- Apr 13, 2013
- 3,224
A real quick and dirty look-see into the CCleaner malware:
Wondering now if I ever used this version... and I get my CCleaner updates through Kaspersky too.
So blocking CCleaner 'net access would have rendered this moot? Apart from update checks, there's no reason this program requires outside access AFAIK.
Unfortunately, that is true, and defenses for the average/semi-advanced user are lacking.The fundamental issue is not specific to CCleaner.
Unfortunately, that is true, and defenses for the average/semi-advanced user are lacking.
This happened to me, I manually deleted ''Agomo'' from the Registry Editor and updated CCleaner to the latest version.
Yeah ....... But, I was supposed to do something, I can not just ignore it .Avast stated that the Agomo key was not relevant, but at the same time they have revised their statements regarding compromised CCleaner a few times already. Revisions of initial analyses and reports are generally common. Just look at Eternal Blue\Double Pulsar\SMB as a prime example.
LS- deleting the agomo key is pointless as it will be repopulated when the malware next starts. Deletion will not prevent subsequent connections.
Okay, ....... but whay do I left the 'agamo' key there (when I know is there), now at least I know that it is gone and if it accidentally appears again, then I will know that the malware reacted again.LS- deleting the agomo key is pointless as it will be repopulated when the malware next starts. Deletion will not prevent subsequent connections.
Yes I check 2 days ago it's empty --- just this: = (default) - REG-SZ - (value not set)Maybe you should check this reg key:
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WbemPerf
Is it empty or not?
So we should not be using ccleaner? How about the portable version?
If we don't use ccleaner, what should we use in it's place?
That is a good point, I am sure that many AVs exclude it even from a behavioural scanning because it is a trusted software. How many others are also neglected?!The horror is when your AV/AM software in your system cannot automatically detect and clean it