Jump to content

login

Experienced Members
  • Posts

    14
  • Joined

  • Last visited

Posts posted by login

  1.  

    What version of the operating system are you using? 32 bit or 64 bit?

     

    -----------------------------------------------

     

    Question for administrators or people close to the topic:

    Were there any cases of infection of 64-bit computers or not? If so, under what conditions 64-bit computers could infect?

  2. This malware issue affected my two 64 bit windows 7 systems.  The malware also attempts to change the Internet Explorer Home Page at every new launch of Internet Explorer.  The warning that some program is trying to do this appears every time.  Uninstalling the malware after using Malwarebytes or Bitdefender eliminates this effect until reboot.  I can establish cause and effect here.  The way that I discovered it was on Sept 19th, Bitdefender blocked the ccleaner exe.  When I rebooted, once the system tray application which runs by default loaded, the problem of the IE homepage hijack returned as well as a subsequent security warning regarding ccleaner.  This means that the malware is not only in the install file, but rather running in one or more of the program modules.  Only total uninstall eliminated the problem.  Additionally, simply because a system is 64 bit and ccleaner installs itself under a 64 bit heading, this does not exclude the fact that 32 bit modules are running.  The system tray module is a 32 bit module.  Lots of software running on 64 bit OS's is 32 bit in whole or in part.

     

    On one of my systems an additional malware was blocked on the program path: backdoor.Agent.ABXS.

     

    Nice thing is that one of my systems was a complete system reload, not used for anything of consequence yet, so the ccleaner exploit happened in a  rather controlled environment.

     

    I have notified http://blog.talosintelligence.com/2017/09/avast-distributes-malware.html of this and made my systems available to them if they want to look since I doubt that we will be receiving any truth from Avast/Piriform. 

     

    I love the story about them keeping it quiet while working with law enforcement.  I called it years ago that this would be the BS excuse for companies to hide security breaches and address the lateness of announcing it to the general public.

     

     

    Did you have a registry folder Agomo?

    HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\Agomo

    Or one of the listed registry folders?

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WbemPerf\001
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WbemPerf\002
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WbemPerf\003
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WbemPerf\004
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WbemPerf\HBP
  3. 1. Was there any malicious code in the 64-bit version of CCleaner?

     

    2. Why is a 32-bit exe-file installed on a 64-bit system?

     

    0d552a4f453fd6ec4e126e5571ead0c5.png

     

    3. Does the 64-bit system always run the 64-bit version of CCleaner?

     

    4. If the 64-bit version is clean, could a Trojan from a 32-bit exe-file get into a 64-bit system? In theory?

     

    5. Why in a 64-bit system when you skip the Account Control for CCleaner, a 32-bit version (CCleaner.exe) is added to the tasks?

     

    fe1817cdf0306381b2dd3c3ed1891e2b.png

  4. if You have 64bit pc You're not infected because if You have installed the 5.33 version runs only the 64bit version on Your sistem (the 32bits is infected and the cloud version).

     

    Does the Trojan work only when running the 32-bit version? The CCleaner installer does not start the Trojan? I correctly understand that the Trojan could get into the 64-bit system only if you manually run the CCleaner.exe (x32)?

     

    You can check in the registry folder to check if there are the registry key on the pc.

     

    In what registry folder can this be checked?

     

    Check for the files TSMSISrv.dll, the 64-bit trojan is EFACli64.dll on Windows C

     

    Files are in the root of folder C, or are you talking about searching the entire directory? Can there be a specific folder where the Trojan is saved?

  5. Sorry for my bad english, this is not my native language.

     

    In connection with the latest events, I'm very nervous:

    https://www.ghacks.net/2017/09/21/ccleaner-malware-second-payload-discovered/

     

    I'm using Windows 10 x64 and CCleaner Free x64, but I do not remember if I installed version 5.33.6162 or not...

     

    I have a few questions:

    1. Whence the virus was installed? From CCleaner.exe (x32), CCleaner64.exe, or from the installer?

    2. How can I check if I have ever had an infected version?

    3. How can I check if I had a virus on my computer?

    4. Does the last update (5.35) remove the virus?

    5. Where to look for trojans, which is written in the news (32-bit trojan is TSMSISrv.dll, the 64-bit trojan is EFACli64.dll)?

     

    3bfc72cee3e8c7421d09a2300e43351d.png

     

    PS: Forgive me if questions have already been asked, but it's difficult for me to navigate in a non-native language even with Google translator.  :(

  6. The untranslated element in version 5.30. Example of translation:

     

    Enable silent background updateВключить фоновое обновление

     

    99eb94fa0feb9e53de2f32edb580bfa9.png

     

    Other examples of translation:

    Фоновое обновление

    Автоматическое обновление

    Включить обновление в фоне

    — Включить автообновление

  7. Greetings from Russia. Sorry for my bad English.

     

    I do not know where to write. The latest version of the program does not fully translate some elements.

     

     

    1. Исправить

     

    056b1b1f4d66e155ed36f72dcc36ea4a.png

     

     

    2. Доступна новая версия CCleaner   Обновить

     

    311fabb18a4968316253eb60f7ba5a58.png

     

     

    3. Включить автоматическое обновление

     

    03a1318ede2162d91430eb1aef00a56a.png

     

     

    4. Is it just a built-in web page? (It is not necessary to translate)

     

    65da9801e8ec9c518ff5bcb0f710bb8d.png

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.