Jump to content


Virus scanner reports false positive for CCleaner


12 replies to this topic

#1 OFFLINE   Kenward

    Newbie

  • Members
  • Pip
  • 4 posts

Posted 12 November 2006 - 10:39 AM

Earlier today, my Sophos anti virus software warned me that it had detected a virus in the "uninstall" bit of CCleaner.

I suspect a false positive, so I came here to see what is happening. I see a new version and try to download it, but Sophos tells me that it is infected.

Checking the archives here, I find an earlier hot tempered report of this behaviour that went round in circles and did not end up in a satisfactory resolution.

As I say, I suspect a false positive. These things happen, but not usually with Sophos, which is better than the usual cowboy stuff from Norton/Symantec. But I am not inclined to install something that is going to deliver these messages.

In this case, maybe a "bought in" component, the uninstaller, is responsible.

Here is the bit of the AV log that matters:

20061112 093251 Virus 'Troj/Zlob-VU' has been detected in "C:\Program Files\CCleaner\uninst.exe"

20061112 093251 Infected file "C:\Program Files\CCleaner\uninst.exe" has been moved to "C:\Documents and Settings\All Users\Application Data\Sophos\Sophos Anti-Virus\INFECTED\uninst.exe.000".

20061112 101711 Virus 'Troj/Zlob-VU' has been detected in "C:\Documents and Settings\{username}\Local Settings\Temp\vq4xpv7i.exe"

20061112 101711 Infected file "C:\Documents and Settings\{username}\Local Settings\Temp\vq4xpv7i.exe" has been moved to "C:\Documents and Settings\All Users\Application Data\Sophos\Sophos Anti-Virus\INFECTED\vq4xpv7i.exe.000".

The second half is the result of trying to download the latest version of CCleaner.

You might like to tell Sophos that you are good guys.

#2 OFFLINE   jgjgjg

    Newbie

  • Members
  • Pip
  • 1 posts

Posted 12 November 2006 - 12:42 PM

Similar thing happened to me this morning - but not during a download.

Sophos just reported this virus in c:\programfiles\ccleaner\uninst.exe troj/zlob-VU

I am running ccleaner 1.34.407 (downloaded a while back)
Sophos 6.0.5 last updated this morning.

I've never had A/V problems with the ccleaner before so I assume it is the latest Sophos update that has triggered a false positive.

#3 OFFLINE   rridgely

    I hate computers

  • Moderators
  • 8,858 posts
  • Gender:Male

Posted 12 November 2006 - 05:48 PM

Yes, its just false positive. MrG will have to contact sophos and have the issue fixed. Thanks for the information. :)

#4 OFFLINE   Kenward

    Newbie

  • Members
  • Pip
  • 4 posts

Posted 12 November 2006 - 06:48 PM

View Postrridgely, on Nov 12 2006, 05:48 PM, said:

Yes, its just false positive. MrG will have to contact sophos and have the issue fixed. Thanks for the information. :)
While it isn't good for you folks, for me at least it is a relief to know that I am not the only one in the same boat!

It is, of course, typical that this happened at the weekend!

#5 OFFLINE   Kenward

    Newbie

  • Members
  • Pip
  • 4 posts

Posted 13 November 2006 - 02:18 PM

View PostKenward, on Nov 12 2006, 06:48 PM, said:

While it isn't good for you folks, for me at least it is a relief to know that I am not the only one in the same boat!

It is, of course, typical that this happened at the weekend!

May have been fixed in a new Sophos update. It did not object to today's download.

#6 OFFLINE   TheOdds

    Advanced Member

  • Members
  • PipPipPip
  • 74 posts
  • Gender:Male

Posted 13 November 2006 - 06:03 PM

http://forum.ccleane...?showtopic=7521

#7 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 13 November 2006 - 06:18 PM

I'll report this to Sophos for you.

#8 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,458 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 13 November 2006 - 06:22 PM

Already done Tony and sorted by Sophos with an update.

Sophos also flagged AVG antispyware's installer as having the same trojan this morning.
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#9 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 13 November 2006 - 06:25 PM

Ah, thank you - I was just about to report it... ;)

#10 OFFLINE   MrG

    Administrator

  • Admin
  • 1,105 posts
  • Gender:Male
  • Location:London, UK

Posted 14 November 2006 - 03:35 AM

Great work reporting this to Sophos! :)

#11 OFFLINE   KBG

    Newbie

  • Members
  • Pip
  • 1 posts

Posted 30 June 2007 - 04:54 AM

View PostMrG, on Nov 13 2006, 08:35 PM, said:

Great work reporting this to Sophos! :)
Hi i've had the same experience twice now and am using cox security suite which I think uses authentium for antivirus.
Hopefully you can e-mail them as well. Thank you for your time.

#12 OFFLINE   ampex

    Newbie

  • Members
  • Pip
  • 4 posts

Posted 30 June 2007 - 10:49 AM

Saturday - 30 June. Attempted to check for CCleaner update and Eset NOD32 virus scanner reported the following:

ARCHIVE http://ds.serving-sys.com/BurstingCachedSc...erMain_62_36.js
THREAT us/Tivso.14a.gen Trojan

I've never had a problem with CCleaner before and wonder if this is what is already being discussed/reported here.

#13 OFFLINE   fireryone

    Lets Get Dangerous

  • Members
  • PipPipPipPip
  • 1,626 posts
  • Gender:Male
  • Location:QLD,Australia
  • Interests:PC, LOTRO

Posted 30 June 2007 - 10:58 AM

I have the latest NOD32 & CCleaner and have not had that problem,
You may want to submit a hijack this log in that section of the forum to be sure it wasn't some other hidden malware not just a false positive!
fireryone



There are 10 types of people in this world.
Those who understand binary, and those who don't.