VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:6%Antivirus software(2/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2016-05-26 23:17:30 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 5
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 150725-1 4.7.4 2015-07-25 Found nothing 60
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 60
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 8
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 60
clamav 19861 0.97.5 2014-12-31 Found nothing 60
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 60
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 60
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 60
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 60
gdata 25.6707 25.6707 2016-05-25 Found nothing 9
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 60
jiangmin 16.0.100 1.0.0.0 2015-07-25 Backdoor/AndroidOS.apik 40
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 60
kingsoft 2.1 2.1 2013-09-22 Android.MALWARE.at_Fakegupdt.am.(kcloud) 4
mcafee 7638 5400.1158 2014-11-30 Found nothing 60
nod32 0920 3.0.21 2014-12-23 Found nothing 60
panda 9.05.01 9.05.01 2015-07-26 Found nothing 4
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 60
qh360 1.0.1 1.0.1 1.0.1 Found nothing 2
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 60
quickheal 14.00 14.00 2015-07-25 Found nothing 2
rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 1
sophos 5.08 3.55.0 2014-12-01 Found nothing 60
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 60
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 13
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 60
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 60
权限列表
许可名称 信息
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.BROADCAST_STICKY 发送持久广播
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.VIBRATE 允许设备震动
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.DISABLE_KEYGUARD 禁用键盘锁
android.permission.RESTART_PACKAGES 重启其他程序
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.SET_WALLPAPER 设置桌面壁纸
com.android.launcher.permission.INSTALL_SHORTCUT 创建快捷方式
com.android.launcher.permission.UNINSTALL_SHORTCUT 删除快捷方式
android.permission.INSTALL_PACKAGES 安装应用
android.permission.DELETE_PACKAGES 删除应用
android.permission.CLEAR_APP_CACHE 清除应用缓存
android.permission.CLEAR_APP_USER_DATA 清除用户数据
android.permission.KILL_BACKGROUND_PROCESSES 关闭后台进程
android.permission.FORCE_STOP_PACKAGES
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:ffcb07df7a4ff0478a89f8bbfa26ad25
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.android.strm
最低运行环境:Android 2.3, 2.3.1, 2.3.2
版权:Android
关键行为
VirSCANVirSCAN
行为描述: 检测自身是否被调试
详情信息: N/A
行为描述: 获取硬件属性检测虚拟机
详情信息: 检测Vmware: 调用WMI接口获取硬件信息
行为描述: 获取TickCount值
详情信息: TickCount = 1135656, SleepMilliseconds = 60000.
TickCount = 1135687, SleepMilliseconds = 60000.
TickCount = 1135703, SleepMilliseconds = 60000.
TickCount = 1135718, SleepMilliseconds = 60000.
TickCount = 1135750, SleepMilliseconds = 60000.
TickCount = 1135765, SleepMilliseconds = 60000.
TickCount = 1135781, SleepMilliseconds = 60000.
TickCount = 1135812, SleepMilliseconds = 60000.
TickCount = 1135843, SleepMilliseconds = 60000.
TickCount = 1135859, SleepMilliseconds = 60000.
TickCount = 1135890, SleepMilliseconds = 60000.
TickCount = 1135906, SleepMilliseconds = 60000.
TickCount = 1135953, SleepMilliseconds = 60000.
TickCount = 1136000, SleepMilliseconds = 60000.
TickCount = 1136015, SleepMilliseconds = 60000.
进程行为
VirSCANVirSCAN
行为描述: 检测自身是否被调试
详情信息: N/A
行为描述: 获取硬件属性检测虚拟机
详情信息: 检测Vmware: 调用WMI接口获取硬件信息
行为描述: 获取TickCount值
详情信息: TickCount = 1135656, SleepMilliseconds = 60000.
TickCount = 1135687, SleepMilliseconds = 60000.
TickCount = 1135703, SleepMilliseconds = 60000.
TickCount = 1135718, SleepMilliseconds = 60000.
TickCount = 1135750, SleepMilliseconds = 60000.
TickCount = 1135765, SleepMilliseconds = 60000.
TickCount = 1135781, SleepMilliseconds = 60000.
TickCount = 1135812, SleepMilliseconds = 60000.
TickCount = 1135843, SleepMilliseconds = 60000.
TickCount = 1135859, SleepMilliseconds = 60000.
TickCount = 1135890, SleepMilliseconds = 60000.
TickCount = 1135906, SleepMilliseconds = 60000.
TickCount = 1135953, SleepMilliseconds = 60000.
TickCount = 1136000, SleepMilliseconds = 60000.
TickCount = 1136015, SleepMilliseconds = 60000.
文件行为
VirSCANVirSCAN
行为描述: 覆盖已有文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
行为描述: 修改文件内容
详情信息: C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT ---> Offset = 0
行为描述: 查找文件
详情信息: FileName = C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
FileName = C:\WINDOWS\Microsoft.NET\Framework\\*
FileName = C:\WINDOWS\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.INI
FileName = C:\Documents and Settings\Administrator\Local Settings\Temp
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%
FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\Local Settings
其他行为
VirSCANVirSCAN
行为描述: 检测自身是否被调试
详情信息: N/A
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.ELH
行为描述: 获取硬件属性检测虚拟机
详情信息: 检测Vmware: 调用WMI接口获取硬件信息
行为描述: 创建事件对象
详情信息: EventName = Global\CPFATE_1532_v4.0.30319
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
行为描述: 获取TickCount值
详情信息: TickCount = 1135656, SleepMilliseconds = 60000.
TickCount = 1135687, SleepMilliseconds = 60000.
TickCount = 1135703, SleepMilliseconds = 60000.
TickCount = 1135718, SleepMilliseconds = 60000.
TickCount = 1135750, SleepMilliseconds = 60000.
TickCount = 1135765, SleepMilliseconds = 60000.
TickCount = 1135781, SleepMilliseconds = 60000.
TickCount = 1135812, SleepMilliseconds = 60000.
TickCount = 1135843, SleepMilliseconds = 60000.
TickCount = 1135859, SleepMilliseconds = 60000.
TickCount = 1135890, SleepMilliseconds = 60000.
TickCount = 1135906, SleepMilliseconds = 60000.
TickCount = 1135953, SleepMilliseconds = 60000.
TickCount = 1136000, SleepMilliseconds = 60000.
TickCount = 1136015, SleepMilliseconds = 60000.
行为描述: 窗口信息
详情信息: Pid = 1532, Hwnd=0x4036c, Text = 确定, ClassName = Button.
Pid = 1532, Hwnd=0x6035e, Text = Object reference not set to an instance of an object., ClassName = Static.
行为描述: 调用Sleep函数
详情信息: [1]: MilliSeconds = 60000.
[2]: MilliSeconds = 60000.
[3]: MilliSeconds = 60000.
[4]: MilliSeconds = 60000.
[5]: MilliSeconds = 60000.
Activities
VirSCANVirSCAN
活动名 类型
com.android.ops.stub.activity.DisplayItemActivity android.intent.action.MAIN
com.android.ops.stub.activity.DisplayItemActivity com.android.ops.stub.DISPLAYITEM
com.android.ops.stub.activity.RecommendActivity android.intent.action.MAIN
危险函数
VirSCANVirSCAN
函数名称 信息
ContentResolver;->query 读取联系人、短信等数据库
HttpClient;->execute 请求远程服务器
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
TelephonyManager;->getLine1Number 获取手机号
getRuntime 获取命令行环境
java/lang/Runtime;->exec 执行字符串命令
java/net/URL;->openConnection 连接URL
java/net/HttpURLConnection;->connect 连接URL
LocationManager;->getLastKnownLocation 获取地址位置
启动方式
VirSCANVirSCAN
名称 信息
com.android.ops.stub.receiver.DownloadReceiver 开机启动服务
com.android.ops.stub.receiver.DownloadReceiver 网络连接改变时启动服务
com.android.ops.stub.receiver.DownloadReceiver
com.android.ops.stub.receiver.DownloadReceiver
com.android.ops.stub.receiver.DownloadReceiver
com.android.ops.stub.receiver.OpReceiver 网络连接改变时启动服务
com.android.ops.stub.receiver.OpReceiver 开机启动服务
com.android.ops.stub.receiver.OpReceiver 应用卸载时启动服务
com.android.ops.stub.receiver.OpReceiver
com.android.ops.stub.receiver.OpReceiver
com.android.ops.stub.receiver.OpReceiver
com.android.ops.stub.receiver.OpReceiver 屏幕解锁启动服务
com.android.ops.stub.receiver.PushReceiver
com.android.ops.stub.receiver.PushReceiver
com.android.ops.stub.receiver.PushReceiver
com.android.ops.stub.receiver.PushReceiver
com.android.ops.stub.receiver.PushReceiver
com.android.ops.stub.receiver.PushReceiver
com.android.ops.stub.receiver.PushReceiver
com.android.ops.stub.receiver.PushReceiver 网络连接改变时启动服务
com.android.ops.stub.receiver.PushReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver 开机启动服务
com.android.ops.stub.receiver.AllShowReceiver 网络连接改变时启动服务
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver
com.android.ops.stub.receiver.AllShowReceiver 应用安装时启动服务
com.android.ops.stub.receiver.AllShowReceiver 应用卸载时启动服务
com.android.ops.stub.receiver.SysMetricCollectorReceiver
com.android.ops.stub.receiver.SysMetricCollectorReceiver 网络连接改变时启动服务
com.android.ops.stub.receiver.SysMetricCollectorReceiver
com.android.ops.stub.receiver.UBCReceiver 网络连接改变时启动服务
广告信息
VirSCANVirSCAN
名称 信息
com.baidu 百度
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.BROADCAST_STICKY 发送持久广播
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.VIBRATE 允许设备震动
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.DISABLE_KEYGUARD 禁用键盘锁
android.permission.RESTART_PACKAGES 重启其他程序
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.SET_WALLPAPER 设置桌面壁纸
com.android.launcher.permission.INSTALL_SHORTCUT 创建快捷方式
com.android.launcher.permission.UNINSTALL_SHORTCUT 删除快捷方式
android.permission.INSTALL_PACKAGES 安装应用
android.permission.DELETE_PACKAGES 删除应用
android.permission.CLEAR_APP_CACHE 清除应用缓存
android.permission.CLEAR_APP_USER_DATA 清除用户数据
android.permission.KILL_BACKGROUND_PROCESSES 关闭后台进程
android.permission.FORCE_STOP_PACKAGES
服务列表
VirSCANVirSCAN
名称
com.android.ops.stub.service.OpService
com.android.ops.stub.service.DownloadService
com.android.ops.stub.service.FloatingService
com.android.ops.stub.service.SysMetricCollectorService
com.android.ops.stub.service.UBCService
Providers
VirSCANVirSCAN
名称 信息
com.android.ops.stub.service.OpService
com.android.ops.stub.service.DownloadService
com.android.ops.stub.service.FloatingService
com.android.ops.stub.service.SysMetricCollectorService
com.android.ops.stub.service.UBCService
文件列表
VirSCANVirSCAN
文件名 校验码
assets/impl 0x16ec3a63
assets/qdh 0xb7b48f94
assets/res.apk 0x1ead5705
assets/ubcconfig.xml 0xc66635e
assets/ubcprofile.xml 0x8fc9a8d2
assets/yyops.x509.pem 0x46f2e8c0
res/anim/fade_in.xml 0xe5af8201
res/anim/fade_out.xml 0xf354ee79
res/anim/zoom_in.xml 0x73bb7e93
res/anim/zoom_out.xml 0x33bdb894
res/drawable/mybutton.xml 0xfed9087f
res/layout/activity_main.xml 0xa9c4f0c9
res/layout/channel_set.xml 0xcf339a80
res/layout/message_hint.xml 0x21227551
res/layout/progress_hint.xml 0x9884625c
res/layout/test_activity_main.xml 0xd94c472b
res/menu/main.xml 0xacd29a92
AndroidManifest.xml 0x502174b9
resources.arsc 0xa414b568
res/drawable-hdpi/ic_launcher.png 0xf248df62
classes.dex 0xc50bd755
META-INF/MANIFEST.MF 0xd99cc744
META-INF/CERT.SF 0x833954ec
META-INF/CERT.RSA 0x8b72d94
运行截图
VirSCANVirSCAN
VirSCAN