- Apr 28, 2015
- 271
Try UltraSearch (there is a portable version): Fastest File Search: UltraSearch
HitmanPro 3.7.20.286
www.hitmanpro.com
Computer name . . . . : HOME
Windows . . . . . . . : 10.0.0.15063.X64/8
User name . . . . . . : Home\........
UAC . . . . . . . . . : Enabled
License . . . . . . . : Paid (295 days left)
Scan date . . . . . . : 2017-09-23 21:38:26
Scan mode . . . . . . : Normal
Scan duration . . . . : 1m 33s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 1
Traces . . . . . . . : 2
Objects scanned . . . : 2 017 696
Files scanned . . . . : 58 583
Remnants scanned . . : 427 534 files / 1 531 579 keys
Malware _____________________________________________________________________
C:\Program Files\CCleaner\CCleaner.exe
Size . . . . . . . : 7 680 216 bytes
Age . . . . . . . : 51.4 days (2017-08-03 11:42:22)
Entropy . . . . . : 6.7
SHA-256 . . . . . : 6F7840C77F99049D788155C1351E1560B62B8AD18AD0E9ADDA8218B9F432F0A9
Product . . . . . : CCleaner
Publisher . . . . : Piriform Ltd
Description . . . : CCleaner
Version . . . . . : 5.33.00.6162
Copyright . . . . : Copyright © 2005-2017 Piriform Ltd
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Bitdefender . . . : Trojan.PRForm.A
> Kaspersky . . . . : Backdoor.Win32.InfeCleaner.a
> HitmanPro . . . . : Troj/Mogoa-A
Fuzzy . . . . . . : 87.0
Startup
C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
You have to update to the latest version of CCleaner v5.35.6210 (20 Sep 2017).I analysed with HitmanPro :
View attachment 167944 View attachment 167945
Code:HitmanPro 3.7.20.286 www.hitmanpro.com Computer name . . . . : HOME Windows . . . . . . . : 10.0.0.15063.X64/8 User name . . . . . . : Home\........ UAC . . . . . . . . . : Enabled License . . . . . . . : Paid (295 days left) Scan date . . . . . . : 2017-09-23 21:38:26 Scan mode . . . . . . : Normal Scan duration . . . . : 1m 33s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 1 Traces . . . . . . . : 2 Objects scanned . . . : 2 017 696 Files scanned . . . . : 58 583 Remnants scanned . . : 427 534 files / 1 531 579 keys Malware _____________________________________________________________________ C:\Program Files\CCleaner\CCleaner.exe Size . . . . . . . : 7 680 216 bytes Age . . . . . . . : 51.4 days (2017-08-03 11:42:22) Entropy . . . . . : 6.7 SHA-256 . . . . . : 6F7840C77F99049D788155C1351E1560B62B8AD18AD0E9ADDA8218B9F432F0A9 Product . . . . . : CCleaner Publisher . . . . : Piriform Ltd Description . . . : CCleaner Version . . . . . : 5.33.00.6162 Copyright . . . . : Copyright © 2005-2017 Piriform Ltd RSA Key Size . . . : 2048 LanguageID . . . . : 1033 Authenticode . . . : Valid > Bitdefender . . . : Trojan.PRForm.A > Kaspersky . . . . : Backdoor.Win32.InfeCleaner.a > HitmanPro . . . . : Troj/Mogoa-A Fuzzy . . . . . . : 87.0 Startup C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
The 3 engines of HitmanPro have detected the threat but before this analyse I run a deep scan with Bitdefender and it found nothing !
Thanks @paulderdashTry UltraSearch (there is a portable version): Fastest File Search: UltraSearch
You still have to update CCleaner to the latest version or uninstall...Thanks @paulderdash
The search found nothing.
Can I hope that my PC is safe and secure ?
View attachment 167960
That is not certain, I found nothing either.Thanks @paulderdash
The search found nothing.
Can I hope that my PC is safe and secure ?
View attachment 167960
You have to update to the latest version of CCleaner v5.35.6210 (20 Sep 2017).
You still have to update CCleaner to the latest version or uninstall...
Thanks @Av GurusYou still didn't uninstall Ccleaner?
Why?
Thanks @paulderdashCCleaner v5
That is not certain, I found nothing either.
But it is unlikely that you as a consumer are a target, these guys were more targetting the big guys: tech companies, banks, even .gov.
CCleaner v5
Thanks @Av GurusWhen you uninstall staff with Revo it frst remove program then scan for leftovers, if it find some you have to click Delete.
View attachment 167972
So who (what program) is finding those reg stuff from post above (is it related to ccleaner)?Thanks @Av Gurus
Of course after selecting, I clicked on "Delete"
Thanks @Marko :)Guys, just reinstall Windows, problem solved. There's no point of trying to clean malware because it can be anywhere. As far as I know, we only know about that one registry key and that's it.
Revo Uninstaller Pro 3.1.9 when checking with "forced uninstalling".So who (what program) is finding those reg stuff from post above (is it related to ccleaner)?
If you don't know how to reinstall Windows, don't mess with that. You can mess up whole Windows installation so your PC won't boot. It might be the best to ask someone who knows to install it for you.Thanks @Marko :)
I'm not a geek, so can you explain me an easy way to reinstall Windows alone ?
Revo Uninstaller Pro 3.1.9 when checking with "forced uninstalling".
After a third attempt and another restart, I think the job was doneAnd you cannot uninstall/delete with it?
OK I'm waiting a friend can do this Windows' reinstallIf you don't know how to reinstall Windows, don't mess with that. You can mess up whole Windows installation so your PC won't boot. It might be the best to ask someone who knows to install it for you.