|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
Can't remove exploit:java/cve-2012-5076.gaa virus
Hi, MSE removes this virus and it returns upon re-boot. Superantivirus, Malwarebytes and Emsisoft don't even detect it. Anyone know how to get rid of this thing?
Thanks
__________________
Greg 1- Gigabyte GA-P55A; i5-760 CPU; HSF XIGMATEK Gaia SD1283; 16 Gig Corsair XMS DDR 3 1600 Mem; HIS H577FK 1 GB Radeon 5770 VC; Asus RT-N10+ Router; SSD Intel 330 120 GIG HD; WD VelociRaptor 150 GIG HD; WD 6402AAEX HD; 2 LG SATA DVD Burners; PSU CORSAIR CMPSU-750TX 750W; Win 7 64 Bit; Acer 22" LCD Monitor |
|
|
|
|
|
#2 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
|
Are you having the problem with the machine in your signature or another machine?
If it is a different machine to the one in your signature, is it a laptop or store bought PC?
__________________
Niwa no niwa ni wa, niwa no niwatori wa niwaka ni wani o tabeta. |
|
|
|
|
|
#3 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
It's the one in my signature, I built myself. This is the first virus I've gotten I couldn't figure out how to get rid of. It doesn't seem to be causing any trouble but MS says it is severe and irregurardless I wouldn't leave any bug on my PC if I knew it was there. Searching Google there is really no solutions I could find, some company named Tee Support has many links on how to remove it, their manual instructions are BS, they want you to pay something, and researching them pretty much says they are a scam company. Microsoft says this is a bad bug but offers no way of removing other than the things I've already done.
|
|
|
|
|
|
#4 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
|
First thing I would do is slave the harddrive to another machine to run the usual scans. If Malwarebytes and Emsisoft are not even detecting it I think I would research the idea that it might be a false positive.
Where does MSE say the virus is located? Have you installed any new software lately? |
|
|
|
|
|
#5 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
When I get rid of these they will be back the next time I re-boot.
Well I attached what MSE says, hope it comes through. No I haven't loaded any new software lately. |
|
|
|
|
|
#6 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
|
|
|
|
|
|
#7 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
|
|
|
|
|
|
|
#8 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
No, I've never used ccCleaner. I'll give it a try. Is it pretty self explanatory?
|
|
|
|
|
|
#9 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
|
It is a doddle to use.
Get a copy from FileHippo.com - Download Free Software and take a look. |
|
|
|
|
|
#10 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
Thanks for your help rjfvillarosa let me try all these things, and I'll post back my results. False postitive or not I'd like to get rid of it.
|
|
|
|
|
|
#11 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
|
Panama Red and myself are doing a little research at the moment into the so called "you have been downloading illegally" viruses, please post back with whatever you find.
|
|
|
|
|
|
#12 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
Yes I will. If you mean that Ransom virus, I have had luck with Emsisoft, when nothing else worked, there are several variations of it, it was the worst I have encountered so far, even in safe mode it came up.
|
|
|
|
|
|
#13 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
|
The reason I asked you what machine the problem is on, is because we have both noticed that the "ransomeware" nonsense appears to be infecting the recovery partition on some branded machines.
|
|
|
|
|
|
#14 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
The PC I cleaned the Ransomware off of was an HP that was a couple of years old. I don't know if it had infected the recovery partition. I did successfully remove it, after serveral tries. I never had one that bad on my PC, I'm careful what I ok and where I go.
|
|
|
|
|
|
#15 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
|
The only way you will know if the recovery partition is infected is when you "Slave" the harddrive, you can then see all the partitions on the harddrive and you can select it to be scanned. Usually the recovery partition is hidden so any scanner you run from the Windows environment will not detect it.
|
|
|
|
|
|
#16 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
Yes the infection was so severe I did slave his hard drive to my PC, I had to, I could not do anything with it, but I really didn't take notice where all the files it had cleaned were.
|
|
|
|
|
|
#17 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
|
Have you tried Ccleaner on your machine yet?
|
|
|
|
|
|
#18 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
Not yet I slaved it and am scanning.
|
|
|
|
|
|
#19 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
Well ran ccleaner before and after full scans by superantispyware, emsisoft, malwarebytes and MSE on a slaved HD and exploit:java/cve-2012-5076.gaa is still there? This is a tough one.
|
|
|
|
|
|
#20 |
|
Member (10 bit)
Premium Member
Join Date: Jun 2008
Location: Northern Wisconsin
Posts: 697
|
Have a look at this link for manual removal:
I can't remove exploit java/cve-2012-5076.gaa,it keeps coming - Microsoft Community |
|
|
|
|
|
#21 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
Thanks usnavyretired I did see that site and cleared the Java Cache, and ccCleaner cleaned all the temporary files and none of that worked. I haven't uninstalled Java yet, I'm not sure I want to do that. With my luck the first site I go to will say I need it.
|
|
|
|
|
|
#22 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
Hey usnavyretired for the hell of it I emptied the Java cache again and with all the scans I did and total deletion of a lot of unnecessary files by ccCleaner. The virus is gone! Along with the above mentioned scans that found nothing I used aswMBR, and ESET which both found some things, which didn't look like the Exploit virus, but doing that and empting the Java cache again it's gone, MSE didn't detect it again and I'm a happy camper, Thanks rjfvillarosa and usnavyretired for you help.
|
|
|
|
|
|
#23 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 41,162
|
Note: When you use CCleaner, you need to go into Options: Advanced and uncheck the box to only delete temp files older than 24 hours. If you use MSE, you also have to go into Cleaner: Applications and uncheck MS AntiMalware, MS Management Console, and MS Security Client.
|
|
|
|
|
|
#24 |
|
Member (11 bit)
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,296
|
Thanks glc, I didn't do that, it erased all my passwords, and my MSE would not go into protected mode, I had to uninstall it and re-install it. So I guess that explains that. I should have asked more on how to use it. Since I didn't do any of that is there anymore surprised waiting for me? I'm also going to uninstall Java and see if everything runs alright without it.
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|