Threat Database Trojans Exploit:Java/Blacole.CC

Exploit:Java/Blacole.CC

By SpideyMan in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 6
First Seen: December 9, 2011
Last Seen: May 22, 2023
OS(es) Affected: Windows

Exploit:Java/Blacole.CC is a hazardous Java Trojan that propagates via security vulnerabilities in the affected PC system and applications installed on it. Exploit:Java/Blacole.CC's free malicious payload is created to fulfill harmful actions on the corrupted PC system. Exploit:Java/Blacole.CC receives commands from remote hackers on how to execute harmful actions. Exploit:Java/Blacole.CC creates and maintains secret connection line that links it in live mode to a remote server so that hackers could assign it with the tasks they find appropriate. Exploit:Java/Blacole.CC can also download and install other malware infections. Uninstall Exploit:Java/Blacole.CC as soon as possible.

File System Details

Exploit:Java/Blacole.CC may create the following file(s):
# File Name Detections
1. C:\WINDOWS\system32\svchost.exe
2. C:\Program Files\Java\jre6\bin\jqs.exe
3. C:\Windows\system32\DRIVERS\epfwwfp.sys
4. C:\Windows\system32\DllHost.exe
5. C:\WINDOWS\system32\spoolsv.exe
6. %AppData%\RANDOM CHARACTERS
7. C:\WINDOWS\system32\services.exe_Trojan horse Exploit:Java/Blacole.CC

Registry Details

Exploit:Java/Blacole.CC may create the following registry entry or registry entries:
"%windir%\system32\sessmgr.exe"=Exploit:Java/Blacole.CC
"c:\Program Files\Virtual Firefox\firefox.exe"="c:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"c:\Program Files\Bonjour\mDNSResponder.exe"=
HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List
"c:\Program Files\McAfee\\Managed VirusScan\Agent\myAgtSvc.exe"=
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

Trending

Most Viewed

Loading...