Jump to content


Virus alert with CCcleaner files


20 replies to this topic

#1 OFFLINE   gagelle

    Newbie

  • Members
  • Pip
  • 2 posts

Posted 19 September 2006 - 06:48 PM

My Kaspersky anti-virus picked up a trojan downloader file win32.zlob.kz in several CCcleaner files including ccsetup133.exe and uninst.exe. I had Kaspersky delete these files. Does anyone know if this is a false alarm? When I go on the CCcleaner web site and try to download the program again, I get an alert that the installation program is infected with this same trojan.

#2 OFFLINE   Eldmannen

    Annoyance

  • Banned
  • PipPipPipPipPip
  • 2,198 posts
  • Location:Internet
  • Interests:Free software, open-source, GNU GPL, Linux, security, encryption, privacy, anonymity.

Posted 19 September 2006 - 07:28 PM

Could be a false positive.

You can upload the file to an online scanner.
http://forum.ccleane...?showtopic=5496



#3 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 07:35 PM

Hi and welcome. :)

It's either a false positive or ALL of us are now infected... LOL!

... just kidding of course, and I'm unable to duplicate that. I just downloaded the latest version from here:

http://www.ccleaner.com/download/

I uploaded the installer to be tested at http://www.virustota...h/index_en.html , a site which uses a number of different AVs, including Kaspersky, to scan a file, and the results were negative, as is to be expected.

Not sure what exactly it was you downloaded, or where you found it...

#4 OFFLINE   Tsumana

    Newbie

  • Members
  • Pip
  • 1 posts

Posted 19 September 2006 - 07:49 PM

The same thing happened to me in the past half hour or so, I use Kaspersky and I downloaded CCleaner from the 'Alternative Download' page. All the online scanners I checked told me it was fine so I think must just be Kaspersky. :unsure:

#5 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,327 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 19 September 2006 - 07:49 PM

Kaspersky has detected CCleaner before and it's always been a false positive, so this info really isn't anything new. And the last time something was detected called "Not-A-Virus" I think they refused to remove it from their detection.
Complexity of incoherent design.

#6 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 07:53 PM

OK, I downloaded a copy from the Alternative download page and will try to duplicate that.

If so I'll submit the FP in a specialized forum where it ought toi be noticed by the right folks.

#7 OFFLINE   qurks

    Newbie

  • Members
  • Pip
  • 3 posts

Posted 19 September 2006 - 07:55 PM

Hi,
I'm new to this forum. I've come here because I have the same problem as stated above. Only that as of now, I still haven't decided who to trust, Kaspersky or CCleaner? I have been using both programs for a while now, and they have both always performed very well. Now Kaspersky is telling me to delete Ccleaner, or at least the uninstall.exe file. Any opinions? (I've attached a screenshot, if you'd like to see it)

THANKS!

Attached File  kaspersky.png   16.24K   161 downloads

Ooops, I guess you guys already posted your opinion while I was typing and taking screenshots...

#8 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 08:03 PM

Well, I'm still unable to duplicate it using the VT scan. Possibly the online scanner isn't using the Extended Virus databases...

Will try http://virusscan.jotti.org/ now...

View Postqurks, on Sep 19 2006, 09:55 PM, said:

Now Kaspersky is telling me to delete Ccleaner, or at least the uninstall.exe file. Any opinions?

I'll post in the specialized forum in question, where it should be noticed by someone from KAV.

But feel free to contact them yourselves as well. It can only be a FP...


....


Well, still unable to duplicate it using either Jotti's or Kaspersky's own online scan:

http://www.kaspersky.../remoteviruschk

It didn't object to my uninst.exe either...

FP Submitted at the board.

#9 OFFLINE   qurks

    Newbie

  • Members
  • Pip
  • 3 posts

Posted 19 September 2006 - 08:08 PM

View PostTonyKlein, on Sep 19 2006, 10:03 PM, said:

But feel free to contact them yourselves as well. It can only be a FP...

I've sent them an email.

Thanks for your help.

#10 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 08:09 PM

Allrighty, I just read it should be fixed in the next update:

http://forum.kaspers...showtopic=21876

#11 OFFLINE   MrG

    Administrator

  • Admin
  • 1,105 posts
  • Gender:Male
  • Location:London, UK

Posted 19 September 2006 - 08:12 PM

Don't worry it's just another false positive. I think Kaspersky need to improve their QA a little bit. :)

I'll put a note on the homepage to let people know.

MrG

#12 OFFLINE   qurks

    Newbie

  • Members
  • Pip
  • 3 posts

Posted 19 September 2006 - 08:16 PM

I have just updated Kaspersky and scanned the whole CCleaner directory again. No problems reported. Everything's solved. thanks.

#13 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 08:18 PM

That's good to hear, thanks for the heads up. :)

#14 OFFLINE   MrG

    Administrator

  • Admin
  • 1,105 posts
  • Gender:Male
  • Location:London, UK

Posted 19 September 2006 - 08:24 PM

View Postqurks, on Sep 19 2006, 08:16 PM, said:

I have just updated Kaspersky and scanned the whole CCleaner directory again. No problems reported. Everything's solved. thanks.

Great thanks! :D

#15 OFFLINE   gagelle

    Newbie

  • Members
  • Pip
  • 2 posts

Posted 19 September 2006 - 11:20 PM

Thank You everone. I think I'll have to reinstall Ccleaner because I used "Your Uninstaller!" to remove the CCleaner registry entries and then manually deleted the rest of the files. I guess I overreacted because I thought other parts of the program might be infected.

#16 OFFLINE   jebwhs87

    Newbie

  • Members
  • Pip
  • 1 posts

Posted 21 September 2006 - 12:23 PM

I too am getting a virus message on the Uninst.ext file (win32/zlob.oa). I am using F-Prot. This started showing up about a week ago.

#17 OFFLINE   Eldmannen

    Annoyance

  • Banned
  • PipPipPipPipPip
  • 2,198 posts
  • Location:Internet
  • Interests:Free software, open-source, GNU GPL, Linux, security, encryption, privacy, anonymity.

Posted 21 September 2006 - 02:13 PM

This is why CCleaner should have file hashes on the website.



#18 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 22 September 2006 - 06:38 AM

View Postjebwhs87, on Sep 21 2006, 02:23 PM, said:

I too am getting a virus message on the Uninst.ext file (win32/zlob.oa). I am using F-Prot. This started showing up about a week ago.

OK, so please report the False Positive to F-Prot so they can correct this... I'll report it myself as well.


...


done! :)

#19 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 22 September 2006 - 05:44 PM

OK, according to Frisk/F-Prot's Mike:

Quote

That was fixed already - they should update...

So there ya go...

#20 OFFLINE   DEWOPA

    Newbie

  • Members
  • Pip
  • 1 posts

Posted 08 October 2007 - 04:32 PM

Hey Gang -

I have been using CCleaner for a couple of years now and recently updated the client to the most current version. Minutes after installing the new version and running it for the first time, I got the attached McAfee VirusScan Alert. This has never happened before, for me. I have ran everything I can think of and nothing indicates a virus. Suggestions?

Attached Files