CCLEANER HACKED- BACKDOOR INSERTED

CCleaner was hacked and malware inserted into CCleaners code, even if you got ccleaner from their website you're still infected.

I suggest you run virus scans. Windows Defender picked it up at first which is what made me curious, removed it, then i ran MBAM and it picked up more crap windefender left out.

"Security warning: Hackers compromised CCleaner and installed a backdoor"
>>betanews.com/2017/09/18/ccleaner-hacked-backdoor/

"Hundreds of thousands of computers getting penetrated by a corrupted version... ...it's becoming clear exactly how bad the results of the recent CCleaner malware outbreak may be. Researchers now believe that the hackers behind it were bent not only on mass infections, but on targeted espionage that tried to gain access to the networks of at least 20 tech firms."
>wired.com/story/ccleaner-malware-targeted-tech-firms/
>bleepingcomputer.com/news/security/ccleaner-hack-carried-out-in-order-to-target-big-tech-companies/

"CCleaner Command and Control Causes Concern"
>blog.talosintelligence.com/2017/09/ccleaner-c2-concern.html
Above is an amazingly awesome read BTW.

HOW TO REMOVE FLOXIF VIRUS INFECTED BY GENUINE CCLEANER
>bleepingcomputer.com/virus-removal/remove-floxif-ccleaner-trojan

Is it okay for OP to say... inb4 the russians did it?

Other urls found in this thread:

wired
unvis.it/wired.com/story/ccleaner-malware-targeted-tech-firms
betanews.com/2017/09/18/ccleaner-hacked-backdoor/
zdnet.com/article/windows-bloat-its-always-been-that-way/
twitter.com/SFWRedditGifs

>wired com/story/ccleaner-malware-targeted-tech-firms
unvis.it/wired.com/story/ccleaner-malware-targeted-tech-firms

holy shit that was a quick response

Do you know what the maleware does?

>These malicious versions were available for download between between August 15 and September 12.

inb4 Aug. 15, 2009 to Sept. 12, 2017

Wow, Thank You, I was thinking of downloading this program just now. I still have the page up. user you helped me dodge a bullet. Your Awesome!

I probably have like stage 10 aids from using ccleaner and firefox.

>mfw all the idiots download the latest version of it even though nothing actually needs to be updated
>They don't store a local copy on an external hard drive so that they can just copy it over every time they want to use it instead of downloading it
Plebs, the lot of you.

Most people are running the 64-bit version anyways...

>the Floxif Trojan was bundled with 32-bit versions of CCleaner 5.33.6162 and CCleaner Cloud 1.07.3191 that were available between August 15 and September 12.
tfw 64-bit.

Are you good if you have an old version? I haven't updated in months.

What if youre running a 3 year old version?

You're a retard for even using programs like this. What the fuck did you think would happen with a 'registry cleaner'

>using CC cleaner....

I have no words anyone who still uses that garbage asked for this to happen to them.

It's basically one of the few programs that helps fight windows bloat, what is your problem.

I'm not a computer expert but as far as I know the backdoor does some keylogging (those links are some long reads and the Talos intelligence is probably the best of those links) but it was really meant to compromise systems by "Intel, Google, Microsoft, Akamai, Samsung, Sony, VMware, HTC, Linksys, D-Link and Cisco" and they apparently were successful in penetrating. It gathers info from your system and sends it back to the hackers servers (im nto sure what info if passwords or CC information), it also has the ability to download, modify and install/run binaries. Again its a long read but it all looks like negative shit i dont want on my pc.

Glad to help! its apparently been patched with a new digital signature and all so its assumed safe again for now though. (i like the app- its really useful, i updated to the newest version)

You and me both, i run it religiously almost daily.

This! So much! i read that info about 32bit being infected.... yet I run 64bit.... and i just got done removing the fucking thing! da fuq!? i wouldnt trust the "if ur using 64-bit ur safe" mentality. Scan your shit up!

For me it popped up as "Floxif" under windows defender.

Why even run a program to protect your privacy.
Pointless really I don't really care if the FBI knows I'm gonna bomb the CIA. I bet the FBI wants that tho. Better to let them know ahead of time otherwise it wont be any fun. And if any CIA agents read this don't worry I'm actually bombing the FBI.

>g-guise ccleaner wuz hacked

t. pleb who isn't using Advanced System Care

Almighty one, care to elaborate, or are you just going to namefag and shitpost?

It removes cookies and can overwrite your hard drive. You'd be completely retarded to use Sup Forums without it.

I run 64-bit but I got infected anyway.. I would err on the side of caution and run an antivirus.

Lol its a firefox plugin.
also
>not knowing how to clear your registry without an external program.

it's just a first stage recon tool for the chinese

it picks up your running processes, if you're running as an admin, your domain, your machine name, and then passes it to a C2 somewhere. if you're running a machine connected to any domain in pic related it will serve a second stage to you

just install a new copy of windows if you're really scared, i do that every 3-4 months

I bet it was the British GCHQ that hacked American companies this time around.

Possibly Germany too.

Just because some British nigger hackers fuck around with CCleaner.

That's a good one. The RAM cleaner has a screenshot thing in it. wisecare is also good.

Are you an AI?

what fucking bloat?

you're retarded enough to even let your browse store cookies you deserve the malware you were infected with

i like how they're targeting the windows nt dev team at microsoft in particular. i bet they're going to try and one-up russia with the mother of all supply chain attacks.

Fucking windows

You don't even need it anymore. Everything it does has a Windows build in function.
>Delete Temp files
>Defragment
Registry cleaning is redundant

>5.33+ 32bit
>have 5.09 64bit
>rarely use it anymore
im good, i have recently done a scan too

Windows doesn't have an overwrite as far as I'm aware.

What more need a to be said?

The whole software is a fucking joke. Cleaning up registries? Jesus Christ I'm glad I saved 2 whole mb from 10 years of unused registries on my XP install.

It's literally memeware. Sure it has an actual function but at the end of the day it's a mute point. It's more effective to just reinstall Windows every few years.

Any increase in speed you perceive from running this software is legit just placebo unused registries have 0 effect on your computer. If there was any speed increase there is a bigger underlying problem with your OS and at that point a reinstall is the real solution.

>betanews.com/2017/09/18/ccleaner-hacked-backdoor/
>We would like to apologize for a security incident that we have recently found in CCleaner version 5.33.6162
>Check my version because I never update
>Mfw when running version 5.26.5937

spoopy, i install it two years ago to the day

Overwrite what? Keep in mind I haven't used it in 3 years

zdnet.com/article/windows-bloat-its-always-been-that-way/
There's a reason why the more you use the windows the slower it gets.

what if mbam and where do I get it?

Windowslets. When will they learn.

>There's a reason why the more you use the windows the slower it gets.
no it doesnt you just keep on installing useless shit that runs in the background like cccleaner and you're article is shit, it doesnt list any bloat it is just some boomer whining.

You mean Secure Delete? Use SDelete from Microsoft website. It's a cmd tool

I've noticed my computer is taking forever to startup recently. I'm thinking this has something to do with it,

>using CCleaner
>using Windows
Sup Forums is really retarded

They won't

>mfw running 5.9.0.5343

Thank god I never update anything.

Use BleachBit

I actually might do that, its just a PITA because I run DBAN before every fresh reinstall and it takes about 24-26 hours to finish.

Calm down Pajeet, no one's going to stop using Windows because of bloating anytime soon.

It was Israel

...

who the hell would use cc cleaner anyway

nice political thread, OP. ya dingus

Does blocking the CCleaner from accessing the internet do anything to stop the malware?

pic related, how you bypass Piriform's automatic update checks when you run pirated version of their programs.

Scan your computer.
If nothing. Defragment and use junk removal build in tool every Windows has from Vista onwards

what if I never updated CCleaner?

Im gonna go fap now

I have >40 windows VMs running right now you retard. most with a single CPU core and 1GB ram. you're the idiot who is using malware infested software because he doesnt know how to use his computer

5.31.6105 here

why is this posted on Sup Forums and not on Sup Forums???

It was posted on Sup Forums a week ago. It's old news

oh, ok
i missed it
ty, leaf

>I'm running a Windows operating system on 1 GB of RAM!
Uh...

>3 years
It's had it longer
>Overwrite what
Ccleaner has a tool overwrite your hard drive. Either fully or just free space, with passes ranging from one to 35(gutsman).

Back then they even named each of those pass options after the organizations that could repair and decipher them but then after an update they renamed them since they made the program sound malicious.

>32 bit versions

Whew.. dodged a bullet

My favourite Windows cleaner is that one that deletes system32.

We have been deploying CCleaner onto all out client endpoints for years, piece of shit software anyway.

Luckily the AV we also deploy had updated their definitions in time to isolate it

Windows runs just fine on 1GB RAM, pic related.

only one version was affected, and it was a 32bit build

>not relying purely on combofix and common sense

dumbasses

yeah goy just use (((antiviruses))) for only 3 gorillion shekels to protect yourself trust me you stupid goy

Have you tried new headless Windows without GUI completely?

Well yeah most the server roles you have running their will run fine with 1GB, wouldn't recommend it on a workstation though

I've noticed that the wiping the disk option is entirely useless with SSD drives. I'm guessing with SSD when you delete a file it gets removed completely, not just a pointer to it in a table somewhere. Tested it out by deleteing a file and then using Recuva, nothing came up.

there*

Heh.

"Interestingly, this configuration specifies 'PRC' as the time zone, which corresponds with People's Republic of China (PRC)."

I can't tell whether China is being framed in such a retarded manner... or it actually is China operating with the assumption that nobody would assume it would be that stupid.

Why are you using SSD for anything other than vidya?

Just pirate it. Or you're too stupid to do even that?
np

Use SDelete from Microsoft a cmd tool, you pleb

No I dont use Nano, and Microsoft killed it off a few months ago anyways. Most of my VMs are Core editions, and I only use the Desktop Experience editions when software forces me to like SharePoint or Exchange Server.

The type of people who can afford workstations hopefully know enough about computers to not use cccleaner

Because it can be faster and has no mechanical moving parts, my case is cramped and HDD's were adding 5 to 10 degrees celsius to the internal temperature.

I first noticed an issue with "Windows Wireless LAN 802.11 Extensibility Framework" using a shit ton on CPU, I was wondering why my fan kept running b/c my laptop is pretty fast and i kept ending the process and manually restarting it for a few times... then I went to update windows manually and I see a warning saying I've got to restart... i open windows defender and thats when i realize this whole mess.


Is "Windows Wireless LAN 802.11 Extensibility Framework" using a lot of cpu on ur machine?

Gotcha, work in DataCenter, was wondering about that.

Fuck sake.
Cheers user ill get on that now

>From microsoft
Why are you passing this off as a good thing?

Why is their logo the same as heroes of the storm

sdelete works fine you retard. i use it all the time to shrink thin provisioned disks.

Don't forget And

i hate apple only because it was such a PITA using the old school macintosh back in the 90's.. never cared for it again. Linux can be quite the challenge if you just want something that starts up and works decently well and you dont have to do a lot of manual shit to get it doing what u want. I'd love it if a new...more security hardened, modern OS came around. ....one that supports my NVIDIA graphics card without being a FUCKING BITCH to get working. What are you running?

I haven't updated CCleaner in ages. Am I still at risk?

I am also using the 64bit client

Do you play around with Azure very much? We get Microsoft credits that top up monthly that let us run or or two Azure servers, very low spec ones though.

Hey me too. Feels good not being infected. I run scans everyday with Windows Defender and Malware Bytes.

wow, not even downloading some common software from a legit source it's safe.

makes you wonder how bugged is a typical system

It has a Source Code and gets updated? Plus you can verify you're not getting it from sourceforge type websites.

I think it's a win win

No I havent used Azure or AWS at all.

hey man... it looks like the chinese or a nation-backed group of hackers was able to penetrate systems owned by US, Japan, S. Korea and Germany (if not others)... Theres plently of Sup Forums worthy discussion here.

Anyone recall Putin a few weeks/days ago stating that "the nation that masters AI first will rule the world" or some crap? And then russia and china started working together on such projects... Plenty of Sup Forums worthy discussions to be had..

No, it only affected 32-bit users. Us 64-bit users are golden.

Good morning, Norbro. Is there a reason you didn't use archive.is. I use that because of you. Should I switch?

i actually have a pirated version of ccleaner... i though the infection came from the hack.... just go to piriform's website... click downloads and download the ccleaner pro trial... install it and the old hack should stick. no need to find a new crack... update it via the download and install.

Not politics, you piece of shit

This isn't Sup Forums and you fags aren't talking about anything politically related to this incident

Fuck off

Windows 10 protects everyone from this.

Windows Defender is all you need.

Microsoft is pushing Windows Defender to coroproate now too.

Also, Windows Defender is better than other malware detectors because Microsoft has access to unique data the other vendors don't have access too.

Also, no popups which is great

>Doesn't know how to use his computer
>Meanwhile I'm writing extremely low level programs
>And you're using a fucking Mac machine
>Everyone was talking about end-user systems not servers originally
Oh boy really gave me a chuckle there, user. Really showed me.