VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:25%Scanner(s) (10/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-03 14:41:21 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
权限列表
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.SEND_SMS 发送短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.READ_SMS 读取短信
android.permission.WRITE_SMS 写短信
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.KILL_BACKGROUND_PROCESSES 关闭后台进程
文件信息
VirSCANVirSCAN
安全评分 :39
基本信息
VirSCANVirSCAN
MD5:7f3eada20946dfef8d945399f668aa50
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:sdgfds.retert.sdgbcxsdgds
最低运行环境:Android 2.2.x
版权:Android
关键行为
VirSCANVirSCAN
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [Tab,SysTabControl32]
[Window,Class] = [Selected Tab,#32770]
[Window,Class] = [,nsdockspliter]
[Window,Class] = [,wedockspliter]
[Window,Class] = [,splitterContainer]
[Window,Class] = [,wespliter]
[Window,Class] = [,Scintilla]
文件行为
VirSCANVirSCAN
行为描述: 修改文件内容
详情信息: C:\%temp%\1414948809.229220.exe_7zdump\langs.xml---> Offset = 0
C:\%temp%\1414948809.270897.exe_7zdump\config.xml---> Offset = 0
C:\%temp%\1414948809.312643.exe_7zdump\stylers.xml---> Offset = 0
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
其他行为
VirSCANVirSCAN
行为描述: 窗口信息
详情信息: Pid = 728, Hwnd=0xc01b2, Text = Selected Tab, ClassName = #32770.
Pid = 728, Hwnd=0xc01ee, Text = Caption, ClassName = Button.
Pid = 728, Hwnd=0xa01f0, Text = Tab1, ClassName = SysTabControl32.
Pid = 728, Hwnd=0xc01b6, Text = Selected Tab, ClassName = #32770.
Pid = 728, Hwnd=0xe01b8, Text = Caption, ClassName = Button.
Pid = 728, Hwnd=0xb01a2, Text = Tab1, ClassName = SysTabControl32.
Pid = 728, Hwnd=0xb0164, Text = Selected Tab, ClassName = #32770.
Pid = 728, Hwnd=0xb0192, Text = Caption, ClassName = Button.
Pid = 728, Hwnd=0xb0174, Text = Tab1, ClassName = SysTabControl32.
Pid = 728, Hwnd=0xa0196, Text = Selected Tab, ClassName = #32770.
Pid = 728, Hwnd=0xb01be, Text = Caption, ClassName = Button.
Pid = 728, Hwnd=0xb0170, Text = Tab1, ClassName = SysTabControl32.
Pid = 728, Hwnd=0xb016a, Text = N, ClassName = Scintilla.
Pid = 728, Hwnd=0xd01c8, Text = N, ClassName = Scintilla.
Pid = 728, Hwnd=0xc01c2, Text = N, ClassName = Scintilla.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [Tab,SysTabControl32]
[Window,Class] = [Selected Tab,#32770]
[Window,Class] = [,nsdockspliter]
[Window,Class] = [,wedockspliter]
[Window,Class] = [,splitterContainer]
[Window,Class] = [,wespliter]
[Window,Class] = [,Scintilla]
行为描述: 创建互斥体
详情信息: nppInstance
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
危险行为
VirSCANVirSCAN
行为描述: 监听包含特定号码或内容的短信
详情信息: 1
动态列表行为
VirSCANVirSCAN
行为描述: 传递附加信息
详情信息: Ljava/lang/String;=android.app.extra.DEVICE_ADMIN | Landroid/os/Parcelable;=ComponentInfo{sdgfds.retert.sdgbcxsdgds/sdgfds.retert.sdgbcxsdgds.DevicesReceiver2}
Ljava/lang/String;=android.app.extra.ADD_EXPLANATION | Ljava/lang/String;=
行为描述: 添加设备管理器
详情信息:
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
sdgfds.retert.sdgbcxsdgds.MyServers1
com.android.mms.transaction.SmsReceiverService
行为描述: 读取文件
详情信息: path:/proc/758/cmdline length:105
path:/proc/760/cmdline length:105
path:/proc/772/cmdline length:105
path:/proc/774/cmdline length:105
path:/proc/783/cmdline length:105
path:/proc/799/cmdline length:105
path:/proc/811/cmdline length:105
path:/proc/841/cmdline length:105
path:/proc/852/cmdline length:105
path:/proc/878/cmdline length:105
path:/proc/880/cmdline length:105
行为描述: 注册ContentObserver
详情信息: URI=content://sms/
行为描述: 监听包含特定号码或内容的短信
详情信息: 1
行为描述: 设置组件属性
详情信息: Landroid/content/ComponentName;=ComponentInfo{sdgfds.retert.sdgbcxsdgds/sdgfds.retert.sdgbcxsdgds.MainActivity} | I=2 | I=1
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/sdgfds.retert.sdgbcxsdgds-1.apk
path:/mnt/sdcard/bjshow/file/cao.apk
行为描述: 初始化Intent
详情信息: Landroid/content/Context;=sdgfds.retert.sdgbcxsdgds.MainActivity@415385f8 | Ljava/lang/Class;=class sdgfds.retert.sdgbcxsdgds.MyServers1
Ljava/lang/String;=android.app.action.ADD_DEVICE_ADMIN
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/sdgfds.retert.sdgbcxsdgds/shared_prefs/data.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
VirSCANVirSCAN
活动名 类型
sdgfds.retert.sdgbcxsdgds.MainActivity android.intent.action.MAIN
sdgfds.retert.sdgbcxsdgds.MainActivity android.intent.category.LAUNCHER
启动方式
VirSCANVirSCAN
名称 信息
sdgfds.retert.sdgbcxsdgds.laixinxis 监控短信(收到短信)启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.SEND_SMS 发送短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.READ_SMS 读取短信
android.permission.WRITE_SMS 写短信
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.KILL_BACKGROUND_PROCESSES 关闭后台进程
服务列表
VirSCANVirSCAN
名称
sdgfds.retert.sdgbcxsdgds.MyServers1
文件列表
VirSCANVirSCAN
文件名 校验码
res/layout/main.xml 0xc16ddaae
res/menu/main.xml 0x1592ecff
res/raw/cao.apk 0xaf413f
res/xml/lock_screen.xml 0xeab2c16b
AndroidManifest.xml 0x1b977b59
resources.arsc 0x321ef670
res/drawable-hdpi/icon.jpg 0x3cfd8b52
classes.dex 0xabedd573
lib/armeabi/libfinalMa.so 0xdbafead9
META-INF/MANIFEST.MF 0xdba41d6
META-INF/CERT.SF 0xe7d72e01
META-INF/CERT.RSA 0xbb1b9dc3
运行截图
VirSCANVirSCAN
VirSCAN