AIM based Trojan (Oscarbot) installs backdoor on PC

By Angsuman Chakraborty, Gaea News Network
Monday, May 9, 2005

Oscarbot(aka Doyorg), an windows only Trojan, continued to spread on Monday among America Online instant messaging clients. It installs backdoor on the infected PC when users click on a link within lines like “hey check out this” or “i thought youd wanna see this” from a buddy on their AIM contact list.

Following the hyperlink results results in the user being prompted to save/run an executable file (such as pictures@gallery.com). If users choose to download and/or run this file, Oscarbot will contact a remote IRC server, logon to a specified channel and wait for further instructions. It propagates by sending the same message to every buddy in the system’s AOL Instant Messenger client’s address book.

The backdoor component can be used later by the attacker to upload software of his choice to the compromised PC. Such machines are typically added to botnets and are often used as spam proxies or to launch denial of service(DDoS) attacks.

Update your Anti-Virus software to safeguard against this attack. Also do not click on links delivered via AIM, nor download any software from those URLs, even if the message comes from a trusted friend.

This threat copies itself to the WINDOWS (%WinDir%) directory as svchost.exe (note a valid svchost.exe file exists in the WINDOWS SYSTEM directory). The shell is hooked via the registry to ensure the threat is run at system startup.

Source

Filed under: Computer Security, Web, Windows

Tags:
Discussion

used computers
July 21, 2010: 4:51 pm

iphone is the best technological marvel. It is fast, launches applications, games, internet, videos etc. quickly. Its a very powerful touch sensitivity mobile computer with added voice control features. It a revolutionary mobile phone, a widescreen ipod, and a breakthrough internet device. The iphone may drive many of the existing smart phones and touch phones to extinction.Ibm-PC drove many other computer design architectures into extinction

July 21, 2010: 11:56 am

I guess the shell is hooked via the registry to ensure the threat is run at system startup.

May 14, 2007: 1:45 pm

How do you get on myspace like nobody knows how to get on there. So please help me!!!

Thanxs
Allison

YOUR VIEW POINT
NAME : (REQUIRED)
MAIL : (REQUIRED)
will not be displayed
WEBSITE : (OPTIONAL)
YOUR
COMMENT :