Site icon WinCert

Recent updates of CCleaner were packed with a backdoor threat

<p>If you have never used it&comma; there&&num;8217&semi;s a good chance that you have heard about the CCleaner utility application&period; CCleaner has been presented like a number one tool for cleaning your Windows machine&period; It protects your privacy and makes your computer faster and more secure&period;<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2017&sol;09&sol;computer&lowbar;attacker&period;jpg"><img class&equals;"alignnone size-full wp-image-2275" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2017&sol;09&sol;computer&lowbar;attacker&period;jpg" alt&equals;"ccleaner" width&equals;"640" height&equals;"423" &sol;><&sol;a><&sol;p>&NewLine;<h4>Today&comma; CCleaner developer Piriform has confirmed that several recent versions of their known utility have been compromised by a backdoor virus&period;<&sol;h4>&NewLine;<p>Piriform said that an unauthorized modification of CCleaner&period;exe binary resulted in the injection of a two-stage backdoor virus&period; This allows the attacker to run the code from a remote IP address on affected systems&period;<&sol;p>&NewLine;<p>Piriform also said that both 32-bit versions of CCleaner v&period;5&period;33&period;6162 and Cloud version v1&period;07&period;3191 were affected&period; Malicious code was apparently inserted and hidden in the application&&num;8217&semi;s initialization Common Runtime &lpar;CRT&rpar; code&period; CRT is usually inserted with the compilation by the compiler&period;<&sol;p>&NewLine;<p>Once the backdoor was installed&comma; it started collecting various private information like the IP and MAC address of the infected machine&comma; installed applications etc&period; Gathered information was then sent to a remote IP address&period;<&sol;p>&NewLine;<p>The threat has now been disabled according to Piriform as they have managed to block the rogue server&period; Even though the threat has been disabled&comma; consumers are advised to upgrade to the latest available version&period; CCleaner Cloud application has already been automatically updated&period;<&sol;p>&NewLine;<p>Piriform said that they&&num;8217&semi;re still investigating the source of the attack&period; They have also confirmed that no harm was done before prior to blocking the affected version&period;<&sol;p>&NewLine;

Exit mobile version