VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:12%Scanner(s) (5/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-10-30 17:38:31 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 3
antivir 1.9.2.0 1.9.159.0 7.11.182.42 Found nothing 40
antiy 114701 AVL141003 2014-10-04 Found nothing 9
arcavir 1.0 2011 2014-05-30 Found nothing 11
asquared 9.0.0.4157 9.0.0.4157 2014-07-30 Found nothing 3
avast 141029-1 4.7.4 2014-10-29 Found nothing 60
avg 2109/7906 10.0.1405 2014-10-17 Found nothing 13
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 3
baidusd 1.0 1.0 2014-04-02 Found nothing 4
bitdefender 7.57431 7.90123 2014-10-29 Android.Riskware.Tekwon.A 10
clamav 19554 0.97.5 2014-10-30 Found nothing 17
comodo 15023 5.1 2014-10-03 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 2
drweb 5.0.2.3300 5.0.1.1 2014-10-30 Found nothing 59
fortinet 23.078, 23.078 5.1.158 2014-10-30 Android/Tekwon.A!tr 13
fprot 4.6.2.117 6.5.1.5418 2014-10-29 Found nothing 10
fsecure 2014-04-02-01 9.13 2014-04-02 Android.Riskware.Tekwon.A 29
gdata 24.3819 24.3819 2014-08-29 Found nothing 12
hauri 2.73 2.73 2014-06-13 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-10-29 Found nothing 58
jiangmin 16.0.100 1.0.0.0 2014-07-28 Found nothing 15
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 56
kingsoft 2.1 2.1 2013-09-22 Found nothing 56
mcafee 7520 5400.1158 2014-08-04 Found nothing 42
nod32 0436 3.0.21 2014-09-18 a variant of Android/Tekwon.A trojan 20
panda 9.05.01 9.05.01 2014-06-15 Found nothing 4
pcc 11.242.06 9.500-1005 2014-10-29 Found nothing 8
qh360 1.0.1 1.0.1 1.0.1 Found nothing 12
qqphone 1.0.0.0 1.0.0.0 2014-10-30 Found nothing 2
quickheal 14.00 14.00 2014-06-14 Found nothing 10
rising 25.17.00.04 25.17.00.04 2014-06-02 Found nothing 14
sophos 5.04 3.51.0 2014-08-05 Andr/TekWon-A 25
sunbelt 3.9.2589.2 3.9.2589.2 2014-06-13 Found nothing 11
symantec 20141028.001 1.3.0.24 2014-10-28 Found nothing 3
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 7
thehacker 6.8.0.5 6.8.0.5 2014-06-12 Found nothing 8
tws 17.47.17308 1.0.2.2108 2014-06-16 Found nothing 14
vba 3.12.26.3 3.12.26.3 2014-10-29 Found nothing 37
virusbuster 15.0.952.0 5.5.2.13 2014-10-28 Found nothing 49
权限列表
许可名称 信息
android.permission.VIBRATE 允许设备震动
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_CONTACTS 读取联系人信息
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.WRITE_CONTACTS 写入联系人信息
android.permission.SEND_SMS 发送短信
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ADD_SYSTEM_SERVICE
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.INSTALL_PACKAGES 安装应用
android.permission.MOUNT_UNMOUNT_FILESYSTEMS 挂载、反挂载外部文件系统
android.permission.CHANGE_NETWORK_STATE 变更网络状态
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.RESTART_PACKAGES 重启其他程序
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.ACCESS_SURFACE_FLINGER 访问SurfaceFlinger
android.permission.EXPAND_STATUS_BAR 操控状态栏
android.permission.BROADCAST_STICKY 发送持久广播
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.WRITE_APN_SETTINGS 改写APN设置(如:cmwap)
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
com.android.launcher.permission.INSTALL_SHORTCUT 创建快捷方式
com.android.launcher.permission.UNINSTALL_SHORTCUT 删除快捷方式
com.android.launcher.permission.READ_SETTINGS 读取快捷方式信息
android.permission.DISABLE_KEYGUARD 禁用键盘锁
android.permission.CAMERA 访问照相机设备
android.permission.CALL_PHONE 拨打电话
android.permission.BLUETOOTH_ADMIN 搜寻蓝牙设备
android.permission.BLUETOOTH 连接蓝牙设备
android.permission.CHANGE_CONFIGURATION 修改当前设置(如:本地化)
android.permission.ACCESS_FINE_LOCATION 获取精确的位置(通过GPS)
android.permission.ACCESS_MOCK_LOCATION 获取模拟定位信息
android.permission.ACCESS_COARSE_LOCATION 获取粗略的位置(通过wifi、基站)
android.permission.UPDATE_DEVICE_STATS 更新设备状态
adnroid.permission.ACCESS_CHECKIN_PROPERTTES
android.permission.CHANGE_WIFI_STATE 改变WIFI连接状态
android.permission.MODIFY_PHONE_STATE 修改电话状态
android.permission.BATTERY_STATS 电量统计
android.permission.RECORD_AUDIO 录音(使用AudioRecord)
android.permission.WRITE_CALENDAR 写入日程提醒
android.permission.READ_CALENDAR 读取日程提醒
文件信息
VirSCANVirSCAN
安全评分 :86
基本信息
VirSCANVirSCAN
MD5:0c43fba456629a89e9ad9cdabc6446fe
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.wondertek.ahPalm10000
最低运行环境:Android 2.1.x
版权:wd
关键行为
VirSCANVirSCAN
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
进程行为
VirSCANVirSCAN
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
文件行为
VirSCANVirSCAN
行为描述: 创建可执行文件
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-7R099.tmp\is-V8GST.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-UL4V3.tmp\_isetup\_shfoldr.dll
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
其他行为
VirSCANVirSCAN
行为描述: 窗口信息
详情信息: Pid = 188, Hwnd=0xb01ce, Text = Welcome to the IE Privacy Keeper Setup Wizard , ClassName = TNewStaticText.
Pid = 188, Hwnd=0xb0170, Text = This will install IE Privacy Keeper 2.7.3 on your computer. It is recommended that you close all other applications before con, ClassName = TNewStaticText.
Pid = 188, Hwnd=0xa018c, Text = LICENSE AGREEMENT IE Privacy Keeper is distributed as freeware. This means: 1. All copyrights to IE Privacy Keeper are e, ClassName = TRichEditViewer.
Pid = 188, Hwnd=0xa0198, Text = The setup program detected the older version of IE Privacy Keeper installed on this machine. It is very important to correctly un, ClassName = TRichEditViewer.
Pid = 188, Hwnd=0xb01be, Text = &Next >, ClassName = TButton.
Pid = 188, Hwnd=0xa0196, Text = Cancel, ClassName = TButton.
Pid = 188, Hwnd=0xe01c2, Text = Setup - IE Privacy Keeper, ClassName = TWizardForm.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
动态列表行为
VirSCANVirSCAN
行为描述: 缓冲区读取一行数据
详情信息: Processor : ARMv7 Processor rev 0
BogoMIPS : 453.83
Features : swp half thumb fastmult vfp edsp neon vfpv3
CPU implementer : 0x41
CPU architecture: 7
CPU variant : 0x0
CPU part : 0xc08
CPU revision : 0
Hardware : Goldfish
Revision : 0000
Serial : 0000000000000000
null
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
com.android.mms.transaction.SmsReceiverService
行为描述: 读取文件
详情信息: path:/proc/cpuinfo length:105
path:/proc/cpuinfo length:105
path:/proc/799/cmdline length:105
path:/proc/811/cmdline length:105
path:/proc/841/cmdline length:105
path:/proc/854/cmdline length:105
path:/proc/877/cmdline length:105
path:/proc/879/cmdline length:105
path:/proc/901/cmdline length:105
path:/proc/903/cmdline length:105
path:/proc/912/cmdline length:105
path:/proc/1/cmdline length:105
path:/proc/2/cmdline length:105
path:/proc/3/cmdline length:105
path:/proc/4/cmdline length:105
path:/proc/5/cmdline length:105
path:/proc/6/cmdline length:105
path:/proc/7/cmdline length:105
path:/proc/8/cmdline length:105
path:/proc/9/cmdline length:105
path:/proc/10/cmdline length:105
path:/proc/11/cmdline length:105
path:/proc/12/cmdline length:105
path:/proc/13/cmdline length:105
path:/proc/14/cmdline length:105
path:/proc/24/cmdline length:105
path:/proc/25/cmdline length:105
path:/proc/26/cmdline length:105
path:/proc/27/cmdline length:105
path:/proc/28/cmdline length:105
path:/proc/29/cmdline length:105
path:/proc/30/cmdline length:105
path:/proc/32/cmdline length:105
path:/proc/33/cmdline length:105
path:/proc/34/cmdline length:105
path:/proc/35/cmdline length:105
path:/proc/36/cmdline length:105
path:/proc/37/cmdline length:105
path:/proc/38/cmdline length:105
path:/proc/39/cmdline length:105
path:/proc/40/cmdline length:105
path:/proc/41/cmdline length:105
path:/proc/42/cmdline length:105
path:/proc/45/cmdline length:105
path:/proc/46/cmdline length:105
path:/proc/148/cmdline length:105
path:/proc/252/cmdline length:105
path:/proc/297/cmdline length:105
path:/proc/340/cmdline length:105
path:/proc/353/cmdline length:105
path:/proc/374/cmdline length:105
path:/proc/385/cmdline length:105
path:/proc/425/cmdline length:105
path:/proc/454/cmdline length:105
path:/proc/484/cmdline length:105
path:/proc/519/cmdline length:105
path:/proc/541/cmdline length:105
path:/proc/554/cmdline length:105
path:/proc/572/cmdline length:105
path:/proc/589/cmdline length:105
path:/proc/637/cmdline length:105
path:/proc/649/cmdline length:105
path:/proc/691/cmdline length:105
path:/proc/783/cmdline length:105
path:/proc/799/cmdline length:105
path:/proc/811/cmdline length:105
path:/proc/841/cmdline length:105
path:/proc/854/cmdline length:105
path:/proc/912/cmdline length:105
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/com.wondertek.ahPalm10000-1.apk
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:98
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:94
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:94
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:63
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:104
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:86
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:101
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:100
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:83
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:89
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:80
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:80
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:72
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:83
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:82
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:71
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:69
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:104
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:93
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:76
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:77
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:81
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:89
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:87
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:83
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:77
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:90
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:80
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:85
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:92
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:77
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:103
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:86
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:96
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:98
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:98
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:90
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:96
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:91
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:101
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:100
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:98
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:69
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:72
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:92
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:95
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:95
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:93
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:96
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:98
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:100
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:93
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:92
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:95
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:96
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:100
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:100
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:99
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:85
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:72
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:40
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:81
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:94
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:92
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:22
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:101
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:72
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:87
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:104
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:71
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:89
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:103
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:104
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:98
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:66
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:86
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:74
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:81
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:78
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:96
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:97
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:92
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:94
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:92
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:93
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:93
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:83
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:65
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:88
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:71
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:53
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:57
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:59
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:65
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:55
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:105
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:96
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:91
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:94
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:104
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:96
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:93
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:98
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:102
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:103
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:102
path:/data/data/com.wondertek.ahPalm10000/framework.dat length:96