Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » CCleaner now installs with adware?
Uniqs:
6850
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Ubuntu Linux 7.10 fixes Highly Critical flaws in KOffice »
« Security Software Updates - 15 Nov 2007  
page: 1 · 2

Goodbye CCleaner

@cox.net

CCleaner now installs with adware?

D/Led the new version 2.02.257 - and when i ran my av overnight I found that Adware.SystemProcess was also now installed. AV removed it, but I was wondering if anyone else saw this too? The new CC version was all I d/led yesterday.

Thankss

Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire

Re: CCleaner now installs with adware?

i just updated my version and nothing untoward found
what is the location of the suspected adware process and what AV reported it?

Cudni

Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:


1 edit
An infector that was first found in 2005? Not likely that it came with CC. Your system let this BHO get installed from elsewhere.

»www.rickmaybury.com/fffpages/fff···v05.html
quote:
26-27/11/05
MALWARE INFESTATION WON''T GO AWAY
Hi Rick, I use Ad-Aware SE Personnel and Firefox. However, I keep getting a malware called "Adware.SystemProcess". Do you know where it originates and whether it is a cause for concern?
Nigel Deller
 
A. No problem, Adware SystemProcess is a persistent piece of malware that hides inside the Registry and latches on to Internet Explorer (yet another good reason to switch to Firefox), it then makes use of your internet connection and fiddles with your Firewall settings to allow it to connect with an outside company (usually ValueClick or one of its affiliates) to display ads in pop-up windows. AdAware should have removed it, however, the specific malware definition was included in update SE1R72, released on the 26th of October, so I suggest you download the latest updates and run it again. Otherwise there are manual removal procedures, (which involve editing the Registry) on the Symantec web site.
--
What’s the point of owning a supercar if you can’t scare yourself stupid from time to time?

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest

said by Goodbye CCleaner :

D/Led the new version 2.02.257 - and when i ran my av overnight I found that Adware.SystemProcess was also now installed. AV removed it, but I was wondering if anyone else saw this too? The new CC version was all I d/led yesterday.

Thankss
Out of curiosity what AV are you using,because my NIS 2007 zapped that the other day after an update.I thought it was a FP !! it could be if your using NAV too.

Just curious are you??
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:

Re: CCleaner now installs with adware?

I'm using NAV 2006 and have CC 2.02.257. I ran a AV scan yesterday and I just noticed that it tagged the same thing - Adware.SystemProcess

Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:

Re: CCleaner now installs with adware?

»www.symantec.com/security_respon···&tabid=2
quote:
Updated: February 13, 2007 11:46:22 AM
Type: Adware
Version: 1.0.0.1
Risk Impact: High
File Names: ccapp.exe,navshext.dll
Systems Affected: Windows 2000, Windows 98, Windows CE, Windows Me, Windows NT, Windows Server 2003, Windows XP

When Adware.SystemProcess is executed, it performs the following actions:

1. Creates the following files:

* %System%\ccapp.exe
* %System%\navshext.dll
* %System%\p.dat
* %System%\system.dat

Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

2. Downloads the following file:

%System%\ustart.exe (This is detected as Adware.WintaskAd.)

3. Creates the following registry subkeys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\Uninstall\Startup
HKEY_LOCAL_MACHINE\SOFTWARE\System Process
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
\{C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\Explorer\Browser Helper Objects
\{C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB}
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\anrdoezrs.net
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\bfast.com
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\cc-dt.com
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\commission-junction.com
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\dpbolvw.net
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\fastclick.com
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\fastclick.net
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\jdoqocy.com
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\kqzyfj.com
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\linksynergy.com
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\qksrv.net
HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003
\Software\Microsoft\Windows\CurrentVersion\Internet Settings
\P3P\History\tkqlhce.com

4. Adds the value:

"*.system-processes.com" = ""

to the registry subkey:

HKEY_USERS\S-1-5-21-448539723-413027322-839522115-1003\Software
\Microsoft\Internet Explorer\New Windows\Allow

5. Adds the value:

"%Windir%\system32\ccapp.exe" = "%Windir%\system32\ccapp.exe:*:Enabled:System Process"

to the registry subkey:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
\SharedAccess\Parameters\FirewallPolicy\StandardProfile
\AuthorizedApplications\List

6. Adds the value:

"System Process Uninstall" = "%Windir%\system32\ccapp.exe UAF"

to the registry subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce


--
What’s the point of owning a supercar if you can’t scare yourself stupid from time to time?

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable


1 edit
Just for everyone's info - I have sent the link to this topic to my contact at Symantec so it can be reviewed.

-amy-

--
DSLR Phishtracker

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH

Re: CCleaner now installs with adware?

Thanks Amy.

Was trying to find some info on this,but did not come up with much.

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

Re: CCleaner now installs with adware?

What would really help is for everyone to post the name of the file that was flagged during the scan - go to the Log Viewer / Security Risks for the source and name of the file found.

Thanks !!!

-amy-

--
DSLR Phishtracker

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest

Re: CCleaner now installs with adware?

said by amysheehan See Profile :

What would really help is for everyone to post the name of the file that was flagged during the scan - go to the Log Viewer / Security Risks for the source and name of the file found.

Thanks !!!

-amy-

This is what I have amy it is not showing a source.
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

Re: CCleaner now installs with adware?

Click for full size
Detailed Risk Properties Info
said by MagMan See Profile :

said by amysheehan See Profile :

What would really help is for everyone to post the name of the file that was flagged during the scan - go to the Log Viewer / Security Risks for the source and name of the file found.

Thanks !!!

-amy-

This is what I have amy it is not showing a source.
I found more details for a 'tracking cookie' that was found this AM that had no details by going to Quick Tasks / View History / Security History / Advanced Details / Risk Properties / Details.

See screenshot for more info - have a look there if you can. [2007 and 2008 versions]

-amy-
--
DSLR Phishtracker

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest

Re: CCleaner now installs with adware?

Click for full size
said by amysheehan See Profile :

said by MagMan See Profile :

said by amysheehan See Profile :

What would really help is for everyone to post the name of the file that was flagged during the scan - go to the Log Viewer / Security Risks for the source and name of the file found.

Thanks !!!

-amy-

This is what I have amy it is not showing a source.
I found more details for a 'tracking cookie' that was found this AM that had no details by going to Quick Tasks / View History / Security History / Advanced Details / Risk Properties / Details.

See screenshot for more info - have a look there if you can. [2007 and 2008 versions]

-amy-
This is what mine shows.
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:
·Comcast
·Alameda Power & Te..

Host:
Broadband Modem (H..
MSN
DSL Extreme
Windstream
Southeast Asian Br..

1 edit
Amy, I'm not showing anything in my Log Viewer / Security Risks for yesterday's date.

FWIW, I submitted the file to Symantec for review.

NAV said it was found in 25 registry entries. Also NAV never made a peep when I downloaded and installed the new version of CCleaner which was when it first come out. It squawked during my weekly full scan.




--
TH ~ NE ~ EPN ~ NC ~ TD

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

Re: CCleaner now installs with adware?

said by sashwa See Profile :

Amy, I'm not showing anything in my Log Viewer / Security Risks for yesterday's date.

FWIW, I submitted the file to Symantec for review.

NAV said it was found in 25 registry entries. Also NAV never made a peep when I downloaded and installed the new version of CCleaner which was when it first come out. It squawked during my weekly full scan.

[att=1][att=2]
Thanks for the screenshot and for submitting your item to them. Looks like it may just be registry entries that were found. I'm sure that info will be helpful to Symantec.

-amy-

--
DSLR Phishtracker

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH

1 edit

Re: CCleaner now installs with adware?

Thanks for your imput.

Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:

Re: CCleaner now installs with adware?

Your screen shot shows 71 Registry Entries and 2 Files.

What were the 2 Files?

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest

Re: CCleaner now installs with adware?

said by Doctor Olds See Profile :

Your screen shot shows 71 Registry Entries and 2 Files.

What were the 2 Files?
This.
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable


2 edits

Re: CCleaner now installs with adware?

said by MagMan See Profile :

said by Doctor Olds See Profile :

Your screen shot shows 71 Registry Entries and 2 Files.

What were the 2 Files?
This.
P.DAT is one of the files referenced in the Symantec write up -

Also the registry entry HKLM/ Software / ''System Process ''
»www.symantec.com/security_respon···&tabid=2

-amy-

--
DSLR Phishtracker

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest

Re: CCleaner now installs with adware?

said by amysheehan See Profile :

said by MagMan See Profile :

said by Doctor Olds See Profile :

Your screen shot shows 71 Registry Entries and 2 Files.

What were the 2 Files?
This.
P.DAT is one of the files referenced in the Symantec write up -
»www.symantec.com/security_respon···&tabid=2

-amy-

So your point being is what according to what NIS is saying it is toast.Which as far as I am concerned never existed in the first place.

My machine was not infected with this to me this is an FP.
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

Re: CCleaner now installs with adware?

said by MagMan See Profile :

So your point being is what according to what NIS is saying it is toast.Which as far as I am concerned never existed in the first place.

My machine was not infected with this to me this is an FP.
To clarify - I think that the app was flagged because for whatever reason there were registry entries and / or files that matched this definition. I would think it's a FP, but I am NOT the expert.

-amy-

--
DSLR Phishtracker

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest

The reason I say this is the other day after NIS updated and you know how it runs a quick scan after updating it showed up.Now previously to that there was no unusual behavior going on with my machine and zap all of sudden there it is.Plus it is odd to the fact that this has been around for awhile and it never got flagged before by any of the apps that I have and use regularly.
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

Re: CCleaner now installs with adware?

Click for full size
VirusTotal results
Just FYI: I downloaded the full version ccsetup202.exe and ran it thru VirusTotal.

Panda 9.0.0.4 2007.11.11 Suspicious file
Prevx1 V2 2007.11.11 Heuristic: Suspicious Hijacker

Additional information
File size: 2725528 bytes
MD5: 50d8917e026b3402af3d4933018ea33a
SHA1: a9ed613388243cd3997d0b7b8f4e6f4ee7e08101
packers: WiseSFX Dropper, WiseSFX Dropper, WiseSFX Dropper
Prevx info: »fileinfo.prevx.com/fileinfo.asp?···C43DBD89

sashwa See Profile submitted her files to Symantec for review - My older version of CCleaner doesn't get flagged by anyone.


--
DSLR Phishtracker

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH

Re: CCleaner now installs with adware?

So are we coming to a conclusion here of CCleaner being the culprit.
PrntRhd

join:2004-11-03
Fairfield, CA
·Comcast
·Comcast Formerly ..


1 edit

Re: CCleaner now installs with adware?

said by MagMan See Profile :

So are we coming to a conclusion here of CCleaner being the culprit.
Yeah, it was not CCleaner, it is NIS FP.

Also notice it was a anonymous poster who started the thread.

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:

Re: CCleaner now installs with adware?

PrntRhd, it's not just NIS as I only use NAV.

MarkAW
Barry White or lil bratt
Premium
join:2001-08-27
Canada
·Bell Sympatico
·Cogeco Cable


1 edit
said by PrntRhd See Profile :

said by MagMan See Profile :

So are we coming to a conclusion here of CCleaner being the culprit.
Yeah, it was not CCleaner, it is NIS FP.

Also notice it was a anonymous poster who started the thread.
Mods sorry for the OT post. What does a anon post have to do with the problem that others say they have seen as well.
--
Advertising is legalized lying. - H.G. Wells
Pleasure in the job puts perfection in the work. - Aristotle

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest

said by PrntRhd See Profile :

said by MagMan See Profile :

So are we coming to a conclusion here of CCleaner being the culprit.
Yeah, it was not CCleaner, it is NIS FP.

Also notice it was a anonymous poster who started the thread.
Ya your right I forgot about that,and that poster has not posted any other information about his situation in this thread.
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:
·Comcast
·Alameda Power & Te..

Host:
Broadband Modem (H..
MSN
DSL Extreme
Windstream
Southeast Asian Br..

1 edit

Re: CCleaner now installs with adware?

But regardless of the OP being anon, there are those of us using NAV and/or NIS that are seeing this. It could be from the CC upgrade or it could just be a conscience it happened around the same time and has nothing to do with the upgrade.
--
TH ~ NE ~ EPN ~ NC ~ TD

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest

Re: CCleaner now installs with adware?

said by sashwa See Profile :

But regardless of the OP being anon, there are those of us using NAV and/or NIS that are seeing this. It could be from the CC upgrade or it could just be a conscience it happened around the same time and has nothing to do with the upgrade.
Well whatever is going on we need some answers to it either way.
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:
·Comcast
·Alameda Power & Te..

Host:
Broadband Modem (H..
MSN
DSL Extreme
Windstream
Southeast Asian Br..
Amy, I wonder if it could have something to do with the virus update yesterday rather than from the CC upgrade? My upgrade was done around 11/5/07 and no peep from NAV until I did my weekly full scan.
--
TH ~ NE ~ EPN ~ NC ~ TD

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable


1 edit

Re: CCleaner now installs with adware?

said by sashwa See Profile :

Amy, I wonder if it could have something to do with the virus update yesterday rather than from the CC upgrade? My upgrade was done around 11/5/07 and no peep from NAV until I did my weekly full scan.
I scanned thru all the detections added and modified by Symantec for November and didn't find any changes or additions to Adware.SystemProcess
»www.symantec.com/avcenter/whats_···-11.html

But I may have missed it
--
DSLR Phishtracker

planet

join:2001-11-05
Olmsted Falls, OH

Re: CCleaner now installs with adware?

Check this thread, wonder if they are related?
»Norton and SpywareBlaster updates causing FP (likely)

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:

Re: CCleaner now installs with adware?

I'm not using SpywareBlaster but I do use Spybot and Ad-Aware 2007.

Owlbet
Ignite the Ice
Premium,MVM
join:2002-09-24
Palmer, AK
clubs:
·MTA Online


1 edit
said by sashwa See Profile :

Amy, I wonder if it could have something to do with the virus update yesterday rather than from the CC upgrade? My upgrade was done around 11/5/07 and no peep from NAV until I did my weekly full scan.
I'm in agreement with you. NAV 2006 (2 computers) and NAV 2007 (4 computers) all scan on Friday nights at 8:00 pm and nary a peep out of any of them. Those scans used the definitions for 11/09/2007.

However, since this topic has appeared, I've performed a Full System Scan on all six of my computers with definitions dated 11/11/2007. All six computers have been treated for Adware.SystemProcess and Spywareblaster shows 6 items with protection disabled.

It makes me wonder if my unrelated thread about the off status of Live Update is somehow related as well.

Oh the joys of computer ownership.

Edited to add: I'm not using CCleaner on any of my computers.
--
Alaska Aces 2007-2008 record as of this post: 6-3-1

aeloel

@1starnet.com

There is no source file. My NAV CE logs don't have good detail, except to say the infection was succesfully quarantined, but in looking at the event logs on the PC, I found the following symantec application message.

Event Type: Information
Event Source: Symantec AntiVirus
Event Category: None
Event ID: 3
Date: 11/12/2007
Time: 2:02:06 AM
User: N/A
Computer: 01WS010704
Description:

Risk: in File: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linksynergy.com by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file was quarantined successfully.

In reviewing the documentation on this Adware.systemprocess infection. It seems weird that this was the only element present in any of the affected machines.

FYI: we only use NAV CE now, but used to also have SpyBot S&D on some of them too.

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

Something to do - re: possible SpyBot old entries

quote:
In reviewing the documentation on this Adware.systemprocess infection. It seems weird that this was the only element present in any of the affected machines.

FYI: we only use NAV CE now, but used to also have SpyBot S&D on some of them too.
Open regedit
Navigate to this key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
If there are still entries from the old install of SpyBot S&D
and to this key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
and see if there are still entries that include domain names.

If so, let me know and I will give you a quick fix to remove all the leftovers from the old install.

That will insure that all domains are removed and should you decide to add those entries in the future that they will install properly.

-amy-


--
DSLR Phishtracker

blue

@telus.net

Re: Something to do - re: possible SpyBot old entries

Hello,
Thanks Amy for posting this info.
I too had this infection over the weekend. Do you know which program cause this???
I had a look under the regedit and there are lots under the zonemap\domains but I am still using Spy bot S&D. Please advise on what to do next. My pc is running good, but I am having lots of cookies every day, and not even using the internet.If I delete the files in the regedit under zonemap\domains will that remove the Spy bot S&D program?
Please post the quick fix.
Thanks

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

Re: Something to do - re: possible SpyBot old entries

said by blue :

Hello,
Thanks Amy for posting this info.
I too had this infection over the weekend. Do you know which program cause this???
I had a look under the regedit and there are lots under the zonemap\domains but I am still using Spy bot S&D. Please advise on what to do next. My pc is running good, but I am having lots of cookies every day, and not even using the internet.If I delete the files in the regedit under zonemap\domains will that remove the Spy bot S&D program?
Please post the quick fix.
Thanks
On the machine that has SpyBOT installed you can remove the SBot entries made by removing the immunization.
After you close SBot check the registry for any entries that are still present for each user account in the registry at the locations I noted before. Manually delete any entries you did not make yourself and close the registry.
Immunization will work best if zonemap\domains no longer lists any SUBKEYS. Do NOT delete the zonemap\domains key just any SUBKEYS.
Now you should be ready for a clean re-immunization with SpyBot.
If you note any strange reg entries please post back with the info.

-amy-

--
DSLR Phishtracker

w8sdz

join:2001-05-21
Port Orange, FL


3 edits

Re: Something to do - re: possible SpyBot old entries

This inf file will clean the Domains keys:

; DelDomains.inf
; Created by: Mike Burgess Microsoft MVP
; »mvps.org/winhelp2002/

(edited to remove code because next posting by Amy Sheehan has an improved version)
--
73 de w8sdz - sip:271752@fwd.pulver.com

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable


1 edit

Deldomains and how to reset restricted zones - MORE

Thank you for posting the deldomains info.

I was going to post the link and info once I got home to the computer to retrieve it all.

Again, thank you !!!

Some additional info:
How to download and more about deldomains and etc:

»mvps.org/winhelp2002/ [split] DelDomains.inf [remove split from URL to access]
For instructions on how to use Deldomains go to: »mvps.org/winhelp2002/restricted.htm
and scroll down to the section titled ''To remove all the sites listed in the Restricted Zone''
NOTE: Also new to IE7 the "Reset Internet Explorer settings" will remove all sites in the Trusted and Restricted Zones. Go to internet options/advanced and the reset button is at the bottom of the window.

-amy-



--
DSLR Phishtracker

dadkins
Can you do Blu?
Premium,MVM
join:2003-09-26
Hercules, CA
·Comcast

Click for full size
Nope
Click for full size
Doesn't exist
Click for full size
Zilch
Newest(shocker?) CrapCleaner here, went through the manual removal steps at the Symantec site - nada.

avast never made a peep when I installed CCleaner - ever.
Just finished a system scan with avast - nada.

Me thinks, like Doctor Olds, it came from somewhere else.
If, in fact, you did get this old critter, you should be more concerned on how or why it got past your current AV.
--
Think outside the Fox... Opera

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest

Re: CCleaner now installs with adware?

Let me clarify my post I was never infected with this,or was there any unusual behavior going on with in my machine.That is why I am saying it is a false positive for me.Especially after checking the log file and it shows no source.
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

hayc59
VoodooChild
Premium
join:2001-02-26
David R.I.P.
Ran NOD32/SUPERAntispyware/KAV
found no such beast here!!

dadkins
Can you do Blu?
Premium,MVM
join:2003-09-26
Hercules, CA
·Comcast

Re: CCleaner now installs with adware?

said by hayc59 See Profile :

Ran NOD32/SUPERAntispyware/KAV
found no such beast here!!
You can add a2 to that list as well...
--
Think outside the Fox... Opera

hayc59
VoodooChild
Premium
join:2001-02-26
David R.I.P.

Re: CCleaner now installs with adware?

said by dadkins See Profile :

said by hayc59 See Profile :

Ran NOD32/SUPERAntispyware/KAV
found no such beast here!!
You can add a2 to that list as well...
Yes indeed, just got done running that

amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

Click for full size
3 versions available
Which version of CCleaner did you download ???
Standard
Portable
or
Slim

Current CC build info: »www.ccleaner.com/download/builds.aspx

-amy-

--
DSLR Phishtracker

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:

1 edit

Re: CCleaner now installs with adware?

I use the standard but opted out of the toolbar and the other stuff they offered but can't remember.

MarkAW
Barry White or lil bratt
Premium
join:2001-08-27
Canada
·Bell Sympatico
·Cogeco Cable


1 edit
Click for full size
Ok you all got me wondering since i have CCleaner v2.02.527, so i ran a few scans and found nothing using A2, Avast, Avg Anti-spyware (which did it's auto weekly scan today), SuperAntiSpyware, AboutBuster, Qoofix,E2Takeout. Neither Mamutu or WinPatrol popped up with any kind of warning and my HJT logs are clear.
So i'd have to say that with your problem it got onto your system some other way and not with CCleaner

a-squared Free - Version 3.0
Last update: 11/11/2007 3:26:42 AM

Scan settings:

Objects: Memory, Traces, Cookies
Scan archives: On
Heuristics: On
ADS Scan: On

Scan start: 11/11/2007 1:16:20 PM

Scanned

Files: 1952
Traces: 340633
Cookies: 4
Processes: 48

Found

Files: 0
Traces: 0
Cookies: 0
Processes: 0
Registry keys: 0

Scan end: 11/11/2007 1:17:50 PM
Scan time: 12:01:30 AM
--
Advertising is legalized lying. - H.G. Wells
Pleasure in the job puts perfection in the work. - Aristotle
PrntRhd

join:2004-11-03
Fairfield, CA
Sorry guys, Norton or NIS, all the same to me. I also use SB and it is not tripping Avast or any online scans either.

Dogwood
Premium
join:2001-01-14
Texas
clubs:
Yep, I have CC v2.02.257 and KAV says NO to Adware.SystemProcess being there, nor any other baddies.
--
Proud Member of Team Discovery

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
I'm still using v2.01.507, so I can't check for this issue, but has anyone contacted the CCleaner developers themselves to ask about this?

hayc59
VoodooChild
Premium
join:2001-02-26
David R.I.P.

Re: CCleaner now installs with adware?

said by La Luna See Profile :

I'm still using v2.01.507, so I can't check for this issue, but has anyone contacted the CCleaner developers themselves to ask about this?
pmed the author as soon as I saw this thread
will see if he/she[Mr.G.] shows

Ryan
Premium
join:2001-03-03
Attleboro, MA
Nod32 everything clean here. Either a false positive by symantec or picked up a unrelated infection.

MarkAW
Barry White or lil bratt
Premium
join:2001-08-27
Canada
·Bell Sympatico
·Cogeco Cable


1 edit
Click for full size
scan on my system
Click for full size
web results
Click for full size
full version
Click for full size
slim version
Ok i ran another scan using my version of Prevx csi and came up clean, then i uploaded the full version and the slim version of CCleaner to VirusTotal and got two different results. The first result if i had to guess was a detection of the Yahoo Toolbar which is in the full version of CCleaner, while the scan of the slim version came up without the same Heuristic:Suspicious HiJacker but this is only a guess on my part.
--
Advertising is legalized lying. - H.G. Wells
Pleasure in the job puts perfection in the work. - Aristotle

yuutomo
The Wonder Kitter
Premium
join:2001-08-27
Missoula, MT
can you poet the link of where you downloaded it from, need to see what server or service is hosting it.

MagMan
Life is simpler when you tell the truth.
Premium
join:2003-10-01
Westlake, OH
·AT&T Midwest
·AT&T Midwest


1 edit
Check out this thread Norton is not playing nice with SB or SWB.

CCleaner is probably not the culprit here.

»Norton and SpywareBlaster updates causing FP (likely)
--
"The truth is incontrovertible, malice may attack it, ignorance may deride it, but in the end; there it is."

Olav the Viking

@cableone.net

I have had Norton remove this 3 times in the past 2 days, but in order to verify that it was a false positive, I went to IE Tools, Privacy, Sites and entered the following 3 sites as "blocked" (cookie blocking):

bfast.com
fastclick.com
fastclick.net

(they had been previously removed by Norton the day before)

Sure enough, Norton found these and removed them. Hey, Norton, these sites were here for a reason - to BLOCK these site's cookies. It seems that their removal tool is not checking the registry key for the value that indicates that these sites are blocked (5) rather than allowed (1).

The day before, Norton removed these 2 entries from my hosts file:

ads.mcafee.com
go2.microsoft.com

Again, those entries were put there for a reason, but Norton thought that I didn't really want them there. I'm not sure if go2.microsoft.com is malicious, it was part of a host file list that I entered into my hosts file a few years ago - I have not had anything that I ever needed blocked by it to my knowledge. The ads.mcafee.com entry was there for obvious reasons.

Me thinks that the people at Symantec need to fix their removal tool. . .

batterup
I Can Not Tell A Lie.
Premium
join:2003-02-06
Netcong, NJ
clubs:
·Verizon Online DSL

said by Goodbye CCleaner :

D/Led the new version 2.02.257 - and when i ran my av overnight I found that Adware.SystemProcess was also now installed. AV removed it, but I was wondering if anyone else saw this too? The new CC version was all I d/led yesterday.

Thankss
Sweet, times are hard and the hustle has just begun.

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:
·Comcast
·Alameda Power & Te..

Host:
Broadband Modem (H..
MSN
DSL Extreme
Windstream
Southeast Asian Br..
I just got this back from Symantec regarding my submission:

Below is a status update on your virus submission:

Date: November 11, 2007

Dear XXXXX,

We have analyzed your submission. The following is a report of our findings for each file you have submitted:

filename: DUMMY_FILE
machine: XXXXXXX
result: This file is clean

Developer notes:
DUMMY_FILE is zero bytes in length

We have determined that no virus exists on the samples provided.


So can I restore that file now or should I wait?
--
TH ~ NE ~ EPN ~ NC ~ TD

Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:

Re: CCleaner now installs with adware?

If the file is "zero bytes in length" then it is empty of good or bad content.

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:
·Comcast
·Alameda Power & Te..

Host:
Broadband Modem (H..
MSN
DSL Extreme
Windstream
Southeast Asian Br..

Re: CCleaner now installs with adware?

I saw the "zero bytes" and thought that was kinda strange too. So I guess I'm just going to leave things as they are right now. It's sounding more and more like this was a FP for me.
--
TH ~ NE ~ EPN ~ NC ~ TD

Bubba17
Less is More
Premium
join:2006-09-21

Updated CC here to 2.02.527 on 11/06 ..

Not a peep from KIS7 v125 (as mirrored from VirusTotal).
Nothing from SAS Pro.
Nothing from WinPatrol Plus (always resident, patrolling registry).

Can not find any of the listed files/reg changes on my system that would indicate the adware's presence.

Still -- 71 registry changes and two files?? .. that's some dandy FP.
--
HN7000s | Horizons 1 (127W) | Gateway: 1110Mhz | Dish: .98m 2 Watt | Pro+

"Fast is fine, but accuracy is everything" --Wyatt Earp
okjoe

join:2003-05-20
Auto scan after 11/10 NIS update.
"84 Registry Entrys, 2 Files Affected"
Risk Name: Adware.SystemProcess.
Status "Removed"

CCleaner 1.40

Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:

Re: CCleaner now installs with adware?

said by okjoe See Profile :

Auto scan after 11/10 NIS update.
"84 Registry Entrys, 2 Files Affected"
Risk Name: Adware.SystemProcess.
Status "Removed"

CCleaner 1.40
What were the names of the two files in your system?
--
What’s the point of owning a supercar if you can’t scare yourself stupid from time to time?
okjoe

join:2003-05-20

Re: CCleaner now installs with adware?

said by Doctor Olds See Profile :

said by okjoe See Profile :

Auto scan after 11/10 NIS update.
"84 Registry Entrys, 2 Files Affected"
Risk Name: Adware.SystemProcess.
Status "Removed"

CCleaner 1.40
What were the names of the two files in your system?
C:\WINDOWS\system32\p.dat
C:\Documents and Settings\xxxx\Local Settings\Temp\ibho.log
Forums » Up and Running » Security » SecurityUbuntu Linux 7.10 fixes Highly Critical flaws in KOffice »
« Security Software Updates - 15 Nov 2007  
page: 1 · 2


Monday, 14-Dec 17:41:31 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [97] Google To Sell Phone Directly To Consumers
· [63] TiVO Tries To Figure Out Where It Fits
· [51] Verizon Kindly Forgives Kid's $21,917 3G Bandwidth Bill
· [50] Faster Verizon DSL Service Will Burn Your House Down
· [42] NY Times: AT&T 3G Network Is Secretly Awesome
· [20] Sweden First To Get LTE Service
· [19] Rural Broadband User? You're Screwed
· [1] Monday Morning Links
Most people now reading
· Official Mediacom Email Discussion Thread [Mediacom]
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· personal check etiquette [General Questions]
· DKs and their obsession with Agility [World of Warcraft]
· What VOIP changes did you make in 2009? [VOIP Tech Chat]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· how to get money back when ripped off [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· So independants will be out of business in..........? [Canadian Broadband]