Unsolved

This post is more than 5 years old

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

3522

September 18th, 2017 05:00

WARNING: (32-bit) CCleaner v5.33.6162 compromised

CCleaner  v5.33.6162 (32-bit version) has been compromised (security-wise).    Anyone still using this particular version should upgrade to 5.34, which was released on 12 September.

The following was copied/pasted from http://www.piriform.com/news/release-announcements/2017/9/18/security-notification-for-ccleaner-v5336162-and-ccleaner-cloud-v1073191-for-32-bit-windows-users

Security Notification for CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 for 32-bit Windows users

We recently determined that older versions of our Piriform CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 had been compromised. We resolved this quickly and believe no harm was done to any of our users. This compromise only affected customers with the 32-bit version of the v5.33.6162 of CCleaner and the v1.07.3191 of CCleaner Cloud. No other Piriform or CCleaner products were affected. We encourage all users of the 32-bit version of CCleaner v5.33.6162 to download v5.34 here: download. We apologize and are taking extra measures to ensure this does not happen again.

Issue Summary: Our new parent company, the security company Avast, determined on the 12th of September that the 32-bit version of our CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 products, which may have been used by up to 3% of our users, had been compromised in a sophisticated manner. Piriform CCleaner v5.33.6162 was released on the 15th of August, and a regularly scheduled update to CCleaner, without compromised code, was released on the 12th of September. CCleaner Cloud v1.07.3191 was released on the 24th of August, and updated with a version without compromised code on September 15. The compromise could cause the transmission of non-sensitive data (computer name, IP address, list of installed software, list of active software, list of network adapters) to a 3rd party computer server in the USA. We have no indications that any other data has been sent to the server. Working with US law enforcement, we caused this server to be shut down on the 15th of September before any known harm was done. It would have been an impediment to the law enforcement agency’s investigation to have gone public with this before the server was disabled and we completed our initial assessment. Between the 12th and the 15th, we took immediate action to make sure that our Piriform CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 users were safe—we worked with download sites to remove CCleaner v5.33.6162, we pushed out a notification to update CCleaner users from v5.33.6162 to v5.34, we automatically updated CCleaner Cloud users from v1.07.3191 to 1.07.3214, and for users using Avast Antivirus, they received an automatic update.

We are continuing to investigate how this compromise happened, who did it, and why. We are working with US law enforcement in their investigation. A more technical description of the issue is on our Piriform blog at: www.piriform.com/news/blog. Again, we sincerely apologize for this and are committed to making sure nothing similar happens again. We encourage any user of the 32-bit version of CCleaner v5.33.6162 to download the latest version of Piriform CCleaner found here: www.piriform.com/ccleaner/download/standard.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 18th, 2017 07:00

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 18th, 2017 08:00

CCleaner, distributed by anti-virus firm Avast, contained malicious backdoor

Digitally-signed version of CCleaner 5.33 secretly stole information from users’ computers.

https://www.grahamcluley.com/ccleaner-backdoor/

12 Elder

 • 

45.2K Posts

 • 

172.6K Points

September 18th, 2017 11:00

Geez... but many thanks for the warning.  :emotion-3:

Is there any indication if this might include versions earlier than the one known to be compromised?  Might be worthwhile to check earlier versions since the hackers could have skipped a version or two before hacking 5.33.6162, to avoid detection.

I'm still running 5.30.6065 (Win 7, 32-bit)  which -hopefully- wasn't impacted. And guess I'll stay here for a while longer.

Sure hope they find out how this happened and chop somebody's fingers off at the elbows! :emotion-5:

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 18th, 2017 16:00

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 18th, 2017 16:00

12 Elder

 • 

45.2K Posts

 • 

172.6K Points

September 18th, 2017 17:00

Thanks for those links. What total mess!

Don't have the HKLM\SOFTWARE\Piriform\Agomo key on this 32-bit system. Never had 33.6162 and haven't updated to 5.34, which would -or not- have removed that key. So I should be ok, at least for now.

We obviously don't know if any prior versions were hacked which could have installed a registry key in some location other than under HKLM\SOFTWARE\Piriform\

What I'd really like somebody to do is install the hacked version on a PC where the firewall is set to "Ask Permission" for every process trying to phone home. Would that have identified the malicious process as CCleaner or as something else?

For now, I've set ZoneAlarm firewall to block all attempts by CCleaner to send outgoing data...

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

September 18th, 2017 19:00

I guess that explains why Malwarebytes 3 Premium blocked my access to CCleaner when I tried to run it earlier today, and quarantined the executable. I then ran the Kaspersky Virus Removal Tool for good measure: it found and quarantined the ccsetup installer.

The only systems I had with the guilty CC version were both 64 bit, but still ...

That is Strike one, Piriform/Avast.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 19th, 2017 04:00

I'm still running CCleaner v5.08 --- and in fact, the 64-bit version.   MBAM2 is letting it run... which I guess is good, since that version of CCleaner should be "clean".

12 Elder

 • 

45.2K Posts

 • 

172.6K Points

September 19th, 2017 11:00

since that version of CCleaner should be "clean".

How do we know MBAM2 can detect this malware even if it's there? Since everything that was supposedly installed by the hacked version was signed, would MBAM2 or any other protection suite see it as a threat?

Again, this is something for somebody to test: Install the hacked version on a 32-bit system and verify that the malicious key appears in the registry. Then run MBAM2 and see if it spots it or not...

If I had to bet, it won't catch the hack because -if it did- somebody out there in the CCleaner universe would have already been complaining about it, even before Piriform found it.

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

September 19th, 2017 13:00

MBAM has been detecting this backdoor registry signature since yesterday. The registry hack appears in both 32 and 64 bit versions, but is only active on 32 bit systems. (On my Win 7 64 bit system, I didn't bother to check for the registry hack, but MB 3 certainly quarantined the malware as soon as I tried to open CC).

See Malwarebytes blog:
blog.malwarebytes.com/.../

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 20th, 2017 10:00

CCleaner v5.35.6210 (released 20 Sep 2017)

- All builds signed with new Digital Signatures

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

September 21st, 2017 19:00

CCleaner malware outbreak is much worse than it first appeared

Microsoft, Cisco, and VMWare among those infected with additional mystery payload.
Dan Goodin - 9/21/2017, 5:43 PM

"Previously, researchers found no evidence that any of the computers infected by the booby-trapped version of the widely used CCleaner utility had received a second-stage payload the backdoor was capable of delivering. The new evidence—culled from data left on a command-and-control server during the last four days attackers operated it—shows otherwise."

Full read from Ars Technica:
arstechnica.com/.../

12 Elder

 • 

45.2K Posts

 • 

172.6K Points

September 22nd, 2017 12:00

CCleaner malware outbreak is much worse than it first appeared

Microsoft, Cisco, and VMWare among those infected with additional mystery payload.
Dan Goodin - 9/21/2017, 5:43 PM

"Previously, researchers found no evidence that any of the computers infected by the booby-trapped version of the widely used CCleaner utility had received a second-stage payload the backdoor was capable of delivering. The new evidence—culled from data left on a command-and-control server during the last four days attackers operated it—shows otherwise."

Full read from Ars Technica:
arstechnica.com/.../ 

Tend to doubt those big company targets are still using 32-bit PCs, so was the claim that this only impacted 32-bit systems just a ruse to hide that something is actually going on inside 64-bit systems..???  :emotion-3:

And maybe you'll want to remove ccleaner from your list of "protections" in your sig..?  :emotion-4:

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

September 23rd, 2017 02:00

And maybe you'll want to remove ccleaner from your list of "protections" in your sig..?  :emotion-4:

Actually, I have no plans to dump CCleaner from my machines, or from my sig. CC has no "security" functions (apart from cleaning temporary internet files, where malicious programs and code sometimes reside). It is just a housecleaning utility I have found useful over the years. I base this decision to keep it on the fact that:

- This is the first grief CC has ever given me over many years. I use the word "grief" advisedly, since all it involved was the need to upgrade to a new version. I have no evidence my 64 bit PCs were compromised, and the question remains moot.
- To date, only some 20 individual PCs (out of millions) have been found to be compromised, and all appeared to have been targeted at big name corporations. Avast admits the true number may be in the hundreds. That is still a drop in the ocean, that does not to date include the shores of the home user.
- Avast, the parent company of Piriform, is a reputable outfit I have trusted for years. They readily acknowledged the CC problem, and remedied it with a new version/signed digital signature.

Currently, there is a lot of FUD around this incident. I am seeing recommendations elsewhere to use restore points prior to the August 15 compromised version, to restore a system image made prior to this date, and even to reformat one's PC. Yikes!

For the time being, I'll just sit tight with what I have. (That includes the latest version of CC).


 

No Events found!

Top