Welcome to the Virus Encyclopedia of Panda Security.
It can receive remote control orders, log the keystrokes typed by the user, harvest passwords, etc. It spreads via email.
|First detected on:||Oct. 19, 2005|
|Detection updated on:||Oct. 26, 2005|
|Yes, using TruPrevent Technologies
Samony.A is a worm with backdoor characteristics that remains listening to port 321, in order to receive control commands, which allow the affected computer to be remotely administrated. It can be instructed to download, run, copy and delete files, list directories, etc.
It obtains the passwords stored in the system, such as those belonging to Protected Storage, including Outlook or Internet Explorer keys. It also logs the keystrokes typed by the user, thus posing a threat to the user's confidentiality.
Additionally, Samony.A spreads via email in a message that deals with Skype, which is a telephony over IP program.
Samony.A is easy to recognize, as it reaches the computer in an email message with the following characteristics:
Skylook for Skype
Hello, You asked me to send you Skylook - here it is:
With Skylook, you can get 1 hour of world-wide calls FREE!
Skype Voice Calls (as MP3), Instant Messages, Email, Appointments, Contacts all organized and under control in Microsoft® Outlook®!
Try it before October 31 and receive 1 hour of free world-wide calls (SkypeOut). Also You`ll get 40% off a business license or 30% off a home license.
Use Skylook 1.0 to record Skype VoIP Calls to MP3!