Popular software CCleaner infected with backdoor

Published by

Click here to post a comment for Popular software CCleaner infected with backdoor on our message forum
https://forums.guru3d.com/data/avatars/m/212/212598.jpg
Thanks for the info Hilbert. +1
https://forums.guru3d.com/data/avatars/m/56/56686.jpg
CCleaner version 5.33.6162 and CCleaner Cloud version 1.07.3191 those the only verison infected? i update CCleaner on my PC but never ever new build probably once few months? gona have to check and see when get access to my pc I normal only d/l the portable version though for reason, the install has 3rd party stuff asked to be installed
https://forums.guru3d.com/data/avatars/m/191/191769.jpg
allesclar:

Jesus, makes you wonder doesn't it. Inside job?
I was thinking the same myself. Im sure Piriform was purhcased recently by an antivirus company. Maybe someone is upset over the sale of Piriform.
https://forums.guru3d.com/data/avatars/m/229/229509.jpg
I'm on the old 5.3. Should be OK 🙂
https://forums.guru3d.com/data/avatars/m/225/225084.jpg
I update every time there is one so now i'm concerned. Currently running v5.34.6207 (64-bit) and running scans as i type this.
https://forums.guru3d.com/data/avatars/m/209/209001.jpg
They stated only the 32 bit version was affected! "We recently determined that older versions of our Piriform CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 had been compromised. We estimate that 2.27 million people used the affected software. We resolved this quickly and believe no harm was done to any of our users. This compromise only affected customers with the 32-bit version of the v5.33.6162 of CCleaner and the v1.07.3191 of CCleaner Cloud. No other Piriform or CCleaner products were affected. We encourage all users of the 32-bit version of CCleaner v5.33.6162 to download v5.34 here: download. We apologize and are taking extra measures to ensure this does not happen again." http://www.piriform.com/news/release-announcements/2017/9/18/security-notification-for-ccleaner-v5336162-and-ccleaner-cloud-v1073191-for-32-bit-windows-users
https://forums.guru3d.com/data/avatars/m/56/56686.jpg
DarKSeeD:

They stated only the 32 bit version was affected! "We recently determined that older versions of our Piriform CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 had been compromised. We estimate that 2.27 million people used the affected software. We resolved this quickly and believe no harm was done to any of our users. This compromise only affected customers with the 32-bit version of the v5.33.6162 of CCleaner and the v1.07.3191 of CCleaner Cloud. No other Piriform or CCleaner products were affected. We encourage all users of the 32-bit version of CCleaner v5.33.6162 to download v5.34 here: download. We apologize and are taking extra measures to ensure this does not happen again." http://www.piriform.com/news/release-announcements/2017/9/18/security-notification-for-ccleaner-v5336162-and-ccleaner-cloud-v1073191-for-32-bit-windows-users
that kind dont make sense to me seeing I have not see 32bit version of it in years? it been native 64bit for quiet some time no? well let me rephrase that 32 bit and 64bit are in installer/portable but i was under impression if your on 64 bit OS it automatic lunched 64 bit client cause manual clicking ccleaner.exe runs ccleaner64.exe for me. They also made it sound like the installer is what is infect? or was ccleaner exe infect? like said i dont use the installer i used the portable, so if it just installer that was compromised one would be safe if they used the portable?,
https://forums.guru3d.com/data/avatars/m/215/215825.jpg
I am glad I have been ignoring the update request for months! 😛
https://forums.guru3d.com/data/avatars/m/212/212598.jpg
Luckily, don´t have that version on any of my pc´s. But will run scans when got idle time.
https://forums.guru3d.com/data/avatars/m/269/269912.jpg
DarKSeeD:

We encourage all users of the 32-bit version of CCleaner v5.33.6162 to download v5.34 here: download. We apologize and are taking extra measures to ensure this does not happen again."
You weren't taking any measures before this happened?
https://forums.guru3d.com/data/avatars/m/191/191875.jpg
Wow haven't used CCleaner since I jumped to Win 8 some two and a bit years ago. Used to always have some form of it or another installed on my computer prior to that.
https://forums.guru3d.com/data/avatars/m/56/56686.jpg
Bansaku:

I am glad I have been ignoring the update request for months! 😛
most the time i dont update it less it stops working cause Windows 10 will stop it from working on account of "compatiablity" these days i just have manual cleaning of temp folders/firefox histroy and stuff like that set to run once day
https://forums.guru3d.com/data/avatars/m/79/79740.jpg
Dont know why cc cleaner is seen as so unique, theres lot of good alternatives.
https://forums.guru3d.com/data/avatars/m/246/246171.jpg
Good thing I haven't really booted into Windows for extensive use in a couple months. I normally don't like tools like CCleaner but Windows has been becoming real tedious to clean up after. What I really don't understand is why CCleaner updates so often. There's nothing that special about it to warrant so many updates.
https://forums.guru3d.com/data/avatars/m/251/251862.jpg
schmidtbag:

What I really don't understand is why CCleaner updates so often. There's nothing that special about it to warrant so many updates.
I enjoy a good conspiracy theory, but really there is no mystery here. Piriform provides release notes with each version to tell you exactly what they updated. Try checking the version history. This should help you understand why the software is updated. https://www.piriform.com/ccleaner/version-history The real question here is whether this came from within the organization. They stated the software was "illegally modified before it was released to the public" , so it seems someone has access to their servers and maybe their source.
https://forums.guru3d.com/data/avatars/m/246/246171.jpg
WareTernal:

I enjoy a good conspiracy theory, but really there is no mystery here. Piriform provides release notes with each version to tell you exactly what they updated. Try checking the version history. This should help you understand why the software is updated. https://www.piriform.com/ccleaner/version-history
Uh... I for one don't enjoy conspiracy theories, and I wasn't making one myself. I'm merely complaining that a simple tool gets an absurd amount of updates - I'm not implying that they're out to get me, collect my data, or anything shady, I just think they might be doing a crappy job at maintenance. Also to my recollection, I have had updates occur multiple times per month; something this changelog does not appear to specify. I looked at that version history and very little of it seems compelling. I don't want GUI "improvements"; the interface has been fine for a while. "Bug fixes" is uselessly vague, and a tool like this should not have any remaining bugs after this many years. Most of the bugs they explicitly mention (such as the "UI lock" or the issue regarding deleting Firefox extensions) seem to be a result of developer negligence, and again, things that should have been fixed a while ago. And I know I'm not wrong about the negligence, because why else is there a virus in this? Normally, frequent updates don't bother me that much, but CCleaner's installer is tedious and the application just isn't complex enough to warrant so many of them. So, I often just ignore updates.
The real question here is whether this came from within the organization. They stated the software was "illegally modified before it was released to the public" , so it seems someone has access to their servers and maybe their source.
And yet I'm the one making conspiracy theories...
https://forums.guru3d.com/data/avatars/m/128/128096.jpg
Is it so hard to source? We recently determined that older versions of our Piriform CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 had been compromised. We estimate that 2.27 million people used the affected software. We resolved this quickly and believe no harm was done to any of our users. This compromise only affected customers with the 32-bit version of the v5.33.6162 of CCleaner and the v1.07.3191 of CCleaner Cloud. No other Piriform or CCleaner products were affected. We encourage all users of the 32-bit version of CCleaner v5.33.6162 to download v5.34 here: download. We apologize and are taking extra measures to ensure this does not happen again. Issue Summary: Our new parent company, the security company Avast, determined on the 12th of September that the 32-bit version of our CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 products, which may have been used by up to 3% of our users, had been compromised in a sophisticated manner. Piriform CCleaner v5.33.6162 was released on the 15th of August, and a regularly scheduled update to CCleaner, without compromised code, was released on the 12th of September. CCleaner Cloud v1.07.3191 was released on the 24th of August, and updated with a version without compromised code on September 15. The compromise could cause the transmission of non-sensitive data (computer name, IP address, list of installed software, list of active software, list of network adapters) to a 3rd party computer server in the USA. We have no indications that any other data has been sent to the server. Working with US law enforcement, we caused this server to be shut down on the 15th of September before any known harm was done. It would have been an impediment to the law enforcement agency’s investigation to have gone public with this before the server was disabled and we completed our initial assessment. Between the 12th and the 15th, we took immediate action to make sure that our Piriform CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 users were safe - we worked with download sites to remove CCleaner v5.33.6162, we pushed out a notification to update CCleaner users from v5.33.6162 to v5.34, we automatically updated those where it was possible to do so, and we automatically updated CCleaner Cloud users from v1.07.3191 to 1.07.3214. We are continuing to investigate how this compromise happened, who did it, and why. We are working with US law enforcement in their investigation. A more technical description of the issue is on our Piriform blog at: www.piriform.com/news/blog. Again, we sincerely apologize for this and are committed to making sure nothing similar happens again. We encourage any user of the 32-bit version of CCleaner v5.33.6162 to download the latest version of Piriform CCleaner found here: www.piriform.com/ccleaner/download/standard.
https://forums.guru3d.com/data/avatars/m/238/238382.jpg
Interesting, I've always blocked ccleaner from having access to the internet on having a hunch it would be used to collect data.