Cloud Antivirus > Surveillance de l’activité > ARPoisoner.A

Détails du virusARPoisoner.A

Tous les détails, la description et les effets de ARPoisoner.A

CLOUD ANTIVIRUS - Share/Bookmark
Noms courants : ARPoisoner.A
Noms techniques :
Alias :
   
Type : TROJAN
Taille : 29231 Bytes
   

DETECTIONS

Nombre de détections :
Date de première détection : November 12, 2007 at 00:00 AM
Premier pays où il est apparu :
Dernier pays où il est apparu :
   

Brief Description

ARPoisoner.A is a Trojan that only affects computers that belong to the same local network.

Its main aim is to capture and modify the HTTP-type network packets that are sent from the computers.

As a consequence, the websites requested by the user will be displayed with alterations. However, this anomaly will not be displayed in the infected computer.

ARPoisoner.A does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer.

Effects

ARPoisoner.A only affects computers that belong to the same local network.

Its main aim is to capture and modify the network packets that are sent from the computers. The only packets it modifies are those belonging to the HTTP protocol.

As a consequence, the website requested by the user will be displayed with alterations, a string of BBBBBBBBBBB appear, as in the image below:

This does not mean that these computers are infected by ARPoisoner.A, but that there is an infected computer in the network they belong to. Concretely, the visited websites in the infected computer will not be displayed with the anomaly mentioned above.

In a normal network configuration, the systems are connected to the Internet via a router, as in the image below:

 

However, ARPoisoner.A is able to capture the network packets before they reach the router:

In order to do so, it uses the Windows packet capture library called Winpcap.

Once it captures the network packets, it sends them to the router, the router gives them back to the Trojan, the Trojan modifies them by adding the BBBBBBBB and finally they are sent to the user that requested them.

http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=Plus d’informations sur virus ARPoisoner.A dans l’Encyclopédie