VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:6%Antivirus software(2/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2016-05-04 10:38:50 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 5
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 150725-1 4.7.4 2015-07-25 Found nothing 20
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 6
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 7
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 1
clamav 19861 0.97.5 2014-12-31 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 47
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 4
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 30
gdata 25.6452 25.6452 2016-05-03 Android.Trojan.AutoSMS.PG 8
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 8
jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 44
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 37
kingsoft 2.1 2.1 2013-09-22 Android.Troj.hideIcon.ao.(kcloud) 5
mcafee 7638 5400.1158 2014-11-30 Found nothing 30
nod32 0920 3.0.21 2014-12-23 Found nothing 1
panda 9.05.01 9.05.01 2015-07-26 Found nothing 5
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 2
qh360 1.0.1 1.0.1 1.0.1 Found nothing 2
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 1
quickheal 14.00 14.00 2015-07-25 Found nothing 2
rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 1
sophos 5.08 3.55.0 2014-12-01 Found nothing 5
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 13
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 8
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 5
权限列表
许可名称 信息
android.permission.RECEIVE_WAP_PUSH 接收wap push信息
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.MODIFY_AUDIO_SETTINGS 修改声音设置
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.RECEIVE_USER_PRESENT
android.permission.READ_CONTACTS 读取联系人信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.READ_SMS 读取短信
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.VIBRATE 允许设备震动
android.permission.RECEIVE_SMS 监控接收短信
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.WRITE_SMS 写短信
android.permission.SEND_SMS 发送短信
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:52b46b952f757e7291fa138a4b07830a
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.qihoo360.contacts
最低运行环境:Android 2.2.x
版权:Android
关键行为
VirSCANVirSCAN
行为描述: 探测 Virtual PC是否存在
详情信息: N/A
行为描述: 获取TickCount值
详情信息: TickCount = 488018, SleepMilliseconds = 50.
TickCount = 488925, SleepMilliseconds = 50.
TickCount = 489096, SleepMilliseconds = 50.
TickCount = 489175, SleepMilliseconds = 50.
TickCount = 489190, SleepMilliseconds = 50.
TickCount = 489206, SleepMilliseconds = 50.
TickCount = 489268, SleepMilliseconds = 50.
TickCount = 489456, SleepMilliseconds = 50.
TickCount = 489971, SleepMilliseconds = 50.
TickCount = 490971, SleepMilliseconds = 50.
TickCount = 491971, SleepMilliseconds = 50.
TickCount = 492050, SleepMilliseconds = 50.
TickCount = 492128, SleepMilliseconds = 50.
TickCount = 492143, SleepMilliseconds = 50.
TickCount = 492175, SleepMilliseconds = 50.
行为描述: 查找指定内核模块
详情信息: lstrcmpiA: ntice.sys <------> ntkrnlpa.exe Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> hal.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> KDCOM.DLL Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BOOTVID.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ACPI.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> WMILIB.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> pci.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> isapnp.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> compbatt.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BATTC.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> intelide.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> PCIIDEX.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> MountMgr.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ftdisk.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> dmload.sys Des: SoftICE驱动
行为描述: 查找反病毒常用工具窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [OLLYDBG,]
NtUserFindWindowEx: [Class,Window] = [GBDYLLO,]
NtUserFindWindowEx: [Class,Window] = [pediy06,]
NtUserFindWindowEx: [Class,Window] = [FilemonClass,]
NtUserFindWindowEx: [Class,Window] = [,File Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
NtUserFindWindowEx: [Class,Window] = [,Process Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [RegmonClass,]
NtUserFindWindowEx: [Class,Window] = [,Registry Monitor - Sysinternals: www.sysinternals.com]
行为描述: 尝试打开调试器或监控软件的驱动设备对象
详情信息: \??\SICE
\??\SIWVID
\??\NTICE
进程行为
VirSCANVirSCAN
行为描述: 探测 Virtual PC是否存在
详情信息: N/A
行为描述: 获取TickCount值
详情信息: TickCount = 488018, SleepMilliseconds = 50.
TickCount = 488925, SleepMilliseconds = 50.
TickCount = 489096, SleepMilliseconds = 50.
TickCount = 489175, SleepMilliseconds = 50.
TickCount = 489190, SleepMilliseconds = 50.
TickCount = 489206, SleepMilliseconds = 50.
TickCount = 489268, SleepMilliseconds = 50.
TickCount = 489456, SleepMilliseconds = 50.
TickCount = 489971, SleepMilliseconds = 50.
TickCount = 490971, SleepMilliseconds = 50.
TickCount = 491971, SleepMilliseconds = 50.
TickCount = 492050, SleepMilliseconds = 50.
TickCount = 492128, SleepMilliseconds = 50.
TickCount = 492143, SleepMilliseconds = 50.
TickCount = 492175, SleepMilliseconds = 50.
行为描述: 查找指定内核模块
详情信息: lstrcmpiA: ntice.sys <------> ntkrnlpa.exe Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> hal.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> KDCOM.DLL Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BOOTVID.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ACPI.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> WMILIB.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> pci.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> isapnp.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> compbatt.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BATTC.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> intelide.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> PCIIDEX.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> MountMgr.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ftdisk.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> dmload.sys Des: SoftICE驱动
行为描述: 查找反病毒常用工具窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [OLLYDBG,]
NtUserFindWindowEx: [Class,Window] = [GBDYLLO,]
NtUserFindWindowEx: [Class,Window] = [pediy06,]
NtUserFindWindowEx: [Class,Window] = [FilemonClass,]
NtUserFindWindowEx: [Class,Window] = [,File Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
NtUserFindWindowEx: [Class,Window] = [,Process Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [RegmonClass,]
NtUserFindWindowEx: [Class,Window] = [,Registry Monitor - Sysinternals: www.sysinternals.com]
行为描述: 尝试打开调试器或监控软件的驱动设备对象
详情信息: \??\SICE
\??\SIWVID
\??\NTICE
网络行为
VirSCANVirSCAN
行为描述: 建立到一个指定的套接字连接
详情信息: URL: , IP: **.0.0.**:44405, SOCKET = 0x000006a4
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-*\Software\Webzen\MU\Config\WindowMode
其他行为
VirSCANVirSCAN
行为描述: 探测 Virtual PC是否存在
详情信息: N/A
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.ELH
MSCTF.Shared.MUTEX.MMC
行为描述: 创建事件对象
详情信息: EventName = DINPUTWINMM
EventName = MSCTF.SendReceive.Event.MMC.IC
EventName = MSCTF.SendReceiveConection.Event.MMC.IC
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [18467-41,]
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [MU,MU]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
行为描述: 尝试打开调试器或监控软件的驱动设备对象
详情信息: \??\SICE
\??\SIWVID
\??\NTICE
行为描述: 搜索kernel32.dll基地址
详情信息: Instruction Address = 0x004af989
行为描述: 窗口信息
详情信息: Pid = 124, Hwnd=0x202b0, Text = 1280×1024, ClassName = Button(RadioButton).
Pid = 124, Hwnd=0x302b8, Text = 屏幕分辨率:, ClassName = Afx:400000:b:10011:1900015:0.
Pid = 124, Hwnd=0x302da, Text = 1024×768, ClassName = Button(RadioButton).
Pid = 124, Hwnd=0x202c6, Text = 800×600, ClassName = Button(RadioButton).
Pid = 124, Hwnd=0x202ca, Text = 服务器开放中, ClassName = Afx:400000:b:10011:1900015:0.
Pid = 124, Hwnd=0x202d8, Text = 运行游戏, ClassName = Button.
Pid = 124, Hwnd=0x202d6, Text = 王者奇迹, ClassName = WTWindow.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,Afx:400000:8:10011:1900015:0]
行为描述: 获取TickCount值
详情信息: TickCount = 488018, SleepMilliseconds = 50.
TickCount = 488925, SleepMilliseconds = 50.
TickCount = 489096, SleepMilliseconds = 50.
TickCount = 489175, SleepMilliseconds = 50.
TickCount = 489190, SleepMilliseconds = 50.
TickCount = 489206, SleepMilliseconds = 50.
TickCount = 489268, SleepMilliseconds = 50.
TickCount = 489456, SleepMilliseconds = 50.
TickCount = 489971, SleepMilliseconds = 50.
TickCount = 490971, SleepMilliseconds = 50.
TickCount = 491971, SleepMilliseconds = 50.
TickCount = 492050, SleepMilliseconds = 50.
TickCount = 492128, SleepMilliseconds = 50.
TickCount = 492143, SleepMilliseconds = 50.
TickCount = 492175, SleepMilliseconds = 50.
行为描述: 查找指定内核模块
详情信息: lstrcmpiA: ntice.sys <------> ntkrnlpa.exe Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> hal.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> KDCOM.DLL Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BOOTVID.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ACPI.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> WMILIB.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> pci.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> isapnp.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> compbatt.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BATTC.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> intelide.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> PCIIDEX.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> MountMgr.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ftdisk.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> dmload.sys Des: SoftICE驱动
行为描述: 查找反病毒常用工具窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [OLLYDBG,]
NtUserFindWindowEx: [Class,Window] = [GBDYLLO,]
NtUserFindWindowEx: [Class,Window] = [pediy06,]
NtUserFindWindowEx: [Class,Window] = [FilemonClass,]
NtUserFindWindowEx: [Class,Window] = [,File Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
NtUserFindWindowEx: [Class,Window] = [,Process Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [RegmonClass,]
NtUserFindWindowEx: [Class,Window] = [,Registry Monitor - Sysinternals: www.sysinternals.com]
Activities
VirSCANVirSCAN
活动名 类型
com.phone2.stop.activity.MainActivity android.intent.action.MAIN
com.phone2.stop.activity.MainActivity android.intent.category.LAUNCHER
com.phone2.stop.activity.DeleteActivity android.intent.action.DELETE
com.phone2.stop.activity.DeleteActivity android.intent.category.DEFAULT
危险函数
VirSCANVirSCAN
函数名称 信息
ContentResolver;->delete 删除短信、联系人
ContentResolver;->query 读取联系人、短信等数据库
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
java/net/URL;->openConnection 连接URL
启动方式
VirSCANVirSCAN
名称 信息
com.phone.stop.receiver.BootReceiver 开机启动服务
com.phone.stop.receiver.SMSReceiver 监控短信(收到短信)启动服务
com.phone.stop.receiver.MyDeviceAdminReceiver
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.RECEIVE_WAP_PUSH 接收wap push信息
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.MODIFY_AUDIO_SETTINGS 修改声音设置
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.RECEIVE_USER_PRESENT
android.permission.READ_CONTACTS 读取联系人信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.READ_SMS 读取短信
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.VIBRATE 允许设备震动
android.permission.RECEIVE_SMS 监控接收短信
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.WRITE_SMS 写短信
android.permission.SEND_SMS 发送短信
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
服务列表
VirSCANVirSCAN
名称
com.phone.stop6.service.SecondService
com.phone.stop6.service.BootService
com.phone.stop6.service.SmsService
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0xb769b317
META-INF/CERT.SF 0x534162ea
META-INF/CERT.RSA 0x92efcbd9
javamail.smtp.provider 0x990c469d
javamail.default.address.map 0xf20496b
mailcap 0xd7759e43
mimetypes.default 0x97dd5cdb
javamail.imap.provider 0x8934555a
res/drawable-hdpi/app_logo.png 0x4f9ddbf3
res/xml/devicepolicymanager_permission.xml 0xeab2c16b
resources.arsc 0xb25342fa
classes.dex 0xedca1861
javamail.default.providers 0x45ea1b21
mailcap.default 0x6f616b6
javamail.charset.map 0xad0dfcee
AndroidManifest.xml 0x37d6183f
res/layout/activity_aa.xml 0x60332653
javamail.smtp.address.map 0xf20496b
res/layout/activity_main.xml 0x19203b2e
res/drawable-hdpi/icon.png 0xac8b5a00
dsn.mf 0x1e4e9355
javamail.pop3.provider 0xa23c9bc
运行截图
VirSCANVirSCAN
VirSCAN