{"id":14923,"date":"2020-07-03T00:03:00","date_gmt":"2020-07-02T22:03:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=14923"},"modified":"2020-07-03T02:33:19","modified_gmt":"2020-07-03T00:33:19","slug":"adwcleaner-8-0-6-schliet-erneut-dll-hijacking-schwachstelle","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/07\/03\/adwcleaner-8-0-6-schliet-erneut-dll-hijacking-schwachstelle\/","title":{"rendered":"AdwCleaner 8.0.6 closes again a DLL hijacking vulnerability"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" height=\"47\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/?p=233055\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Malwarebytes has released the Windows tool AdwCleaner 8.0.6. This update fixes a DLL hijacking vulnerability in AdwCleaner 8.0.5 that I reported to the developers.<\/p>\n<p><!--more--><\/p>\n<h2>A never ending story of the AdwCleaner<\/h2>\n<p>My blog post <a href=\"https:\/\/borncity.com\/win\/2019\/12\/19\/adwcleaner-8-0-1-closes-a-dll-hijacking-vulnerability\/\">AdwCleaner 8.0.1 closes a DLL Hijacking vulnerability<\/a> from December 2019 dealt with a DLL hijacking vulnerability in this tool. There you can also find hints about what the AdwCleaner does. I reported the vulnerability to Malwarebytes and have been in contact with one of the developers since then. They are willing and able to fix this vulnerability in the free AdwCleaner.<\/p>\n<p><img decoding=\"async\" title=\"AdwCleaner\" src=\"https:\/\/i.imgur.com\/ijeRVcM.jpg\" alt=\"AdwCleaner\" \/><\/p>\n<p>Unfortunately the DLL hijacking vulnerability in AdwCleaner 8.0.3 was back again. I mentioned this in the blog post <a href=\"https:\/\/borncity.com\/win\/2020\/04\/04\/adwcleaner-8-0-4-closes-again-a-dll-hijacking-vulnerability\/\">AdwCleaner 8.0.4 closes again a DLL Hijacking vulnerability<\/a>.<\/p>\n<h2>Again a DLL hijacking vulnerability in AdwCleaner 8.0.5<\/h2>\n<p>A few weeks ago I accidentally came across a link on one of the US sites (I don't know if it was Bleeping Computer, Neowin or MS Power User) that offered AdwCleaner 8.0.5. So I downloaded this version and ran it over my testbed. AdwCleaner does not need to be installed, but requires administrative permissions at startup. The user will grant these, because he wants to clean his system from junkware.<\/p>\n<p><img decoding=\"async\" title=\"DLL-Hijacking-Schwachstelle in AdwCleaner 8.0.3\" src=\"https:\/\/i.imgur.com\/xHMQtRS.jpg\" alt=\"DLL-Hijacking-Schwachstelle in AdwCleaner 8.0.3\" \/><\/p>\n<p>When I started the program, I was informed via the above dialog box that version 8.0.5 of AdwCleaner was vulnerable to DLL hijacking. This means that all DLL files reloaded by the AdwCleaner are also executed as a process with administrative privileges. If a malware knows that a tool has a DLL hijacking vulnerability for certain DLLs, it only needs to place a file with the same name in the folder containing the application. For AdwCleaner, this is most likely the Downloads folder. This DLL is then loaded instead of the Windows DLL (hijacking).<\/p>\n<blockquote><p>The testbed is provided by Stefan Kanthak, who deals with such security issues. You can download the file <a href=\"https:\/\/skanthak.homepage.t-online.de\/download\/FORWARD.CAB\" target=\"_blank\" rel=\"noopener noreferrer\">Forward.cab<\/a> from his website and unzip it into a folder. There is also a <a href=\"https:\/\/skanthak.homepage.t-online.de\/sentinel.html\" target=\"_blank\" rel=\"noopener noreferrer\">Sentinel.exe<\/a> which also moves into this folder.<\/p>\n<p>If a virus scanner jumps on when visiting the Kanthak website: It delivers the Eicar test virus in a data block attribute on its website to test whether browsers evaluate it and load it into memory for execution. A virus scanner should then be activated.<\/p><\/blockquote>\n<h2>The developer fixes immediately<\/h2>\n<p>Since I have already been in contact with the developer at Malwarebytes twice because of the same problem, and the problem has been fixed again and again, I sent him an email. There I clearly checked why all second versions of AdwCleaner come with DLL hijacking vulnerability. The developer promised to take care and make sure that this bug does not recur in new builds. Well, the developer also promised to inform me when AdwCleaner 8.0.6 is available &#8211; I am still waiting for the mail till today.<\/p>\n<blockquote><p><strong>Addendum:<\/strong> My blogging colleague Lawrence Abrams just described at <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/malwarebytes-adwcleaner-now-removes-malware-from-the-command-line\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bleeping Computer<\/a>\u00a0that AdwCleaner 8.0.6 now can remove malware from the command line.<\/p><\/blockquote>\n<p>Yesterday evening the idea came to me to just check if this version has already been released and run a test. The AdwCleaner 8.0.6 is currently available for free download on <a href=\"https:\/\/de.malwarebytes.com\/adwcleaner\/\" target=\"_blank\" rel=\"noopener noreferrer\">this Malwarebytes website<\/a>. A test showed that the DLL hijacking vulnerability has been fixed once again.<\/p>\n<p>According to <a href=\"https:\/\/forums.malwarebytes.com\/topic\/261329-release-adwcleaner-806\/?tab=comments#comment-1391478\" target=\"_blank\" rel=\"noopener noreferrer\">this forum entry<\/a>, AdwCleaner 8.0.6 must have been published on the evening of 1 July 2020. So the whole thing is still fresh. If you use the tool, you should get the latest version 8.0.6. By the way, the forum entry describes what has changed in the new version of the tool.<\/p>\n<p><strong>Similar articles:<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/12\/12\/malwarebytes-adwcleaner-8-0-a-2nd-view\/\">Malwarebytes AdwCleaner 8.0, a 2nd view<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/12\/19\/adwcleaner-8-0-1-closes-a-dll-hijacking-vulnerability\/\">AdwCleaner 8.0.1 closes a DLL Hijacking vulnerability<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2020\/04\/04\/adwcleaner-8-0-4-closes-again-a-dll-hijacking-vulnerability\/\">AdwCleaner 8.0.4 closes again a DLL Hijacking vulnerability<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Malwarebytes has released the Windows tool AdwCleaner 8.0.6. This update fixes a DLL hijacking vulnerability in AdwCleaner 8.0.5 that I reported to the developers.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,1547],"tags":[2502,69],"class_list":["post-14923","post","type-post","status-publish","format-standard","hentry","category-security","category-software","tag-adwcleaner","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=14923"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14923\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=14923"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=14923"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=14923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}