Welcome to the Virus Encyclopedia of Panda Security.
|Alias:||Win32.HLLP.Savno, W32/HLLP.Savno!p2p, W32.HLLP.Spreda.B|
|Effects: ||It infects PE files and occasionally drops a Trojan that steals passwords.|
|Detection updated on:||Nov. 19, 2003|
Savno.A is a virus with worm characteristics that infects the PE files with a size greater than 102,400 bytes but smaller than 10,385,024 bytes that are in the shared directory of KaZaA.
Savno.A searches for files with an URL extension that fulfill a certain condition. If it finds any, it drops a Trojan, which tries to steal the passwords used to access certain services on the Internet. The Trojan will send the collected passwords to a website.
Savno.A is a direct action virus, which does not go memory resident.
Savno.A is difficult to recognize, as it does not show any messages or warnings that indicate it has reached the computer.