VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:0%Antivirus software(0/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2015-10-01 09:57:23 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 5
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 150725-1 4.7.4 2015-07-25 Found nothing 0
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 0
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 4
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 0
clamav 19861 0.97.5 2014-12-31 Found nothing 0
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 0
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 0
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 0
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 0
gdata 25.3686 25.3686 2015-09-30 Found nothing 8
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 0
jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 41
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 0
kingsoft 2.1 2.1 2013-09-22 Found nothing 7
mcafee 7638 5400.1158 2014-11-30 Found nothing 0
nod32 0920 3.0.21 2014-12-23 Found nothing 0
panda 9.05.01 9.05.01 2015-07-26 Found nothing 4
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 0
qh360 1.0.1 1.0.1 1.0.1 Found nothing 2
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 0
quickheal 14.00 14.00 2015-07-25 Found nothing 2
rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 1
sophos 5.08 3.55.0 2014-12-01 Found nothing 0
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 0
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 13
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 0
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 0
权限列表
许可名称 信息
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.INTERNET 连接网络(2G或3G)
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.READ_PHONE_STATE 读取电话状态
文件信息
VirSCANVirSCAN
安全评分 :71
基本信息
VirSCANVirSCAN
MD5:96dd16a34636e25308f179ddc5f946c8
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.ivali.qhbao
最低运行环境:Android 2.2.x
版权:Ivali Inc.
关键行为
VirSCANVirSCAN
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
[Window,Class] = [,ThunderRT6Main]
文件行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: CiceroSharedMemDefaultS-1-5-21-1482476501-1645522239-1417001333-500
Local\Mso97SharedDg19211108221
Local\Mso97SharedDg20321108221
Local\Mso97SharedDg19521108221
Local\Mso97SharedDg19531108221
DfSharedHeap63B74
\monitor\sample.xls
DfRoot000063B74
\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DF3B80.tmp
Local\MSO_Formal11108221_S-1-5-21-1482476501-1645522239-1417001333-500
Local\MSO_AdHoc11108221_S-1-5-21-1482476501-1645522239-1417001333-500
MSCTF.MarshalInterface.FileMap.ELJ..DCOGF
MSCTF.MarshalInterface.FileMap.ELJ.B.CDOGF
MSCTF.MarshalInterface.FileMap.ELJ.C.CDOGF
MSCTF.MarshalInterface.FileMap.ELJ.D.CDOGF
行为描述: 修改文件内容
详情信息: C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\sample.xls.LNK---> Offset = 0
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\index.dat---> Offset = 28
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\monitor.LNK---> Offset = 0
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\StartupItems\;j
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\MTTT
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\DocumentRecovery\56B55\56B55
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Common\ReviewCycle\ReviewToken
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\DocumentRecovery\56DF5\56DF5
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\StartupItems\um
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\StartupItems\n
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\Common\Assistant\CurrAsstState
行为描述: 删除注册表键
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\StartupItems
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\DocumentRecovery\56B55
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\DocumentRecovery
行为描述: 删除注册表键值
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\StartupItems\;j
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\DocumentRecovery\56B55\56B55
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\StartupItems\um
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\Resiliency\StartupItems\n
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Office\11.0\Excel\ExcelName
其他行为
VirSCANVirSCAN
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
NtUserFindWindowEx: [Class,Window] = [MSOBALLOON,]
NtUserFindWindowEx: [Class,Window] = [MsoHelp11,]
NtUserFindWindowEx: [Class,Window] = [AgentAnim,]
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
[Window,Class] = [,ThunderRT6Main]
行为描述: 创建互斥体
详情信息: Local\Mutex_MSOSharedMem
CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1645522239-1417001333-500MUTEX.DefaultS-1-5-21-1482476501-1645522239-1417001333-500
Local\Mso97SharedDg19211108221Mutex
Local\Mso97SharedDg20321108221Mutex
Local\Mso97SharedDg19521108221Mutex
Local\Mso97SharedDg19531108221Mutex
Global\MTX_MSO_Formal1_S-1-5-21-1482476501-1645522239-1417001333-500
Global\MTX_MSO_AdHoc1_S-1-5-21-1482476501-1645522239-1417001333-500
OfficeAssistantStateMutex
MSCTF.Shared.MUTEX.AEH
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
危险行为
VirSCANVirSCAN
行为描述: 执行系统命令
详情信息: chmod 777 /data/data/com.ivali.qhbao/files/libqupc.so
动态列表行为
VirSCANVirSCAN
行为描述: 调用哈希算法
详情信息: MD5
行为描述: 读取文件
详情信息: path:/proc/761/cmdline length:105
path:/proc/777/cmdline length:105
path:/proc/790/cmdline length:105
path:/proc/820/cmdline length:105
path:/proc/830/cmdline length:105
行为描述: 访问URL
详情信息: libcore.net.http.HttpURLConnectionImpl:http://api.jiagu.360.cn/s.html?ov=4.1.1&t=new&b=5d0f45dfa062fbbc016d6ea0cc06f30b&c=1002&md=Full+Android+on+Emulator&r=83F64110DF08255F3A&a=1.0.4.1&pn=com.ivali.qhbao&im=e6ad39748d6749b188a7b347d520bd15&vn=1.2&cs=0d690b6c9c9a580619fcf9064f19a7c7
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/com.ivali.qhbao-1.apk
行为描述: 获取用户ID
详情信息: 310260000000000
行为描述: 执行系统命令
详情信息: chmod 777 /data/data/com.ivali.qhbao/files/libqupc.so
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/com.ivali.qhbao/files/libqupc.so length:104
path:/data/data/com.ivali.qhbao/files/libqupc.so length:55
path:/data/data/com.ivali.qhbao/files/libqupc.so length:56
path:/data/data/com.ivali.qhbao/files/libqupc.so length:49
path:/data/data/com.ivali.qhbao/files/libqupc.so length:52
path:/data/data/com.ivali.qhbao/files/libqupc.so length:58
path:/data/data/com.ivali.qhbao/files/libqupc.so length:45
path:/data/data/com.ivali.qhbao/files/libqupc.so length:39
path:/data/data/com.ivali.qhbao/files/libqupc.so length:51
path:/data/data/com.ivali.qhbao/files/libqupc.so length:88
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:102
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:105
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:50
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:53
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:44
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:53
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:36
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:57
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:105
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:55
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:53
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:50
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:54
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:56
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:64
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:60
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:60
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:52
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:50
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:59
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:60
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:50
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:46
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:50
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:59
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:52
path:/data/data/com.ivali.qhbao/files/libprotectClass.so length:55
path:/data/data/com.ivali.qhbao/shared_prefs/qihooLock.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
行为描述: 获取设备ID
详情信息: 357242043237511
Activities
VirSCANVirSCAN
活动名 类型
com.tencent.tauth.AuthActivity android.intent.action.VIEW
com.tencent.tauth.AuthActivity android.intent.category.DEFAULT
com.tencent.tauth.AuthActivity android.intent.category.BROWSABLE
com.ivali.qhbao.MainActivity android.intent.action.MAIN
com.ivali.qhbao.MainActivity android.intent.category.LAUNCHER
危险函数
VirSCANVirSCAN
函数名称 信息
java/net/URL;->openConnection 连接URL
java/net/HttpURLConnection;->connect 连接URL
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
getRuntime 获取命令行环境
java/lang/Runtime;->exec 执行字符串命令
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.INTERNET 连接网络(2G或3G)
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.READ_PHONE_STATE 读取电话状态
服务列表
VirSCANVirSCAN
名称
com.ivali.qhbao.NotificationListener
com.ivali.qhbao.WxAccessibilityService
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0xb23e0f38
META-INF/IVALI.SF 0xe71aff7f
META-INF/IVALI.RSA 0x56007008
AndroidManifest.xml 0x7dc28dea
assets/ 0x0
assets/com.tencent.open.config.json 0xb3d4a81a
assets/libprotectClass.so 0x2ffe3c52
assets/libprotectClass_x86.so 0xec531b66
assets/libqupc.so 0xcab5b1cf
assets/libwbsafeedit 0xb05a63a9
classes.dex 0x49949bd1
res/anim/icon_run.xml 0xbaae0881
res/anim/rock.xml 0x75c64b55
res/anim/share.xml 0x5a0351b8
res/anim/share_dialog_bg.xml 0xdbc205ee
res/anim/share_dialog_bg_corners.xml 0x3371f1f0
res/anim/share_dialog_in_anim.xml 0xea0bfaca
res/anim/share_dialog_out_anim.xml 0x612334d0
res/anim/share_select.xml 0xdb459ab0
res/anim/share_unselect.xml 0x95c798f8
res/drawable-hdpi-v4/hongbao_share.png 0x21dee9a1
res/drawable-hdpi-v4/title_bar_back.9.png 0xae6c72ee
res/drawable-xhdpi-v4/logo_qq.png 0xa2fff7e4
res/drawable-xhdpi-v4/logo_qzone.png 0xfc0a902f
res/drawable-xhdpi-v4/logo_wechat.png 0x499fa2a2
res/drawable-xhdpi-v4/logo_wechatmoments.png 0xf3e0cf25
res/drawable-xxhdpi-v4/hongbao1.png 0xa4fa8336
res/drawable-xxhdpi-v4/hongbao2.png 0x5a33ca2b
res/drawable-xxhdpi-v4/hongbao3.png 0x7caccc1a
res/drawable-xxhdpi-v4/hongbao4.png 0x9cad7790
res/drawable-xxhdpi-v4/hongbao5.png 0x57ebc579
res/drawable-xxhdpi-v4/hongbao6.png 0x31b0988f
res/drawable-xxhdpi-v4/hongbao7.png 0xfc469163
res/drawable-xxhdpi-v4/ivali_logo.png 0xf1fed34d
res/drawable-xxhdpi-v4/logo.png 0x310a535d
res/drawable-xxhdpi-v4/logo_rq.jpg 0x4d181e4b
res/drawable-xxhdpi-v4/power_by_meejian.png 0x78c23af3
res/drawable-xxhdpi-v4/remind.jpg 0x828b97a
res/drawable-xxhdpi-v4/run.png 0x2384b43
res/drawable-xxhdpi-v4/run1.png 0xaaf4cc6e
res/drawable-xxhdpi-v4/run2.png 0x6bad7b4
res/drawable-xxhdpi-v4/run3.png 0x1164e492
res/drawable-xxhdpi-v4/top.jpg 0x7d5244c1
res/layout/activity_main.xml 0xbf75063a
res/layout/browser.xml 0xedcbb228
res/layout/notify_status_bar_latest_event_view.xml 0xa45d4b06
res/layout/share_dialog.xml 0x58953793
res/layout/version_dialog.xml 0x30249d75
res/xml/listener_service.xml 0x28b37ae2
resources.arsc 0xa055faef
运行截图
VirSCANVirSCAN
VirSCAN