VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:2%Scanner(s) (1/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-02 17:41:10 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 4
antivir 1.9.2.0 1.9.159.0 7.11.182.186 Found nothing 15
antiy 105037 AVL141031 2014-11-01 Found nothing 5
arcavir 1.0 2011 2014-05-30 Found nothing 8
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 141101-0 4.7.4 2014-11-01 Found nothing 29
avg 2109/7906 10.0.1405 2014-10-17 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 4
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.57492 7.90123 2014-11-02 Found nothing 6
clamav 19565 0.97.5 2014-10-31 Found nothing 1
comodo 15023 5.1 2014-10-31 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-10-31 Found nothing 34
fortinet 23.098, 23.098 5.1.158 2014-11-02 Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-10-31 Found nothing 1
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 2
gdata 24.4725 24.4725 2014-11-02 Found nothing 8
hauri 2.73 2.73 2014-10-31 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-11-01 Found nothing 14
jiangmin 16.0.100 1.0.0.0 2014-08-20 AdWare/AndroidOS.bpo 32
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 19
kingsoft 2.1 2.1 2013-09-22 Found nothing 3
mcafee 7520 5400.1158 2014-08-04 Found nothing 8
nod32 0436 3.0.21 2014-09-18 Found nothing 1
panda 9.05.01 9.05.01 2014-11-01 Found nothing 4
pcc 11.250.03 9.500-1005 2014-11-01 Found nothing 1
qh360 1.0.1 1.0.1 1.0.1 Found nothing 13
qqphone 1.0.0.0 1.0.0.0 2014-11-02 Found nothing 1
quickheal 14.00 14.00 2014-11-01 Found nothing 2
rising 25.38.01.01 25.38.01.01 2014-10-28 Found nothing 1
sophos 5.04 3.51.0 2014-08-05 Found nothing 7
sunbelt 3.9.2595.2 3.9.2595.2 2014-10-29 Found nothing 1
symantec 20141028.001 1.3.0.24 2014-10-28 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2014-10-31 Found nothing 2
tws 17.47.17308 1.0.2.2108 2014-11-01 Found nothing 6
vba 3.12.26.3 3.12.26.3 2014-10-31 Found nothing 3
virusbuster 15.0.955.0 5.5.2.13 2014-11-01 Found nothing 16
权限列表
许可名称 信息
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.VIBRATE 允许设备震动
文件信息
VirSCANVirSCAN
安全评分 :89
基本信息
VirSCANVirSCAN
MD5:d01126fa42e2ca1d1a3478b7ca43d8c0
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.leoly.fullnexus4
最低运行环境:Android 4.0, 4.0.1, 4.0.2
版权:
关键行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
[Window,Class] = [选项,WindowsForms10.Window.8.app.0.378734a]
行为描述: 按名称获取主机地址
详情信息: wpad.
www.cncert.net
进程行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
[Window,Class] = [选项,WindowsForms10.Window.8.app.0.378734a]
行为描述: 按名称获取主机地址
详情信息: wpad.
www.cncert.net
文件行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: \%temp%\1414907159.208062.exe_7zdump\skiller3.70\幻境网盾3.7.exe
_xvm_mem_0x7B8_0x32E57125
_xvm_mem_FA2BD2821BE32FEA179326AC5435A26C_0x32E57125
_xvm_mem_3F51CD1B726CB662BEF2CDB2DAF3422D_0x32E57125
_xvm_mem_24CD835EEB944E8EF75A28EE01FF6FF5_0x32E57125
Global\Cor_Private_IPCBlock_1976
Global\Cor_Public_IPCBlock_1976
_xvm_mem_7DEAF4A6FA52E8D23F75CF998D6CFE2B_0x32E57125
\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
Global\NLS_00000804_Exception_Table_3_2
Global\NLS_CodePage_936_3_2_0_0
_xvm_mem_D587B1CE10753E9DFF53B27A4AA656FD_0x32E57125
Global\netfxcustomperfcounters.1.0.net clr networking
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
网络行为
VirSCANVirSCAN
行为描述: 按名称获取主机地址
详情信息: wpad.
www.cncert.net
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\GDIPlus\FontCachePath
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: _xvm_mtx_file_CnCerT.Net.SKiller.exe_0x32E57125
_xvm_mtx_reg_CnCerT.Net.SKiller.exe_0x32E57125
_xvm_mtx_other_CnCerT.Net.SKiller.exe_0x32E57125
RasPbFile
Global\.net clr networking
行为描述: 内联HOOK
详情信息: C:\WINDOWS\system32\ntdll.dll--->NtClose Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->NtDuplicateObject Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->NtMakeTemporaryObject Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->NtQueryObject Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->ZwSetInformationObject Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->ZwSignalAndWaitForSingleObject Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->NtWaitForMultipleObjects Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->ZwWaitForSingleObject Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->NtQuerySecurityObject Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->NtSetSecurityObject Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->ZwCreateSection Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->ZwExtendSection Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->NtMapViewOfSection Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->NtOpenSection Offset = 0x0
C:\WINDOWS\system32\ntdll.dll--->NtQuerySection Offset = 0x0
行为描述: 样本控制台输出内容
详情信息: N/A
行为描述: 获取系统权限
详情信息: SE_INC_BASE_PRIORITY_PRIVILEGE
SE_DEBUG_PRIVILEGE
行为描述: 窗口信息
详情信息: Pid = 1976, Hwnd=0xa018c, Text = 日志, ClassName = WindowsForms10.Window.8.app.0.378734a.
Pid = 1976, Hwnd=0xc01b4, Text = MAC:FF-FF-FF-FF-FF-FF, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xb0170, Text = statusStrip1, ClassName = WindowsForms10.Window.8.app.0.378734a.
Pid = 1976, Hwnd=0xb01ce, Text = 强度, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xd01ac, Text = 网络延时探测, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xb0164, Text = +, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xb0192, Text = toolStrip1, ClassName = WindowsForms10.Window.8.app.0.378734a.
Pid = 1976, Hwnd=0xd0190, Text = -, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xc01b6, Text = >, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xe01b8, Text = 本机, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xb01e0, Text = 本机, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xc01b2, Text = 网关, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xb018a, Text = 网关, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xa01f0, Text = MAC:FF-FF-FF-FF-FF-FF, ClassName = WindowsForms10.STATIC.app.0.378734a.
Pid = 1976, Hwnd=0xc016a, Text = 确定, ClassName = Button.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
[Window,Class] = [选项,WindowsForms10.Window.8.app.0.378734a]
动态列表行为
VirSCANVirSCAN
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
com.android.mms.transaction.SmsReceiverService
行为描述: 读取文件
详情信息: path:/proc/783/cmdline length:105
path:/proc/799/cmdline length:105
path:/proc/811/cmdline length:105
path:/proc/841/cmdline length:105
path:/proc/854/cmdline length:105
path:/proc/863/cmdline length:105
path:/proc/865/cmdline length:105
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/com.leoly.fullnexus4-1.apk
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
VirSCANVirSCAN
活动名 类型
.activities.FullNexus4Activity android.intent.action.MAIN
.activities.FullNexus4Activity android.intent.category.LAUNCHER
危险函数
VirSCANVirSCAN
函数名称 信息
getRuntime 获取命令行环境
java/lang/Runtime;->exec 执行字符串命令
启动方式
VirSCANVirSCAN
名称 信息
com.leoly.fullnexus4.services.BootReceiver 开机启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.VIBRATE 允许设备震动
服务列表
VirSCANVirSCAN
名称
com.leoly.fullnexus4.services.FullNexus4Service
文件列表
VirSCANVirSCAN
文件名 校验码
assets/input2.jar 0x93207193
assets/input2_hc.jar 0xb8af101b
assets/input2_jb.jar 0x6b1abc9d
res/layout/changlog.xml 0x6c4ee1ec
res/layout/keys.xml 0x301ebfca
res/layout/list_item.xml 0x3e32180f
res/layout/main.xml 0xc9e9bc26
res/layout/main_left.xml 0xf4d93a16
res/layout/main_right.xml 0xdc2ce30
res/layout/main_setting.xml 0xcdee1536
AndroidManifest.xml 0xa4ec33bd
resources.arsc 0x820ee32c
res/drawable-hdpi/add.png 0x3f10faaa
res/drawable-hdpi/drag_horizontal.png 0x460d8cf1
res/drawable-hdpi/drag_vertical.png 0xba0355d9
res/drawable-hdpi/fullnexus.png 0x29f4720
res/drawable-hdpi/ic_back.png 0x666a1a6c
res/drawable-hdpi/ic_camera.png 0xe3f0f867
res/drawable-hdpi/ic_home.png 0x3e98adde
res/drawable-hdpi/ic_menu.png 0xb81247ce
res/drawable-hdpi/ic_power.png 0x1dfff67a
res/drawable-hdpi/ic_recent.png 0xdf4f4e4b
res/drawable-hdpi/ic_search.png 0xac17a80f
res/drawable-hdpi/ic_valum_down.png 0xf175395c
res/drawable-hdpi/ic_valum_up.png 0x581fc637
res/drawable-ldpi/add.png 0x3f10faaa
res/drawable-ldpi/drag_horizontal.png 0x460d8cf1
res/drawable-ldpi/drag_vertical.png 0xba0355d9
res/drawable-ldpi/fullnexus.png 0x29f4720
res/drawable-ldpi/ic_back.png 0x666a1a6c
res/drawable-ldpi/ic_camera.png 0xe3f0f867
res/drawable-ldpi/ic_home.png 0x3e98adde
res/drawable-ldpi/ic_menu.png 0xb81247ce
res/drawable-ldpi/ic_power.png 0x1dfff67a
res/drawable-ldpi/ic_recent.png 0xdf4f4e4b
res/drawable-ldpi/ic_search.png 0xac17a80f
res/drawable-ldpi/ic_valum_down.png 0xf175395c
res/drawable-ldpi/ic_valum_up.png 0x581fc637
res/drawable-mdpi/add.png 0x3f10faaa
res/drawable-mdpi/drag_horizontal.png 0x460d8cf1
res/drawable-mdpi/drag_vertical.png 0xba0355d9
res/drawable-mdpi/fullnexus.png 0x29f4720
res/drawable-mdpi/ic_back.png 0x666a1a6c
res/drawable-mdpi/ic_camera.png 0xe3f0f867
res/drawable-mdpi/ic_home.png 0x3e98adde
res/drawable-mdpi/ic_menu.png 0xb81247ce
res/drawable-mdpi/ic_power.png 0x1dfff67a
res/drawable-mdpi/ic_recent.png 0xdf4f4e4b
res/drawable-mdpi/ic_search.png 0xac17a80f
res/drawable-mdpi/ic_valum_down.png 0xf175395c
res/drawable-mdpi/ic_valum_up.png 0x581fc637
classes.dex 0xdae22108
com/leoly/fullnexus4/activities/changlog.txt 0x836a6344
META-INF/MANIFEST.MF 0xa79a8290
META-INF/CERT.SF 0xffa0540c
META-INF/CERT.RSA 0x328f77e9
运行截图
VirSCANVirSCAN
VirSCAN