VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:6%Antivirus software(2/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2016-05-12 21:41:57 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 5
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 150725-1 4.7.4 2015-07-25 Found nothing 23
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 6
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 9
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 1
clamav 19861 0.97.5 2014-12-31 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 46
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 4
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 30
gdata 25.6554 25.6554 2016-05-11 Android.Trojan.Agent.gXYSM 8
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 9
jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 40
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 42
kingsoft 2.1 2.1 2013-09-22 Found nothing 4
mcafee 7638 5400.1158 2014-11-30 Found nothing 30
nod32 0920 3.0.21 2014-12-23 Found nothing 1
panda 9.05.01 9.05.01 2015-07-26 Found nothing 4
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 4
qh360 1.0.1 1.0.1 1.0.1 Found nothing 2
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 1
quickheal 14.00 14.00 2015-07-25 Found nothing 2
rising 25.76.04.01 25.76.04.01 2015-07-24 Trojan.Android.SMSreg.g 2
sophos 5.08 3.55.0 2014-12-01 Found nothing 6
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 2
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 2
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 13
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 8
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 6
权限列表
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.SEND_SMS 发送短信
android.permission.READ_SMS 读取短信
android.permission.WRITE_SMS 写短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.CALL_PHONE 拨打电话
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:b4e7491df9bd402209fbf32a66c47804
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.umpay.huafubao
最低运行环境:Android 1.6
版权:umpay
关键行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016051220160513
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds Cache
进程行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016051220160513
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds Cache
文件行为
VirSCANVirSCAN
行为描述: 创建文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016051220160513\index.dat
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\dnserrordiagoff[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\noConnect[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\background_gradient[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\down[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\favcenter[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\tools[2]
行为描述: 覆盖已有文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\dnserrordiagoff[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\noConnect[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\background_gradient[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\down[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\favcenter[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\tools[2]
行为描述: 删除文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\dnserrordiagoff[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\ErrorPageTemplate[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\noConnect[3]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\bullet[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\background_gradient[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\down[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\favcenter[3]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\tools[1]
行为描述: 修改文件内容
详情信息: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016051220160513\index.dat ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\dnserrordiagoff[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\ErrorPageTemplate[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\noConnect[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[2] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\background_gradient[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\down[2] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\favcenter[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\tools[2] ---> Offset = 0
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016051220160513
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds Cache
网络行为
VirSCANVirSCAN
行为描述: 打开HTTP连接
详情信息: InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489), hSession = 0x00cc0004
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Internet Explorer\Default MHTML Editor\Last
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016051220160513\CachePath
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016051220160513\CachePrefix
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016051220160513\CacheLimit
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016051220160513\CacheOptions
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016051220160513\CacheRepair
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Count
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Time
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\LoadTime
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\LoadTimeCount
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
行为描述: 删除注册表键值
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
行为描述: 删除注册表键
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012015082520150826\
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: Local\!PrivacIE!SharedMemory!Mutex
SmartScreen_UrsCacheMutex_2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2High_S-*
Local\c:!documents and settings!administrator!local settings!history!history.ie5!mshist012016051220160513!
Local\c:!documents and settings!administrator!local settings!application data!microsoft!feeds cache!
RasPbFile
行为描述: 创建事件对象
详情信息: EventName = Global\crypt32LogoffEvent
EventName = DINPUTWINMM
EventName = Global\userenv: User Profile setup event
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [MS_AutodialMonitor,]
NtUserFindWindowEx: [Class,Window] = [MS_WebCheckMonitor,]
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [缩放级别,ToolbarWindow32]
[Window,Class] = [,msctls_progress32]
行为描述: 窗口信息
详情信息: Pid = 3248, Hwnd=0x702c0, Text = 导航栏, ClassName = WorkerW.
Pid = 3248, Hwnd=0x102de, Text = 地址组合控制, ClassName = ToolbarWindow32.
Pid = 3248, Hwnd=0x102e2, Text = 页面控制, ClassName = ToolbarWindow32.
Pid = 3248, Hwnd=0x102f2, Text = 搜索..., ClassName = Edit.
Pid = 3248, Hwnd=0x102f6, Text = 搜索组合控制, ClassName = ToolbarWindow32.
Pid = 3248, Hwnd=0x102f8, Text = 搜索控制, ClassName = ToolbarWindow32.
Pid = 3248, Hwnd=0x10312, Text = 命令栏, ClassName = ToolbarWindow32.
Pid = 3248, Hwnd=0x1030a, Text = 收藏夹命令栏, ClassName = ToolbarWindow32.
Pid = 3248, Hwnd=0x102fe, Text = LinksBand, ClassName = LinksBandClass.
Pid = 3248, Hwnd=0x10306, Text = 收藏夹栏, ClassName = ToolbarWindow32.
Pid = 3248, Hwnd=0x10302, Text = 添加到收藏夹栏, ClassName = ToolbarWindow32.
Pid = 3328, Hwnd=0x10328, Text = ITBarHost, ClassName = InternetToolbarHost.
Pid = 3328, Hwnd=0x1032a, Text = 菜单栏, ClassName = WorkerW.
Pid = 3328, Hwnd=0x1033c, Text = 缩放级别, ClassName = ToolbarWindow32.
Activities
VirSCANVirSCAN
活动名 类型
.ui.SplashActivity android.intent.action.MAIN
.ui.SplashActivity android.intent.category.LAUNCHER
.ui.BillingActivity com.umpay.huahubao.billing
.ui.BillingActivity android.intent.category.DEFAULT
危险函数
VirSCANVirSCAN
函数名称 信息
HttpClient;->execute 请求远程服务器
ContentResolver;->delete 删除短信、联系人
android/app/NotificationManager;->notify 信息通知栏
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
SmsManager;->sendTextMessage 发送普通短信
启动方式
VirSCANVirSCAN
名称 信息
com.umpay.huafubao.receiver.SMSReceiver 监控短信(收到短信)启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.SEND_SMS 发送短信
android.permission.READ_SMS 读取短信
android.permission.WRITE_SMS 写短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.CALL_PHONE 拨打电话
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
服务列表
VirSCANVirSCAN
名称
com.umpay.huafubao.service.AppUpgradeService
文件列表
VirSCANVirSCAN
文件名 校验码
res/anim/rotate.xml 0x24ca1290
res/drawable/btn.xml 0xc4a29572
res/drawable/btn2.xml 0xef94bbd3
res/drawable/btn_normal.9.png 0x3c9a931
res/drawable/btn_pressed.9.png 0xee31a5ca
res/drawable/cmcc.png 0xa1f640bf
res/drawable/exit_mainitem.xml 0xa85cbd3a
res/drawable/exit_normal.9.png 0xc0927a66
res/drawable/exit_pressed.9.png 0x74a79077
res/drawable/info_mainitem.xml 0xf65f79fc
res/drawable/info_normal.9.png 0x6bffe3ba
res/drawable/info_pressed.9.png 0x88f481f6
res/drawable/listview_bg.9.png 0xccb492ed
res/drawable/main_info_bg.xml 0xfbef86d8
res/drawable/merdesc_info_bg.xml 0x5ce3631f
res/drawable/progressbar.xml 0x3316c96
res/drawable/progressbar_moreloading.xml 0x2e63da2a
res/drawable/pull_to_refresh_header_background.xml 0x4b9e4f12
res/drawable/record_mainitem.xml 0xbb34e158
res/drawable/record_normal.9.png 0xbc836301
res/drawable/record_pressed.9.png 0xb8b2611d
res/drawable/refreshable_listview_arrow.png 0x32192a53
res/drawable/result_bg.9.png 0xc167a795
res/drawable/service_mainitem.xml 0xc564a4f8
res/drawable/service_normal.9.png 0xbeac627
res/drawable/service_pressed.9.png 0xa98ad06
res/drawable/tab_click.9.png 0x257fc22a
res/drawable/tab_log_item_bg.xml 0x4510f1f4
res/drawable/tab_textcolor.xml 0xd928263
res/drawable/top.jpg 0xb4a22aa8
res/drawable/update_mainitem.xml 0xaa472132
res/drawable/update_normal.9.png 0x1da636e2
res/drawable/update_pressed.9.png 0xf505fd05
res/layout/activity_main.xml 0xd75183a6
res/layout/app_upgrade_notification.xml 0x71db3dc1
res/layout/billing2.xml 0xb020ed60
res/layout/info.xml 0x12b04aad
res/layout/info_list_item.xml 0x78cbd53
res/layout/lay1.xml 0x99e27fc6
res/layout/lay2.xml 0x446a2f29
res/layout/layout1.xml 0x1ebc986f
res/layout/listview_footer.xml 0x267613ea
res/layout/log_detail.xml 0x7243f15
res/layout/log_list_item.xml 0x1a2414a3
res/layout/main.xml 0x26397227
res/layout/news.xml 0x7e259d5f
res/layout/refreshable_list_header.xml 0xe10b7ea5
res/layout/splash.xml 0x196cafce
res/layout/success.xml 0x79de814d
res/layout/title3.xml 0xbe905daf
res/layout/title_one.xml 0xdad94341
AndroidManifest.xml 0x19ded97e
resources.arsc 0xc253ce14
res/drawable-hdpi/application.png 0xb1126a64
res/drawable-hdpi/tab_button.xml 0x8dc1a72f
res/drawable-ldpi/app_title_bg.png 0xed36d193
res/drawable-ldpi/application.png 0x3e4b67f8
res/drawable-ldpi/btn_back_bg.xml 0xbcd601fd
res/drawable-ldpi/btn_back_n.9.png 0x3c42eeeb
res/drawable-ldpi/btn_back_p.9.png 0xfbeed4cc
res/drawable-ldpi/logo_info.png 0xd7625a0
res/drawable-ldpi/tab_item_n.9.png 0x8d181922
res/drawable-ldpi/tab_item_p.9.png 0xe7c5add7
res/drawable-mdpi/android.png 0x27501cc9
res/drawable-mdpi/app_title_bg.png 0xd873f84c
res/drawable-mdpi/application.png 0xfee12bfb
res/drawable-mdpi/line.png 0x6a55fdee
res/drawable-mdpi/loading.png 0xff7e6b77
res/drawable-mdpi/logo.png 0xc5b32311
res/drawable-mdpi/main_bg.jpg 0xed6fa885
res/drawable-mdpi/spinner_white_48.png 0x50fc7611
classes.dex 0x6009d0f0
META-INF/MANIFEST.MF 0xdeb33bb8
META-INF/CERT.SF 0x54468f5e
META-INF/CERT.RSA 0xb21f5df5
运行截图
VirSCANVirSCAN
VirSCAN