VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:0%Scanner(s) (0/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-01 19:51:02 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 4
antivir 1.9.2.0 1.9.159.0 7.11.182.144 Found nothing 16
antiy 112604 AVL141030 2014-10-31 Found nothing 5
arcavir 1.0 2011 2014-05-30 Found nothing 12
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 2
avast 141031-1 4.7.4 2014-10-31 Found nothing 37
avg 2109/7906 10.0.1405 2014-10-17 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 5
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.57469 7.90123 2014-10-31 Found nothing 16
clamav 19561 0.97.5 2014-10-31 Found nothing 1
comodo 15023 5.1 2014-10-31 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-10-31 Found nothing 58
fortinet Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-10-31 Found nothing 3
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 2
gdata 24.4702 24.4702 2014-11-01 Found nothing 9
hauri 2.73 2.73 2014-10-30 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-10-31 Found nothing 29
jiangmin 16.0.100 1.0.0.0 2014-08-20 Found nothing 33
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 49
kingsoft 2.1 2.1 2013-09-22 Found nothing 4
mcafee 7520 5400.1158 2014-08-04 Found nothing 25
nod32 0436 3.0.21 2014-09-18 Found nothing 1
panda 9.05.01 9.05.01 2014-10-31 Found nothing 5
pcc 11.246.06 9.500-1005 2014-10-31 Found nothing 1
qh360 1.0.1 1.0.1 1.0.1 Found nothing 14
qqphone 1.0.0.0 1.0.0.0 2014-11-01 Found nothing 1
quickheal 14.00 14.00 2014-10-31 Found nothing 2
rising 25.38.01.01 25.38.01.01 2014-10-28 Found nothing 1
sophos 5.04 3.51.0 2014-08-05 Found nothing 7
sunbelt 3.9.2595.2 3.9.2595.2 2014-10-29 Found nothing 3
symantec 20141028.001 1.3.0.24 2014-10-28 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
thehacker 6.8.0.5 6.8.0.5 2014-10-27 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-10-31 Found nothing 6
vba 3.12.26.3 3.12.26.3 2014-10-31 Found nothing 10
virusbuster 15.0.953.1 5.5.2.13 2014-10-31 Found nothing 41
权限列表
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.VIBRATE 允许设备震动
com.ywqc.color.permission.MIPUSH_RECEIVE
文件信息
VirSCANVirSCAN
安全评分 :72
基本信息
VirSCANVirSCAN
MD5:98011d7062d2ca3bf77bc8077a8a8347
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.ywqc.color
最低运行环境:Android 2.2.x
版权:Ywqc Studio
关键行为
VirSCANVirSCAN
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,Afx:400000:8:10011:1900015:0]
其他行为
VirSCANVirSCAN
行为描述: 窗口信息
详情信息: Pid = 1460, Hwnd=0xb01de, Text = 加载中。请耐心等待....., ClassName = Button(GroupBox).
Pid = 1460, Hwnd=0xb016a, Text = 启动中。。。请稍等............, ClassName = WTWindow.
Pid = 1460, Hwnd=0xb0336, Text = 确定, ClassName = Button.
Pid = 1460, Hwnd=0xa03a6, Text = 欢迎使用九尾在线充值系统, ClassName = Static.
Pid = 1460, Hwnd=0xa039e, Text = 九尾软件, ClassName = #32770.
Pid = 1460, Hwnd=0xb03b0, Text = 注册, ClassName = Button.
Pid = 1460, Hwnd=0x9035c, Text = 版本切换, ClassName = Button.
Pid = 1460, Hwnd=0xb0332, Text = 更新时间:, ClassName = Afx:400000:b:10011:1900015:0.
Pid = 1460, Hwnd=0xd038e, Text = 2014年11月1日19时13分1秒, ClassName = Afx:400000:b:10011:1900015:0.
Pid = 1460, Hwnd=0xd01c4, Text = 最新版本,自动更新! 检测版本为:腾讯QQ服务器端版1.6.1 ---------------- 购买注册码的用户在此期间可以免费向客服索要黑客大礼包 , ClassName = Afx:400000:b:10011:1900015:0.
Pid = 1460, Hwnd=0xd01f6, Text = 必看 :刷钻步骤 > 输入激活码激活软件 >勾选开通业务 > 选择刷钻服务器 > 输入QQ号> 开刷, ClassName = Afx:400000:b:10011:1900015:0.
Pid = 1460, Hwnd=0xb0170, Text = 全自动发卡网站jiuwei.28ka.com , ClassName = Afx:400000:b:10011:1900015:0.
Pid = 1460, Hwnd=0xc01b4, Text = 安全模式, ClassName = Button(CheckBox).
Pid = 1460, Hwnd=0xb01be, Text = 电信服务器, ClassName = Button(RadioButton).
Pid = 1460, Hwnd=0xa0196, Text = 网通服务器(推荐), ClassName = Button(RadioButton).
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,Afx:400000:8:10011:1900015:0]
行为描述: 创建互斥体
详情信息: RasPbFile
动态列表行为
VirSCANVirSCAN
行为描述: 传递附加信息
详情信息: Ljava/lang/String;=_mmessage_sdkVersion | I=553844737
Ljava/lang/String;=_mmessage_appPackage | Ljava/lang/String;=com.ywqc.color
Ljava/lang/String;=_mmessage_content | Ljava/lang/String;=weixin://registerapp?appid=wxef13d3064414829b
Ljava/lang/String;=_mmessage_checksum | [B={48, 99, 97, 51, 50, 98, 49, 99, 101, 50, 57, 100, 100, 98, 97, 99, 97, 101, 101, 99, 102, 97, 98, 55, 57, 54, 48, 100, 52, 100, 101, 53}
Ljava/lang/String;=mipush_app_package | Ljava/lang/String;=com.ywqc.color
Ljava/lang/String;=mipush_app_id | Ljava/lang/String;=2882303761517241590
Ljava/lang/String;=mipush_payload | [B={8, 0, 1, 0, 0, 0, 1, 2, 0, 2, 0, 2, 0, 3, 1, 11, 0, 4, 0, 0, 0, 104, 11, 0, 3, 0, 0, 0, 17, 79, 106, 111, 119, 49, 51, 57, 56, 56, 53, 49, 48, 56, 54, 48, 53, 51, 11, 0, 4, 0, 0, 0, 19, 50, 56, 56, 50, 51, 48, 51, 55, 54, 49, 53, 49, 55, 50, 52, 49, 53, 57, 48, 11, 0, 5, 0, 0, 0, 5, 49, 46, 50, 46, 49, 11, 0, 6, 0, 0, 0, 14, 99, 111, 109, 46, 121, 119, 113, 99, 46, 99, 111, 108, 111, 114, 11, 0, 7, 0, 0, 0, 13, 53, 55, 48, 49, 55, 50, 52, 49, 53, 53, 53, 57, 48, 0, 11, 0, 5, 0, 0, 0, 19, 50, 56, 56, 50, 51, 48, 51, 55, 54, 49, 53, 49, 55, 50, 52, 49, 53, 57, 48, 11, 0, 6, 0, 0, 0, 14, 99, 111, 109, 46, 121, 119, 113, 99, 46, 99, 111, 108, 111, 114, 12, 0, 7, 10, 0, 1, 0, 0, 0, 0, 0, 0, 0, 5, 11, 0, 2, 0, 0, 0, 6, 102, 97, 107, 101, 105, 100, 11, 0, 3, 0, 0, 0, 10, 120, 105, 97, 111, 109, 105, 46, 99, 111, 109, 11, 0, 4, 0, 0, 0, 0, 0, 0}
Ljava/lang/String;=mipush_session | Ljava/lang/String;=FcmKcZ
行为描述: 调用哈希算法
详情信息: MD5
行为描述: 读取文件
详情信息: path:/proc/meminfo length:105
path:/proc/783/cmdline length:105
path:/proc/798/cmdline length:105
path:/proc/810/cmdline length:105
path:/proc/840/cmdline length:105
path:/proc/851/cmdline length:105
path:/proc/907/cmdline length:105
path:/data/data/com.ywqc.color/shared_prefs/mipush.xml length:105
path:/proc/907/cmdline length:105
行为描述: 对指定数据计算哈希
详情信息: eixin://
53d9b28afd98c57a5d018713
139885108730553d9b28afd98c57a5d018713357242043237511
行为描述: 访问URL
详情信息: libcore.net.http.HttpURLConnectionImpl:http://117show.com/service/redirect/query?p=com.ywqc.color&pt=android&f=config
行为描述: 数据泄露
详情信息: sink:File operation:write data:data:<?xml version='1.0' encoding='utf-8' standalone='yes' ?> <map> <long name="session_end_time" value="
sink:File operation:write data:data:<?xml version='1.0' encoding='utf-8' standalone='yes' ?> <map> <long name="a_start_time" value="1398
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/com.ywqc.color-1.apk
行为描述: 设置组件属性
详情信息: Landroid/content/ComponentName;=ComponentInfo{com.ywqc.color/com.xiaomi.push.service.XMPushService} | I=1 | I=1
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
com.android.mms.transaction.SmsReceiverService
行为描述: 初始化Intent
详情信息: Ljava/lang/String;=com.tencent.mm.plugin.openapi.Intent.ACTION_HANDLE_APP_REGISTER
Landroid/content/Context;=com.ywqc.color.UIApplication@41539bb0 | Ljava/lang/Class;=class com.xiaomi.push.service.XMPushService
Landroid/content/Context;=com.ywqc.utility.update.UpdateService@415634a0 | Ljava/lang/Class;=class com.ywqc.utility.update.UpdateService
Ljava/lang/String;=com.xiaomi.mipush.RECEIVE_MESSAGE
行为描述: 获取设备ID
详情信息: 357242043237511
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/com.ywqc.color/shared_prefs/mipush.xml length:70
path:/data/data/com.ywqc.color/shared_prefs/mipush_extra.xml length:70
path:/data/data/com.ywqc.color/shared_prefs/mipush.xml length:105
path:/data/data/com.ywqc.color/shared_prefs/com.ywqc.color_preferences.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
VirSCANVirSCAN
活动名 类型
.MainActivity android.intent.action.MAIN
.MainActivity android.intent.category.LAUNCHER
危险函数
VirSCANVirSCAN
函数名称 信息
ContentResolver;->delete 删除短信、联系人
ContentResolver;->query 读取联系人、短信等数据库
java/net/URL;->openConnection 连接URL
java/net/HttpURLConnection;->connect 连接URL
getRuntime 获取命令行环境
java/lang/Runtime;->exec 执行字符串命令
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
HttpClient;->execute 请求远程服务器
android/app/NotificationManager;->notify 信息通知栏
启动方式
VirSCANVirSCAN
名称 信息
com.xiaomi.push.service.receivers.NetworkStatusReceiver 网络连接改变时启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.VIBRATE 允许设备震动
com.ywqc.color.permission.MIPUSH_RECEIVE
服务列表
VirSCANVirSCAN
名称
com.ywqc.utility.update.UpdateService
com.xiaomi.push.service.XMPushService
com.xiaomi.mipush.sdk.PushMessageHandler
文件列表
VirSCANVirSCAN
文件名 校验码
assets/117Color/img/share-tips.png 0x7f387dd
assets/117Color/res/libs.min.js 0xd6ba5d84
assets/117Color/res/m.min.css 0x5bf69074
assets/117Color/res/main.min.js 0xe7714c3f
assets/117Color/index.html 0x2a474464
res/drawable/icon.png 0xe10b6004
res/drawable/selector_install_btn.xml 0xc8bac96c
res/drawable/selector_skip_btn.xml 0x2f3cc062
res/layout/activity_main.xml 0x89ff9902
res/layout/entry.xml 0x25df269f
res/layout/view_downloading_notify.xml 0x2db919ff
AndroidManifest.xml 0xbc82fd74
resources.arsc 0x2cfb61b8
res/drawable-hdpi/icon.png 0xe10b6004
res/drawable-hdpi/install_normal.png 0x2c888f81
res/drawable-hdpi/install_pressed.png 0xf776464b
res/drawable-hdpi/skip_normal.png 0xff84dee2
res/drawable-hdpi/skip_pressed.png 0xdbc4804a
res/drawable-ldpi/icon.png 0xe10b6004
res/drawable-mdpi/icon.png 0xe10b6004
res/drawable-xhdpi/icon.png 0xe10b6004
res/drawable-xxhdpi/icon.png 0xe10b6004
classes.dex 0xe73172b4
META-INF/MANIFEST.MF 0xeabbaf15
META-INF/CERT.SF 0xaa5c48ce
META-INF/CERT.RSA 0xfdb49c94
运行截图
VirSCANVirSCAN
VirSCAN