Piriform Community Forums: Virus alert with CCcleaner files - Piriform Community Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Virus alert with CCcleaner files Virus alert with CCcleaner files

#1 User is offline   gagelle 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 2
  • Joined: 19-September 06

Posted 19 September 2006 - 06:48 PM

My Kaspersky anti-virus picked up a trojan downloader file win32.zlob.kz in several CCcleaner files including ccsetup133.exe and uninst.exe. I had Kaspersky delete these files. Does anyone know if this is a false alarm? When I go on the CCcleaner web site and try to download the program again, I get an alert that the installation program is infected with this same trojan.
0

#2 User is offline   Eldmannen 

  • Annoyance
  • PipPipPipPipPip
  • Group: Banned
  • Posts: 2,198
  • Joined: 27-May 05
  • Location:Internet
  • Interests:Free software, open-source, GNU GPL, Linux, security, encryption, privacy, anonymity.

Posted 19 September 2006 - 07:28 PM

Could be a false positive.

You can upload the file to an online scanner.
http://forum.ccleane...?showtopic=5496


0

#3 User is offline   TonyKlein 

  • Power Member
  • Icon
  • Group: Spyware Moderators
  • Posts: 603
  • Joined: 12-June 06
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 07:35 PM

Hi and welcome. :)

It's either a false positive or ALL of us are now infected... LOL!

... just kidding of course, and I'm unable to duplicate that. I just downloaded the latest version from here:

http://www.ccleaner.com/download/

I uploaded the installer to be tested at http://www.virustota...h/index_en.html , a site which uses a number of different AVs, including Kaspersky, to scan a file, and the results were negative, as is to be expected.

Not sure what exactly it was you downloaded, or where you found it...
0

#4 User is offline   Tsumana 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 1
  • Joined: 19-September 06

Posted 19 September 2006 - 07:49 PM

The same thing happened to me in the past half hour or so, I use Kaspersky and I downloaded CCleaner from the 'Alternative Download' page. All the online scanners I checked told me it was fine so I think must just be Kaspersky. :unsure:
0

#5 User is offline   Andavari 

  • Captain Spectacular
  • Icon
  • Group: Moderators
  • Posts: 11,229
  • Joined: 10-November 04
  • Gender:Male
  • Location:Shadow Moses

Posted 19 September 2006 - 07:49 PM

Kaspersky has detected CCleaner before and it's always been a false positive, so this info really isn't anything new. And the last time something was detected called "Not-A-Virus" I think they refused to remove it from their detection.
Piriform Internal Links:
Piriform Docs - Official documentation for Piriform software.
Solutions when CCleaner won't install.

External Links:
ERUNT · Macrium Reflect Free Edition · Paragon Rescue Kit Express
0

#6 User is offline   TonyKlein 

  • Power Member
  • Icon
  • Group: Spyware Moderators
  • Posts: 603
  • Joined: 12-June 06
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 07:53 PM

OK, I downloaded a copy from the Alternative download page and will try to duplicate that.

If so I'll submit the FP in a specialized forum where it ought toi be noticed by the right folks.
0

#7 User is offline   qurks 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 3
  • Joined: 19-September 06

Posted 19 September 2006 - 07:55 PM

Hi,
I'm new to this forum. I've come here because I have the same problem as stated above. Only that as of now, I still haven't decided who to trust, Kaspersky or CCleaner? I have been using both programs for a while now, and they have both always performed very well. Now Kaspersky is telling me to delete Ccleaner, or at least the uninstall.exe file. Any opinions? (I've attached a screenshot, if you'd like to see it)

THANKS!

Attached File  kaspersky.png (16.24K)
Number of downloads: 161

Ooops, I guess you guys already posted your opinion while I was typing and taking screenshots...
0

#8 User is offline   TonyKlein 

  • Power Member
  • Icon
  • Group: Spyware Moderators
  • Posts: 603
  • Joined: 12-June 06
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 08:03 PM

Well, I'm still unable to duplicate it using the VT scan. Possibly the online scanner isn't using the Extended Virus databases...

Will try http://virusscan.jotti.org/ now...

View Postqurks, on Sep 19 2006, 09:55 PM, said:

Now Kaspersky is telling me to delete Ccleaner, or at least the uninstall.exe file. Any opinions?


I'll post in the specialized forum in question, where it should be noticed by someone from KAV.

But feel free to contact them yourselves as well. It can only be a FP...


....


Well, still unable to duplicate it using either Jotti's or Kaspersky's own online scan:

http://www.kaspersky.../remoteviruschk

It didn't object to my uninst.exe either...

FP Submitted at the board.
0

#9 User is offline   qurks 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 3
  • Joined: 19-September 06

Posted 19 September 2006 - 08:08 PM

View PostTonyKlein, on Sep 19 2006, 10:03 PM, said:

But feel free to contact them yourselves as well. It can only be a FP...


I've sent them an email.

Thanks for your help.
0

#10 User is offline   TonyKlein 

  • Power Member
  • Icon
  • Group: Spyware Moderators
  • Posts: 603
  • Joined: 12-June 06
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 08:09 PM

Allrighty, I just read it should be fixed in the next update:

http://forum.kaspers...showtopic=21876
0

#11 User is offline   MrG 

  • Administrator
  • Icon
  • Group: Admin
  • Posts: 991
  • Joined: 05-November 04
  • Gender:Male
  • Location:London, UK

Posted 19 September 2006 - 08:12 PM

Don't worry it's just another false positive. I think Kaspersky need to improve their QA a little bit. :)

I'll put a note on the homepage to let people know.

MrG
0

#12 User is offline   qurks 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 3
  • Joined: 19-September 06

Posted 19 September 2006 - 08:16 PM

I have just updated Kaspersky and scanned the whole CCleaner directory again. No problems reported. Everything's solved. thanks.
0

#13 User is offline   TonyKlein 

  • Power Member
  • Icon
  • Group: Spyware Moderators
  • Posts: 603
  • Joined: 12-June 06
  • Gender:Male
  • Location:Netherlands

Posted 19 September 2006 - 08:18 PM

That's good to hear, thanks for the heads up. :)
0

#14 User is offline   MrG 

  • Administrator
  • Icon
  • Group: Admin
  • Posts: 991
  • Joined: 05-November 04
  • Gender:Male
  • Location:London, UK

Posted 19 September 2006 - 08:24 PM

View Postqurks, on Sep 19 2006, 08:16 PM, said:

I have just updated Kaspersky and scanned the whole CCleaner directory again. No problems reported. Everything's solved. thanks.


Great thanks! :D
0

#15 User is offline   gagelle 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 2
  • Joined: 19-September 06

Posted 19 September 2006 - 11:20 PM

Thank You everone. I think I'll have to reinstall Ccleaner because I used "Your Uninstaller!" to remove the CCleaner registry entries and then manually deleted the rest of the files. I guess I overreacted because I thought other parts of the program might be infected.
0

#16 User is offline   jebwhs87 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 1
  • Joined: 21-September 06

Posted 21 September 2006 - 12:23 PM

I too am getting a virus message on the Uninst.ext file (win32/zlob.oa). I am using F-Prot. This started showing up about a week ago.
0

#17 User is offline   Eldmannen 

  • Annoyance
  • PipPipPipPipPip
  • Group: Banned
  • Posts: 2,198
  • Joined: 27-May 05
  • Location:Internet
  • Interests:Free software, open-source, GNU GPL, Linux, security, encryption, privacy, anonymity.

Posted 21 September 2006 - 02:13 PM

This is why CCleaner should have file hashes on the website.


0

#18 User is offline   TonyKlein 

  • Power Member
  • Icon
  • Group: Spyware Moderators
  • Posts: 603
  • Joined: 12-June 06
  • Gender:Male
  • Location:Netherlands

Posted 22 September 2006 - 06:38 AM

View Postjebwhs87, on Sep 21 2006, 02:23 PM, said:

I too am getting a virus message on the Uninst.ext file (win32/zlob.oa). I am using F-Prot. This started showing up about a week ago.


OK, so please report the False Positive to F-Prot so they can correct this... I'll report it myself as well.


...


done! :)
0

#19 User is offline   TonyKlein 

  • Power Member
  • Icon
  • Group: Spyware Moderators
  • Posts: 603
  • Joined: 12-June 06
  • Gender:Male
  • Location:Netherlands

Posted 22 September 2006 - 05:44 PM

OK, according to Frisk/F-Prot's Mike:

Quote

That was fixed already - they should update...


So there ya go...
0

#20 User is offline   DEWOPA 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 1
  • Joined: 08-October 07

Post icon  Posted 08 October 2007 - 04:32 PM

Hey Gang -

I have been using CCleaner for a couple of years now and recently updated the client to the most current version. Minutes after installing the new version and running it for the first time, I got the attached McAfee VirusScan Alert. This has never happened before, for me. I have ran everything I can think of and nothing indicates a virus. Suggestions?

Attached File(s)


0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic