VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:0%Scanner(s) (0/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-14 20:59:39 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 3
antivir 1.9.2.0 1.9.159.0 7.11.185.62 Found nothing 14
antiy 114701 AVL141003 2014-10-04 Found nothing 5
arcavir 1.0 2011 2014-05-30 Found nothing 8
asquared 9.0.0.4157 9.0.0.4157 2014-07-30 Found nothing 1
avast 141113-0 4.7.4 2014-11-13 Found nothing 28
avg 2109/8019 10.0.1405 2014-11-06 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 3
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.57701 7.90123 2014-11-13 Found nothing 6
clamav 19618 0.97.5 2014-11-12 Found nothing 1
comodo 15023 5.1 2014-10-03 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-10-31 Found nothing 29
fortinet 23.171, 23.171 5.1.158 2014-11-13 Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-11-13 Found nothing 1
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 3
gdata 24.3819 24.3819 2014-08-29 Found nothing 7
hauri 2.73 2.73 2014-06-13 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-11-13 Found nothing 14
jiangmin 16.0.100 1.0.0.0 2014-07-28 Found nothing 14
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 20
kingsoft 2.1 2.1 2013-09-22 Found nothing 60
mcafee 7520 5400.1158 2014-08-04 Found nothing 8
nod32 0436 3.0.21 2014-09-18 Found nothing 2
panda 9.05.01 9.05.01 2014-06-15 Found nothing 3
pcc 11.274.04 9.500-1005 2014-11-13 Found nothing 1
qh360 1.0.1 1.0.1 1.0.1 Found nothing 15
qqphone 1.0.0.0 1.0.0.0 2014-11-14 Found nothing 1
quickheal 14.00 14.00 2014-06-14 Found nothing 5
rising 25.17.00.04 25.17.00.04 2014-06-02 Found nothing 1
sophos 5.04 3.51.0 2014-08-05 Found nothing 8
sunbelt 3.9.2589.2 3.9.2589.2 2014-06-13 Found nothing 1
symantec 20141111.002 1.3.0.24 2014-11-11 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2014-06-12 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-06-16 Found nothing 6
vba 3.12.26.3 3.12.26.3 2014-11-13 Found nothing 3
virusbuster 15.0.967.0 5.5.2.13 2014-11-13 Found nothing 15

没有相关的权限信息

文件信息
VirSCANVirSCAN
安全评分 :70
基本信息
VirSCANVirSCAN
MD5:e150d81b43ed77fd149973f318ad5b75
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.monotype.android.font.AiFont82455
最低运行环境:Android 2.2.x
版权:Android
关键行为
VirSCANVirSCAN
行为描述: 跨进程写入数据
详情信息: TargetProcess = urmain.exe, WriteAddress = 0x00aaac62, Size = 2
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [安装向导,TApplication]
行为描述: 创建远程线程
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\urmain.exe
行为描述: 跨进程写代码段数据
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\urmain.exe, WriteAddress = 0x00AAAC62, EntryPoint = 0x00AAAC62
行为描述: 查找反病毒常用工具窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [FileMonClass,]
NtUserFindWindowEx: [Class,Window] = [RegMonClass,]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
行为描述: 按名称获取主机地址
详情信息: www.ursoftware.com
进程行为
VirSCANVirSCAN
行为描述: 跨进程写入数据
详情信息: TargetProcess = urmain.exe, WriteAddress = 0x00aaac62, Size = 2
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [安装向导,TApplication]
行为描述: 创建远程线程
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\urmain.exe
行为描述: 跨进程写代码段数据
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\urmain.exe, WriteAddress = 0x00AAAC62, EntryPoint = 0x00AAAC62
行为描述: 查找反病毒常用工具窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [FileMonClass,]
NtUserFindWindowEx: [Class,Window] = [RegMonClass,]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
行为描述: 按名称获取主机地址
详情信息: www.ursoftware.com
文件行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: Local\UrlZonesSM_Administrator
LSI-1A025C51
1A025C51::SharedIndexInfo
ShmNPA_UnitVersioning_2184
行为描述: 创建可执行文件
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-5PKPT.tmp\sample.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\_isetup\_shfoldr.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\isxdl.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\urmain.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\vcl70.bpl
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\rtl70.bpl
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\vclx70.bpl
网络行为
VirSCANVirSCAN
行为描述: 建立到一个指定的套接字连接
详情信息: 127.0.0.1:1040
127.0.0.1:1041
127.0.0.1:1042
127.0.0.1:1043
127.0.0.1:1044
127.0.0.1:1045
127.0.0.1:1046
127.0.0.1:1047
127.0.0.1:1048
127.0.0.1:1049
127.0.0.1:1050
127.0.0.1:1051
127.0.0.1:1052
127.0.0.1:1053
127.0.0.1:1054
行为描述: 按名称获取主机地址
详情信息: www.ursoftware.com
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-RVKPL.tmp\urmain.exe
\REGISTRY\MACHINE\SOFTWARE\Licenses\{K7C0DB872A3F777C0}
\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{13BEED4D-8960-1108-BBFD-885E2359744F}\
\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{13BEED4D-8960-1108-BBFD-885E2359744F}\InprocServer32\
\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{13BEED4D-8960-1108-BBFD-885E2359744F}\InprocServer32\ThreadingModel
\REGISTRY\MACHINE\SOFTWARE\Licenses\{I1A025C51A1747CC8}
\REGISTRY\MACHINE\SOFTWARE\Licenses\{01A025C51A1747CC8}
行为描述: 删除注册表键值
详情信息: \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{13BEED4D-8960-1108-BBFD-885E2359744F}\0
\REGISTRY\MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\DW\DWFileTreeRoot
行为描述: 删除注册表键
详情信息: \REGISTRY\MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\DW
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
888::DAF9AED7F1
DILLOCREATE
DILLOOEP
RAL1A025C51
1A025C51::WK
MutexNPA_UnitVersioning_2184
oleacc-msaa-loaded
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [安装向导,TApplication]
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [ThunderRT6FormDC,Shareware Cheater v 3.0]
NtUserFindWindowEx: [Class,Window] = [ThunderRT6FormDC,]
NtUserFindWindowEx: [Class,Window] = [MS_WINHELP,]
行为描述: 尝试打开调试器或监控软件的驱动设备对象
详情信息: \??\SICE
\??\NTICE
\??\SIWVID
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
SE_INC_BASE_PRIORITY_PRIVILEGE
行为描述: 枚举窗口
详情信息: N/A
行为描述: 直接操作物理设备
详情信息: \??\PHYSICALDRIVE0
行为描述: 查找反病毒常用工具窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [FileMonClass,]
NtUserFindWindowEx: [Class,Window] = [RegMonClass,]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
异常崩溃
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
888::DAF9AED7F1
DILLOCREATE
DILLOOEP
RAL1A025C51
1A025C51::WK
MutexNPA_UnitVersioning_2184
oleacc-msaa-loaded
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [安装向导,TApplication]
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [ThunderRT6FormDC,Shareware Cheater v 3.0]
NtUserFindWindowEx: [Class,Window] = [ThunderRT6FormDC,]
NtUserFindWindowEx: [Class,Window] = [MS_WINHELP,]
行为描述: 尝试打开调试器或监控软件的驱动设备对象
详情信息: \??\SICE
\??\NTICE
\??\SIWVID
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
SE_INC_BASE_PRIORITY_PRIVILEGE
行为描述: 枚举窗口
详情信息: N/A
行为描述: 直接操作物理设备
详情信息: \??\PHYSICALDRIVE0
行为描述: 查找反病毒常用工具窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [FileMonClass,]
NtUserFindWindowEx: [Class,Window] = [RegMonClass,]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0xa1f87880
META-INF/CERT.SF 0x3e49e371
META-INF/CERT.RSA 0xdaeb66
assets/fonts/AiFont82455.ttf 0x238f807a
AndroidManifest.xml 0xd82f4128
res/drawable/icon.png 0xc6000e88
resources.arsc 0x2e362247
classes.dex 0x8361cb2d
assets/xml/AiFont82455.xml 0x102b1148
运行截图
VirSCANVirSCAN
VirSCAN