Jump to content


CCleaner yet another trojan on Uninstaller


14 replies to this topic

#1 OFFLINE   Bollen

    Newbie

  • Members
  • Pip
  • 1 posts

Posted 01 December 2006 - 09:08 AM

Well I read about this earlier and its not the first time uninstallers has been false flagged as trojans. This time its from the program Spyware Doctor from PC Tools. Maybe you should contact them, since its really not good if CCleaner get a reputation for having a trojan in it.
Anyways love the program and I just wanted to report this :)

Added a picture what Spyware Doctor said.

Attached File  ccleaner_trojan.JPG   78.15K   159 downloads

#2 OFFLINE   TheFiresInTheSky

    aka "neighberaaron"

  • Members
  • PipPipPipPip
  • 1,738 posts
  • Gender:Male
  • Location:somewhere in the glove
  • Interests:computers, myspace, website building, skating, ITG, DDR, summers, hanging out at the mall.

Posted 01 December 2006 - 12:34 PM

welcome bollen :D
are you sure you have the latest version?
my dad has spyware doctor and also ccleaner, no problems.
-aaron

#3 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,328 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 01 December 2006 - 02:22 PM

I'll check it out to see if I can confirm it with the newest version which is 4.0 - been meaning to try out the program anyways.
Complexity of incoherent design.

#4 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,328 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 01 December 2006 - 03:36 PM

I just scanned with Spyware Doctor 4.0 and it didn't detect any CCleaner files as infected.

Make sure your Spyware Doctor is up-to-date.
Complexity of incoherent design.

#5 OFFLINE   heinzhonk

    Newbie

  • Members
  • Pip
  • 2 posts

Posted 03 December 2006 - 07:05 PM

hi, i got the same message by ccleaner. to be absolutly sure, can anyone give me his/her md5-checksum?

best regards

#6 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,328 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 03 December 2006 - 08:07 PM

To be absolutely sure you can always do the normal which is upload for malware scanning to these two malware scanners:
Complexity of incoherent design.

#7 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 04 December 2006 - 08:20 AM

View Postheinzhonk, on Dec 3 2006, 08:05 PM, said:

hi, i got the same message by ccleaner. to be absolutly sure, can anyone give me his/her md5-checksum?

5bb116b6b982f79626fcea7ccee9d8c0

#8 OFFLINE   heinzhonk

    Newbie

  • Members
  • Pip
  • 2 posts

Posted 04 December 2006 - 03:51 PM

I got another one, but i think, to installdir should be saved in the exe-file. so, there is a different checksum.

or is there anybody, who got the same checksum as tonyklein (5bb116b6b982f79626fcea7ccee9d8c0) or me (0783a79ef1b9948718d04737cf49ae3f) ?

#9 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,328 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 04 December 2006 - 04:29 PM

How are you getting the checksums?

MrG the CCleaner developer added a VeriSign Digital Signature to the CCleaner setup file!

You can view it by right clicking the setup file and selecting Properties->Digital Signatures->hightlight Pirform Ltd->click Details

Now you can click View Certificate->Certificate Path to see the Certificate Status. It should read: This certificate is OK.
Complexity of incoherent design.

#10 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 04 December 2006 - 04:35 PM

View PostAndavari, on Dec 4 2006, 05:29 PM, said:

How are you getting the checksums?
Personally, I'm using Summerproperties, a nice little shell extension which adds a 'Checksums" tab to your file's properties. Very handy.

http://www.earthmagic.org/?software

Attached Files

  • Attached File  Sum.gif   15.65K   38 downloads


#11 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,328 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 04 December 2006 - 10:01 PM

Using the tool TK linked to this is what I got, text and screenshot included:
CCleaner Version (Slim Install): 1.35.424
File: C:\Program Files\CCleaner\uninst.exe
CRC16: 255a
CBR32: 2cb86e75
MD5: 80b4f6b6955fc10fc804efadc4be2688
SHA1: ec1c6be1bc5e8f7bce65bbabb7fd835824972805
Posted Image
Complexity of incoherent design.

#12 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 05 December 2006 - 06:17 AM

LOL! :lol:

This is using Patrick Kolla's FileAlyzer. Not unexpectedly identical to what I got before.

There seem to be numerous legitimate versions of this file... :rolleyes:

Attached Files



#13 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,328 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 05 December 2006 - 06:36 AM

View PostTonyKlein, on Dec 5 2006, 12:17 AM, said:

There seem to be numerous legitimate versions of this file... :rolleyes:
So what are you saying, is it just some generic uninstall routine? Sort of like what Inno Setup has (well at least Inno Setup's uninstaller has matching checksums.)
Complexity of incoherent design.

#14 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 05 December 2006 - 06:43 AM

View PostAndavari, on Dec 5 2006, 07:36 AM, said:

So what are you saying?

I wish I knew what I was saying... Posted Image

I guess MrG is the only one who can answer this question.

#15 OFFLINE   MrG

    Administrator

  • Admin
  • 1,105 posts
  • Gender:Male
  • Location:London, UK

Posted 05 December 2006 - 12:39 PM

I've received confirmation that the latest definitions for Spyware Doctor have fixed this false positive detection. So hopefully this won't happen again. :)

I'm pretty sure the installer engine (NSIS) creates the uninstaller dynamically during the installation process. So it's not possible to digitally sign this file or guarantee what it's MD5 sig will be.

MrG