The Technology2Reality Blog Feed

 
 

Las Vegas, NV (PRWEB) April 1, 2011

SecureMac has discovered a new version of BlackHole RAT trojan horse as labeled by the hacker as 2.0 for Mac OS X. This new version should not be confused with an older variant already detected back in February by SecureMac as BlackHole RAT 1.0c that has recently been in the news called OSX/BlackHoleRAT.B.

Upon first release of BlackHole RAT 1.0, SecureMac identified three variants of the trojan horse, including one disguised as Apple’s Safari web browser. At that time, it was noted that the trojan horse appeared to be a work-in-progress, and that further variants would probably appear in the future.

SecureMac’s prediction proved to be correct, as there is a brand new version of the trojan horse currently being passed around on hacker message boards. This new version of the trojan horse is substantially different than previous variants, and is described as version 2.0 by the hacker who created it.

The new version of the trojan horse adds itself as a login item disguised as Java, has a more believable prompt for username and password, slows down the computer by tying up the CPU with a loop function, executes shell commands, and can attempt to erase the hard drive.

In the version analyzed by SecureMac, the author states that the trojan horse is unstable, but an upcoming version will improve stability. It appears that development of this program is ongoing, and the author recently posted to a hacker message board that the new version has been completed and is currently in testing, so we expect that it will soon be distributed in a more widespread fashion.

This new version of the trojan horse is detected by MacScan as “BlackHole RAT 2.0a” in the spyware definitions update released on March 31st, 2011. A 30-day free trial of MacScan can be downloaded by visiting http://macscan.securemac.com/.

The original SecureMac security bulletin about BlackHole RAT 1.0 trojan horse can be found here: http://www.securemac.com/blackholerat-bulletin.php

# # #







Related Mac Security Press Releases

Tagged with:
 

Question by iAsk: A fatal error has been detected by the Java Runtime Environment?
# A fatal error has been detected by the Java Runtime Environment:
#
# EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x6d8dc6af, pid=5304, tid=5648
#
# JRE version: 6.0_20-b02
# Java VM: Java HotSpot(TM) Client VM (16.3-b01 mixed mode, sharing windows-x86 )
# Problematic frame:
# V [jvm.dll+0xdc6af]
#
# If you would like to submit a bug report, please visit:
# http://java.sun.com/webapps/bugreport/crash.jsp
#

————— T H R E A D —————

Current thread (0x0282ec00): VMThread [stack: 0x04a90000,0x04b90000] [id=5648]

siginfo: ExceptionCode=0xc0000005, reading address 0×00004600

Registers:
EAX=0×00004600, EBX=0x3431dce0, ECX=0x2bacac00, EDX=0x25ade03c
ESP=0x04b8fb3c, EBP=0x04b8fb50, ESI=0x25addff4, EDI=0x04b8fc60
EIP=0x6d8dc6af, EFLAGS=0×00010287

Top of Stack: (sp=0x04b8fb3c)
0x04b8fb3c: 25c2fff8 25adde28 04b8fc60 3431dce8
0x04b8fb4c: 3431db00 04b8fb70 6d9af258 25adde28
0x04b8fb5c: 25ade03c 001ddc98 04b8fc60 00000000
0x04b8fb6c: 001de6f0 04b8fb84 6d8a37cd 04b8fc60
0x04b8fb7c: 001dcd60 00000000 04b8fb98 6d8c86da
0x04b8fb8c: 04b8fc60 001dcd60 04b8fc20 04b8fc90
0x04b8fb9c: 6d8a3bc7 00000000 04b8fc60 04b8fc38
0x04b8fbac: 001ddc98 6d8a4644 001dcdb0 001dcd60

Instructions: (pc=0x6d8dc6af)
0x6d8dc69f: 89 55 0c 73 6d 8b 06 85 c0 74 5a 3b 47 20 73 55
0x6d8dc6af: 8b 08 83 e1 03 80 f9 03 75 1f 8a 0d f9 09 a5 6d

Stack: [0x04a90000,0x04b90000], sp=0x04b8fb3c, free space=3fe04b8f6b0k
Native frames: (J=compiled Java code, j=interpreted, Vv=VM code, C=native code)
V [jvm.dll+0xdc6af]
V [jvm.dll+0x1af258]
V [jvm.dll+0xa37cd]
V [jvm.dll+0xc86da]
V [jvm.dll+0xa3bc7]
V [jvm.dll+0xc94b8]
V [jvm.dll+0x7e7cb]
V [jvm.dll+0x1f45ab]
V [jvm.dll+0x1f7043]
V [jvm.dll+0x1f62de]
V [jvm.dll+0x1f662c]
V [jvm.dll+0x1f6a52]
V [jvm.dll+0x17f96c]
C [MSVCR71.dll+0x9565]
C [kernel32.dll+0x44911]
C [ntdll.dll+0x3e4b6]
C [ntdll.dll+0x3e489]

VM_Operation (0x06c3ea24): GenCollectForAllocation, mode: safepoint, requested by thread 0x0283dc00

————— P R O C E S S —————

Java Threads: ( => current thread )
0x0283b800 JavaThread “Thread-11″ daemon [_thread_blocked, id=4752, stack(0x089a0000,0x08aa0000)]
0x0283cc00 JavaThread “Thread-9″ daemon [_thread_blocked, id=2128, stack(0x080a0000,0x081a0000)]
0x0283c400 JavaThread “Thread-8″ daemon [_thread_blocked, id=5436, stack(0x07ba0000,0x07ca0000)]
0x0283c000 JavaThread “Java Sound Event Dispatcher” daemon [_thread_blocked, id=5564, stack(0x05e70000,0x05f70000)]
0x0283f000 JavaThread “Thread-6″ daemon [_thread_blocked, id=5776, stack(0x06d70000,0x06e70000)]
0x0283e800 JavaThread “Thread-5″ daemon [_thread_blocked, id=1296, stack(0x019f0000,0x01af0000)]
0x0283e400 JavaThread “DestroyJavaVM” [_thread_blocked, id=5912, stack(0x00030000,0x00130000)]
0x0283dc00 JavaThread “Thread-4″ daemon [_thread_blocked, id=5356, stack(0x06b40000,0x06c40000)]
0x0283d800 JavaThread “Thread-3″ daemon [_thread_blocked, id=4056, stack(0x06870000,0x06970000)]
0x0283d000 JavaThread “AWT-EventQueue-0″ [_thread_blocked, id=5696, stack(0x06450000,0x06550000)]
0x0283b400 JavaThread “AWT-Windows” daemon [_thread_in_native, id=4476, stack(0x05b50000,0x05c50000)]
0x0283ac00 JavaThread “AWT-Shutdown” [_thread_blocked, id=5764, stack(0x05a50000,0x05b50000)]
0x0283a800 JavaThread “Java2D Disposer” daemon [_thread_blocked, id=2292, stack(0x05540000,0x05640000)]
0x0283a000 JavaThread “Low Memory Detector” daemon [_thread_blocked, id=4884, stack(0x05090000,0x05190000)]
0×02844800 JavaThread “CompilerThread0″ daemon [_thread_blocked, id=284, stack(0x04f90000,0x05090000)]
0x02839c00 JavaThread “Attach Listener” daemon [_thread_blocked, id=2432, stack(0x04e90000,0x04f90000)]
0×02839400 JavaThread “Signal Dispatcher” daemon [_thread_blocked, id=4116, stack(0x04d90000,0x04e90000)]
0×02835400 JavaThread “Finalizer” daemon [_thread_blocked, id=2536, stack(0x04c90000,0x04d90000)]
0×02830800 JavaThread “Reference Handler” daemon [_thread_blocked, id=6112, stack(0x04b90000,0x04c90000)]

Other Threads:
=>0x0282ec00 VMThread [stack: 0x04a90000,0x04b90000] [id=5648]
0×02855800 WatcherThread [stack: 0x05190000,0x05290000] [id=5552]

VM state:at safepoint (normal execution)

VM Mutex/Monitor currently owned by a thread: ([mutex/lock_event])
[0x001d7528] Threads_lock – owner thread: 0x0282ec00
[0x001d7938] Heap_lock – owner thread: 0x0283dc00

Heap
def new generation total 26816K, used 25259K [0×24200000, 0x25f10000, 0×29750000)
eden space 23872K, 100% used [0×24200000, 0×25950000, 0×25950000)
from space 2944K, 47% used [0x25c30000, 0x25d8acd8, 0x25f10000)
to space 2944K, 99% used [0×25950000, 0x25c2fff8, 0x25c30000)
tenured ge

Best answer:

Answer by Badajoz
This error is intermittent. The best thing to do is to reinstall JRE from scratch.

Add your own answer in the comments!

Tagged with:
 

Question by Ritvarens: A fatal error has been detected by the Java Runtime Environment – java erors…How to fix?
# A fatal error has been detected by the Java Runtime Environment:
#
# EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x6d851824, pid=3200, tid=2304
#
# JRE version: 6.0_17-b04
# Java VM: Java HotSpot(TM) Client VM (14.3-b01 mixed mode, sharing windows-x86 )
# Problematic frame:
# V [jvm.dll+0x51824]
#
# If you would like to submit a bug report, please visit:
# http://java.sun.com/webapps/bugreport/crash.jsp
#

————— T H R E A D —————

Current thread (0x02af2400): JavaThread “CompilerThread0″ daemon [_thread_in_native, id=2304, stack(0x02d20000,0x02d70000)]

siginfo: ExceptionCode=0xc0000005, writing address 0×00000008

Registers:
EAX=0×00000000, EBX=0x0c79e198, ECX=0x0c7bcc88, EDX=0x000001e4
ESP=0x02d6f368, EBP=0x02d6f390, ESI=0x0c79dca0, EDI=0x0c79dc10
EIP=0x6d851824, EFLAGS=0×00010202

Top of Stack: (sp=0x02d6f368)
0x02d6f368: 0c79dc10 000001e4 02d6f648 000002b0
0x02d6f378: 0c79dc10 0c79dc10 02d6f648 02d6f3ac
0x02d6f388: 0c79dc10 0c79e198 02d6f3ac 6d851acf
0x02d6f398: 000001e4 00000763 0c79dc10 02d6f648
0x02d6f3a8: 02d6f648 02d6f3cc 6d853923 0c79dc10
0x02d6f3b8: 0000022a 0c7bcbf8 00000002 02d6f648
0x02d6f3c8: 0c79dc10 02d6f3fc 6d853d02 0000022a
0x02d6f3d8: 02d6f648 0c79dc10 0c79d301 0c79dca0

Instructions: (pc=0x6d851824)
0x6d851814: a4 6d 89 46 08 eb 0c 89 73 08 8b 0d 4c f8 a4 6d
0x6d851824: 89 48 08 8b 43 08 89 43 18 8b 5f 0c 8d 47 0c 8d

Stack: [0x02d20000,0x02d70000], sp=0x02d6f368, free space=316k
Native frames: (J=compiled Java code, j=interpreted, Vv=VM code, C=native code)
V [jvm.dll+0x51824]
V [jvm.dll+0x51acf]
V [jvm.dll+0x53923]
V [jvm.dll+0x53d02]
V [jvm.dll+0x53d85]
V [jvm.dll+0x54219]
V [jvm.dll+0x55155]
V [jvm.dll+0x26a67]
V [jvm.dll+0x26b0a]
V [jvm.dll+0x26c71]
V [jvm.dll+0x26d84]
V [jvm.dll+0x84df0]
V [jvm.dll+0x858cf]
V [jvm.dll+0x1d0414]
V [jvm.dll+0x173e4c]
C [msvcr71.dll+0x9565]
C [kernel32.dll+0xb6d9]

Current CompileTask:
C1: 19% ! Class83_Sub19_Sub37.method1373(BI)V @ 119 (836 bytes)

————— P R O C E S S —————

Java Threads: ( => current thread )
0x0c111800 JavaThread “Thread-9″ daemon [_thread_blocked, id=3568, stack(0x0c220000,0x0c270000)]
0x02b04c00 JavaThread “Thread-8″ daemon [_thread_in_native, id=3564, stack(0x0bdd0000,0x0be20000)]
0x02b04400 JavaThread “Java Sound Event Dispatcher” daemon [_thread_blocked, id=1864, stack(0x0bbe0000,0x0bc30000)]
0x02b3b400 JavaThread “Thread-6″ daemon [_thread_blocked, id=3348, stack(0x0b930000,0x0b980000)]
0x02b6e400 JavaThread “Thread-5″ daemon [_thread_blocked, id=3272, stack(0x034c0000,0x03510000)]
0x003f6400 JavaThread “DestroyJavaVM” [_thread_blocked, id=3216, stack(0x008d0000,0x00920000)]
0x02e79400 JavaThread “Thread-4″ daemon [_thread_in_vm, id=2984, stack(0x033f0000,0x03440000)]
0x02e7a000 JavaThread “Thread-3″ daemon [_thread_blocked, id=3100, stack(0x033a0000,0x033f0000)]
0x02e77800 JavaThread “D3D Screen Updater” daemon [_thread_blocked, id=3116, stack(0x03350000,0x033a0000)]
0x02b8a400 JavaThread “AWT-EventQueue-0″ [_thread_in_native, id=3084, stack(0x031d0000,0x03220000)]
0x02b7dc00 JavaThread “AWT-Windows” daemon [_thread_in_native, id=3260, stack(0x030f0000,0x03140000)]
0x02b7c800 JavaThread “AWT-Shutdown” [_thread_blocked, id=3252, stack(0x030a0000,0x030f0000)]
0x02b80400 JavaThread “Java2D Disposer” daemon [_thread_blocked, id=648, stack(0x03050000,0x030a0000)]
0x02af8c00 JavaThread “Low Memory Detector” daemon [_thread_blocked, id=3248, stack(0x02d70000,0x02dc0000)]
=>0x02af2400 JavaThread “CompilerThread0″ daemon [_thread_in_native, id=2304, stack(0x02d20000,0x02d70000)]
0x02af0c00 JavaThread “Attach Listener” daemon [_thread_blocked, id=440, stack(0x02cd0000,0x02d20000)]
0x02aefc00 JavaThread “Signal Dispatcher” daemon [_thread_blocked, id=1264, stack(0x02c80000,0x02cd0000)]
0x02ab1000 JavaThread “Finalizer” daemon [_thread_blocked, id=3236, stack(0x02c30000,0x02c80000)]
0x02aac400 JavaThread “Reference Handler” daemon [_thread_blocked, id=3240, stack(0x02be0000,0x02c30000)]

Other Threads:
0x02aaac00 VMThread [stack: 0x02b90000,0x02be0000] [id=3212]
0x02b0c800 WatcherThread [stack: 0x02dc0000,0x02e10000] [id=3264]

VM state:not at safepoint (normal execution)

VM Mutex/Monitor currently owned by a thread: None

Heap
def new generation total 1536K, used 657K [0x229d0000, 0x22b70000, 0x22eb0000)
eden space 1408K, 37% used [0x229d0000, 0x22a54420, 0x22b30000)
from space 128K, 100% used [0x22b30000, 0x22b50000, 0x22b50000)
to space 128K, 0% used [0x22b50000, 0x22b50000, 0x22b70000)
tenured generation total 19560K, used 13413K [0x22eb0000, 0x241ca000, 0x269d0000)
the space 19560K, 68% used [0x22eb0000, 0x23bc94f8, 0x23bc9600, 0x241ca000)
compacting perm gen total 12288K, used 3361K [0x269d0000, 0x275d0000, 0x2a9d0000)
the space 12288K, 27% used [0x269d0000, 0×26

Best answer:

Answer by Pramod
//pk

It looks that java is trying to access some memory which is blocked or need permission.

Know better? Leave your own answer in the comments!

Tagged with:
 

Question by Ritvarens: A fatal error has been detected by the Java Runtime Environment – how to fix ?
# A fatal error has been detected by the Java Runtime Environment:
#
# EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x6d851824, pid=3200, tid=2304
#
# JRE version: 6.0_17-b04
# Java VM: Java HotSpot(TM) Client VM (14.3-b01 mixed mode, sharing windows-x86 )
# Problematic frame:
# V [jvm.dll+0x51824]
#
# If you would like to submit a bug report, please visit:
# http://java.sun.com/webapps/bugreport/crash.jsp
#

————— T H R E A D —————

Current thread (0x02af2400): JavaThread “CompilerThread0″ daemon [_thread_in_native, id=2304, stack(0x02d20000,0x02d70000)]

siginfo: ExceptionCode=0xc0000005, writing address 0×00000008

Registers:
EAX=0×00000000, EBX=0x0c79e198, ECX=0x0c7bcc88, EDX=0x000001e4
ESP=0x02d6f368, EBP=0x02d6f390, ESI=0x0c79dca0, EDI=0x0c79dc10
EIP=0x6d851824, EFLAGS=0×00010202

Top of Stack: (sp=0x02d6f368)
0x02d6f368: 0c79dc10 000001e4 02d6f648 000002b0
0x02d6f378: 0c79dc10 0c79dc10 02d6f648 02d6f3ac
0x02d6f388: 0c79dc10 0c79e198 02d6f3ac 6d851acf
0x02d6f398: 000001e4 00000763 0c79dc10 02d6f648
0x02d6f3a8: 02d6f648 02d6f3cc 6d853923 0c79dc10
0x02d6f3b8: 0000022a 0c7bcbf8 00000002 02d6f648
0x02d6f3c8: 0c79dc10 02d6f3fc 6d853d02 0000022a
0x02d6f3d8: 02d6f648 0c79dc10 0c79d301 0c79dca0

Instructions: (pc=0x6d851824)
0x6d851814: a4 6d 89 46 08 eb 0c 89 73 08 8b 0d 4c f8 a4 6d
0x6d851824: 89 48 08 8b 43 08 89 43 18 8b 5f 0c 8d 47 0c 8d

Stack: [0x02d20000,0x02d70000], sp=0x02d6f368, free space=316k
Native frames: (J=compiled Java code, j=interpreted, Vv=VM code, C=native code)
V [jvm.dll+0x51824]
V [jvm.dll+0x51acf]
V [jvm.dll+0x53923]
V [jvm.dll+0x53d02]
V [jvm.dll+0x53d85]
V [jvm.dll+0x54219]
V [jvm.dll+0x55155]
V [jvm.dll+0x26a67]
V [jvm.dll+0x26b0a]
V [jvm.dll+0x26c71]
V [jvm.dll+0x26d84]
V [jvm.dll+0x84df0]
V [jvm.dll+0x858cf]
V [jvm.dll+0x1d0414]
V [jvm.dll+0x173e4c]
C [msvcr71.dll+0x9565]
C [kernel32.dll+0xb6d9]

Current CompileTask:
C1: 19% ! Class83_Sub19_Sub37.method1373(BI)V @ 119 (836 bytes)

————— P R O C E S S —————

Java Threads: ( => current thread )
0x0c111800 JavaThread “Thread-9″ daemon [_thread_blocked, id=3568, stack(0x0c220000,0x0c270000)]
0x02b04c00 JavaThread “Thread-8″ daemon [_thread_in_native, id=3564, stack(0x0bdd0000,0x0be20000)]
0x02b04400 JavaThread “Java Sound Event Dispatcher” daemon [_thread_blocked, id=1864, stack(0x0bbe0000,0x0bc30000)]
0x02b3b400 JavaThread “Thread-6″ daemon [_thread_blocked, id=3348, stack(0x0b930000,0x0b980000)]
0x02b6e400 JavaThread “Thread-5″ daemon [_thread_blocked, id=3272, stack(0x034c0000,0x03510000)]
0x003f6400 JavaThread “DestroyJavaVM” [_thread_blocked, id=3216, stack(0x008d0000,0x00920000)]
0x02e79400 JavaThread “Thread-4″ daemon [_thread_in_vm, id=2984, stack(0x033f0000,0x03440000)]
0x02e7a000 JavaThread “Thread-3″ daemon [_thread_blocked, id=3100, stack(0x033a0000,0x033f0000)]
0x02e77800 JavaThread “D3D Screen Updater” daemon [_thread_blocked, id=3116, stack(0x03350000,0x033a0000)]
0x02b8a400 JavaThread “AWT-EventQueue-0″ [_thread_in_native, id=3084, stack(0x031d0000,0x03220000)]
0x02b7dc00 JavaThread “AWT-Windows” daemon [_thread_in_native, id=3260, stack(0x030f0000,0x03140000)]
0x02b7c800 JavaThread “AWT-Shutdown” [_thread_blocked, id=3252, stack(0x030a0000,0x030f0000)]
0x02b80400 JavaThread “Java2D Disposer” daemon [_thread_blocked, id=648, stack(0x03050000,0x030a0000)]
0x02af8c00 JavaThread “Low Memory Detector” daemon [_thread_blocked, id=3248, stack(0x02d70000,0x02dc0000)]
=>0x02af2400 JavaThread “CompilerThread0″ daemon [_thread_in_native, id=2304, stack(0x02d20000,0x02d70000)]
0x02af0c00 JavaThread “Attach Listener” daemon [_thread_blocked, id=440, stack(0x02cd0000,0x02d20000)]
0x02aefc00 JavaThread “Signal Dispatcher” daemon [_thread_blocked, id=1264, stack(0x02c80000,0x02cd0000)]
0x02ab1000 JavaThread “Finalizer” daemon [_thread_blocked, id=3236, stack(0x02c30000,0x02c80000)]
0x02aac400 JavaThread “Reference Handler” daemon [_thread_blocked, id=3240, stack(0x02be0000,0x02c30000)]

Other Threads:
0x02aaac00 VMThread [stack: 0x02b90000,0x02be0000] [id=3212]
0x02b0c800 WatcherThread [stack: 0x02dc0000,0x02e10000] [id=3264]

VM state:not at safepoint (normal execution)

VM Mutex/Monitor currently owned by a thread: None

Heap
def new generation total 1536K, used 657K [0x229d0000, 0x22b70000, 0x22eb0000)
eden space 1408K, 37% used [0x229d0000, 0x22a54420, 0x22b30000)
from space 128K, 100% used [0x22b30000, 0x22b50000, 0x22b50000)
to space 128K, 0% used [0x22b50000, 0x22b50000, 0x22b70000)
tenured generation total 19560K, used 13413K [0x22eb0000, 0x241ca000, 0x269d0000)
the space 19560K, 68% used [0x22eb0000, 0x23bc94f8, 0x23bc9600, 0x241ca000)
compacting perm gen total 12288K, used 3361K [0x269d0000, 0x275d0000, 0x2a9d0000)
the space 12288K, 27% used [0x269d0000, 0×26

Best answer:

Answer by Abhishek
Please give the code or the program name which is causing the exception

What do you think? Answer below!

Tagged with:
 

Question by Krishna prasad: I am not able to access the internet, but my network is detected. Error ‘active network adapter not found’.
I am using windows XP sp2. I accidentally removed the ‘restore point’ and booted in safe-mode. Then booted in normally. Thereafter, my network (internet) connectivity is effected and I am no longer able to connect to the net. The ‘netwroking’ tab in the windows task manager throws this error: ‘Active network adapter not found’. Even after trying various options and searching numerous topics in this regard, I am still not able to access the internet. I use broadband internet connection. Also, I am not able to start this service “Windows Firewall/Internet Connection Sharing (ICS)”.

Any help/idea or any information in this is appreciated. You can send your answers/suggestions etc. to: Lrvkp1976@yahoo.com

Thx.
I just had to add this … a) I was able to access the internet before the current problem.
b) I am using a desktop PC and this does NOT have any wireless connection.

Thx.
c) Even after I ran my motherboard CD, the missing network adapter/driver etc. could not be enabled. Also, it showed that the one on pc are the latest.

Best answer:

Answer by Jay
It sounds like you could access the internet before.

You may just be missing Drivers for the Network card, or The Modem you are using, your modem should come with drivers for it along with a router if you use one, Check your Device manager to see if you can find drivers the the Networking Card.

Add your own answer in the comments!

Tagged with: