VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:3%Antivirus software(1/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2016-08-29 11:09:49 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 5
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 150725-1 4.7.4 2015-07-25 Found nothing 60
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 60
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 7
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 60
clamav 19861 0.97.5 2014-12-31 Found nothing 60
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 60
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 60
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 60
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 60
gdata 25.8072 25.8072 2016-08-28 Found nothing 9
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 60
jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 42
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 60
kingsoft 2.1 2.1 2013-09-22 Android.Troj.at_emial.aw.(kcloud) 5
mcafee 7638 5400.1158 2014-11-30 Found nothing 60
nod32 0920 3.0.21 2014-12-23 Found nothing 60
panda 9.05.01 9.05.01 2015-07-26 Found nothing 4
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 60
qh360 1.0.1 1.0.1 1.0.1 Found nothing 3
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 60
quickheal 14.00 14.00 2015-07-25 Found nothing 2
rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 1
sophos 5.08 3.55.0 2014-12-01 Found nothing 60
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 60
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 13
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 60
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 60
权限列表
许可名称 信息
android.permission.RECEIVE_WAP_PUSH 接收wap push信息
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.MODIFY_AUDIO_SETTINGS 修改声音设置
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.RECEIVE_USER_PRESENT
android.permission.READ_CONTACTS 读取联系人信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.READ_SMS 读取短信
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.WRITE_SMS 写短信
android.permission.SEND_SMS 发送短信
android.permission.VIBRATE 允许设备震动
android.permission.RECEIVE_SMS 监控接收短信
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:d7acbb5f8205e33360da13ff40f8828f
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.Nhxoowysol.hhapoixikvw
最低运行环境:Android 2.2.x
版权:chenhailong-1-9
关键行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 直接获取CPU时钟
详情信息: N/A
行为描述: 获取TickCount值
详情信息: TickCount = 5352331, SleepMilliseconds = 50.
TickCount = 5352378, SleepMilliseconds = 50.
TickCount = 5352393, SleepMilliseconds = 50.
TickCount = 5352456, SleepMilliseconds = 50.
TickCount = 5352550, SleepMilliseconds = 50.
TickCount = 5352565, SleepMilliseconds = 50.
TickCount = 5352987, SleepMilliseconds = 50.
TickCount = 5353034, SleepMilliseconds = 50.
TickCount = 5353050, SleepMilliseconds = 50.
TickCount = 5353081, SleepMilliseconds = 50.
TickCount = 5353096, SleepMilliseconds = 50.
TickCount = 5353128, SleepMilliseconds = 50.
TickCount = 5353159, SleepMilliseconds = 50.
TickCount = 5353175, SleepMilliseconds = 50.
TickCount = 5353206, SleepMilliseconds = 50.
进程行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 直接获取CPU时钟
详情信息: N/A
行为描述: 获取TickCount值
详情信息: TickCount = 5352331, SleepMilliseconds = 50.
TickCount = 5352378, SleepMilliseconds = 50.
TickCount = 5352393, SleepMilliseconds = 50.
TickCount = 5352456, SleepMilliseconds = 50.
TickCount = 5352550, SleepMilliseconds = 50.
TickCount = 5352565, SleepMilliseconds = 50.
TickCount = 5352987, SleepMilliseconds = 50.
TickCount = 5353034, SleepMilliseconds = 50.
TickCount = 5353050, SleepMilliseconds = 50.
TickCount = 5353081, SleepMilliseconds = 50.
TickCount = 5353096, SleepMilliseconds = 50.
TickCount = 5353128, SleepMilliseconds = 50.
TickCount = 5353159, SleepMilliseconds = 50.
TickCount = 5353175, SleepMilliseconds = 50.
TickCount = 5353206, SleepMilliseconds = 50.
文件行为
VirSCANVirSCAN
行为描述: 创建文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\wpad[1].dat
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\qqsqq111[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\navcancl[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\background_gradient[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\info_48[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\bullet[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\qqsqq112[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\navcancl[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\background_gradient[2]
行为描述: 覆盖已有文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\navcancl[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\background_gradient[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\info_48[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\bullet[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\navcancl[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\background_gradient[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\info_48[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\navcancl[1]
行为描述: 查找文件
详情信息: FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\Local Settings
FileName = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
FileName = C:\WINDOWS\system32\Ras\*.pbk
FileName = C:\Documents and Settings\Administrator\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
FileName = C:\WINDOWS
FileName = C:\WINDOWS\system32
FileName = C:\WINDOWS\system32\urlmon.dll
FileName = C:\WINDOWS\system32\ieframe.dll
FileName = C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016061420160615\*.*
行为描述: 删除文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\wpad[1].dat
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\qqsqq111[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\navcancl[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\ErrorPageTemplate[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\background_gradient[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\info_48[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\bullet[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\qqsqq112[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\navcancl[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\background_gradient[1]
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 修改文件内容
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\navcancl[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\ErrorPageTemplate[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\background_gradient[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\info_48[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\bullet[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\navcancl[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\ErrorPageTemplate[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\errorPageStrings[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\httpErrorPagesScripts[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\background_gradient[2] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\info_48[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[2] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\navcancl[1] ---> Offset = 0
网络行为
VirSCANVirSCAN
行为描述: 联网打开网址
详情信息: InternetOpenUrlA: http://**.133.40.**:128/wpad.dat, hInternet = 0x00cc0010, Flags = 0x00000010
行为描述: 连接指定站点
详情信息: InternetConnectA: ServerName = ad****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
InternetConnectA: ServerName = **.133.40.**, PORT = 128, UserName = , Password = , hSession = 0x00cc0010, hConnect = 0x00cc0014, Flags = 0x00000010
InternetConnectA: ServerName = 12****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0008, hConnect = 0x00cc000c, Flags = 0x00000000
InternetConnectA: ServerName = 12****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0008, hConnect = 0x00cc0014, Flags = 0x00000000
InternetConnectA: ServerName = 12****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0008, hConnect = 0x00cc001c, Flags = 0x00000000
InternetConnectA: ServerName = 12****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0008, hConnect = 0x00cc0024, Flags = 0x00000000
InternetConnectA: ServerName = zc****om, PORT = 80, UserName = , Password = , hSession = 0x00cc0008, hConnect = 0x00cc002c, Flags = 0x00000000
行为描述: 打开HTTP连接
详情信息: InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0), hSession = 0x00cc0004
InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 8.0; Win32; Trident/4.0), hSession = 0x00cc0010
InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489), hSession = 0x00cc0008
行为描述: 建立到一个指定的套接字连接
详情信息: URL: wpad, IP: **.133.40.**:128, SOCKET = 0x0000046c
URL: ad****cn, IP: **.133.40.**:80, SOCKET = 0x00000464
URL: 12****cn, IP: **.133.40.**:80, SOCKET = 0x00000438
URL: 12****cn, IP: **.133.40.**:80, SOCKET = 0x00000348
URL: 12****cn, IP: **.133.40.**:80, SOCKET = 0x00000310
URL: 12****cn, IP: **.133.40.**:80, SOCKET = 0x0000034c
URL: 12****cn, IP: **.133.40.**:80, SOCKET = 0x00000518
URL: 12****cn, IP: **.133.40.**:80, SOCKET = 0x0000028c
URL: 12****cn, IP: **.133.40.**:80, SOCKET = 0x00000288
URL: 12****cn, IP: **.133.40.**:80, SOCKET = 0x000002c0
URL: zc****om, IP: **.133.40.**:80, SOCKET = 0x00000248
URL: zc****om, IP: **.133.40.**:80, SOCKET = 0x0000038c
行为描述: 读取网络文件
详情信息: hFile = 0x00cc0018, BytesToRead =4010, BytesRead = 4010.
hFile = 0x00cc000c, BytesToRead =102400, BytesRead = 102400.
hFile = 0x00cc0010, BytesToRead =4096, BytesRead = 4096.
hFile = 0x00cc0020, BytesToRead =4096, BytesRead = 4096.
hFile = 0x00cc0028, BytesToRead =4096, BytesRead = 4096.
hFile = 0x00cc0030, BytesToRead =4096, BytesRead = 4096.
行为描述: 发送HTTP包
详情信息: GET /wpad.dat HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32; Trident/4.0) Host: **.133.40.**:128
GET /setup/ssxczgg2673.txt HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0) Accept: */* Host: ad****cn Cache-Control: no-cache
GET /ad/qqsqq111.htm HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: 12****cn Connection: Keep-Alive
GET /ad/qqsqq112.htm HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: 12****cn Connection: Keep-Alive
GET /ad/qqsqq113.htm HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: 12****cn Connection: Keep-Alive
GET /ad/qqsqqgg11.htm HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: 12****cn Connection: Keep-Alive
GET /chs/v2/ HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible;MSIE 5.1; Windows NT 6.1; Trident/4.0;SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0E; .NET4.0C) Host: zc****om Connection: Keep-Alive
行为描述: 打开HTTP请求
详情信息: HttpOpenRequestA: ad****cn:80/setup/ssxczgg2673.txt, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x84000000
HttpOpenRequestA: **.133.40.**:128/wpad.dat, hConnect = 0x00cc0014, hRequest = 0x00cc0018, Verb: GET, Referer: , Flags = 0x00000010
HttpOpenRequestA: 12****cn:80/ad/qqsqq111.htm, hConnect = 0x00cc000c, hRequest = 0x00cc0010, Verb: GET, Referer: , Flags = 0x00400000
HttpOpenRequestA: 12****cn:80/ad/qqsqq111.htm, hConnect = 0x00cc000c, hRequest = 0x00cc0010, Verb: GET, Referer: , Flags = 0x00400010
HttpOpenRequestA: 12****cn:80/ad/qqsqq112.htm, hConnect = 0x00cc0014, hRequest = 0x00cc0018, Verb: GET, Referer: , Flags = 0x00400000
HttpOpenRequestA: 12****cn:80/ad/qqsqq112.htm, hConnect = 0x00cc0014, hRequest = 0x00cc0018, Verb: GET, Referer: , Flags = 0x00400010
HttpOpenRequestA: 12****cn:80/ad/qqsqq113.htm, hConnect = 0x00cc001c, hRequest = 0x00cc0020, Verb: GET, Referer: , Flags = 0x00400000
HttpOpenRequestA: 12****cn:80/ad/qqsqq113.htm, hConnect = 0x00cc001c, hRequest = 0x00cc0020, Verb: GET, Referer: , Flags = 0x00400010
HttpOpenRequestA: 12****cn:80/ad/qqsqqgg11.htm, hConnect = 0x00cc0024, hRequest = 0x00cc0028, Verb: GET, Referer: , Flags = 0x00400000
HttpOpenRequestA: 12****cn:80/ad/qqsqqgg11.htm, hConnect = 0x00cc0024, hRequest = 0x00cc0028, Verb: GET, Referer: , Flags = 0x00400010
HttpOpenRequestA: zc****om:80/chs/v2/, hConnect = 0x00cc002c, hRequest = 0x00cc0030, Verb: GET, Referer: , Flags = 0x00400200
HttpOpenRequestA: zc****om:80/chs/v2/, hConnect = 0x00cc002c, hRequest = 0x00cc0030, Verb: GET, Referer: , Flags = 0x00400010
行为描述: 按名称获取主机地址
详情信息: GetAddrInfoW: computer
GetAddrInfoW: wpad
GetAddrInfoW: ad****cn
GetAddrInfoW: 12****cn
GetAddrInfoW: zc****om
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
\REGISTRY\MACHINE\SOFTWARE\Microsoft\ESENT\Process\996E\DEBUG\Trace Level
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1407
\REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0\win32\
行为描述: 删除注册表键值
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
\REGISTRY\MACHINE\SOFTWARE\Microsoft\ESENT\Process\996E\DEBUG\Trace Level
其他行为
VirSCANVirSCAN
行为描述: 调整进程token权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
行为描述: 创建互斥体
详情信息: RasPbFile
CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
Local\c:!documents and settings!administrator!ietldcache!
Local\!PrivacIE!SharedMemory!Mutex
CritOpMutex
MSIMGSIZECacheMutex
行为描述: 创建事件对象
详情信息: EventName = DINPUTWINMM
EventName = Global\userenv: User Profile setup event
EventName = Global\crypt32LogoffEvent
EventName = MSCTF.SendReceive.Event.MGF.IC
EventName = MSCTF.SendReceiveConection.Event.MGF.IC
行为描述: 直接获取CPU时钟
详情信息: N/A
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [MS_AutodialMonitor,]
NtUserFindWindowEx: [Class,Window] = [MS_WebCheckMonitor,]
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
NtUserFindWindowEx: [Class,Window] = [,]
行为描述: 窗口信息
详情信息: Pid = 1400, Hwnd=0x103ce, Text = 您想运行或保存此文件吗?, ClassName = Static.
Pid = 1400, Hwnd=0x103d2, Text = 名称:, ClassName = Static.
Pid = 1400, Hwnd=0x103d4, Text = update.exe, ClassName = SysLink.
Pid = 1400, Hwnd=0x103d6, Text = 发行者:, ClassName = Static.
Pid = 1400, Hwnd=0x103da, Text = 类型:, ClassName = Static.
Pid = 1400, Hwnd=0x103dc, Text = 应用程序, 358KB, ClassName = Static.
Pid = 1400, Hwnd=0x103de, Text = 从:, ClassName = Static.
Pid = 1400, Hwnd=0x103e0, Text = 123.51pc114.cn, ClassName = Static.
Pid = 1400, Hwnd=0x103e2, Text = 运行(&R), ClassName = Button.
Pid = 1400, Hwnd=0x103e4, Text = 保存(&S), ClassName = Button.
Pid = 1400, Hwnd=0x103e6, Text = 取消, ClassName = Button.
Pid = 1400, Hwnd=0x103e8, Text = 打开此类文件前总是询问(&W), ClassName = Button(CheckBox).
Pid = 1400, Hwnd=0x103ee, Text = 来自 Internet 的文件可能对您有所帮助,但此文件类型可能危害您的计算机。如果您不信任其来源,请不要运行或保存该软件。<A>有何风险?</A>, ClassName = SysLink.
Pid = 1400, Hwnd=0x103cc, Text = 文件下载 - 安全警告, ClassName = #32770.
Pid = 1400, Hwnd=0x17031e, Text = 下载完毕, ClassName = Static.
行为描述: 获取TickCount值
详情信息: TickCount = 5352331, SleepMilliseconds = 50.
TickCount = 5352378, SleepMilliseconds = 50.
TickCount = 5352393, SleepMilliseconds = 50.
TickCount = 5352456, SleepMilliseconds = 50.
TickCount = 5352550, SleepMilliseconds = 50.
TickCount = 5352565, SleepMilliseconds = 50.
TickCount = 5352987, SleepMilliseconds = 50.
TickCount = 5353034, SleepMilliseconds = 50.
TickCount = 5353050, SleepMilliseconds = 50.
TickCount = 5353081, SleepMilliseconds = 50.
TickCount = 5353096, SleepMilliseconds = 50.
TickCount = 5353128, SleepMilliseconds = 50.
TickCount = 5353159, SleepMilliseconds = 50.
TickCount = 5353175, SleepMilliseconds = 50.
TickCount = 5353206, SleepMilliseconds = 50.
行为描述: 获取光标位置
详情信息: CursorPos = (71,18468), SleepMilliseconds = 60000.
CursorPos = (6364,26501), SleepMilliseconds = 60000.
CursorPos = (19199,15725), SleepMilliseconds = 60000.
CursorPos = (11508,29359), SleepMilliseconds = 60000.
CursorPos = (26992,24465), SleepMilliseconds = 60000.
CursorPos = (5735,28146), SleepMilliseconds = 60000.
CursorPos = (23311,16828), SleepMilliseconds = 60000.
CursorPos = (9991,492), SleepMilliseconds = 60000.
CursorPos = (3025,11943), SleepMilliseconds = 60000.
CursorPos = (4857,5437), SleepMilliseconds = 60000.
CursorPos = (32421,14605), SleepMilliseconds = 60000.
CursorPos = (3932,154), SleepMilliseconds = 60000.
CursorPos = (322,12383), SleepMilliseconds = 60000.
CursorPos = (17451,18717), SleepMilliseconds = 60000.
CursorPos = (19748,19896), SleepMilliseconds = 100.
行为描述: 打开事件
详情信息: HookSwitchHookEnabledEvent
\SECURITY\LSA_AUTHENTICATION_INITIALIZED
Global\SvcctrlStartEvent_A3752DX
\INSTALLATION_SECURITY_HOLD
Global\crypt32LogoffEvent
MSFT.VSA.COM.DISABLE.1400
MSFT.VSA.IEC.STATUS.6c736db0
_fCanRegisterWithShellService
CTF.ThreadMIConnectionEvent.000007B4.00000000.00000040
CTF.ThreadMarshalInterfaceEvent.000007B4.00000000.00000040
MSCTF.SendReceiveConection.Event.ELH.IC
MSCTF.SendReceive.Event.ELH.IC
CTF.ThreadMIConnectionEvent.000007B4.00000000.00000041
CTF.ThreadMarshalInterfaceEvent.000007B4.00000000.00000041
CTF.ThreadMIConnectionEvent.000007B4.00000000.00000042
行为描述: 调用Sleep函数
详情信息: [1]: MilliSeconds = 60000.
[2]: MilliSeconds = 100.
[3]: MilliSeconds = 60000.
[4]: MilliSeconds = 60000.
[5]: MilliSeconds = 100.
[6]: MilliSeconds = 60000.
[7]: MilliSeconds = 60000.
[8]: MilliSeconds = 100.
[9]: MilliSeconds = 60000.
[10]: MilliSeconds = 60000.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,SysLink]
[Window,Class] = [,Static]
[Window,Class] = [文件大小未知,Static]
[Window,Class] = [打开此类文件前总是询问(&W),Button]
[Window,Class] = [发行者:,Static]
行为描述: 打开互斥体
详情信息: RasPbFile
ShimCacheMutex
Local\_!MSFTHISTORY!_
Local\c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Local\c:!documents and settings!administrator!cookies!
Local\c:!documents and settings!administrator!local settings!history!history.ie5!
Local\WininetStartupMutex
Local\WininetConnectionMutex
Local\WininetProxyRegistryMutex
Local\!IETld!Mutex
Local\c:!documents and settings!administrator!ietldcache!
CtfmonInstMutexDefaultS-*
Activities
VirSCANVirSCAN
活动名 类型
com.phone2.stop.activity.MainActivity android.intent.action.MAIN
com.phone2.stop.activity.MainActivity android.intent.category.LAUNCHER
com.phone2.stop.activity.DeleteActivity android.intent.action.DELETE
com.phone2.stop.activity.DeleteActivity android.intent.category.DEFAULT
com.phone2.stop.activity.DefaultSmsActivity android.intent.action.SEND
com.phone2.stop.activity.DefaultSmsActivity android.intent.action.SENDTO
com.phone2.stop.activity.DefaultSmsActivity android.intent.category.DEFAULT
com.phone2.stop.activity.DefaultSmsActivity android.intent.category.BROWSABLE
危险函数
VirSCANVirSCAN
函数名称 信息
ContentResolver;->delete 删除短信、联系人
ContentResolver;->query 读取联系人、短信等数据库
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
SmsManager;->sendTextMessage 发送普通短信
java/net/URL;->openConnection 连接URL
启动方式
VirSCANVirSCAN
名称 信息
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver 网络连接改变时启动服务
com.phone.stop.receiver.BootReceiver 应用安装时启动服务
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver
com.phone.stop.receiver.BootReceiver 开机启动服务
com.phone.stop.receiver.SMSReceiver 监控短信(收到短信)启动服务
com.phone.stop.receiver.SMSReceiver
com.phone.stop.receiver.MyDeviceAdminReceiver
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.RECEIVE_WAP_PUSH 接收wap push信息
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.MODIFY_AUDIO_SETTINGS 修改声音设置
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.RECEIVE_USER_PRESENT
android.permission.READ_CONTACTS 读取联系人信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.READ_SMS 读取短信
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.WRITE_SMS 写短信
android.permission.SEND_SMS 发送短信
android.permission.VIBRATE 允许设备震动
android.permission.RECEIVE_SMS 监控接收短信
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
服务列表
VirSCANVirSCAN
名称
com.phone.stop6.service.SecondService
com.phone.stop6.service.BootService
com.phone.stop6.service.SmsService
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0xb6afcc85
META-INF/CERT.SF 0x7029f7bc
META-INF/CERT.RSA 0x8b42625b
org/apache/harmony/awt/internal/nls/messages.properties 0x5f88eb12
com/sun/mail/dsn/mailcap 0x7605dc17
javamail.smtp.provider 0x990c469d
javamail.default.address.map 0xf20496b
mailcap 0xd7759e43
mimetypes.default 0x97dd5cdb
javamail.imap.provider 0x8934555a
res/drawable-hdpi/app_logo.png 0x98a3c0bd
res/xml/devicepolicymanager_permission.xml 0x2d3dc45
resources.arsc 0xee0da336
classes.dex 0xf7102be0
javamail.default.providers 0x45ea1b21
mailcap.default 0x6f616b6
AndroidManifest.xml 0xa3795657
javamail.charset.map 0xad0dfcee
res/layout/activity_aa.xml 0x6b9d1060
javamail.smtp.address.map 0xf20496b
res/layout/activity_main.xml 0xfa5a049a
res/drawable-hdpi/ap1p_logo.png 0x593366b5
res/drawable-hdpi/icon.png 0xac8b5a00
res/drawable-hdpi/app2_logo.png 0xa346342c
dsn.mf 0x1e4e9355
javamail.pop3.provider 0xa23c9bc
运行截图
VirSCANVirSCAN
VirSCAN