{"id":13602,"date":"2017-09-18T18:38:26","date_gmt":"2017-09-18T22:38:26","guid":{"rendered":"http:\/\/www.thundercloud.net\/infoave\/new\/?p=13602"},"modified":"2017-09-22T10:56:44","modified_gmt":"2017-09-22T14:56:44","slug":"avast-buys-ccleaner-then-distributes-an-infected-hacked-version-to-users","status":"publish","type":"post","link":"https:\/\/www.thundercloud.net\/infoave\/new\/avast-buys-ccleaner-then-distributes-an-infected-hacked-version-to-users\/","title":{"rendered":"Avast Buys CCleaner Then Distributes an Infected, Hacked Version to Users"},"content":{"rendered":"<h1>Avast Buys CCleaner Then Distributes an Infected, Hacked Version to Users<\/h1>\n<p>We&#8217;ve cautioned users against trusting their computers to Avast many times. We based this on the number of computers we&#8217;ve worked that had Avast installed and that were infected with malware.\u00a0 We written several warnings about Avast, for instance <a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/if-youre-using-avast-you-need-to-read-this\/\" target=\"_blank\" rel=\"noopener\">this one<\/a> that we wrote in 2014.<\/p>\n<p>In July 2017, Avast purchased Piriform &#8211; the company that makes CCleaner. By August 15, 2017, Avast started distributing an infected, hacked version of CCleaner that compromised users&#8217; computers, opened a backdoor for the potential installation of more malware, and allowed the compromised computer to send back personal information to the hijackers.<\/p>\n<p>&#8220;Forbes&#8221; explains:<\/p>\n<div>\n<blockquote><p>Users of Avast-owned security application CCleaner for Windows have been advised to update their software immediately, after researchers discovered criminal hackers had installed a backdoor in the tool. The tainted application allows for download of further malware, be it ransomware or keyloggers, with fears millions are affected.<\/p>\n<p>The affected app, CCleaner, is a maintenance and file clean-up software run\u00a0by a\u00a0subsidiary of anti-virus giant Avast. It has 2 billion downloads and claims to be getting 5 million extra a week, making the threat particularly severe, researchers at Cisco Talos\u00a0<a href=\"http:\/\/blog.talosintelligence.com\/2017\/09\/avast-distributes-malware.html\" target=\"_blank\" rel=\"noopener\">warned<\/a>. Comparing it to the\u00a0<a href=\"https:\/\/www.forbes.com\/sites\/thomasbrewster\/2017\/06\/27\/petya-notpetya-ransomware-is-more-powerful-than-wannacry\/\" target=\"_self\">NotPetya ransomware outbreak<\/a>, which spread after a Ukrainian accounting app was infected, the\u00a0researchers\u00a0discovered the threat on September 13 after CCleaner 5.33 caused Talos systems to flag malicious activity.<\/p>\n<p>Further investigation found the CCleaner download server was hosting the backdoored app as far back as September 11. Talos warned in a blog Monday that the affected version was released on August 15, but on September 12 an untainted version 5.34 was released. For weeks then, the malware was spreading inside supposedly-legitimate security software. If CCleaner&#8217;s claims on user numbers, millions are likely affected.<\/p>\n<p>(<a href=\"https:\/\/www.forbes.com\/sites\/thomasbrewster\/2017\/09\/18\/ccleaner-cybersecurity-app-infected-with-backdoor\/#75bb7c28316a\" target=\"_blank\" rel=\"noopener\">read more &#8230;<\/a> )<\/p><\/blockquote>\n<\/div>\n<p>According the information from Cisco Talos, Avast distributed the compromised, hacked version of CCleaner from August 15, 2017 until September 12, 2017. That means that for nearly four weeks, Avast continued to distribute an infected, hacked CCleaner which contained a backdoor Trojan that was capable of downloading malware, keyloggers, ransomware and other malware onto the user&#8217;s computer &#8212; without the user&#8217;s knowledge. Plus, it open a pathway for the user&#8217;s confidential information to be sent surreptitiously to clandestine web servers belonging to the hacker.<\/p>\n<p>It&#8217;s a sad state of affairs when a security vendor, who inherently has users&#8217; trust, could allow something like this to happen &#8212; let alone take almost 4 weeks to discover it. All that time, Avast\/Piriform\u00a0 continued to distribute the compromised CCleaner<\/p>\n<p>If Avast can allow something like this to happen to their own servers and software products, then just how well do you think Avast is protecting your computer?\u00a0 This is really a shame;\u00a0 this is all about a compromised security vendor, something that should never have been allowed to happen.<\/p>\n<p>Sometimes free is just too expensive.<\/p>\n<p>Those of you who are using Emsisoft are protected from the effects of the CCleaner hacking. If you&#8217;re not using Emsisoft, consider taking advantage of <a href=\"http:\/\/thundercloud.net\/direct\/2017\/Emsisoft\/\" target=\"_blank\" rel=\"noopener\">our special offer<\/a>.<\/p>\n<p>To those using CCleaner, we urge you to consider an alternative, or at the very least, update CCleaner immediately. If you&#8217;re looking for an easy cleanup solution,\u00a0 try <a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/windows-disk-cleanup-the-disk-cleaning-program-you-forgot-you-had\/\">Windows Disk Cleanup<\/a> &#8211; it comes with every version of Windows &#8211; you already have it.<\/p>\n<p>We use and offer Reg Organizer and it&#8217;s discounted for Cloudeight subscribers &amp; readers. While it is not free, it is a great tool for cleanup, tweaking, optimizing and more. Reg Organizer 8.0 has new cleanup and privacy features. <a href=\"http:\/\/thundercloud.net\/ro\/\" target=\"_blank\" rel=\"noopener\"><strong>You can read more about the newest version of Reg Organizer with enhanced cleanup features here.\u00a0<\/strong><\/a><\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<h2><a href=\"http:\/\/thundercloud.net\/direct\/2017\/Emsisoft\/\" target=\"_blank\" rel=\"noopener\"><strong>Our recommendation of Emsisoft &amp; a Special Offer<\/strong><\/a><\/h2>\n<p><a href=\"http:\/\/thundercloud.net\/direct\/2017\/Emsisoft\/\"> <img loading=\"lazy\" decoding=\"async\" class=\"auto-style796\" src=\"http:\/\/thundercloud.net\/infoave\/images\/2017\/mz-with-install.png\" alt=\"No Foolin' Special - Emsisoft with Free Installation\" width=\"378\" height=\"95\" \/><\/a><\/p>\n<p>Several years ago, we made a decision to recommend Emsisoft to our readers. We did not do so lightly. We spent weeks testing many security and anti-virus programs before we decided on Emsisoft. It&#8217;s one of the best decisions we&#8217;ve ever made. Not only does Emsisoft provide superior protection, the team behind it provides world-class to support to all our mutual customers.<\/p>\n<p>For the last month or so, we&#8217;ve been offering Emsisoft, with a one-year license, plus free installation and set-up by Cloudeight &#8211; all for less than the retail price. Now, because of of the Avast\/Piriform CCleaner hack, we&#8217;re including with our Emsisoft offer, a free checkup to make sure your computer has not been affected. We will completely uninstall your current security software,\u00a0 check your PC for malware, check CCleaner, make sure it&#8217;s updated, (or remove it at your request) plus and install and configure Emsisoft (including a one-year license)&#8230; all for one low price. <strong><a href=\"http:\/\/thundercloud.net\/direct\/2017\/Emsisoft\/\" target=\"_blank\" rel=\"noopener\">See this page for more information<\/a><\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Avast Buys CCleaner Then Distributes an Infected, Hacked Version to Users We&#8217;ve cautioned users against trusting their computers to Avast many times. We based this on the number of computers we&#8217;ve worked that had Avast installed and that were infected with malware.\u00a0 We written several warnings about Avast, for instance this one that we wrote in 2014. In\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/avast-buys-ccleaner-then-distributes-an-infected-hacked-version-to-users\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":13604,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1678,1,1426,1670,1656,1674,779,10],"tags":[1006,1832,1833,1823,1115,4],"_links":{"self":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/13602"}],"collection":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/comments?post=13602"}],"version-history":[{"count":6,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/13602\/revisions"}],"predecessor-version":[{"id":13639,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/13602\/revisions\/13639"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media\/13604"}],"wp:attachment":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media?parent=13602"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/categories?post=13602"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/tags?post=13602"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}