IMPORTANT: CCleaner has been hacked and if you use it your computer... (1 Viewer)

sallylillian

LIFE MEMBER
Oct 29, 2011
3,944
5,014
Falmouth, Cornwall
Funster No
18,670
MH
Palace Liner 90LO
Exp
2011
If you have downloaded or updated CCleaner application on your computer between August 15 and September 12 of this year from its official website, then pay attention—your computer has been compromised.

2Bn downloads of this software so chances are someone on here uses it....

http://thehackernews.com/2017/09/ccleaner-hacked-malware.html
I have used this in the past but not on this laptop but as you are knowledgeable I thought I would mention something odd that happened recently.
I started getting undeliverable email notifications from the bt servers, I have a btconnect email account. These ramped up in short order to 200 plus in 15 mins. I run defender and Malaware bytes which were reporting clean. So my SMTP login was compromised. Interestingly as my contact list has some spoof contacts which feed back to me if my list was compromised and I did not have any emails to these it did not seem likely that my laptop was infected.
So went onto my bt email account to change my password. It wanted me to answer special question mother's maiden name but it rejected my legitimate answer.
So now onto bt they cannot get past the block, but eventually do and I reset my password and special question. By now 500 undeliverable mails, which then ceased over the next 12 hours.
BUT, a week later I start getting emails from random btconnect email accounts, clearly other hacked btconnect clients like me. They were arriving at about 10 a day. I posted a ticket to bt which got a standard reply, I hit them again and for 2 days now no btconnect scam email.
So do you know about this?
 
OP
OP
Gromett
Feb 27, 2011
14,737
75,974
UK
Funster No
15,452
MH
Self Build
Exp
Since 2005
@sallylillian Sorry there are too many variables.. For instance, was your original password weak and they guessed it. Did you use the password on multiple sites and one was hacked, was your local computer hacked? Then, do you keep your address book with email addresses in your mail client (most people do).

How to clean up? It again depends on so many variables branching from the results of the above questions...

My best advice would be to drop bt internet for email.... This is hard to do if you have lots of email contacts and use it regularly.

However, what I would do in your situation is set up a fresh gmail account. Use a really strong password that is unique to gmail and not used anywhere else.
Then send out a mass email to all your contacts letting them know you have moved across.

Each time you log into a website, update the email address. You don't need to do this all at once.

Over time you will find that the bt address is used less and less by real people and purely by spammers. Once you are comfortable you can stop monitoring the bt account.

The reason I recommend moving across is that bt do not provide their own mail services, last time I had any involvement they were using Yahoo for their services but I think they may have changed again since then. BT cannot assist you as all they will do is pass your request onto yahoo who have no incentive to assist.

Gmail on the other hand are an extremely good provider of email services and have a major incentive to improve their service. They are extremely good at filtering spam and protecting you from nasties.

I am sorry I can't give specific information on how to fix your current issue, without getting into lots of detail with you this is the best advice I can give sorry.

Subscribers  do not see these advertisements

 

DBK

LIFE MEMBER
Jan 9, 2013
18,023
48,095
Plympton, Devon
Funster No
24,219
MH
PVC, Murvi Morocco
Exp
2013
I have used this in the past but not on this laptop but as you are knowledgeable I thought I would mention something odd that happened recently.
I started getting undeliverable email notifications from the bt servers, I have a btconnect email account. These ramped up in short order to 200 plus in 15 mins. I run defender and Malaware bytes which were reporting clean. So my SMTP login was compromised. Interestingly as my contact list has some spoof contacts which feed back to me if my list was compromised and I did not have any emails to these it did not seem likely that my laptop was infected.
So went onto my bt email account to change my password. It wanted me to answer special question mother's maiden name but it rejected my legitimate answer.
So now onto bt they cannot get past the block, but eventually do and I reset my password and special question. By now 500 undeliverable mails, which then ceased over the next 12 hours.
BUT, a week later I start getting emails from random btconnect email accounts, clearly other hacked btconnect clients like me. They were arriving at about 10 a day. I posted a ticket to bt which got a standard reply, I hit them again and for 2 days now no btconnect scam email.
So do you know about this?
I suggest binning BT email. I was hacked a couple of years ago and it happened to my brother a couple of weeks ago.
I suggest using gmail, though there are other providers of course. You can still keep your BT email address but set up the account so all incoming emails are redirected to your new email address. This way you won't lose contact with anyone.
Gmail may have had spam problems in the past, but not anymore. You will only very rarely find spam getting past their filters. BT email seems to breed spam. :)
 
Feb 13, 2013
992
1,084
Edinburgh
Funster No
24,680
MH
Rapido 881F
Exp
Since 2015
Seems to be only 32 bit version that was hacked, but a great warning, thanks. In depth virus scan carried out over night and no issues.

Subscribers  do not see these advertisements

 

sallylillian

LIFE MEMBER
Oct 29, 2011
3,944
5,014
Falmouth, Cornwall
Funster No
18,670
MH
Palace Liner 90LO
Exp
2011
Thanks @Gromett to be clear I do not currently have a problem now the password and special question has been reset. What I am now seeing is a stream of btconnect account emails which demonstrate that my btconnect account was (as contrary to my last post I am still receiving these) not the only one hacked.

They appear to have switched to Microsoft managing the email accounts which gives me concern in any event.

Your advise to switch to Gmail is worth consideration as I already have a gmail account and I will look closer at that option when I get back home. Thank you for taking the time to respond.
 
D

Deleted member 29692

Deleted User
Gmail may have had spam problems in the past, but not anymore. You will only very rarely find spam getting past their filters

That's the major problem with gmail. Their spam filters have ended up being far too fierce.

Our rugby club email addresses are Google/gmail hosted using our own domain name and even email between ourselves have been known to end up in the junk folder. Woe betide you if you need to put another email address in the body of the message you're writing.

I've got to say I'm not a fan at all. I won't use it for any of my own stuff.
 
  • Like
Reactions: DBK

DBK

LIFE MEMBER
Jan 9, 2013
18,023
48,095
Plympton, Devon
Funster No
24,219
MH
PVC, Murvi Morocco
Exp
2013
It is a bit keen. :) I tried initially to use a Gmail address with MailChimp to send out a newsletter. MailChimp picked up on this straight away and said the Gmail servers would identify the newsletter as spam (correct I suppose :)) and block it.

Subscribers  do not see these advertisements

 
Last edited:
D

Deleted member 29692

Deleted User
Gmail hates HTML signatures as well.

If they aren't absolutely perfect the message is off to the spam folder.
 
D

Deleted member 29692

Deleted User
If I need a single use/throwaway email address I usually use mail.com because the signup process is about twice as simple and fast as anyone else.

I don't know if they're the most secure option but it doesn't really matter for what I use them for.
 
OP
OP
Gromett
Feb 27, 2011
14,737
75,974
UK
Funster No
15,452
MH
Self Build
Exp
Since 2005
It is a bit keen. :) I tried initially to use a Gmail address with MailChimp to send out a newsletter. MailChimp picked up on this straight away and said the Gmail servers would identify the newsletter as spam (correct I suppose :)) and block it.

I run my own mailserver and I block MailChimp at the EHLO stage (the very very first stage). The problem is not with Gmail it is with Mailchimp. They let too many spammers in..

On the other hand. I whitelist amazon's maillist servers because they aggresively attack spammers..

The beauty of running your own mailserver is you can develop your own spam filters :)

Subscribers  do not see these advertisements

 

Join us or log in to post a reply.

To join in you must be a member of MotorhomeFun

Join MotorhomeFun

Join us, it quick and easy!

Log in

Already a member? Log in here.

Latest journal entries

Funsters who are viewing this thread

Back
Top