Jump to content

CCleaner yet another trojan on Uninstaller


Bollen

Recommended Posts

Well I read about this earlier and its not the first time uninstallers has been false flagged as trojans. This time its from the program Spyware Doctor from PC Tools. Maybe you should contact them, since its really not good if CCleaner get a reputation for having a trojan in it.

Anyways love the program and I just wanted to report this :)

 

Added a picture what Spyware Doctor said.

 

post-8730-1164964089_thumb.jpg

Link to comment
Share on other sites

I got another one, but i think, to installdir should be saved in the exe-file. so, there is a different checksum.

 

or is there anybody, who got the same checksum as tonyklein (5bb116b6b982f79626fcea7ccee9d8c0) or me (0783a79ef1b9948718d04737cf49ae3f) ?

Link to comment
Share on other sites

  • Moderators

How are you getting the checksums?

 

MrG the CCleaner developer added a VeriSign Digital Signature to the CCleaner setup file!

 

You can view it by right clicking the setup file and selecting Properties->Digital Signatures->hightlight Pirform Ltd->click Details

 

Now you can click View Certificate->Certificate Path to see the Certificate Status. It should read: This certificate is OK.

Link to comment
Share on other sites

  • Moderators

Using the tool TK linked to this is what I got, text and screenshot included:

CCleaner Version (Slim Install): 1.35.424
File: C:\Program Files\CCleaner\uninst.exe
CRC16: 255a
CBR32: 2cb86e75
MD5: 80b4f6b6955fc10fc804efadc4be2688
SHA1: ec1c6be1bc5e8f7bce65bbabb7fd835824972805

ccleaner_v135424_uninst.png

Link to comment
Share on other sites

  • Moderators

There seem to be numerous legitimate versions of this file... :rolleyes:

 

So what are you saying, is it just some generic uninstall routine? Sort of like what Inno Setup has (well at least Inno Setup's uninstaller has matching checksums.)

Link to comment
Share on other sites

  • Admin

I've received confirmation that the latest definitions for Spyware Doctor have fixed this false positive detection. So hopefully this won't happen again. :)

 

I'm pretty sure the installer engine (NSIS) creates the uninstaller dynamically during the installation process. So it's not possible to digitally sign this file or guarantee what it's MD5 sig will be.

 

MrG

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.