WARNING FROM PREVX

Might I invite comment on the following extract from PrevX? So far I have used crap cleaner without probs but this message is, to say the least, 'alarming'. I am genuinely seeking views, including those of Piriform developers of the matter. Thanks in advance

brian

CCSETUP208.EXE

Disagree with this determination?

This executable Piriform program has a file size of 2,914,296 bytes, it is most frequently called CCSETUP208.EXE and is most frequently located in the %desktop%\ folder.

The file header contains the following information:

Vendor : Piriform Ltd

Product: CCleaner Installer

This file is considered unsafe and is part of the malware group, TROJAN.AGENT.GEN. It was first seen on Thursday, May 29 2008. It has been seen frequently by 1,000 users in this section of the community.

CCSETUP208.EXE has been seen to perform the following behaviors:

- This Process Creates Other Processes On Disk

- Adds Products to the system registry

- This Process Deletes Other Processes From Disk

- Executes Processes stored in Temporary Folders

- Executes a Process

- Writes to another Process's Virtual Memory (Process Hijacking)

- Registers a Dynamic Link Library File

- Terminates Processes

CCSETUP208.EXE has been the subject of the following behaviors:

- Created as a process on disk

- Deleted as a process from disk

- Executed as a Process

- Executed by Internet Explorer

- Has code inserted into its Virtual Memory space by other programs

- Executed from Temporary Folders

- Terminated as a Process

- Registered as a Dynamic Link Library File

I think it might be because of Yahoo Toolbar. You don't have to install it though.

http://wiki.castlecops.com/Malware_Removal...out_the_Clutter

That should answer your question and confirm that the alerts are being caused by installation of Yahoo Toolbar.

Here is the info from the Prevx page...btw this is not the first time that CCleaner has triggered false positive alerts.

http://spywarefiles.prevx.com/RRHHDJ447445...TUP208.EXE.html

Noe that the PrevX page also states:

Malicious Objects Created: None

Malware Run Keys: None

The thing that surprises me is that PrevX seems to not know what CCleaner is, and also to engage in "scare tactics" such as this:

SOFTWARE ASSESSMENT: PREVX 4 AXES OF EVIL METHODOLOGY

Personally I would suggest that the creator of CCleaner take a good look at the above PrevX link and see what PrevX has listed because to me anyway, some of PrevX's report about CCleaner seems way exaggerated.

For example

File Names Used: 26

In all the years I've used CCleaner, I've only ever heard two names for it...Crap Cleaner and CCleaner!