Horse Racing Forum - PaceAdvantage.Com - Horse Racing Message Board

Go Back   Horse Racing Forum - PaceAdvantage.Com - Horse Racing Message Board > Off Topic > Off Topic - Computers


Reply
 
Thread Tools Rate Thread
Old 09-18-2017, 10:23 AM   #1
Jeff P
Registered User
 
Jeff P's Avatar
 
Join Date: Dec 2001
Location: JCapper Platinum: Kind of like Deep Blue... but for horses.
Posts: 5,287
CCleanup: A Vast Number of Machines at Risk

CCleanup: A Vast Number of Machines at Risk:
http://blog.talosintelligence.com/20...s-malware.html

Quote:
For a period of time, the legitimate signed version of CCleaner 5.33 being distributed by Avast also contained a multi-stage malware payload that rode on top of the installation of CCleaner. CCleaner boasted over 2 billion total downloads by November of 2016 with a growth rate of 5 million additional users per week. Given the potential damage that could be caused by a network of infected computers even a tiny fraction of this size we decided to move quickly. On September 13, 2017 Cisco Talos immediately notified Avast of our findings so that they could initiate appropriate response activities. The following sections will discuss the specific details regarding this attack.
and:
Quote:
On September 13, 2017 while conducting customer beta testing of our new exploit detection technology, Cisco Talos identified a specific executable which was triggering our advanced malware protection systems. Upon closer inspection, the executable in question was the installer for CCleaner v5.33, which was being delivered to endpoints by the legitimate CCleaner download servers. Talos began initial analysis to determine what was causing this technology to flag CCleaner. We identified that even though the downloaded installation executable was signed using a valid digital signature issued to Piriform, CCleaner was not the only application that came with the download. During the installation of CCleaner 5.33, the 32-bit CCleaner binary that was included also contained a malicious payload that featured a Domain Generation Algorithm (DGA) as well as hardcoded Command and Control (C2) functionality. We confirmed that this malicious version of CCleaner was being hosted directly on CCleaner's download server as recently as September 11, 2017.


-jp

.
__________________
Team JCapper: 2011 PAIHL Regular Season ROI Leader after 15 weeks
www.JCapper.com

Last edited by Jeff P; 09-18-2017 at 10:29 AM.
Jeff P is offline   Reply With Quote Reply
Old 09-18-2017, 10:45 AM   #2
_______
Veteran
 
Join Date: Feb 2013
Location: Washoe County, Nevada
Posts: 2,253
Very useful!

I run the free version. It doesn't appear the compromised version ever loaded onto my home machine. It doesn't seem that individuals would have been the target. This was aimed at enterprise.

Nonetheless, if you have a version that auto updates you were compromised.
_______ is offline   Reply With Quote Reply
Old 09-18-2017, 01:55 PM   #3
AltonKelsey
Veteran
 
AltonKelsey's Avatar
 
Join Date: May 2016
Posts: 1,831
Had an old version installed which I just nuked
AltonKelsey is offline   Reply With Quote Reply
Old 09-18-2017, 02:11 PM   #4
Clocker
Registered User
 
Join Date: Jul 2013
Posts: 17,095
Quote:
Originally Posted by _______ View Post

Nonetheless, if you have a version that auto updates you were compromised.
As I read that article, which is tough because I don't speak geek, it says that the free version does not auto update.

Question for those more computer literate on such matters. I have version 5.24 and the CC web site says version 5.34 is available. It sounds like my current version should be clean, and that it is OK to go ahead and download 5.34, right?
__________________
A man's got to know his limitations. -- Dirty Harry
Clocker is offline   Reply With Quote Reply
Old 09-18-2017, 02:26 PM   #5
_______
Veteran
 
Join Date: Feb 2013
Location: Washoe County, Nevada
Posts: 2,253
Quote:
Originally Posted by Clocker View Post
As I read that article, which is tough because I don't speak geek, it says that the free version does not auto update.

Question for those more computer literate on such matters. I have version 5.24 and the CC web site says version 5.34 is available. It sounds like my current version should be clean, and that it is OK to go ahead and download 5.34, right?
I believe you have this correct.
_______ is offline   Reply With Quote Reply
Old 09-18-2017, 02:50 PM   #6
Jeff P
Registered User
 
Jeff P's Avatar
 
Join Date: Dec 2001
Location: JCapper Platinum: Kind of like Deep Blue... but for horses.
Posts: 5,287
Clocker, I also think you would be OK to download v 5.34.

From the article on the Cisco's Talos Intelligence Group blog:
http://blog.talosintelligence.com/20...s-malware.html

Quote:
It is also important to note that while previous versions of the CCleaner installer are currently still available on the download server, the version containing the malicious payloads has been removed and is no longer available.



-jp

.
__________________
Team JCapper: 2011 PAIHL Regular Season ROI Leader after 15 weeks
www.JCapper.com

Last edited by Jeff P; 09-18-2017 at 03:03 PM.
Jeff P is offline   Reply With Quote Reply
Old 09-18-2017, 03:40 PM   #7
Marshall Bennett
Registered User
 
Join Date: Oct 2007
Location: Houston , Tx.
Posts: 9,586
Quote:
Originally Posted by Clocker View Post
As I read that article, which is tough because I don't speak geek, it says that the free version does not auto update.

Question for those more computer literate on such matters. I have version 5.24 and the CC web site says version 5.34 is available. It sounds like my current version should be clean, and that it is OK to go ahead and download 5.34, right?
I downloaded version 5.34 a few days ago and works well. I use it almost daily.
Marshall Bennett is online now   Reply With Quote Reply
Old 09-18-2017, 04:05 PM   #8
AltonKelsey
Veteran
 
AltonKelsey's Avatar
 
Join Date: May 2016
Posts: 1,831
Quote:
Originally Posted by Marshall Bennett View Post
I downloaded version 5.34 a few days ago and works well. I use it almost daily.

Why would you use that daily. I nearly NEVER use these things. Maybe I'm missing some great experience
AltonKelsey is offline   Reply With Quote Reply
Old 09-18-2017, 04:29 PM   #9
Clocker
Registered User
 
Join Date: Jul 2013
Posts: 17,095
I just checked the CCleaner web site and and the free version of the update (Version 5.34) is available. They are also offering the professional version for $19.95. Anyone use the Pro version, and is it worth getting? Thanks.

http://www.piriform.com/ccleaner/download?upgrade
__________________
A man's got to know his limitations. -- Dirty Harry
Clocker is offline   Reply With Quote Reply
Old 09-18-2017, 05:58 PM   #10
_______
Veteran
 
Join Date: Feb 2013
Location: Washoe County, Nevada
Posts: 2,253
Quote:
Originally Posted by AltonKelsey View Post
Why would you use that daily. I nearly NEVER use these things. Maybe I'm missing some great experience
I use it when I get an alert that I haven't used it lately and it can save me "X" amount of storage. I'm also confused by why anyone would use it daily.
_______ is offline   Reply With Quote Reply
Old 09-18-2017, 06:07 PM   #11
_______
Veteran
 
Join Date: Feb 2013
Location: Washoe County, Nevada
Posts: 2,253
Quote:
Originally Posted by Clocker View Post
I just checked the CCleaner web site and and the free version of the update (Version 5.34) is available. They are also offering the professional version for $19.95. Anyone use the Pro version, and is it worth getting? Thanks.

http://www.piriform.com/ccleaner/download?upgrade
One of the "benefits" of the pro version is automatic updates. The absence of which saved all us cheapskates the trouble of restoring settings to an earlier uncontaminated date.

I'm sure this can be turned off (I don't let my anti-virus auto update) but if you aren't an enterprise I'd be confident saying you don't need the pro version.
_______ is offline   Reply With Quote Reply
Old 09-18-2017, 09:41 PM   #12
Tom
The Voice of Reason!
 
Tom's Avatar
 
Join Date: Mar 2001
Location: Canandaigua, New york
Posts: 112,809
I'm still using 4.09 Free version.
It does the job, so I have never bothered to update it.
If it ain't broke.....
__________________
Who does the Racing Form Detective like in this one?
Tom is online now   Reply With Quote Reply
Old 09-18-2017, 10:08 PM   #13
Zaf
Pace Cappa
 
Zaf's Avatar
 
Join Date: Apr 2002
Location: Canada
Posts: 4,649
Yup I have 5.19 works great, I'll stick with this one.

Z
__________________
http://www.youtube.com/watch?v=J2hFZ8KnsSo
Zaf is offline   Reply With Quote Reply
Old 09-19-2017, 05:27 AM   #14
Marshall Bennett
Registered User
 
Join Date: Oct 2007
Location: Houston , Tx.
Posts: 9,586
Quote:
Originally Posted by AltonKelsey View Post
Why would you use that daily. I nearly NEVER use these things. Maybe I'm missing some great experience
It checks to see all of your storage and where it is. Takes 10 seconds. Also I clean registry (10 seconds) and clean cache on Firefox and Chrome (perhaps 30 seconds). I don't run the cleaner on anything but what I've mentioned.
My computer is older. I suppose if you have a massive amount of storage it makes little difference.
Marshall Bennett is online now   Reply With Quote Reply
Old 09-19-2017, 09:47 AM   #15
Ocala Mike
Registered User
 
Ocala Mike's Avatar
 
Join Date: May 2010
Posts: 5,005
I'm running v5.13.5460. Am I ok?
Ocala Mike is offline   Reply With Quote Reply
Reply




Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

» Advertisement
» Current Polls
Wh deserves to be the favorite? (last 4 figures)
Powered by vBadvanced CMPS v3.2.3

All times are GMT -4. The time now is 07:03 PM.


Powered by vBulletin® Version 3.8.9
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Copyright 1999 - 2023 -- PaceAdvantage.Com -- All Rights Reserved
We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program
designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.