Oy. Don’t use registry cleaners, OK?
Earlier I read if you updated to a later - the most recent version you'd be in the clear.

Furthermore the payload had been neutered before it was released in the bad version. It never phoned home and 'home' for it doesn't exist. We got lucky.

I updated past the infected version last week and users that do will be OK for sure. It is harmless now and from what I read earlier it always was. I hate it when something you trust does something like this though.
aanker is offline   Reply With Quote
Old 08-20-18, 08:22 AM   #9
CTU_Clay
The Lone Wolf
 
CTU_Clay's Avatar
 
Join Date: May 2006
Location: Bellville, TX 77418
Posts: 710
Downloads: 315
Uploads: 0
Default

Quote:
Originally Posted by Skybird View Post
http://blog.talosintelligence.com/20...s-malware.html

http://www.piriform.com/news/blog/20...-windows-users

My cold-hearted advise if you are affected: system reinstall. A system that got compromised, must still be considered to be compromised after any "cleanings", "repairs", or whatever. The only way to deal with a bug and be certain, is to nuke the whole system from orbit.

Note that Talos (first link) disagrees with Piri (second link) on the ammount of damage done. Talos says it potentially could be an immense number of users, Piri says the threat was tackled before it could do damage. Of cpourse, Piri has its own reputation to protect here, Talos is a neutral third party.

I believe I understood it like this: a completely infested version of CCleaner was spread via a manipulated servers of theirs, and so the malware must have reached millions and millionsn of users, see the link for affected version and date. The malware scanned the infested systems, extracted data and downloaded additional malware, which was probbaöly the intended "warhead" to detonate. But if Piri is right, then this malware never got activated, they switched off the rogue server fast. Which means that affected people have downloaded-for-sure, but non-activated malware on their machines now. Their systems probably got scanned and data was extracted. The additonal downloaded malware, the warhead, is still there.

Well, believing is not knowing. So expect the worst. Nuke it. From orbit.

P.S. Note that the critical version of CCleaner was distributed for almost a full month. Thats damn many systems affected.
Is CCleaner still infected as earlier reported?
__________________
"The Lone Wolf"]
https://steelsharksforum.proboards.com/

“Keep your eyes on the stars, and your feet on the ground.” .
CTU_Clay is offline   Reply With Quote
Old 08-20-18, 08:34 AM   #10
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 40,510
Downloads: 9
Uploads: 0


Default

Don't know, don't care, I just use a very old version to easily delete temp files, and do no updates anymore.


Updates to Windows 10 and software runnign under Windows seem to be a bigger and bigger risk in temselves. I do not even use a dedicated security suite for my Windows 10 machine anymore, just the Windows 10 Defender onboard thing. But then, my W10 machine is exclusively a game console.



Compared to what the rules were 5 and 10 years ago, upsides have been turned down, and things were u-turned. Who would claim he saw it coming in this excessive level of distortion? Not before W8 was released I understood where things were heading.
__________________
If you feel nuts, consult an expert.
Skybird is offline   Reply With Quote
Old 08-20-18, 12:43 PM   #11
THEBERBSTER
Growing Old Disgracefully
 
THEBERBSTER's Avatar
 
Join Date: Dec 2012
Location: Dibden Purlieu - Southampton
Posts: 9,605
Downloads: 1123
Uploads: 0


Default

Hi CTU
No, as soon as it became known they updated to a clean application.
Peter
THEBERBSTER is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 08:46 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright © 1995- 2024 Subsim®
"Subsim" is a registered trademark, all rights reserved.