I bet you have never seen such a tempting
Trojan before. The Trojan named Melissa Strip, identified as TROJ_CAPTCHAR.A by
TrendMicro and Trj/RompeCaptchas.A by Panda, starts by asking the user if he wants to play a
game where she (Melissa) will strip for the user if the enters the correct code.
After clicking Start Play the
image of a women on the left side and a captcha on the right is displayed. The program asks the user to enter the captcha to see another
picture of the woman with less clothes on. After entering the captcha correctly and clicking on enter the Trojan loads another picture and captcha asking the user again to type the correct code to see Melissa strip even more.
You might have already guessed that the captcha is actually the captcha of another website, Yahoo for instance, and the Trojan uses the help of users to enter those captchas correctly on those
websites. Captchas are used to tell human users from bots apart and make it more difficulty to create automatic process to signup or submit
data.
http://www.ghacks.net/wp-content/upl...2/melissa1.jpg
The Trojan does not seem to cause harm on the users system. It simply uses him to create correct responses to captcha codes that are used to create accounts on websites like Yahoo Mail.
http://www.ghacks.net/wp-content/upl...2/melissa2.jpg
Trend Micro reports that the Trojan most likely arrives as a file
downloaded by other malware on the system. It could also be send as an
email attachement.
http://www.ghacks.net/wp-content/upl...2/melissa3.jpg