Hello! Help me please. I have utilized C-CLEANING now and it installed an Virtu B Virus in to my of the computer . Kaspersky Internet Security discerns it when I do the Analyzes button of Registry. I revised it with 2 other software of security with the same end. It erases the bad files that are positions in the temporary folders of internet but they go redetected when I do the Analyzes button of Registration. Thanks!
If you're using the downloaded version of CCleaner from CCleaner.com or FileHippo.com it's most likely a false positive detection that needs to be reported to Kaspersky Labs.
If you got CCleaner from somewhere else you can upload the installer to VirusTotal, since there are most likely rip off versions floating about:
If you're using the downloaded version of CCleaner from CCleaner.com or FileHippo.com it's most likely a false positive detection that needs to be reported to Kaspersky Labs.
If you got CCleaner from somewhere else you can upload the installer to VirusTotal, since there are most likely rip off versions floating about:
Thanks you. Software was installed on Filehippo.com. I delivered files to Kaspersky you said and Kaspersky email said the Virtu Viral was on the files I deliver to them. JPEG files made when I do the Analyzes button of Registry. Fake identification is not it Kaspersky said. I have downloaded Filehippo.com again the new C-Cleaner and it made files again.
Thanks again if you could help?
If you're using the downloaded version of CCleaner from CCleaner.com or FileHippo.com it's most likely a false positive detection that needs to be reported to Kaspersky Labs.
If you got CCleaner from somewhere else you can upload the installer to VirusTotal, since there are most likely rip off versions floating about:
I remember to tell you I have WINDOWS VISTA HOME 64 BIT
Thanks to you again.
Pretty positive your problem is due to having an infection on your PC already. It is a file infecter called Virut, and it will infect every new .exe .rar .zip etc files
The only solution for you is to reformat
These need to be wiped : all programs, all .exe + .scr executables, downloaded archives (.zip + .rar) and now, according to a very trustworthy colleague, this newer variant injects all .htm + .html files
Pretty positive your problem is due to having an infection on your PC already. It is a file infecter called Virut, and it will infect every new .exe .rar .zip etc files
The only solution for you is to reformat
These need to be wiped : all programs, all .exe + .scr executables, downloaded archives (.zip + .rar) and now, according to a very trustworthy colleague, this newer variant injects all .htm + .html files
Thanks you RORSCHACH112. I made the computer restart to when it was new with wiped everything. I then did the update of all the VISTA systems and KASPERSKY again. Everything virus was not there now.
Then I put in the new C-Cleaner using FILEHIPPO. KASPERSKY showed VIRTUMONDE TROJAN. The "ALERT" came on the screen of the computer when I hit the Analyzes button on the Registry "TOOLS". It took hours do to this all and C-Cleaner put the VIRTUMONDE TROJAN back on the Computer. Could some persons from the Company Piriform please assist because I like the C-Cleaner. I Emailed the filed to KASPERSKY again and they emailed to me that it is a real infection and not a fake test.
Thanks agian to you RORSCHACH112 and the other helper.
Auguste
Then I put in the new C-Cleaner using FILEHIPPO. KASPERSKY showed VIRTUMONDE TROJAN.
Maybe that's why FileHippo is down now?
Maybe they realize that the whole site is infected?
Maybe that's why FileHippo is down now?Maybe they realize that the whole site is infected?
Hello, thank you. I am IT for Auguste's company. We have located the VIRTUMONDE TROJAN in your download specifically accurate. We downloaded newest CCleaner Version from Filehippo.com on a brand new lap top and burned it to a CD-ROM disk. We analyzed the disk. The VIRTUMONDE TROJAN is donloading with your CCleaner and is code to re-install again and again when using both Clean and Registry tools.
We then re-initiate the computer to first use and had no trace. No software was put on and no connection to web or internoet. We then put the CD-ROM disk in and ran Norton, Kaspersky, AVG and we then found infected files which are not False Positivos. For 100%. Complete firewall lap top happen 3 times with wipe entire drive to new condition.
Thank you. We uninstalled all of your product until you salve this. They are good product and it should also be Filehippo not you.
Put any questions to here and I will answer.
Thank you. Again.
FileHippo is a completely safe place to get CCleaner from, so we will look into this false positive.
MrRon
FileHippo is a completely safe place to get CCleaner from, so we will look into this false positive.
MrRon
Thanks to you MrRon for your posting. No to insult you but this is not "false positive". I comprehend it is your company and to protect it's name but I am in IT and code for 12 years. The donloaded CCleaner file holds code that makes CCleaner when run to create actual files with the Trojan "Replicated" code of VIRTUMONDE and it Replicates again again again. When antiviral stops it the Replicated file (commonly JPEG extenzion) begins again.
I view that you have banned a posting person for same type of posts PLEASE do not ban us. We have interest in end result of this. I polite ask to, that you consider this is not "false positive". Our IT people team if you want will send the files and proving.
Thanks to you again.
Jean Guillaume D'ornani
Thanks to you MrRon for your posting. No to insult you but this is not "false positive". I comprehend it is your company and to protect it's name but I am in IT and code for 12 years. The donloaded CCleaner file holds code that makes CCleaner when run to create actual files with the Trojan "Replicated" code of VIRTUMONDE and it Replicates again again again. When antiviral stops it the Replicated file (commonly JPEG extenzion) begins again.
I view that you have banned a posting person for same type of posts PLEASE do not ban us. We have interest in end result of this. I polite ask to, that you consider this is not "false positive". Our IT people team if you want will send the files and proving.
Thanks to you again.
Jean Guillaume D'ornani
Add to my posting that the VIRTUMONDE files are new and create in Local Temp New folders commonly.
I view that you have banned a posting person for same type of posts PLEASE do not ban us.
Thanks to you again.
Jean Guillaume D'ornani
Please note, the poster I believe you are refering to was not banned for posting similar information to this. The account was suspended because of an unjustified insulting response to another members post.
Piriform and it's support forum welcome any comments and observations, critical or otherwise.
I hope that clears up your misunderstanding of that situation.
Hi all!
Found the forum and issue via Google.
We are having the same results as JGD and Root11 in our analysis. We were pulling all types of warnings a day after CCleaner was installed. I apologize for not posting in the other thread, but the reply buttons didn't seem to want to work.
It appears that there is a possum belly getting into the code and playing dead for a tad. After the first run or two, usually on the Registry Analysis stage, we started getting the warnings. We have some government work on our desktops so we immediately began our analysis and discovered replicating files in the same folders discussed in the other threads, and they are .jpgs with sometimes random assigned names and sometimes hijacked names of .jpgs from pages you have visited recently (e.g. piriform.jpg) as stored in your Temp Low folder. The code does replicate and following standard protocol with wipes, safe mode scans and the like we were able to remove all traces. Then, upon reinstallation of CCleaner it occured on an actual simple Analysis and Cleaning, not the Registry solution as the prior.
We also love your products. In fact, we can't believe they're free!
Let's work together to solve this.
RT
Please PM me with the files you are talking about.
MrRon
This here is the VirusTotal saved scan report, all clean:
https://www.virustotal.com/analisis/b8bf48e...3fa5b73d898146d
Also all clean on Jotti's, and VirScan.org.
The CCleaner.exe file is 100% clean. You have Virut, what that does is infect every file on your PC, including the new ones you download. It is a problem on your side for sure.
Just an observation but if it was the CCleaner .exe from Filehippo that was to 'blame' then wouldn't everyone who uses CCleaner be having this problem?
If Virut does infect .exe files on a PC then this could explain why only a few CCleaner users are experiencing this.
I'm not having any problems here and downloaded, installed and ran CCleaner from the Filehippo site to see.
Just an observation but if it was the CCleaner .exe from Filehippo that was to 'blame' then wouldn't everyone who uses CCleaner be having this problem?
If Virut does infect .exe files on a PC then this could explain why only a few CCleaner users are experiencing this.
I'm not having any problems here and downloaded, installed and ran CCleaner from the Filehippo site to see.
Exactly! I've never had any problems relating to CCleaner or "Virtumonde" and I run 5 different scanners
I have also used Jotti's on the installer file, the original file in Program Files and the uninstall file, all clean