VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:0%Antivirus software(0/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2016-07-10 10:40:44 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 6
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 2
avast 150725-1 4.7.4 2015-07-25 Found nothing 60
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 60
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 5
baidusd 1.0 1.0 2014-04-02 Found nothing 2
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 60
clamav 19861 0.97.5 2014-12-31 Found nothing 60
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 60
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 60
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 60
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 60
gdata 25.7303 25.7303 2016-07-10 Found nothing 14
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 60
jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 49
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 60
kingsoft 2.1 2.1 2013-09-22 Found nothing 4
mcafee 7638 5400.1158 2014-11-30 Found nothing 60
nod32 0920 3.0.21 2014-12-23 Found nothing 60
panda 9.05.01 9.05.01 2015-07-26 Found nothing 4
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 60
qh360 1.0.1 1.0.1 1.0.1 Found nothing 2
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 60
quickheal 14.00 14.00 2015-07-25 Found nothing 3
rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 8
sophos 5.08 3.55.0 2014-12-01 Found nothing 60
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 60
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 11
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 4
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 17
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 60
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 60
权限列表
许可名称 信息
android.permission.READ_EXTERNAL_STORAGE 读外部存储器(如:SD卡)
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.WRITE_MEDIA_STORAGE
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.ACCESS_SUPERUSER
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:f10b0de3c323e2cf10ffd486fcd48833
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:ru.zdevs.zarchiver.pro
最低运行环境:Android 4.0, 4.0.1, 4.0.2
版权:Ant-ON
关键行为
VirSCANVirSCAN
行为描述: 设置特殊文件属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\SkinH_EL.dll
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 获取QQ临时密码
详情信息: HttpOpenRequestA: ui.ptlogin2.qq.com:80/cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://www.qq.com, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400000
HttpOpenRequestA: ui.ptlogin2.qq.com:80/cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://www.qq.com, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400010
HttpOpenRequestA: ui.ptlogin2.qq.com:80/cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://i.gtimg.cn/club/item/face/img/0/16240_100.png, hConnect = 0x00cc0018, hRequest = 0x00cc001c, Verb: GET, Referer: , Flags = 0x00400000
行为描述: 获取TickCount值
详情信息: TickCount = 5369675, SleepMilliseconds = 50.
TickCount = 5369753, SleepMilliseconds = 50.
TickCount = 5369768, SleepMilliseconds = 50.
TickCount = 5369784, SleepMilliseconds = 50.
TickCount = 5369831, SleepMilliseconds = 50.
TickCount = 5369862, SleepMilliseconds = 50.
TickCount = 5369878, SleepMilliseconds = 50.
TickCount = 5369893, SleepMilliseconds = 50.
TickCount = 5369925, SleepMilliseconds = 50.
TickCount = 5369940, SleepMilliseconds = 50.
TickCount = 5369971, SleepMilliseconds = 50.
TickCount = 5369987, SleepMilliseconds = 50.
TickCount = 5370003, SleepMilliseconds = 50.
TickCount = 5370018, SleepMilliseconds = 50.
TickCount = 5370034, SleepMilliseconds = 50.
进程行为
VirSCANVirSCAN
行为描述: 设置特殊文件属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\SkinH_EL.dll
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 获取QQ临时密码
详情信息: HttpOpenRequestA: ui.ptlogin2.qq.com:80/cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://www.qq.com, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400000
HttpOpenRequestA: ui.ptlogin2.qq.com:80/cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://www.qq.com, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400010
HttpOpenRequestA: ui.ptlogin2.qq.com:80/cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://i.gtimg.cn/club/item/face/img/0/16240_100.png, hConnect = 0x00cc0018, hRequest = 0x00cc001c, Verb: GET, Referer: , Flags = 0x00400000
行为描述: 获取TickCount值
详情信息: TickCount = 5369675, SleepMilliseconds = 50.
TickCount = 5369753, SleepMilliseconds = 50.
TickCount = 5369768, SleepMilliseconds = 50.
TickCount = 5369784, SleepMilliseconds = 50.
TickCount = 5369831, SleepMilliseconds = 50.
TickCount = 5369862, SleepMilliseconds = 50.
TickCount = 5369878, SleepMilliseconds = 50.
TickCount = 5369893, SleepMilliseconds = 50.
TickCount = 5369925, SleepMilliseconds = 50.
TickCount = 5369940, SleepMilliseconds = 50.
TickCount = 5369971, SleepMilliseconds = 50.
TickCount = 5369987, SleepMilliseconds = 50.
TickCount = 5370003, SleepMilliseconds = 50.
TickCount = 5370018, SleepMilliseconds = 50.
TickCount = 5370034, SleepMilliseconds = 50.
文件行为
VirSCANVirSCAN
行为描述: 创建文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\krnln.fnr
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\HtmlView.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\script.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\internet.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\iext.fnr
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eAPI.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\downlib.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\xplib.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eCompress.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\shell.fne
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\wpad[1].dat
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\login[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\gg[1].html
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\navcancl[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\navcancl[1]
行为描述: 创建可执行文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\krnln.fnr
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\HtmlView.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\script.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\internet.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\iext.fnr
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eAPI.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\downlib.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\xplib.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eCompress.fne
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\shell.fne
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\SkinH_EL.dll
行为描述: 覆盖已有文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\navcancl[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\navcancl[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\ErrorPageTemplate[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\background_gradient[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\info_48[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\bullet[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\background_gradient[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\info_48[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[2]
行为描述: 查找文件
详情信息: FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\Local Settings
FileName = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
FileName = C:\WINDOWS\system32\Ras\*.pbk
FileName = C:\Documents and Settings\Administrator\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
FileName = C:\WINDOWS
FileName = C:\WINDOWS\system32
FileName = C:\WINDOWS\system32\urlmon.dll
FileName = C:\WINDOWS\system32\ieframe.dll
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\SkinH_EL.dll
行为描述: 设置特殊文件属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\SkinH_EL.dll
行为描述: 删除文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\wpad[1].dat
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\login[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\gg[1].html
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\navcancl[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\navcancl[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\ErrorPageTemplate[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\background_gradient[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\info_48[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\bullet[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\background_gradient[1]
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 修改文件内容
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\krnln.fnr ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\HtmlView.fne ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\script.fne ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\internet.fne ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\iext.fnr ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eAPI.fne ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\downlib.fne ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\xplib.fne ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eCompress.fne ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\shell.fne ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\navcancl[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\navcancl[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6P4O8QNJ\ErrorPageTemplate[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1] ---> Offset = 0
网络行为
VirSCANVirSCAN
行为描述: 联网打开网址
详情信息: InternetOpenUrlA: http://**.133.40.**:128/wpad.dat, hInternet = 0x00cc0010, Flags = 0x00000010
行为描述: 连接指定站点
详情信息: InternetConnectA: ServerName = ui****om, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
InternetConnectA: ServerName = **.133.40.**, PORT = 128, UserName = , Password = , hSession = 0x00cc0010, hConnect = 0x00cc0014, Flags = 0x00000010
InternetConnectA: ServerName = xl****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
InternetConnectA: ServerName = xl****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0010, Flags = 0x00000000
InternetConnectA: ServerName = xl****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0018, hConnect = 0x00cc001c, Flags = 0x00000000
InternetConnectA: ServerName = ui****om, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0018, Flags = 0x00000000
行为描述: 打开HTTP连接
详情信息: InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489), hSession = 0x00cc0004
InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 8.0; Win32; Trident/4.0), hSession = 0x00cc0010
InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0), hSession = 0x00cc0018
行为描述: 建立到一个指定的套接字连接
详情信息: URL: wpad, IP: **.133.40.**:128, SOCKET = 0x00000430
URL: ui****om, IP: **.133.40.**:80, SOCKET = 0x00000424
URL: xl****cn, IP: **.133.40.**:80, SOCKET = 0x000003e0
URL: xl****cn, IP: **.133.40.**:80, SOCKET = 0x00000308
URL: ui****om, IP: **.133.40.**:80, SOCKET = 0x000002fc
URL: xl****cn, IP: **.133.40.**:80, SOCKET = 0x00000330
URL: ui****om, IP: **.133.40.**:80, SOCKET = 0x000002d0
行为描述: 读取网络文件
详情信息: hFile = 0x00cc0018, BytesToRead =4010, BytesRead = 4010.
hFile = 0x00cc000c, BytesToRead =4096, BytesRead = 4096.
hFile = 0x00cc0014, BytesToRead =2048, BytesRead = 2048.
hFile = 0x00cc0020, BytesToRead =512, BytesRead = 512.
hFile = 0x00cc001c, BytesToRead =2048, BytesRead = 2048.
行为描述: 发送HTTP包
详情信息: GET /wpad.dat HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32; Trident/4.0) Host: **.133.40.**:128
GET /cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://www.qq.com HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: ui****om Connection: Keep-Alive
GET /gg.html HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: xl****cn Connection: Keep-Alive
POST /senoe.asp?AC=0A HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0) Host: xl****cn Content-Length: 0 Cache-Control: no-cache
GET /cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://i.gtimg.cn/club/item/face/img/0/16240_100.png HTTP/1.1 Accept: application/x-shockwave-flash, image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml+xml, application/msword, */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: ui****om Connection: Keep-Alive
行为描述: 打开HTTP请求
详情信息: HttpOpenRequestA: **.133.40.**:128/wpad.dat, hConnect = 0x00cc0014, hRequest = 0x00cc0018, Verb: GET, Referer: , Flags = 0x00000010
HttpOpenRequestA: xl****cn:80/gg.html, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400000
HttpOpenRequestA: xl****cn:80/gg.html, hConnect = 0x00cc0010, hRequest = 0x00cc0014, Verb: GET, Referer: , Flags = 0x00400010
HttpOpenRequestA: xl****cn:80/senoe.asp?ac=0a, hConnect = 0x00cc001c, hRequest = 0x00cc0020, Verb: POST, Referer: , Flags = 0x80000000
行为描述: 按名称获取主机地址
详情信息: GetAddrInfoW: computer
GetAddrInfoW: wpad
GetAddrInfoW: ui****om
GetAddrInfoW: xl****cn
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
\REGISTRY\MACHINE\SOFTWARE\Microsoft\ESENT\Process\RunYxfz\DEBUG\Trace Level
\REGISTRY\USER\S-*\Software\Microsoft\Multimedia\DrawDib\vga.drv 1920x973x16(565 0)
行为描述: 删除注册表键值
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
\REGISTRY\MACHINE\SOFTWARE\Microsoft\ESENT\Process\RunYxfz\DEBUG\Trace Level
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
RasPbFile
Local\c:!documents and settings!administrator!ietldcache!
CritOpMutex
Local\!PrivacIE!SharedMemory!Mutex
MSIMGSIZECacheMutex
行为描述: 创建事件对象
详情信息: EventName = DINPUTWINMM
EventName = Global\userenv: User Profile setup event
EventName = Global\crypt32LogoffEvent
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [MS_AutodialMonitor,]
NtUserFindWindowEx: [Class,Window] = [MS_WebCheckMonitor,]
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [,]
行为描述: 获取QQ临时密码
详情信息: HttpOpenRequestA: ui.ptlogin2.qq.com:80/cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://www.qq.com, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400000
HttpOpenRequestA: ui.ptlogin2.qq.com:80/cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://www.qq.com, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400010
HttpOpenRequestA: ui.ptlogin2.qq.com:80/cgi-bin/login?hide_title_bar=0&low_login=0&qlogin_auto_login=1&no_verifyimg=1&link_target=blank&appid=636014201&target=self&s_url=http://i.gtimg.cn/club/item/face/img/0/16240_100.png, hConnect = 0x00cc0018, hRequest = 0x00cc001c, Verb: GET, Referer: , Flags = 0x00400000
行为描述: 窗口信息
详情信息: Pid = 3408, Hwnd=0xb0348, Text = 下载完毕, ClassName = Static.
Pid = 3408, Hwnd=0x203ca, Text = 获取文件信息:, ClassName = Static.
Pid = 3408, Hwnd=0x303b2, Text = update.exe (来自 xlyp.mpc.cn), ClassName = Static.
Pid = 3408, Hwnd=0x30376, Text = 文件大小未知, ClassName = Static.
Pid = 3408, Hwnd=0x2702f0, Text = 估计剩余时间:, ClassName = Static.
Pid = 3408, Hwnd=0x20382, Text = 已下载:, ClassName = Static.
Pid = 3408, Hwnd=0xd033c, Text = 下载到:, ClassName = Static.
Pid = 3408, Hwnd=0xd032c, Text = 传输速度:, ClassName = Static.
Pid = 3408, Hwnd=0xa0330, Text = 下载完成后关闭此对话框(&C), ClassName = Button(CheckBox).
Pid = 3408, Hwnd=0xb0362, Text = 打开(&O), ClassName = Button.
Pid = 3408, Hwnd=0x403bc, Text = 打开文件夹(&F), ClassName = Button.
Pid = 3408, Hwnd=0x30380, Text = 取消, ClassName = Button.
Pid = 3408, Hwnd=0x110350, Text = 已完成安装 0% - gg.html (来自 xlyp.mpc.cn), ClassName = #32770.
Pid = 3408, Hwnd=0x10478, Text = 您想运行或保存此文件吗?, ClassName = Static.
Pid = 3408, Hwnd=0x1047c, Text = 名称:, ClassName = Static.
行为描述: 获取TickCount值
详情信息: TickCount = 5369675, SleepMilliseconds = 50.
TickCount = 5369753, SleepMilliseconds = 50.
TickCount = 5369768, SleepMilliseconds = 50.
TickCount = 5369784, SleepMilliseconds = 50.
TickCount = 5369831, SleepMilliseconds = 50.
TickCount = 5369862, SleepMilliseconds = 50.
TickCount = 5369878, SleepMilliseconds = 50.
TickCount = 5369893, SleepMilliseconds = 50.
TickCount = 5369925, SleepMilliseconds = 50.
TickCount = 5369940, SleepMilliseconds = 50.
TickCount = 5369971, SleepMilliseconds = 50.
TickCount = 5369987, SleepMilliseconds = 50.
TickCount = 5370003, SleepMilliseconds = 50.
TickCount = 5370018, SleepMilliseconds = 50.
TickCount = 5370034, SleepMilliseconds = 50.
行为描述: 调整进程token权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
行为描述: 打开事件
详情信息: HookSwitchHookEnabledEvent
MSFT.VSA.COM.DISABLE.3408
MSFT.VSA.IEC.STATUS.6c736db0
\SECURITY\LSA_AUTHENTICATION_INITIALIZED
Global\SvcctrlStartEvent_A3752DX
\INSTALLATION_SECURITY_HOLD
Global\crypt32LogoffEvent
_fCanRegisterWithShellService
CTF.ThreadMIConnectionEvent.000007B4.00000000.00000040
CTF.ThreadMarshalInterfaceEvent.000007B4.00000000.00000040
MSCTF.SendReceiveConection.Event.ELH.IC
MSCTF.SendReceive.Event.ELH.IC
CTF.ThreadMIConnectionEvent.000007B4.00000000.00000041
CTF.ThreadMarshalInterfaceEvent.000007B4.00000000.00000041
CTF.ThreadMIConnectionEvent.000007B4.00000000.00000042
行为描述: 可执行文件签名信息
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\krnln.fnr(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\HtmlView.fne(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\script.fne(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\internet.fne(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\iext.fnr(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eAPI.fne(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\downlib.fne(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\xplib.fne(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eCompress.fne(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\shell.fne(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\SkinH_EL.dll(签名验证: 未通过)
行为描述: 调用Sleep函数
详情信息: [1]: MilliSeconds = 60000.
[2]: MilliSeconds = 100.
[3]: MilliSeconds = 60000.
[4]: MilliSeconds = 100.
[5]: MilliSeconds = 60000.
[6]: MilliSeconds = 60000.
[7]: MilliSeconds = 60000.
[8]: MilliSeconds = 100.
[9]: MilliSeconds = 60000.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,SysLink]
[Window,Class] = [,Static]
[Window,Class] = [,_EL_PicBox]
[Window,Class] = [,Afx:ff0000:b:10011:1900010:0]
[Window,Class] = [充值,Button]
[Window,Class] = [启动,Button]
[Window,Class] = [离线使用,Button]
[Window,Class] = [连接服务器可能出问题了,请点击离线使用,_EL_Label]
[Window,Class] = [文件大小未知,Static]
[Window,Class] = [打开此类文件前总是询问(&W),Button]
[Window,Class] = [发行者:,Static]
行为描述: 可执行文件MD5
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\krnln.fnr ---> bd01aea6d5bb2e93937531f8b47ec871
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\HtmlView.fne ---> f9a994df4d407bc79f7c84886fe7a654
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\script.fne ---> f8a655e81afbd29bffb1529eb81c0bce
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\internet.fne ---> 7b129c5916896c845752f93b9635fc4c
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\iext.fnr ---> 856495a1605bfc7f62086d482b502c6f
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eAPI.fne ---> 7c1ff88991f5eafab82b1beaefc33a42
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\downlib.fne ---> 015dd2805b00fdc6326b1fc126bb9345
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\xplib.fne ---> 8f385e7c8cf1f8ebdae0448473977cc7
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\eCompress.fne ---> a593d30e9a7ce91ae4c6e896ba2e7631
C:\Documents and Settings\Administrator\Local Settings\Temp\E_N40005\shell.fne ---> 98174c8c2995000efbda01e1b86a1d4d
C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\SkinH_EL.dll ---> 147127382e001f495d1842ee7a9e7912
行为描述: 打开互斥体
详情信息: ShimCacheMutex
Local\!IETld!Mutex
Local\WininetStartupMutex
Local\_!MSFTHISTORY!_
Local\c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Local\c:!documents and settings!administrator!cookies!
Local\c:!documents and settings!administrator!local settings!history!history.ie5!
Local\WininetConnectionMutex
Local\WininetProxyRegistryMutex
RasPbFile
Local\c:!documents and settings!administrator!ietldcache!
CtfmonInstMutexDefaultS-*
行为描述: 加载新释放的文件
详情信息: Image: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\krnln.fnr.
Image: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\script.fne.
Image: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\HtmlView.fne.
Image: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\iext.fnr.
Image: C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe_7zdump\SkinH_EL.dll.
Activities
VirSCANVirSCAN
活动名 类型
ru.zdevs.zarchiver.pro.ZArchiver android.intent.action.MAIN
ru.zdevs.zarchiver.pro.ZArchiver android.intent.action.VIEW
ru.zdevs.zarchiver.pro.ZArchiver ru.zdevs.zarchiver.pro.action.EXTERNAL
ru.zdevs.zarchiver.pro.ZArchiver android.intent.category.LAUNCHER
ru.zdevs.zarchiver.pro.ZArchiver android.intent.category.DEFAULT
ru.zdevs.zarchiver.pro.ZArchiver android.intent.category.BROWSABLE
ru.zdevs.zarchiver.pro.ZArchiver ru.zdevs.zarchiver.pro.category.OPEN
ru.zdevs.zarchiver.pro.ZSelectFile android.intent.action.GET_CONTENT
ru.zdevs.zarchiver.pro.ZSelectFile android.intent.category.DEFAULT
ru.zdevs.zarchiver.pro.ZSelectFile android.intent.category.OPENABLE
ru.zdevs.zarchiver.pro.ZArchiverExt ru.zdevs.zarchiver.pro.action.EXTERNAL
ru.zdevs.zarchiver.pro.ZArchiverExt android.intent.category.DEFAULT
ru.zdevs.zarchiver.pro.ZArchiverExt ru.zdevs.zarchiver.pro.category.EXTRACT
ru.zdevs.zarchiver.pro.ZArchiverExt ru.zdevs.zarchiver.pro.category.COMPRESS
危险函数
VirSCANVirSCAN
函数名称 信息
ContentResolver;->query 读取联系人、短信等数据库
ContentResolver;->delete 删除短信、联系人
android/app/NotificationManager;->notify 信息通知栏
getRuntime 获取命令行环境
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.READ_EXTERNAL_STORAGE 读外部存储器(如:SD卡)
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.WRITE_MEDIA_STORAGE
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.ACCESS_SUPERUSER
服务列表
VirSCANVirSCAN
名称
ru.zdevs.zarchiver.pro.service.ZArchiverService
文件列表
VirSCANVirSCAN
文件名 校验码
res/anim/floating_action_button_elevation.xml 0xdf42ae2c
res/drawable/dark_shape.xml 0x5fb8142e
res/drawable/floating_button.xml 0xc574aa32
res/drawable/floating_button_compose.xml 0x770acf9c
res/drawable/floating_button_pressed.xml 0x4b361b0c
res/drawable/fs_acrobat.png 0x23b4ff77
res/drawable/fs_apk.png 0xfdb76197
res/drawable/fs_archive.png 0x57abf5ed
res/drawable/fs_audio.png 0x163e6f4c
res/drawable/fs_ebook.png 0xb0d08358
res/drawable/fs_encrypt.png 0x49e5c9a6
res/drawable/fs_excel.png 0x2ffbcf78
res/drawable/fs_folder.png 0x951ddb7
res/drawable/fs_picture.png 0x51be7a6c
res/drawable/fs_powerpoint.png 0xab695281
res/drawable/fs_text.png 0xa1214444
res/drawable/fs_unknown.png 0xffd219ac
res/drawable/fs_up.png 0xb820019d
res/drawable/fs_video.png 0xec386fe3
res/drawable/fs_web.png 0x97537fb9
res/drawable/fs_word.png 0xc718dc19
res/drawable/fs_xml.png 0x829ff0b3
res/drawable/fsm_acrobat.png 0xd751ff57
res/drawable/fsm_apk.png 0x2e63333e
res/drawable/fsm_archive.png 0x40752dac
res/drawable/fsm_archive_7z.png 0xf09858a8
res/drawable/fsm_archive_rar.png 0x5333fdca
res/drawable/fsm_archive_zip.png 0x65d99cb6
res/drawable/fsm_audio.png 0x4f6b86cb
res/drawable/fsm_cd_image.png 0xea94d055
res/drawable/fsm_ebook.png 0xd1d825e4
res/drawable/fsm_encrypt.png 0xf3039c79
res/drawable/fsm_excel.png 0x42d62262
res/drawable/fsm_folder.png 0x6492003e
res/drawable/fsm_picture.png 0x60f47485
res/drawable/fsm_powerpoint.png 0xf14a76e4
res/drawable/fsm_text.png 0x2e2d46b5
res/drawable/fsm_unknown.png 0xf300ae4b
res/drawable/fsm_up.png 0xff2574c1
res/drawable/fsm_video.png 0x92b60e20
res/drawable/fsm_web.png 0x565d099d
res/drawable/fsm_word.png 0x86189978
res/drawable/fsm_xml.png 0x34de79f0
res/drawable/ic_alarm.png 0x5baf84e
res/drawable/ic_android.png 0xee18a0ee
res/drawable/ic_app.png 0x3edb96a4
res/drawable/ic_archive.png 0xc6a53150
res/drawable/ic_audio.png 0x82a3e1e7
res/drawable/ic_bin.png 0x7ca4fec3
res/drawable/ic_bluetooth.png 0xbe23411a
res/drawable/ic_book.png 0xcb93dc76
res/drawable/ic_camera.png 0xffde6419
res/drawable/ic_dev.png 0xe8b7af5
res/drawable/ic_document.png 0x6a4604d7
res/drawable/ic_download.png 0x9a4f4d0b
res/drawable/ic_font.png 0x73db9f07
res/drawable/ic_framework.png 0xc6d5778b
res/drawable/ic_home.png 0x6e8da03f
res/drawable/ic_music.png 0x924dc7f6
res/drawable/ic_notifications.png 0x1d47f4c
res/drawable/ic_phone.png 0x17aaf07c
res/drawable/ic_picture.png 0xa55f61d5
res/drawable/ic_play_circle.png 0xc6340c9c
res/drawable/ic_podcast.png 0x776bc99d
res/drawable/ic_ringtone.png 0x7f1e7a65
res/drawable/ic_root.png 0x237e4125
res/drawable/ic_sd.png 0x3133103d
res/drawable/ic_settings.png 0x23903e4e
res/drawable/ic_stat_notify.png 0x3dc9fd66
res/drawable/ic_storage.png 0xd932309b
res/drawable/ic_trash.png 0x1daf7324
res/drawable/ic_usb.png 0xfd1dbfba
res/drawable/ic_video.png 0xe7717999
res/layout/ctm_navigate.xml 0xd354d7da
res/layout/dialog_select_file.xml 0x4d0393d
res/layout/dialog_slider.xml 0x39ed0309
res/layout/dialog_title_icons.xml 0xf0825059
res/layout/dlg_about.xml 0xeb2bfc6b
res/layout/dlg_add_pwd.xml 0xc17490a3
res/layout/dlg_add_to_favotite.xml 0x2ea5c717
res/layout/dlg_ask_overwrite.xml 0x4c3e7358
res/layout/dlg_compress.xml 0x20deb104
res/layout/dlg_donate.xml 0x6978db22
res/layout/dlg_enter_pwd.xml 0x2b28de90
res/layout/dlg_enter_text.xml 0x8aca0a14
res/layout/dlg_fix_sd.xml 0x151863da
res/layout/dlg_info.xml 0x261bed0e
res/layout/dlg_main_grid.xml 0xcf3ab9b0
res/layout/dlg_main_list.xml 0xee8c11f2
res/layout/dlg_menu.xml 0x3c6b862a
res/layout/dlg_multi_text.xml 0xcf145073
res/layout/dlg_options_main.xml 0x67ebea49
res/layout/dlg_permissions.xml 0x54cc104a
res/layout/dlg_progress.xml 0xd3cc4568
res/layout/dlg_root_wrn.xml 0x145fb3f9
res/layout/dlg_select_file.xml 0x47ea6c53
res/layout/dlg_settings.xml 0x8e4bd3de
res/layout/dlg_split_size.xml 0x17e6f8cc
res/layout/ext_bg.xml 0xf5e46a1a
res/layout/item_color_select.xml 0x5fd67f10
res/layout/item_favorite.xml 0xedcf64c0
res/layout/item_find.xml 0x9dc718bb
res/layout/item_fm.xml 0x87976ee3
res/layout/item_fm_grid.xml 0x718026ec
res/layout/item_fm_single_line.xml 0x87a2c94
res/layout/item_icon.xml 0x2749c419
res/layout/item_menu.xml 0xca8e7831
res/layout/item_spinner.xml 0xba1c28ee
res/menu/menu_about.xml 0xead8b9dc
res/menu/menu_fake.xml 0xce8f82ea
res/menu/menu_main.xml 0x65615965
res/menu/toolbar_action.xml 0xa62aa456
res/menu/toolbar_action_select.xml 0x63eabd9c
res/menu/toolbar_default.xml 0x1f8fffbe
res/xml/pref_compression.xml 0x338d5dbf
res/xml/pref_fm.xml 0x777f6e99
res/xml/pref_general.xml 0x52b76ef6
res/xml/pref_gui.xml 0x8dc563de
res/xml/pref_header.xml 0x95ab200f
res/xml/pref_root.xml 0x33d8c329
res/xml/time_zones_by_country.xml 0x1e08e0b2
AndroidManifest.xml 0xce5337bb
resources.arsc 0xb3c96ec9
res/drawable-v21/floating_button.xml 0x76d58bc9
res/drawable-v21/floating_button_pressed.xml 0x27897cfa
res/xml-v21/pref_gui.xml 0xa8948a53
res/drawable-hdpi/action_settings.png 0xf5d1f919
res/drawable-hdpi/content_new_email.png 0xd6ee3c0d
res/drawable-hdpi/content_select_all_dark.png 0x635dbf3e
res/drawable-hdpi/content_select_all_light.png 0x9e8d8bcd
res/drawable-hdpi/content_select_clear_dark.png 0x235f7fb6
res/drawable-hdpi/content_select_clear_light.png 0x10a987c7
res/drawable-hdpi/content_select_invert_dark.png 0x596ae841
res/drawable-hdpi/content_select_invert_light.png 0xbda9b2d0
res/drawable-hdpi/folder_archive.png 0xd4b8506b
res/drawable-hdpi/folder_default.png 0xea48c1a9
res/drawable-hdpi/folder_document.png 0xbde88988
res/drawable-hdpi/folder_download.png 0x771c24df
res/drawable-hdpi/folder_games.png 0xbe617bff
res/drawable-hdpi/folder_home.png 0x9cb69794
res/drawable-hdpi/folder_music.png 0x4014fc54
res/drawable-hdpi/folder_picture.png 0xde9f30ff
res/drawable-hdpi/folder_root.png 0x197c3dd6
res/drawable-hdpi/folder_sd.png 0xb791ef5f
res/drawable-hdpi/folder_usb.png 0xbc6d530a
res/drawable-hdpi/folder_video.png 0x5fdd32aa
res/drawable-hdpi/folderm_default.png 0xb33e28f0
res/drawable-hdpi/folderm_document.png 0x4a35594e
res/drawable-hdpi/folderm_download.png 0x43615d11
res/drawable-hdpi/folderm_games.png 0xc171887f
res/drawable-hdpi/folderm_home.png 0xa74fb236
res/drawable-hdpi/folderm_internal.png 0xfcb68fe1
res/drawable-hdpi/folderm_music.png 0x9405d4fb
res/drawable-hdpi/folderm_picture.png 0xaaa4a069
res/drawable-hdpi/folderm_root.png 0x17158574
res/drawable-hdpi/folderm_sd.png 0x29f2a13c
res/drawable-hdpi/folderm_usb.png 0x211821cb
res/drawable-hdpi/folderm_video.png 0xc57e0019
res/drawable-hdpi/ic_down.png 0xb6b51961
res/drawable-hdpi/ic_launcher.png 0x8455f02d
res/drawable-hdpi/ic_menu_add.png 0x2ede9955
res/drawable-hdpi/ic_menu_add_file.png 0x1948cfe6
res/drawable-hdpi/ic_menu_close_clear_cancel.png 0x670c8a41
res/drawable-hdpi/ic_menu_coment.png 0x4d118ebe
res/drawable-hdpi/ic_menu_copy.png 0xb770b3e8
res/drawable-hdpi/ic_menu_cut.png 0xd1cd8431
res/drawable-hdpi/ic_menu_delete.png 0x496751ef
res/drawable-hdpi/ic_menu_edit.png 0x8108828e
res/drawable-hdpi/ic_menu_goto.png 0x175fff73
res/drawable-hdpi/ic_menu_help.png 0x4806f11d
res/drawable-hdpi/ic_menu_info_details.png 0xf9a844dd
res/drawable-hdpi/ic_menu_load.png 0xa7298455
res/drawable-hdpi/ic_menu_login.png 0x18b82ec0
res/drawable-hdpi/ic_menu_mark.png 0x4a26c9fc
res/drawable-hdpi/ic_menu_paste.png 0x85ee2ea2
res/drawable-hdpi/ic_menu_preferences.png 0xe4c47aea
res/drawable-hdpi/ic_menu_search.png 0x9d8f9a3c
res/drawable-hdpi/ic_menu_send.png 0xde2315da
res/drawable-hdpi/ic_menu_set_as.png 0x189f49d7
res/drawable-hdpi/ic_menu_sort.png 0x43f7b399
res/drawable-hdpi/ic_menu_star.png 0x483ee55a
res/drawable-hdpi/ic_menu_upload.png 0xbc766c92
res/drawable-hdpi/ic_menu_view.png 0x3b041011
res/drawable-hdpi/ic_permission.png 0xccf8ad8e
res/drawable-hdpi/ic_stat_notify.png 0xa645fdaf
res/drawable-hdpi/l_add.png 0x408e787f
res/drawable-hdpi/l_add_blk.png 0x9c23b507
res/drawable-hdpi/l_add_circles.png 0x223ddb10
res/drawable-hdpi/l_add_circles_blk.png 0x8ab99d55
res/drawable-hdpi/l_all.png 0x1385f07b
res/drawable-hdpi/l_all_blk.png 0xeaed1d4e
res/drawable-hdpi/l_apps.png 0x3c0d7433
res/drawable-hdpi/l_apps_blk.png 0x753774e1
res/drawable-hdpi/l_check_all.png 0xd7d54139
res/drawable-hdpi/l_check_all_blk.png 0xfc2b18cb
res/drawable-hdpi/l_check_clear.png 0xcefce9ce
res/drawable-hdpi/l_check_clear_blk.png 0xb92c4a55
res/drawable-hdpi/l_check_inv.png 0x1d566745
res/drawable-hdpi/l_check_inv_blk.png 0x2cb52973
res/drawable-hdpi/l_checkbox.png 0x1a448d46
res/drawable-hdpi/l_checkbox_blk.png 0x7438c3eb
res/drawable-hdpi/l_close.png 0x7c15b985
res/drawable-hdpi/l_close_blk.png 0xb3c1f098
res/drawable-hdpi/l_copy.png 0x2643f7c9
res/drawable-hdpi/l_copy_blk.png 0xf4dc2e0b
res/drawable-hdpi/l_create.png 0xe54080f9
res/drawable-hdpi/l_create_blk.png 0xfcef611b
res/drawable-hdpi/l_cut.png 0x647977c5
res/drawable-hdpi/l_cut_blk.png 0x1a9ed981
res/drawable-hdpi/l_delete.png 0xb1eb4318
res/drawable-hdpi/l_delete_blk.png 0xe4cdd55
res/drawable-hdpi/l_done.png 0xe4d12fc8
res/drawable-hdpi/l_done_blk.png 0x47f9a87f
res/drawable-hdpi/l_down.png 0xa5edcef
res/drawable-hdpi/l_down_blk.png 0xc1cf4262
res/drawable-hdpi/l_download.png 0x4acd86f
res/drawable-hdpi/l_download_blk.png 0x273e954d
res/drawable-hdpi/l_exit.png 0x35bf7b2a
res/drawable-hdpi/l_exit_blk.png 0xfa2dd7ec
res/drawable-hdpi/l_help.png 0xeda32
res/drawable-hdpi/l_help_blk.png 0x33dd0548
res/drawable-hdpi/l_info.png 0x70daba23
res/drawable-hdpi/l_info_blk.png 0x9cd61e74
res/drawable-hdpi/l_launch.png 0xeafdb437
res/drawable-hdpi/l_launch_blk.png 0x7c2cd445
res/drawable-hdpi/l_mail.png 0x947fc54c
res/drawable-hdpi/l_mail_blk.png 0xfabb6c0f
res/drawable-hdpi/l_message.png 0x665558a8
res/drawable-hdpi/l_message_blk.png 0xedb8cfe9
res/drawable-hdpi/l_more.png 0x650f40da
res/drawable-hdpi/l_more_blk.png 0x8af1a891
res/drawable-hdpi/l_paste.png 0x9354d366
res/drawable-hdpi/l_paste_blk.png 0xa4214602
res/drawable-hdpi/l_permission.png 0xcc9b46b3
res/drawable-hdpi/l_permission_blk.png 0x760805e1
res/drawable-hdpi/l_search.png 0x48c0cbfb
res/drawable-hdpi/l_search_blk.png 0x4563200
res/drawable-hdpi/l_send.png 0x17f39129
res/drawable-hdpi/l_send_blk.png 0x4633f448
res/drawable-hdpi/l_settings.png 0x2cbe233e
res/drawable-hdpi/l_settings_blk.png 0x90489ca4
res/drawable-hdpi/l_share.png 0x93e528ea
res/drawable-hdpi/l_share_blk.png 0x1432cf78
res/drawable-hdpi/l_sort.png 0x891a3fdc
res/drawable-hdpi/l_sort_blk.png 0xba2be676
res/drawable-hdpi/l_star.png 0x3cef48cf
res/drawable-hdpi/l_star_blk.png 0xb9e2bfaf
res/drawable-hdpi/l_thumbup.png 0xdbcea228
res/drawable-hdpi/l_thumbup_blk.png 0x25a463ff
res/drawable-hdpi/l_to.png 0x2be93fd5
res/drawable-hdpi/l_to_blk.png 0xc9244015
res/drawable-hdpi/l_to_ro.png 0xfa02a53b
res/drawable-hdpi/l_to_ro_blk.png 0x76f4bf1c
res/drawable-hdpi/l_to_ro_float.png 0x27f8e13
res/drawable-hdpi/l_to_rw.png 0xa2655e16
res/drawable-hdpi/l_to_rw_blk.png 0xe5a81baa
res/drawable-hdpi/l_to_rw_float.png 0xeae0731b
res/drawable-hdpi/l_upload.png 0xfce8998a
res/drawable-hdpi/l_upload_blk.png 0xafe20b9d
res/drawable-hdpi/l_visibility.png 0xafa6fc59
res/drawable-hdpi/l_visibility_blk.png 0xc497d95e
res/drawable-hdpi/navigation_accept.png 0x11a5bac6
res/drawable-hdpi/rating_good.png 0xd4a8982e
res/drawable-hdpi/social_share.png 0x1d799e97
res/drawable-ldpi/ic_launcher.png 0x6e4c544b
res/drawable-mdpi/action_settings.png 0x5778b992
res/drawable-mdpi/content_new_email.png 0x88e98b8f
res/drawable-mdpi/content_select_all_dark.png 0xf1895978
res/drawable-mdpi/content_select_all_light.png 0x4bc7869b
res/drawable-mdpi/content_select_clear_dark.png 0x102c9516
res/drawable-mdpi/content_select_clear_light.png 0xb0d56f75
res/drawable-mdpi/content_select_invert_dark.png 0xe6d1e1a6
res/drawable-mdpi/content_select_invert_light.png 0xfa32a7dc
res/drawable-mdpi/folder_archive.png 0x3c3297ec
res/drawable-mdpi/folder_default.png 0xcac0d41d
res/drawable-mdpi/folder_document.png 0x3ec5803c
res/drawable-mdpi/folder_download.png 0x7ff79be8
res/drawable-mdpi/folder_games.png 0x556e0af2
res/drawable-mdpi/folder_home.png 0x162c365e
res/drawable-mdpi/folder_music.png 0xf10632f5
res/drawable-mdpi/folder_picture.png 0x393672ee
res/drawable-mdpi/folder_root.png 0x3a19b221
res/drawable-mdpi/folder_sd.png 0xd9f0416e
res/drawable-mdpi/folder_usb.png 0x1430a72f
res/drawable-mdpi/folder_video.png 0x509193a8
res/drawable-mdpi/folderm_default.png 0xc5c214da
res/drawable-mdpi/folderm_document.png 0x11e643c3
res/drawable-mdpi/folderm_download.png 0x4da7bd25
res/drawable-mdpi/folderm_games.png 0x4102c113
res/drawable-mdpi/folderm_home.png 0x423356cc
res/drawable-mdpi/folderm_internal.png 0x1b04fe65
res/drawable-mdpi/folderm_music.png 0x78b8482c
res/drawable-mdpi/folderm_picture.png 0x693db107
res/drawable-mdpi/folderm_root.png 0x2d9ba798
res/drawable-mdpi/folderm_sd.png 0xa5bf2a09
res/drawable-mdpi/folderm_usb.png 0x7bcb5672
res/drawable-mdpi/folderm_video.png 0x407f40d1
res/drawable-mdpi/ic_down.png 0x90c3e692
res/drawable-mdpi/ic_launcher.png 0xc1cd754
res/drawable-mdpi/ic_menu_add.png 0x3a919a85
res/drawable-mdpi/ic_menu_add_file.png 0x6e286983
res/drawable-mdpi/ic_menu_close_clear_cancel.png 0xb35a0f4a
res/drawable-mdpi/ic_menu_coment.png 0x78bc18c3
res/drawable-mdpi/ic_menu_copy.png 0xb7317ecb
res/drawable-mdpi/ic_menu_cut.png 0xeb909749
res/drawable-mdpi/ic_menu_delete.png 0xd359ab76
res/drawable-mdpi/ic_menu_edit.png 0x59b59298
res/drawable-mdpi/ic_menu_goto.png 0x14135fc2
res/drawable-mdpi/ic_menu_help.png 0x3113f51a
res/drawable-mdpi/ic_menu_info_details.png 0xafb15df0
res/drawable-mdpi/ic_menu_load.png 0xfdf56062
res/drawable-mdpi/ic_menu_login.png 0xf1cb22e9
res/drawable-mdpi/ic_menu_mark.png 0x16660fe7
res/drawable-mdpi/ic_menu_paste.png 0x923d94e6
res/drawable-mdpi/ic_menu_preferences.png 0x48b719f2
res/drawable-mdpi/ic_menu_search.png 0x6b857a3a
res/drawable-mdpi/ic_menu_send.png 0xa9b256f6
res/drawable-mdpi/ic_menu_set_as.png 0x8a59c22e
res/drawable-mdpi/ic_menu_sort.png 0xc2420dd9
res/drawable-mdpi/ic_menu_star.png 0x54e6382e
res/drawable-mdpi/ic_menu_upload.png 0xef7ba921
res/drawable-mdpi/ic_menu_view.png 0x9bfbb191
res/drawable-mdpi/ic_permission.png 0x433e0436
res/drawable-mdpi/ic_stat_notify.png 0xc7c7bb36
res/drawable-mdpi/l_add.png 0x5495c5b9
res/drawable-mdpi/l_add_blk.png 0x2588750f
res/drawable-mdpi/l_add_circles.png 0x1830e1d6
res/drawable-mdpi/l_add_circles_blk.png 0xadff5934
res/drawable-mdpi/l_all.png 0xeaaf7d9d
res/drawable-mdpi/l_all_blk.png 0x4d2e7884
res/drawable-mdpi/l_apps.png 0x30e49a6
res/drawable-mdpi/l_apps_blk.png 0xc5d69e82
res/drawable-mdpi/l_check_all.png 0x875afe70
res/drawable-mdpi/l_check_all_blk.png 0x8d344803
res/drawable-mdpi/l_check_clear.png 0xfeb46bf6
res/drawable-mdpi/l_check_clear_blk.png 0x79a5ff61
res/drawable-mdpi/l_check_inv.png 0x96d1979
res/drawable-mdpi/l_check_inv_blk.png 0xcb92d0f8
res/drawable-mdpi/l_checkbox.png 0x145dde8b
res/drawable-mdpi/l_checkbox_blk.png 0x577044b
res/drawable-mdpi/l_close.png 0xd669e0cd
res/drawable-mdpi/l_close_blk.png 0xe8603597
res/drawable-mdpi/l_copy.png 0xcb295371
res/drawable-mdpi/l_copy_blk.png 0x7308dd7e
res/drawable-mdpi/l_create.png 0x4439d83
res/drawable-mdpi/l_create_blk.png 0xed2d9b4e
res/drawable-mdpi/l_cut.png 0x31e3e9d6
res/drawable-mdpi/l_cut_blk.png 0x49a98bdc
res/drawable-mdpi/l_delete.png 0x6a7af186
res/drawable-mdpi/l_delete_blk.png 0xd4be427f
res/drawable-mdpi/l_done.png 0x6794d2f7
res/drawable-mdpi/l_done_blk.png 0x88e4bb0b
res/drawable-mdpi/l_down.png 0x988fb2a9
res/drawable-mdpi/l_down_blk.png 0x6079e770
res/drawable-mdpi/l_download.png 0x28bbbc67
res/drawable-mdpi/l_download_blk.png 0x30c7862
res/drawable-mdpi/l_exit.png 0xd40e5ea6
res/drawable-mdpi/l_exit_blk.png 0x1f132d48
res/drawable-mdpi/l_help.png 0x39e39ad5
res/drawable-mdpi/l_help_blk.png 0x1b05053c
res/drawable-mdpi/l_info.png 0xa70e1968
res/drawable-mdpi/l_info_blk.png 0xd5106d4c
res/drawable-mdpi/l_launch.png 0x75eddd55
res/drawable-mdpi/l_launch_blk.png 0x870e007b
res/drawable-mdpi/l_mail.png 0x7473c4be
res/drawable-mdpi/l_mail_blk.png 0xdf2c4911
res/drawable-mdpi/l_message.png 0x3b31cf6c
res/drawable-mdpi/l_message_blk.png 0x152844f0
res/drawable-mdpi/l_more.png 0x436350ff
res/drawable-mdpi/l_more_blk.png 0x5363a368
res/drawable-mdpi/l_paste.png 0x8d82aff4
res/drawable-mdpi/l_paste_blk.png 0xe8c51e66
res/drawable-mdpi/l_permission.png 0xf30faa39
res/drawable-mdpi/l_permission_blk.png 0xc61f6e6b
res/drawable-mdpi/l_search.png 0x40a23d3d
res/drawable-mdpi/l_search_blk.png 0x5faa0c5
res/drawable-mdpi/l_send.png 0xa6866cae
res/drawable-mdpi/l_send_blk.png 0x925214e6
res/drawable-mdpi/l_settings.png 0x80428fc3
res/drawable-mdpi/l_settings_blk.png 0x3ff537a1
res/drawable-mdpi/l_share.png 0xcb5fc9ce
res/drawable-mdpi/l_share_blk.png 0xca765489
res/drawable-mdpi/l_sort.png 0x2ffa3cd
res/drawable-mdpi/l_sort_blk.png 0xe74c9aa
res/drawable-mdpi/l_star.png 0x6db97f39
res/drawable-mdpi/l_star_blk.png 0x88ba0988
res/drawable-mdpi/l_thumbup.png 0x516267f7
res/drawable-mdpi/l_thumbup_blk.png 0xe90c288a
res/drawable-mdpi/l_to.png 0x833fd33e
res/drawable-mdpi/l_to_blk.png 0xc8b8aa48
res/drawable-mdpi/l_to_ro.png 0xd122d1d0
res/drawable-mdpi/l_to_ro_blk.png 0xb8815fbb
res/drawable-mdpi/l_to_ro_float.png 0xcc66f375
res/drawable-mdpi/l_to_rw.png 0x37815840
res/drawable-mdpi/l_to_rw_blk.png 0xfa1de1d4
res/drawable-mdpi/l_to_rw_float.png 0x8d28f1ee
res/drawable-mdpi/l_upload.png 0xbcd03d39
res/drawable-mdpi/l_upload_blk.png 0x90db90c1
res/drawable-mdpi/l_visibility.png 0xe1a73baf
res/drawable-mdpi/l_visibility_blk.png 0x1195c7d1
res/drawable-mdpi/navigation_accept.png 0xe006bfe6
res/drawable-mdpi/rating_good.png 0xbf14e062
res/drawable-mdpi/social_share.png 0x39d4ad82
res/drawable-xhdpi/action_settings.png 0x2d57959
res/drawable-xhdpi/content_new_email.png 0xe946abad
res/drawable-xhdpi/content_select_all_dark.png 0xacd842c1
res/drawable-xhdpi/content_select_all_light.png 0xb24866b9
res/drawable-xhdpi/content_select_clear_dark.png 0xaa41017d
res/drawable-xhdpi/content_select_clear_light.png 0x848d5ba9
res/drawable-xhdpi/content_select_invert_dark.png 0x5ad78792
res/drawable-xhdpi/content_select_invert_light.png 0x325c82c7
res/drawable-xhdpi/folder_archive.png 0x793f4e62
res/drawable-xhdpi/folder_default.png 0x59949125
res/drawable-xhdpi/folder_document.png 0xfb739251
res/drawable-xhdpi/folder_download.png 0xfac58b4e
res/drawable-xhdpi/folder_games.png 0x55ae10dc
res/drawable-xhdpi/folder_home.png 0xf638b665
res/drawable-xhdpi/folder_music.png 0x275c037d
res/drawable-xhdpi/folder_picture.png 0xf1b1b72f
res/drawable-xhdpi/folder_root.png 0x26d7bec3
res/drawable-xhdpi/folder_sd.png 0x37f341e9
res/drawable-xhdpi/folder_usb.png 0x477a20db
res/drawable-xhdpi/folder_video.png 0x48bdfacb
res/drawable-xhdpi/folderm_default.png 0xd422b15e
res/drawable-xhdpi/folderm_document.png 0x624cd20e
res/drawable-xhdpi/folderm_download.png 0x87edcca
res/drawable-xhdpi/folderm_games.png 0x2d48399f
res/drawable-xhdpi/folderm_home.png 0x23cda537
res/drawable-xhdpi/folderm_internal.png 0xa9aa95b5
res/drawable-xhdpi/folderm_music.png 0xc23052b2
res/drawable-xhdpi/folderm_picture.png 0x47220a00
res/drawable-xhdpi/folderm_root.png 0x9dea7a33
res/drawable-xhdpi/folderm_sd.png 0x3fd9e33d
res/drawable-xhdpi/folderm_usb.png 0x9f4ffb42
res/drawable-xhdpi/folderm_video.png 0x21a08510
res/drawable-xhdpi/ic_down.png 0x7181aedf
res/drawable-xhdpi/ic_launcher.png 0xd0d315c7
res/drawable-xhdpi/ic_menu_add.png 0xf596ba14
res/drawable-xhdpi/ic_menu_add_file.png 0x5d697802
res/drawable-xhdpi/ic_menu_close_clear_cancel.png 0x9c370231
res/drawable-xhdpi/ic_menu_coment.png 0x9f3fe655
res/drawable-xhdpi/ic_menu_copy.png 0x9a3ef216
res/drawable-xhdpi/ic_menu_cut.png 0x230056a7
res/drawable-xhdpi/ic_menu_delete.png 0x4265a8e4
res/drawable-xhdpi/ic_menu_edit.png 0xe67f0391
res/drawable-xhdpi/ic_menu_goto.png 0x594ba2ee
res/drawable-xhdpi/ic_menu_help.png 0x837fa01c
res/drawable-xhdpi/ic_menu_info_details.png 0x145a9848
res/drawable-xhdpi/ic_menu_load.png 0x96ff1834
res/drawable-xhdpi/ic_menu_login.png 0x4a98ae63
res/drawable-xhdpi/ic_menu_mark.png 0xd23976f0
res/drawable-xhdpi/ic_menu_paste.png 0xf3d10cd1
res/drawable-xhdpi/ic_menu_preferences.png 0x9cd8aa7
res/drawable-xhdpi/ic_menu_search.png 0x8229f1e4
res/drawable-xhdpi/ic_menu_send.png 0xf300c8b
res/drawable-xhdpi/ic_menu_set_as.png 0xa4556011
res/drawable-xhdpi/ic_menu_sort_by_size.png 0xacbe90a2
res/drawable-xhdpi/ic_menu_star.png 0xfe2273cd
res/drawable-xhdpi/ic_menu_upload.png 0xc8a16878
res/drawable-xhdpi/ic_menu_view.png 0x4f820e98
res/drawable-xhdpi/ic_permission.png 0x60b7870e
res/drawable-xhdpi/ic_stat_notify.png 0x181866c0
res/drawable-xhdpi/l_add.png 0x783a284f
res/drawable-xhdpi/l_add_blk.png 0xbd91e10a
res/drawable-xhdpi/l_add_circles.png 0x2b4f464d
res/drawable-xhdpi/l_add_circles_blk.png 0x3a4c47b5
res/drawable-xhdpi/l_all.png 0x1bb4ab64
res/drawable-xhdpi/l_all_blk.png 0xc9ca5cd3
res/drawable-xhdpi/l_apps.png 0x7442ff61
res/drawable-xhdpi/l_apps_blk.png 0xc07890f3
res/drawable-xhdpi/l_check_all.png 0xd0dd1606
res/drawable-xhdpi/l_check_all_blk.png 0x89b85175
res/drawable-xhdpi/l_check_clear.png 0xe8cfd03c
res/drawable-xhdpi/l_check_clear_blk.png 0xd6da4789
res/drawable-xhdpi/l_check_inv.png 0xbc000f5a
res/drawable-xhdpi/l_check_inv_blk.png 0x86862edd
res/drawable-xhdpi/l_checkbox.png 0x60a9e454
res/drawable-xhdpi/l_checkbox_blk.png 0x381fad6f
res/drawable-xhdpi/l_close.png 0x74bc741f
res/drawable-xhdpi/l_close_blk.png 0x66087a58
res/drawable-xhdpi/l_copy.png 0x462c937
res/drawable-xhdpi/l_copy_blk.png 0x3710a24
res/drawable-xhdpi/l_create.png 0x5de572e0
res/drawable-xhdpi/l_create_blk.png 0x4572f80c
res/drawable-xhdpi/l_cut.png 0x83de58ce
res/drawable-xhdpi/l_cut_blk.png 0xa5b5f9b2
res/drawable-xhdpi/l_delete.png 0xc7485aa7
res/drawable-xhdpi/l_delete_blk.png 0x41c9d995
res/drawable-xhdpi/l_done.png 0x31241418
res/drawable-xhdpi/l_done_blk.png 0xaf3c82d0
res/drawable-xhdpi/l_down.png 0x7b7ea90b
res/drawable-xhdpi/l_down_blk.png 0x33edfa67
res/drawable-xhdpi/l_download.png 0x14a62953
res/drawable-xhdpi/l_download_blk.png 0x8fd7fa23
res/drawable-xhdpi/l_exit.png 0x1a03ba17
res/drawable-xhdpi/l_exit_blk.png 0x2e4b34f2
res/drawable-xhdpi/l_help.png 0xe7e1c443
res/drawable-xhdpi/l_help_blk.png 0xb0dae348
res/drawable-xhdpi/l_info.png 0xd5cb46c1
res/drawable-xhdpi/l_info_blk.png 0x37d414c7
res/drawable-xhdpi/l_launch.png 0x807368a2
res/drawable-xhdpi/l_launch_blk.png 0x6fb506d0
res/drawable-xhdpi/l_mail.png 0x36295ea3
res/drawable-xhdpi/l_mail_blk.png 0x429c4049
res/drawable-xhdpi/l_message.png 0x543d6f61
res/drawable-xhdpi/l_message_blk.png 0x2a3a78ee
res/drawable-xhdpi/l_more.png 0x68c68ddb
res/drawable-xhdpi/l_more_blk.png 0xbf691306
res/drawable-xhdpi/l_paste.png 0x7e311492
res/drawable-xhdpi/l_paste_blk.png 0x7eb5cdc9
res/drawable-xhdpi/l_permission.png 0x86386bd7
res/drawable-xhdpi/l_permission_blk.png 0xd52065d8
res/drawable-xhdpi/l_search.png 0x104433d4
res/drawable-xhdpi/l_search_blk.png 0xa036c730
res/drawable-xhdpi/l_send.png 0x496c752a
res/drawable-xhdpi/l_send_blk.png 0xfd6e0b81
res/drawable-xhdpi/l_settings.png 0x624a6dbe
res/drawable-xhdpi/l_settings_blk.png 0x43d0d919
res/drawable-xhdpi/l_share.png 0x5526348b
res/drawable-xhdpi/l_share_blk.png 0x74fc38e7
res/drawable-xhdpi/l_sort.png 0xd87899aa
res/drawable-xhdpi/l_sort_blk.png 0xea08154d
res/drawable-xhdpi/l_star.png 0xdcb37b3b
res/drawable-xhdpi/l_star_blk.png 0x7eaaa028
res/drawable-xhdpi/l_thumbup.png 0x9ed392f0
res/drawable-xhdpi/l_thumbup_blk.png 0xbd10b938
res/drawable-xhdpi/l_to.png 0x4498f934
res/drawable-xhdpi/l_to_blk.png 0x79d4939d
res/drawable-xhdpi/l_to_ro.png 0x77de0ab3
res/drawable-xhdpi/l_to_ro_blk.png 0x101809b6
res/drawable-xhdpi/l_to_ro_float.png 0xa49a2b98
res/drawable-xhdpi/l_to_rw.png 0x2693aaa2
res/drawable-xhdpi/l_to_rw_blk.png 0x62cd5ae7
res/drawable-xhdpi/l_to_rw_float.png 0xe4b34b87
res/drawable-xhdpi/l_upload.png 0xfbc49740
res/drawable-xhdpi/l_upload_blk.png 0x30291e1d
res/drawable-xhdpi/l_visibility.png 0x9fd1c7a0
res/drawable-xhdpi/l_visibility_blk.png 0xe211dcda
res/drawable-xhdpi/navigation_accept.png 0x618ada9b
res/drawable-xhdpi/rating_good.png 0x4b4017b6
res/drawable-xhdpi/social_share.png 0x95409831
res/drawable-xxhdpi/ic_launcher.png 0xa0389b62
res/layout-land/dlg_compress.xml 0x6f973867
res/layout-land/dlg_info.xml 0xfe133379
res/layout-land/dlg_main_grid.xml 0xad0b858d
res/layout-land/dlg_main_list.xml 0x5027ce69
res/layout-large/dlg_main_grid.xml 0x1d16ebd0
res/layout-large/dlg_main_list.xml 0x86b749c2
res/layout-large-land/dlg_main_grid.xml 0xc7fdd759
res/layout-large-land/dlg_main_list.xml 0xb4c2abe8
classes.dex 0x16ba7a31
lib/x86/libunarc.so 0x96d78807
lib/x86/libp7zbin.so 0x1d4970b4
lib/x86/libp7zip.so 0x55efc347
lib/x86/libcontrol.so 0x1be4c4f1
lib/x86/libunrar.so 0x2e10c703
lib/x86/libhandler.so 0x6cb0a7b7
lib/x86/libcoreutils.so 0x3e5605e7
lib/armeabi/libunarc.so 0xfeff05ac
lib/armeabi/libp7zbin.so 0x74ef48f2
lib/armeabi/libp7zip.so 0x94627078
lib/armeabi/libcontrol.so 0x4fc46e67
lib/armeabi/libunrar.so 0x5bc240b0
lib/armeabi/libhandler.so 0x9febfc43
lib/armeabi/libcoreutils.so 0xf51101e2
META-INF/MANIFEST.MF 0x71415bfe
META-INF/CERT.SF 0xbd0340dd
META-INF/CERT.RSA 0xc4086641
运行截图
VirSCANVirSCAN
VirSCAN