CCLeaner causing SpySweeper to find Virtumonde
#1 OFFLINE
Posted 22 February 2009 - 05:37 PM
#2 OFFLINE
Posted 22 February 2009 - 08:39 PM
Also to make double sure about things, you could post here on the forum, should you need to, after following the guide
http://forum.pirifor...showtopic=20120
http://www.piriform.com/docs
#3 OFFLINE
Posted 22 February 2009 - 11:04 PM
hazelnut, on Feb 22 2009, 02:39 PM, said:
Also to make double sure about things, you could post here on the forum, should you need to, after following the guide
http://forum.pirifor...showtopic=20120
#4 OFFLINE
Posted 23 February 2009 - 12:17 AM
~Scratch~
#5 OFFLINE
Posted 23 February 2009 - 03:52 AM
#6 OFFLINE
Posted 23 February 2009 - 05:32 AM
imnogoodwithcomputers, on Feb 22 2009, 09:52 PM, said:
http://forum.pirifor...showtopic=20120
#7 OFFLINE
Posted 25 February 2009 - 02:51 PM
The files being flagged are three temp files in documents and settings -- application data for Mozilla firefox and for Sun Java. The temp files flagged vary from computer to computer though.
When I used Google Chrome on the older computers, this would constantly happen with Google Chrome files, and so I deleted it thinking it was an incompatibility with Chrome. But I've found it happens with Firefox as well.
I noticed someone posted on here in another thread about a month ago with the Google Chrome problem, but no one at ccleaner or spy sweeper seems to want to test it out.
#8 OFFLINE
Posted 27 February 2009 - 10:54 PM
Piriform needs to address this. Your software is being downloaded with a trojan.
Don't believe me? Those of you with Spysweeper or AdAware- when you go to the quarantine when Virtumonde pops up, click on the box below and locate the files. Turn off system restore, delete the files, run the scan again. Shut down, reboot in safe mode WITHOUT networking so no new files can show up. Run your scans again and again. Delete CCleaner or other Piriform products. Run it again if you'd like.
Then boot up normally. You will see no alerts. Download and run CCleaner. BOOM. There it is again.
Now, how do I know it's not a false positive? It's in .jpg files. CCleaner's .jpg files aren't names of models, or so on. Further, the files and associated processes are attempting to use ports to get outbound and even inbound access.
It is real. And Piriform has ignored my email.
This is all just my humble, uneducated opinion.
#9 OFFLINE
Posted 27 February 2009 - 10:55 PM
Just my humble opinion again.
#10 OFFLINE
Posted 28 February 2009 - 05:10 AM
CHESTON, on Feb 27 2009, 10:54 PM, said:
Piriform needs to address this. Your software is being downloaded with a trojan.
Don't believe me? Those of you with Spysweeper or AdAware- when you go to the quarantine when Virtumonde pops up, click on the box below and locate the files. Turn off system restore, delete the files, run the scan again. Shut down, reboot in safe mode WITHOUT networking so no new files can show up. Run your scans again and again. Delete CCleaner or other Piriform products. Run it again if you'd like.
Then boot up normally. You will see no alerts. Download and run CCleaner. BOOM. There it is again.
Now, how do I know it's not a false positive? It's in .jpg files. CCleaner's .jpg files aren't names of models, or so on. Further, the files and associated processes are attempting to use ports to get outbound and even inbound access.
It is real. And Piriform has ignored my email.
This is all just my humble, uneducated opinion.
I am unable to re-produce this, CCleaner doesn't even install any jpgs. I'm pretty sure this is a failed troll or you're infected with something else.
#11 OFFLINE
Posted 28 February 2009 - 07:27 PM
brian2009, on Feb 28 2009, 12:10 AM, said:
Not a troll, you dolt. This is real, and it's happening on every 64 and 32 bit system we have, all on different ISPs, users and so forth. You obviously work for piriform since your very first post is not one seeking help but one defending the company and attacking an honest poster seeking assistance and being ignored by the company.
I guess everyone else on here is trolling, as well, if they post about an issue this serious.
#12 OFFLINE
Posted 28 February 2009 - 07:35 PM
When you do a registry analysis using even the latest version of CCleaner it installs Virtumonde of 2 different types. It is not a false positive. It is installing, as the trojan does, infected files under random file types and names under the AppData, Temp Internet Files, Low folders.
There you have it Piriform. Whether it's you or your uploading sites that are sticking the malicious code in there, it needs to be fixed. You have a better reputation than this.
#13 OFFLINE
Posted 28 February 2009 - 08:22 PM
CHESTON, on Feb 28 2009, 07:27 PM, said:
I've no intention of repeating the previous comments made on this subject, but I will say to you that none of the members on this forum work for Piriform. We are all volunteer helpers, and if you make another comment like this one, I'll suspend your account without hesitation.
Edit: On second thoughts, I am suspending your account. That remark was unjustified and totally unacceptable.
How To Get Into Safe Mode | Returnil 2008 | Sandboxie | ERUNT GUI | TestDisk | MiniTool Partition Wizard - Home Edition
#14 OFFLINE
Posted 01 March 2009 - 06:29 AM
#15 OFFLINE
Posted 01 March 2009 - 07:06 AM
The problem is for spysweeper to solve, it is a false positive on their part and I am afraid all you can do is keep emailing them about it.
http://www.piriform.com/docs
#16 OFFLINE
Posted 01 March 2009 - 01:01 PM
IT IS a false positive. CHESTON please don't PM staff as well. This is clearly a problem on Webroots part, you can get in touch with them about it.
I have run the CCleaner installer through VirScan.org/Jotti/Virustotal, which scans it with around 40 anti-virus scanners. None of them detect any problems. It is completely clean.
Closing this topic since its clearly wrong and getting nowhere
~Scratch~


This topic is locked









