Search:       

Saturday, 17 May 2008       

Win32.Santana.110 Spyware/Adware Definition


Name: Win32.Santana.110
Category: Viruses
Description: Details
Win32.Santana.1104

Win32.Santana is a memory resident parasitic encrypted Win32 virus. It affects PE EXE files (Win32 executable files) by writing its code to a file end and modifying necessary PE header fields. The virus does not manifest itself in any way. It contains the text string:
Virus "SANTANA" created by Net'$ Wa$te [RespawneD EViL]
When an infected file is executed, the virus gets control, decrypts itself and calls its main routine. That routine scans Windows kernel to get addresses of necessary file access functions and then checks system environment. Under Windows NT the virus then calls direct infection routine: it searches for all PE EXE files in the current directory, infects them and returns control to the host program.
Under Windows 95/98, the virus scans the VxD memory area and looks for a cave in there (zero bytes cave - not used area).. The virus copies its code to that cave, switches its process to kernel mode (Ring0), hooks SetCurrentDirectoryA Windows function (selecting a new directory) and stays in the system memory as a component of the Windows kernel. On selecting the new directory the virus runs its find-and-infect routine. Where there is no cave of reasonable size, the virus calls the direct infection routine in the same way as under Windows NT.


Top Viruses Visited Pages:
ECW.57
Gorgan.271
Gorill
Guerilla.199
HLLP.Nover.771
Holiday Famil
HS.90
Hydra_II Famil
I-Worm.Mimail.
I-Worm.MyLife.
I-Worm.MyLife.
I-Worm.Sobig.
Ice Famil
IDEA.612
Imi.1536.

 


Main Menu
Home
Top Downloads
New Programs
Awards
Submit
Link to us
Spyware Definitions
Viruses Info
Recipes
Jokes
Contact us



Partners
Softs Land
Hotel Reservations
Computer Articles
Viruses Info
Free Downloads
Data Recovery Shareware Downloads Free Articles
Cooks Recipes
Download Programs
Windows Drivers
MySpace Generators

Check PageRank

 

 

- Privacy Policy -