Welcome to the Virus Encyclopedia of Panda Security.
It connects to an IRC server and waits for remote control commands to be performed on the affected computer. On demand, it can spread via AOL Instant Messenger.
|First detected on:||May 17, 2005|
|Detection updated on:||May 18, 2005|
|Yes, using TruPrevent Technologies
Oscarbot.F is a worm with backdoor characteristics that connects to the IRC server jupedatass.edhak.info, joins a certain channel and waits for remote control commands to be carried out on the affected computer. These control commands include downloading and running files, for example.
Though Oscarbot.F does not spread automatically by itself, it can be instructed to use AOL Instant Messenger in order to send messages to all the addresses in the Contact List. These messages include an URL that, on accessing it, download a copy of this worm or other kind of malware to the affected computer.
Oscarbot.F is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.