VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:0%Antivirus software(0/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2015-10-16 14:37:57 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 5
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 150725-1 4.7.4 2015-07-25 Found nothing 0
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 0
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 4
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 0
clamav 19861 0.97.5 2014-12-31 Found nothing 0
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 0
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 0
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 0
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 0
gdata 25.3894 25.3894 2015-10-16 Found nothing 9
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 0
jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 60
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 0
kingsoft 2.1 2.1 2013-09-22 Found nothing 5
mcafee 7638 5400.1158 2014-11-30 Found nothing 0
nod32 0920 3.0.21 2014-12-23 Found nothing 0
panda 9.05.01 9.05.01 2015-07-26 Found nothing 7
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 0
qh360 1.0.1 1.0.1 1.0.1 Found nothing 8
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 0
quickheal 14.00 14.00 2015-07-25 Found nothing 2
rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 1
sophos 5.08 3.55.0 2014-12-01 Found nothing 0
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 0
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 2
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 12
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 0
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 0
权限列表
许可名称 信息
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:a4f69d26da7bbac242b561a86492f58e
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.yuki.android.timing
最低运行环境:Android 2.2.x
版权:Android
关键行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: CiceroSharedMemDefaultS-*
\WINDOWS\system32\zh-cn\ieframe.dll.mui
MSCTF.MarshalInterface.FileMap.MJB..EFCHH
MSCTF.MarshalInterface.FileMap.MJB.B.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.C.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.D.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.E.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.F.DGCHH
MSCTF.MarshalInterface.FileMap.MJB.G.DGCHH
Local\UrlZonesSM_Administrator
Local\!PrivacIE!SharedMem!Counter
\WINDOWS\system32\zh-cn\jscript.dll.mui
\WINDOWS\system32\zh-cn\mshtml.dll.mui
MSCTF.MarshalInterface.FileMap.MJB.H.JIOHH
MSCTF.MarshalInterface.FileMap.MJB.I.JIOHH
行为描述: 屏蔽窗口关闭消息
详情信息: hWnd = 0x000202a8, Text = VST直播, ClassName = WTWindow.
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,_EL_Timer]
[Window,Class] = [,_EL_ClientSock]
[Window,Class] = [,_EL_RgnButton]
[Window,Class] = [,Afx:400000:b:10011:110005b:0]
[Window,Class] = [,Afx:400000:8]
[Window,Class] = [,WTWindow]
进程行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: CiceroSharedMemDefaultS-*
\WINDOWS\system32\zh-cn\ieframe.dll.mui
MSCTF.MarshalInterface.FileMap.MJB..EFCHH
MSCTF.MarshalInterface.FileMap.MJB.B.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.C.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.D.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.E.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.F.DGCHH
MSCTF.MarshalInterface.FileMap.MJB.G.DGCHH
Local\UrlZonesSM_Administrator
Local\!PrivacIE!SharedMem!Counter
\WINDOWS\system32\zh-cn\jscript.dll.mui
\WINDOWS\system32\zh-cn\mshtml.dll.mui
MSCTF.MarshalInterface.FileMap.MJB.H.JIOHH
MSCTF.MarshalInterface.FileMap.MJB.I.JIOHH
行为描述: 屏蔽窗口关闭消息
详情信息: hWnd = 0x000202a8, Text = VST直播, ClassName = WTWindow.
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,_EL_Timer]
[Window,Class] = [,_EL_ClientSock]
[Window,Class] = [,_EL_RgnButton]
[Window,Class] = [,Afx:400000:b:10011:110005b:0]
[Window,Class] = [,Afx:400000:8]
[Window,Class] = [,WTWindow]
文件行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: CiceroSharedMemDefaultS-*
\WINDOWS\system32\zh-cn\ieframe.dll.mui
MSCTF.MarshalInterface.FileMap.MJB..EFCHH
MSCTF.MarshalInterface.FileMap.MJB.B.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.C.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.D.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.E.EFCHH
MSCTF.MarshalInterface.FileMap.MJB.F.DGCHH
MSCTF.MarshalInterface.FileMap.MJB.G.DGCHH
Local\UrlZonesSM_Administrator
Local\!PrivacIE!SharedMem!Counter
\WINDOWS\system32\zh-cn\jscript.dll.mui
\WINDOWS\system32\zh-cn\mshtml.dll.mui
MSCTF.MarshalInterface.FileMap.MJB.H.JIOHH
MSCTF.MarshalInterface.FileMap.MJB.I.JIOHH
行为描述: 创建可执行文件
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\APlayerCaller.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\atl71.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\codecs\audioswitcher.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\codecs\forceshell.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\APlayer.dll
行为描述: 修改文件内容
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\tmp.data---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\navcancl[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\ErrorPageTemplate[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\background_gradient[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\info_48[1]---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\bullet[1]---> Offset = 0
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
行为描述: 查找文件
详情信息: FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\APlayer.dll
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\tmp.data
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\tv.txt
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\VSTLive_UP.exe
FileName = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
FileName = C:\WINDOWS\system32\Ras\*.pbk
FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\Local Settings
FileName = C:\Documents and Settings\Administrator\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
FileName = C:\WINDOWS
FileName = C:\WINDOWS\system32
FileName = C:\WINDOWS\system32\ieframe.dll
网络行为
VirSCANVirSCAN
行为描述: 连接指定站点
详情信息: InternetConnectA: ServerName = live.91vst.com, PORT = 80
InternetConnectA: ServerName = update.91vst.com, PORT = 80
行为描述: 建立到一个指定的套接字连接
详情信息: 127.0.0.1:1031
行为描述: 读取网络文件
详情信息: hFile = 0x00000300, BytesToRead =512, BytesRead = 512.
行为描述: 打开HTTP请求
详情信息: HttpOpenRequestA: live.91vst.com:80/list.html?by=qq243944493, hConnect = 0x000003f4
HttpOpenRequestA: update.91vst.com:80/62796e51cf6d76.json, hConnect = 0x00000308
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name
\REGISTRY\MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\ID
\REGISTRY\USER\S-*\Software\Microsoft\Direct3D\MostRecentApplication\Name
\REGISTRY\MACHINE\SOFTWARE\VSTLive\Aplayer_Ver
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
行为描述: 删除注册表键值_IE连接设置
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
DDrawWindowListMutex
DDrawDriverObjectListMutex
__DDrawExclMode__
__DDrawCheckExclMode__
MSCTF.Shared.MUTEX.ELH
Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,_EL_Timer]
[Window,Class] = [,_EL_ClientSock]
[Window,Class] = [,_EL_RgnButton]
[Window,Class] = [,Afx:400000:b:10011:110005b:0]
[Window,Class] = [,Afx:400000:8]
[Window,Class] = [,WTWindow]
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [MS_AutodialMonitor,]
NtUserFindWindowEx: [Class,Window] = [MS_WebCheckMonitor,]
行为描述: 获取TickCount值
详情信息: TickCount = 546687, SleepMilliseconds = 60000.
TickCount = 546703, SleepMilliseconds = 60000.
TickCount = 546718, SleepMilliseconds = 60000.
TickCount = 546750, SleepMilliseconds = 60000.
TickCount = 546765, SleepMilliseconds = 60000.
TickCount = 547687, SleepMilliseconds = 60000.
TickCount = 547781, SleepMilliseconds = 60000.
TickCount = 488004, SleepMilliseconds = 20.
TickCount = 488020, SleepMilliseconds = 20.
TickCount = 488035, SleepMilliseconds = 20.
TickCount = 488098, SleepMilliseconds = 20.
TickCount = 488285, SleepMilliseconds = 20.
TickCount = 488441, SleepMilliseconds = 20.
TickCount = 488707, SleepMilliseconds = 20.
TickCount = 488941, SleepMilliseconds = 20.
行为描述: 获取光标位置
详情信息: CursorPos = (106,18467), SleepMilliseconds = 20.
CursorPos = (6399,26500), SleepMilliseconds = 20.
CursorPos = (19234,15724), SleepMilliseconds = 20.
CursorPos = (11543,29358), SleepMilliseconds = 20.
CursorPos = (27027,24464), SleepMilliseconds = 20.
CursorPos = (5770,28145), SleepMilliseconds = 20.
CursorPos = (23346,16827), SleepMilliseconds = 20.
CursorPos = (10026,491), SleepMilliseconds = 20.
CursorPos = (3060,11942), SleepMilliseconds = 20.
CursorPos = (4892,5436), SleepMilliseconds = 20.
CursorPos = (32456,14604), SleepMilliseconds = 20.
CursorPos = (3967,153), SleepMilliseconds = 20.
CursorPos = (357,12382), SleepMilliseconds = 20.
CursorPos = (17486,18716), SleepMilliseconds = 20.
CursorPos = (19783,19895), SleepMilliseconds = 20.
行为描述: 屏蔽窗口关闭消息
详情信息: hWnd = 0x000202a8, Text = VST直播, ClassName = WTWindow.
行为描述: 窗口信息
详情信息: Pid = 1396, Hwnd=0x202ca, Text = 当前版本:V1.6.9, ClassName = Afx:400000:b:10011:1900015:0.
Pid = 1396, Hwnd=0x202d8, Text = 准备就绪, ClassName = Afx:400000:b:10011:1900015:0.
Pid = 1396, Hwnd=0x202a8, Text = VST直播, ClassName = WTWindow.
行为描述: 调用Sleep函数
详情信息: [1]: MilliSeconds = 60000.
[2]: MilliSeconds = 60000.
[3]: MilliSeconds = 60000.
[4]: MilliSeconds = 60000.
[5]: MilliSeconds = 60000.
[6]: MilliSeconds = 60000.
[7]: MilliSeconds = 60000.
[8]: MilliSeconds = 60000.
[9]: MilliSeconds = 60000.
[10]: MilliSeconds = 60000.
行为描述: 内联HOOK
详情信息: C:\WINDOWS\system32\ole32.dll--->CoCreateInstance Offset = 0x0
C:\WINDOWS\system32\SHELL32.dll--->Shell_NotifyIconA Offset = 0x0
C:\WINDOWS\system32\SHELL32.dll--->Shell_NotifyIconW Offset = 0x0
动态列表行为
VirSCANVirSCAN
行为描述: 启动服务
详情信息: {"ACTION":"com.yuki.android.timing.action.SERVICE_ACTION","FLAG":0}
{"FLAG":268435456,"COMPONENT_NAME":"ComponentInfo{com.yuki.android.timing\/com.yuki.android.timing.TimingService}"}
行为描述: 发出状态栏通知
详情信息: [u'0', u'Notification(pri=0 contentView=com.yuki.android.timing/0x1090071 vibrate=null sound=null defaults=0x0 flags=0x22 kind=[null])']
行为描述: 注册广播接收器
详情信息: [u'com.yuki.android.timing.TimingListActivity$RefreshListReceiver@414caa70', u'android.content.IntentFilter@414eef38']
[u'com.yuki.android.timing.TimingService$TimeoutReceiver@41551a10', u'android.content.IntentFilter@41551a28']
行为描述: 窗口信息
详情信息: {"text": "定时飞行模式", "class": "android.widget.TextView"}
{"text": "添加", "class": "android.widget.TextView"}
行为描述: Toast->makeText弹出提示
详情信息: text:初始化定时器成功 duration:1
行为描述: 添加View
详情信息: [u'com.android.internal.policy.impl.PhoneWindow$DecorView@4154f0f8', u'WM.LayoutParams{(0,0)(fillxfill) sim=#100 ty=1 fl=#8010100 pfl=0x8 wanim=0x1030001}', u'android.view.CompatibilityInfoHolder@414afa00']
[u'android.widget.LinearLayout@4153d3d0', u'WM.LayoutParams{(0,128)(wrapxwrap) gr=#51 ty=2005 fl=#98 fmt=-3 wanim=0x1030004}']
行为描述: 初始化Intent
详情信息: []
[u'android.os.Parcel@414ad1f0']
[u'android.os.Parcel@414ad1b0']
[]
[u'android.os.Parcel@414ad1b0']
[u'android.os.Parcel@414ad1b0']
[]
[u'android.os.Parcel@414ad1f0']
行为描述: 调用Intent的setAction
详情信息: [u'com.yuki.android.timing.action.SERVICE_ACTION']
行为描述: 数据库查询
详情信息: [u'Liming', u'null', u'null', u'null', u'null', u'null', u'null']
[u'Liming', u'null', u'null', u'null', u'null', u'null', u'null']
[u'Liming', u'null', u'null', u'null', u'null', u'null', u'null']
Activities
VirSCANVirSCAN
活动名 类型
.TimingListActivity android.intent.action.MAIN
.TimingListActivity android.intent.category.LAUNCHER
危险函数
VirSCANVirSCAN
函数名称 信息
android/app/NotificationManager;->notify 信息通知栏
启动方式
VirSCANVirSCAN
名称 信息
com.yuki.android.timing.BootReceiver 开机启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
服务列表
VirSCANVirSCAN
名称
com.yuki.android.timing.TimingService
文件列表
VirSCANVirSCAN
文件名 校验码
res/layout/timing_item_edit.xml 0xf692f5c5
res/layout/timing_list.xml 0xf17fa6e6
res/layout/timing_list_item.xml 0x1057c2b
AndroidManifest.xml 0xcbaef828
resources.arsc 0x5fba94f3
res/drawable-hdpi/ic_launcher.png 0xbba5ebd3
res/drawable-hdpi/launcher_ic.png 0x63905743
res/drawable-hdpi/list_new.png 0x592a0135
res/drawable-hdpi/timing_ariplane_mode_ico.png 0x1030c069
res/drawable-ldpi/ic_launcher.png 0xc6724704
res/drawable-ldpi/launcher_ic.png 0xd0a0d802
res/drawable-ldpi/list_new.png 0xadd81fae
res/drawable-ldpi/timing_ariplane_mode_ico.png 0xd399b3b0
res/drawable-mdpi/ic_launcher.png 0x1e96501c
res/drawable-mdpi/launcher_ic.png 0xd1296f91
res/drawable-mdpi/list_new.png 0x9dfa1b17
res/drawable-mdpi/timing_ariplane_mode_ico.png 0x3e781e05
classes.dex 0xdf357819
META-INF/MANIFEST.MF 0x5bad52a0
META-INF/CERT.SF 0x7f8286e5
META-INF/CERT.RSA 0x33120e35
运行截图
VirSCANVirSCAN
VirSCAN