Les informations contenues dans cette rubrique de notre site web sont constamment mises à jour. Afin de vous garantir un contenu le plus actualisé possible, elles sont uniquement diffusées en anglais.

Virus Profile: Captchar

Threat Search
Imprimer
   
Virus Profile information details
Risk Assessment: Home Low-Profiled | Corporate Low-Profiled
Date Discovered: 30/10/2007
Date Added: 30/10/2007
Origin: N/A
Length: 215,552 bytes
Type: Trojan
Subtype: Win32
DAT Required: 5153
Removal Instructions
   
 
 
   

Description

Captchar is a trojan program, which is used to defeat CAPTCHA(Completely Automated Public Turing test  to tell Computers and Humans Apart) that is often used by web sites to prevent spammers from using automated program to create a large number of accounts.

Indication of Infection

  • an image with the title as "Melissa strip" and the message as described above

 

Methods of Infection

Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems. Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc

Aliases

Trj/RompeCaptchas.A, TROJ_CAPTCHAR.A, Trojan.Captchar.A, Trojan.Win32.Agent.brb, W32/Captchas.A, Win32/Captchar.A
   

Virus Characteristics

-- Update October 31, 2007 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://news.bbc.co.uk/2/hi/technology/7067962.stm

--
Once executed, Captchar trojan starts a hidden instance of iexplore.exe and injects its code into this process. Then it deletes itself.

The trojan attempts to connect a remote server to exchange CAPTCHA information.

After successfully communicating with the server, the trojan displays the following message:

Hi!
My name is  melissa.  I'm 18 years old and you have come to the
right place to play :)
How to play?
;
Easy, enter the code that you will see and I'm taking off
1 of my things. :) Want to start strip me? Then what are you
waiting for? Click the start play.

The trojan then displays the message with a CAPTCHA input field when a user clicks the start button:

Ok, lets start baby! Lets see if you can strip me :).
Put the word that you see on bottom, if its correct I'll
take off 1 of my xxx :)

If a wrong CAPTCHA code is input by the user, the trojan displays the following message:

Hmmm, nope, the word you entered is
incorrect honey! Lets try again?

After the correct CAPTCHA is input by the user, the trojan sends the correct code to its control server, displays one of the following messages and a new CAPTCHA code to enticing the user into continuing the game.

Outch, nice one, you got it right!
ok, ready for next one? Here it is:

 

Un ordinateur infecté ? Obtenez l'aide d'un expert !

McAfee
Service de suppression des virus

Contactez l'un de nos spécialistes en sécurité par téléphone. Regardez votre PC pendant que nous résolvons le problème à distance.

$89.95 (USD)

Publicité