VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:28%Scanner(s) (11/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-06 10:50:24 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 4
antivir 1.9.2.0 1.9.159.0 7.11.183.62 Found nothing 18
antiy 112633 AVL141104 2014-11-05 Found nothing 5
arcavir 1.0 2011 2014-05-30 Found nothing 9
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 141105-0 4.7.4 2014-11-05 Android:SMSThief-AX [Trj] 28
avg 2109/7906 10.0.1405 2014-10-17 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 2
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.57568 7.90123 2014-11-05 Android.Trojan.SmsSend.G 6
clamav 19588 0.97.5 2014-11-05 Found nothing 1
comodo 15023 5.1 2014-11-05 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-10-31 Found nothing 31
fortinet 23.123, 23.123 5.1.158 2014-11-06 Android/SmsThief.ANY!tr 1
fprot 4.6.2.117 6.5.1.5418 2014-11-05 Found nothing 1
fsecure 2014-04-02-01 9.13 2014-04-02 Trojan:Android/SmsThief.I 7
gdata 24.4794 24.4794 2014-11-05 Android.Trojan.SmsSend.G 7
hauri 2.73 2.73 2014-11-05 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-11-05 Trojan-SMS.AndroidOS.Agent 14
jiangmin 16.0.100 1.0.0.0 2014-08-20 Found nothing 31
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 19
kingsoft 2.1 2.1 2013-09-22 Android.Troj.at_emial.aa.(kcloud) 3
mcafee 7520 5400.1158 2014-08-04 Found nothing 8
nod32 0436 3.0.21 2014-09-18 multiple threats 1
panda 9.05.01 9.05.01 2014-11-05 Found nothing 4
pcc 11.258.05 9.500-1005 2014-11-05 Found nothing 2
qh360 1.0.1 1.0.1 1.0.1 Found nothing 16
qqphone 1.0.0.0 1.0.0.0 2014-11-06 a.privacy.emial.m 1
quickheal 14.00 14.00 2014-11-03 Android.Kilal.A 2
rising 25.38.01.01 25.38.01.01 2014-10-28 Found nothing 1
sophos 5.04 3.51.0 2014-08-05 Andr/SMSStl-B 10
sunbelt 3.9.2595.2 3.9.2595.2 2014-11-05 Found nothing 2
symantec 20141104.004 1.3.0.24 2014-11-04 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2014-11-03 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-11-05 Found nothing 6
vba 3.12.26.3 3.12.26.3 2014-11-05 Found nothing 3
virusbuster 15.0.959.0 5.5.2.13 2014-11-05 Found nothing 14
权限列表
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.SEND_SMS 发送短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.READ_SMS 读取短信
android.permission.WRITE_SMS 写短信
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.KILL_BACKGROUND_PROCESSES 关闭后台进程
文件信息
VirSCANVirSCAN
安全评分 :39
基本信息
VirSCANVirSCAN
MD5:7f3eada20946dfef8d945399f668aa50
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:sdgfds.retert.sdgbcxsdgds
最低运行环境:Android 2.2.x
版权:Android
关键行为
VirSCANVirSCAN
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [Tab,SysTabControl32]
[Window,Class] = [Selected Tab,#32770]
[Window,Class] = [,nsdockspliter]
[Window,Class] = [,wedockspliter]
[Window,Class] = [,splitterContainer]
[Window,Class] = [,wespliter]
[Window,Class] = [,Scintilla]
文件行为
VirSCANVirSCAN
行为描述: 修改文件内容
详情信息: C:\%temp%\1414948809.229220.exe_7zdump\langs.xml---> Offset = 0
C:\%temp%\1414948809.270897.exe_7zdump\config.xml---> Offset = 0
C:\%temp%\1414948809.312643.exe_7zdump\stylers.xml---> Offset = 0
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
其他行为
VirSCANVirSCAN
行为描述: 窗口信息
详情信息: Pid = 728, Hwnd=0xc01b2, Text = Selected Tab, ClassName = #32770.
Pid = 728, Hwnd=0xc01ee, Text = Caption, ClassName = Button.
Pid = 728, Hwnd=0xa01f0, Text = Tab1, ClassName = SysTabControl32.
Pid = 728, Hwnd=0xc01b6, Text = Selected Tab, ClassName = #32770.
Pid = 728, Hwnd=0xe01b8, Text = Caption, ClassName = Button.
Pid = 728, Hwnd=0xb01a2, Text = Tab1, ClassName = SysTabControl32.
Pid = 728, Hwnd=0xb0164, Text = Selected Tab, ClassName = #32770.
Pid = 728, Hwnd=0xb0192, Text = Caption, ClassName = Button.
Pid = 728, Hwnd=0xb0174, Text = Tab1, ClassName = SysTabControl32.
Pid = 728, Hwnd=0xa0196, Text = Selected Tab, ClassName = #32770.
Pid = 728, Hwnd=0xb01be, Text = Caption, ClassName = Button.
Pid = 728, Hwnd=0xb0170, Text = Tab1, ClassName = SysTabControl32.
Pid = 728, Hwnd=0xb016a, Text = N, ClassName = Scintilla.
Pid = 728, Hwnd=0xd01c8, Text = N, ClassName = Scintilla.
Pid = 728, Hwnd=0xc01c2, Text = N, ClassName = Scintilla.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [Tab,SysTabControl32]
[Window,Class] = [Selected Tab,#32770]
[Window,Class] = [,nsdockspliter]
[Window,Class] = [,wedockspliter]
[Window,Class] = [,splitterContainer]
[Window,Class] = [,wespliter]
[Window,Class] = [,Scintilla]
行为描述: 创建互斥体
详情信息: nppInstance
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
危险行为
VirSCANVirSCAN
行为描述: 监听包含特定号码或内容的短信
详情信息: 1
动态列表行为
VirSCANVirSCAN
行为描述: 传递附加信息
详情信息: Ljava/lang/String;=android.app.extra.DEVICE_ADMIN | Landroid/os/Parcelable;=ComponentInfo{sdgfds.retert.sdgbcxsdgds/sdgfds.retert.sdgbcxsdgds.DevicesReceiver2}
Ljava/lang/String;=android.app.extra.ADD_EXPLANATION | Ljava/lang/String;=
行为描述: 添加设备管理器
详情信息:
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
sdgfds.retert.sdgbcxsdgds.MyServers1
com.android.mms.transaction.SmsReceiverService
行为描述: 读取文件
详情信息: path:/proc/758/cmdline length:105
path:/proc/760/cmdline length:105
path:/proc/772/cmdline length:105
path:/proc/774/cmdline length:105
path:/proc/783/cmdline length:105
path:/proc/799/cmdline length:105
path:/proc/811/cmdline length:105
path:/proc/841/cmdline length:105
path:/proc/852/cmdline length:105
path:/proc/878/cmdline length:105
path:/proc/880/cmdline length:105
行为描述: 注册ContentObserver
详情信息: URI=content://sms/
行为描述: 监听包含特定号码或内容的短信
详情信息: 1
行为描述: 设置组件属性
详情信息: Landroid/content/ComponentName;=ComponentInfo{sdgfds.retert.sdgbcxsdgds/sdgfds.retert.sdgbcxsdgds.MainActivity} | I=2 | I=1
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/sdgfds.retert.sdgbcxsdgds-1.apk
path:/mnt/sdcard/bjshow/file/cao.apk
行为描述: 初始化Intent
详情信息: Landroid/content/Context;=sdgfds.retert.sdgbcxsdgds.MainActivity@415385f8 | Ljava/lang/Class;=class sdgfds.retert.sdgbcxsdgds.MyServers1
Ljava/lang/String;=android.app.action.ADD_DEVICE_ADMIN
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/sdgfds.retert.sdgbcxsdgds/shared_prefs/data.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
VirSCANVirSCAN
活动名 类型
sdgfds.retert.sdgbcxsdgds.MainActivity android.intent.action.MAIN
sdgfds.retert.sdgbcxsdgds.MainActivity android.intent.category.LAUNCHER
启动方式
VirSCANVirSCAN
名称 信息
sdgfds.retert.sdgbcxsdgds.laixinxis 监控短信(收到短信)启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.SEND_SMS 发送短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.READ_SMS 读取短信
android.permission.WRITE_SMS 写短信
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.KILL_BACKGROUND_PROCESSES 关闭后台进程
服务列表
VirSCANVirSCAN
名称
sdgfds.retert.sdgbcxsdgds.MyServers1
文件列表
VirSCANVirSCAN
文件名 校验码
res/layout/main.xml 0xc16ddaae
res/menu/main.xml 0x1592ecff
res/raw/cao.apk 0xaf413f
res/xml/lock_screen.xml 0xeab2c16b
AndroidManifest.xml 0x1b977b59
resources.arsc 0x321ef670
res/drawable-hdpi/icon.jpg 0x3cfd8b52
classes.dex 0xabedd573
lib/armeabi/libfinalMa.so 0xdbafead9
META-INF/MANIFEST.MF 0xdba41d6
META-INF/CERT.SF 0xe7d72e01
META-INF/CERT.RSA 0xbb1b9dc3
运行截图
VirSCANVirSCAN
VirSCAN