Yesterday, puush users were attacked by a malware that collected stored passwords from browsers when the software was updated to r94. The malware also keylogged anything you typed or copied and paste. The time during which infected updates were sent out was March 29 UTC18:51-21:41. puush checks for updates between every 1-6 hours.

Find out more here: https://twitter.com/puushme

So did anyone get infected?

Edit:
Looks like they released a detailed analysis of the malware.
http://puushstatus.tumblr.com/

Edit 2:
Check to see if you were infected
https://puush.me/dl/puush_is_still_sorry.exe

9 years ago*

Comment has been collapsed.

Did you get infected?

View Results
Yes
No
i don't own puush

I dont even know what Puush is...

Edit: So its a software that allows you to upload screenshots faster... I see

9 years ago
Permalink

Comment has been collapsed.

It's a screenshot capture software so you can quickly share images online.

9 years ago
Permalink

Comment has been collapsed.

Didn't know either :P
I also don't see why you need something faster than only pushing the print screen button....

9 years ago
Permalink

Comment has been collapsed.

'cause you press a button and it takes a screenshot, save it, upload a copy of it online and directly copies the link to reach it in your clipboard. So with a click you've already the link to share.

9 years ago
Permalink

Comment has been collapsed.

Pushing the print screen button only puts your current screen to the clipboard.
Utilities like Puush and Gyazo do a LOT more than just that. They save LOTS of time and hassle.

9 years ago
Permalink

Comment has been collapsed.

Because you can do that with puush: http://puu.sh/gWN7e/2a010af229.png

One shortcut (ctrl +3 in my case), select the zone, release, voilà!

9 years ago
Permalink

Comment has been collapsed.

lel, gyazo would be way better, you just need to lock the screen region and thats it, auto upload...

9 years ago
Permalink

Comment has been collapsed.

and how is that different from puush?

9 years ago
Permalink

Comment has been collapsed.

as far as i know and own the product, never got an update for it, so you never get that infected updates, correct if i'm wrong...

9 years ago
Permalink

Comment has been collapsed.

Just because it doesn't tell you it's updated the client doesn't mean it hasn't done so. All software needs updating from time to time, especially those that use any sort of signon and/or a WAN connection.

9 years ago
Permalink

Comment has been collapsed.

Who's talking about sign in? you don't need to register to be able to use it, and still, everything that updates should show a notification at least... anyway, its not obvious to get infected by an update, specially a prtint uploader program...

9 years ago
Permalink

Comment has been collapsed.

It was germane to your comment.

9 years ago
Permalink

Comment has been collapsed.

9 years ago
Permalink

Comment has been collapsed.

push up ? thaey hacked my push up ?

9 years ago
Permalink

Comment has been collapsed.

Maybe it's a marketing gimmick?

9 years ago
Permalink

Comment has been collapsed.

i dont do push ups

9 years ago
Permalink

Comment has been collapsed.

Oh no.

9 years ago
Permalink

Comment has been collapsed.

I got the notice on one of my machines this morning. If your computer wasn't on during the day of the 29th you won't have gotten the bad update pushed out to you, but you will now see the r100 version pushed out to you regardless.

So it's time for generating new passwords for all my accounts. Woo!

I was planning on formatting my system as well anyway as I'm throwing a new OS build on, so any local unhappiness will go bye bye too.

9 years ago
Permalink

Comment has been collapsed.

Yes. >_>

I don't know if I actually had the r94 version, but this morning I saw the r100 update and my pc was on at the time, so I guess I've been hit with that malware, I'm quite mad about it, I have to throw away 5 different sets of alphanumeric passwords -.-

9 years ago
Permalink

Comment has been collapsed.

Making new passwords is easy. http://xkcd.com/936/

9 years ago
Permalink

Comment has been collapsed.

yup but often you can't put a password that long, I guess I'll use a password service like Keepass

9 years ago
Permalink

Comment has been collapsed.

That sucks! :(

9 years ago
Permalink

Comment has been collapsed.

Only place that I know of that has a low character limit is Hotmail.

9 years ago
Permalink

Comment has been collapsed.

yes you're correct, they have a small character limit, but at least they have a 2 step verification process :3

9 years ago
Permalink

Comment has been collapsed.

69 ppl voted for i don't own puush in this moment lol

9 years ago
Permalink

Comment has been collapsed.

It's why I'm happy that I use ShareX

9 years ago
Permalink

Comment has been collapsed.

Huh. AVG popped up and said it blocked a part of puush. I was confused.

9 years ago
Permalink

Comment has been collapsed.

thx to norton (my antivirus). it blocked every access of the malware & deleted it.

9 years ago
Permalink

Comment has been collapsed.

I highly doubt that, seeing how this "malware" doesn't act like a typical infection. As of right now no AV or anti-malware software detects the puush.daemon.exe file.

9 years ago
Permalink

Comment has been collapsed.

i can for shure confirm to you that puush.daemon.exe was detected & removed by norton... it also blocked the unauthorized access from the malware. "Nicht authorisierter Zugriff blockiert (Datei öffnen)" = not authorized access blocked (open file)

View attached image.
9 years ago
Permalink

Comment has been collapsed.

Uh.. Let me get a screenshot of AVG detection of it.
http://puu.sh/gVRXW/f6f5a2ce50.png
Hey look, a puush

9 years ago*
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 5 years ago.

9 years ago
Permalink

Comment has been collapsed.

Just change Puusher.

9 years ago
Permalink

Comment has been collapsed.

Just downloaded the checker and found out im safe!!

Good thing I have been killing puush.exe everytime I start my computer on the last few days.

9 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 6 years ago.

9 years ago*
Permalink

Comment has been collapsed.

I wonder why I didn't get infected. Only thing I remembered is:

3/28 : I was performing network maintenance at home so no internet connection except for mobile
3/29 : I turned on my VPN yesterday because I was DLing walking dead finale

MY main assumption is the puush malware failed to infect my PC because the exact time posted by OP, my PC is on sleep

9 years ago
Permalink

Comment has been collapsed.

I think my heart just skipped a beat...
Wasn't infected though...

9 years ago
Permalink

Comment has been collapsed.

I suggest my software ShareX

9 years ago
Permalink

Comment has been collapsed.

Thanks mate, best software so far.

9 years ago
Permalink

Comment has been collapsed.

I prefer Gyazo.

9 years ago
Permalink

Comment has been collapsed.

You must be liking advertisements in your screenshot links.

9 years ago
Permalink

Comment has been collapsed.

What ads? I use links for direct images posting like on forums. Right click -> Copy Image URL -> post

9 years ago
Permalink

Comment has been collapsed.

When ShareX can copy direct link automatically why you bother doing "Right click -> Copy Image URL" ?

9 years ago
Permalink

Comment has been collapsed.

Because I haven't heard of anything other than Gyazo until this thread.
Remind me never to post in this forum again, I always get jumped on (like right here) for no reason at all.

9 years ago
Permalink

Comment has been collapsed.

I still wonder how and why I didn't get infected, but hey. My PC was on and everything but I got nothing. Weird. No notification, I even ran their scan and found out I wasn't infected. Not gonna complain but this is still weird.

Edit: oh I know, my PC was actually off when that happened. Thanks, alcohol!

9 years ago
Permalink

Comment has been collapsed.

So... where's the giveaway?

9 years ago
Permalink

Comment has been collapsed.

Bump!
A recent detalied analysis of the whole event was released for those who are curious.
Check it here: http://puushstatus.tumblr.com/

9 years ago
Permalink

Comment has been collapsed.

i made it so puush doesnt ever open 5 days ago, does that count? :O

9 years ago
Permalink

Comment has been collapsed.

As long as you didn't update to r94 during the time it was released, then you'll be fine.

9 years ago
Permalink

Comment has been collapsed.

Had disabled puush running on startup since few months ago
prefer using lightshot
just download checker and it says my notebook not affected

9 years ago*
Permalink

Comment has been collapsed.

Sign in through Steam to add a comment.