Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 03-02-2013, 10:28 AM   #1
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
Can't remove exploit:java/cve-2012-5076.gaa virus

Hi, MSE removes this virus and it returns upon re-boot. Superantivirus, Malwarebytes and Emsisoft don't even detect it. Anyone know how to get rid of this thing?
Thanks
__________________
Greg

1- Gigabyte GA-P55A; i5-760 CPU; HSF XIGMATEK Gaia SD1283; 16 Gig Corsair XMS DDR 3 1600 Mem; HIS H577FK 1 GB Radeon 5770 VC; Asus RT-N10+ Router; SSD Intel 330 120 GIG HD; WD VelociRaptor 150 GIG HD; WD 6402AAEX HD; 2 LG SATA DVD Burners; PSU CORSAIR CMPSU-750TX 750W; Win 7 64 Bit; Acer 22" LCD Monitor
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 10:52 AM   #2
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
Are you having the problem with the machine in your signature or another machine?
If it is a different machine to the one in your signature, is it a laptop or store bought PC?
__________________
Niwa no niwa ni wa, niwa no niwatori wa niwaka ni wani o tabeta.
rjfvillarosa is online now   Reply With Quote
Old 03-02-2013, 11:18 AM   #3
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
It's the one in my signature, I built myself. This is the first virus I've gotten I couldn't figure out how to get rid of. It doesn't seem to be causing any trouble but MS says it is severe and irregurardless I wouldn't leave any bug on my PC if I knew it was there. Searching Google there is really no solutions I could find, some company named Tee Support has many links on how to remove it, their manual instructions are BS, they want you to pay something, and researching them pretty much says they are a scam company. Microsoft says this is a bad bug but offers no way of removing other than the things I've already done.
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 11:23 AM   #4
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
First thing I would do is slave the harddrive to another machine to run the usual scans. If Malwarebytes and Emsisoft are not even detecting it I think I would research the idea that it might be a false positive.
Where does MSE say the virus is located?
Have you installed any new software lately?
rjfvillarosa is online now   Reply With Quote
Old 03-02-2013, 12:02 PM   #5
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
When I get rid of these they will be back the next time I re-boot.
Well I attached what MSE says, hope it comes through. No I haven't loaded any new software lately.
Attached Thumbnails
Can't remove exploit:java/cve-2012-5076.gaa virus-capture.jpg  
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 12:11 PM   #6
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
This is what MS says: Encyclopedia entry: Exploit:Java/CVE-2012-5076.GAA - Learn more about malware - Microsoft Malware Protection Center
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 12:27 PM   #7
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
Quote:
Originally Posted by babylon5guy View Post
It doesn't seem to be causing any trouble
This is what is making me think you may have a false positive.
Have you tried using Ccleaner to all the temporary files before and after the scans and then rebooting?
rjfvillarosa is online now   Reply With Quote
Old 03-02-2013, 12:45 PM   #8
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
No, I've never used ccCleaner. I'll give it a try. Is it pretty self explanatory?
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 12:57 PM   #9
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
It is a doddle to use.
Get a copy from FileHippo.com - Download Free Software and take a look.
rjfvillarosa is online now   Reply With Quote
Old 03-02-2013, 01:09 PM   #10
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
Thanks for your help rjfvillarosa let me try all these things, and I'll post back my results. False postitive or not I'd like to get rid of it.
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 01:24 PM   #11
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
Panama Red and myself are doing a little research at the moment into the so called "you have been downloading illegally" viruses, please post back with whatever you find.
rjfvillarosa is online now   Reply With Quote
Old 03-02-2013, 01:55 PM   #12
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
Yes I will. If you mean that Ransom virus, I have had luck with Emsisoft, when nothing else worked, there are several variations of it, it was the worst I have encountered so far, even in safe mode it came up.
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 02:04 PM   #13
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
The reason I asked you what machine the problem is on, is because we have both noticed that the "ransomeware" nonsense appears to be infecting the recovery partition on some branded machines.
rjfvillarosa is online now   Reply With Quote
Old 03-02-2013, 02:52 PM   #14
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
The PC I cleaned the Ransomware off of was an HP that was a couple of years old. I don't know if it had infected the recovery partition. I did successfully remove it, after serveral tries. I never had one that bad on my PC, I'm careful what I ok and where I go.
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 03:04 PM   #15
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
The only way you will know if the recovery partition is infected is when you "Slave" the harddrive, you can then see all the partitions on the harddrive and you can select it to be scanned. Usually the recovery partition is hidden so any scanner you run from the Windows environment will not detect it.
rjfvillarosa is online now   Reply With Quote
Old 03-02-2013, 03:21 PM   #16
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
Yes the infection was so severe I did slave his hard drive to my PC, I had to, I could not do anything with it, but I really didn't take notice where all the files it had cleaned were.
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 03:25 PM   #17
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
Have you tried Ccleaner on your machine yet?
rjfvillarosa is online now   Reply With Quote
Old 03-02-2013, 03:51 PM   #18
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
Not yet I slaved it and am scanning.
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 09:48 PM   #19
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
Well ran ccleaner before and after full scans by superantispyware, emsisoft, malwarebytes and MSE on a slaved HD and exploit:java/cve-2012-5076.gaa is still there? This is a tough one.
babylon5guy is offline   Reply With Quote
Old 03-02-2013, 10:40 PM   #20
Member (10 bit)
Premium Member
 
Join Date: Jun 2008
Location: Northern Wisconsin
Posts: 697
Have a look at this link for manual removal:
I can't remove exploit java/cve-2012-5076.gaa,it keeps coming - Microsoft Community
usnavyretired is offline   Reply With Quote
Old 03-03-2013, 05:51 AM   #21
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
Thanks usnavyretired I did see that site and cleared the Java Cache, and ccCleaner cleaned all the temporary files and none of that worked. I haven't uninstalled Java yet, I'm not sure I want to do that. With my luck the first site I go to will say I need it.
babylon5guy is offline   Reply With Quote
Old 03-03-2013, 07:10 AM   #22
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
Hey usnavyretired for the hell of it I emptied the Java cache again and with all the scans I did and total deletion of a lot of unnecessary files by ccCleaner. The virus is gone! Along with the above mentioned scans that found nothing I used aswMBR, and ESET which both found some things, which didn't look like the Exploit virus, but doing that and empting the Java cache again it's gone, MSE didn't detect it again and I'm a happy camper, Thanks rjfvillarosa and usnavyretired for you help.
babylon5guy is offline   Reply With Quote
Old 03-03-2013, 09:58 AM   #23
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 41,162
Note: When you use CCleaner, you need to go into Options: Advanced and uncheck the box to only delete temp files older than 24 hours. If you use MSE, you also have to go into Cleaner: Applications and uncheck MS AntiMalware, MS Management Console, and MS Security Client.
glc is offline   Reply With Quote
Old 03-04-2013, 06:35 AM   #24
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
Thanks glc, I didn't do that, it erased all my passwords, and my MSE would not go into protected mode, I had to uninstall it and re-install it. So I guess that explains that. I should have asked more on how to use it. Since I didn't do any of that is there anymore surprised waiting for me? I'm also going to uninstall Java and see if everything runs alright without it.
babylon5guy is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -5. The time now is 12:27 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.1