Home Malware Programs Trojans Exploit:Java/Blacole.CC

Exploit:Java/Blacole.CC

Posted: December 9, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 14
First Seen: December 9, 2011
Last Seen: May 22, 2023
OS(es) Affected: Windows

Exploit:Java/Blacole.CC is a dangerous Java Trojan that spreads via security vulnerabilities in the targeted computer system and software programs installed on it. Exploit:Java/Blacole.CC's free malicious palydlad is generated to execute harmful actions on the compromised machine. Exploit:Java/Blacole.CC receives instructions from remote attackers on how to perform malicious actions. Exploit:Java/Blacole.CC creates and maintains stealthy connection line linking it in live mode to a remote server so that attackers could assign it with the tasks they find appropriate. Exploit:Java/Blacole.CC can also download and install additional malware threats. Remove Exploit:Java/Blacole.CC before it harms your computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Windows\system32\DllHost.exe File name: C:\Windows\system32\DllHost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Java\jre6\bin\jqs.exe File name: C:\Program Files\Java\jre6\bin\jqs.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\WINDOWS\system32\svchost.exe File name: C:\WINDOWS\system32\svchost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\WINDOWS\system32\spoolsv.exe File name: C:\WINDOWS\system32\spoolsv.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\RANDOM CHARACTERS File name: %AppData%\RANDOM CHARACTERS
Group: Malware file
C:\Windows\system32\DRIVERS\epfwwfp.sys File name: C:\Windows\system32\DRIVERS\epfwwfp.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
C:\WINDOWS\system32\services.exe_Trojan horse Exploit:Java/Blacole.CC File name: C:\WINDOWS\system32\services.exe_Trojan horse Exploit:Java/Blacole.CC
Mime Type: unknown/CC
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\ListHKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
Loading...