VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
File Name :5.0_至尊宝盒.apk (File not down)
File Size :8339860 byte
File Type :Zip archive data
MD5:ebcec2fce8bb9e0fee4db319b2b956c8
SHA1:863d50f84b39a0de9140287bd71ba6cd18ed5541
SHA256:362fc7164598d0e06b95a3f5baa1f9fcf5976743fb2a1f3437b5093a421893a4
SSDEEP:196608:3cRjoMKACpPyJtwMb1aHsgWnVeUaTmYik:3cdKjyB1aHbWnYUaTzik
  • 扫描结果
  • 权限
  • 文件行为分析
  • Scanner results
    Scanner results:0%Scanner(s) (0/32)found malware!
    Behavior analysis report:         Habo file analysis
    Time: 2017-07-27 06:19:27 (CST)
    VirSCANVirSCAN
    Scanner Engine Ver Sig Ver Sig Date Scan result Time
    antiy AVL SDK 2.0 1970-01-01 Found nothing 6
    asquared 9.0.0.4799 9.0.0.4799 2015-03-08 Found nothing 1
    avast 170303-1 4.7.4 2017-03-03 Found nothing 60
    avg 2109/14149 10.0.1405 2017-07-04 Found nothing 60
    baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 3
    baidusd 1.0 1.0 2017-03-22 Found nothing 2
    bitdefender 7.58879 7.90123 2015-01-16 Found nothing 60
    clamav 23596 0.97.5 2017-07-26 Found nothing 60
    drweb 5.0.2.3300 5.0.1.1 2017-06-18 Found nothing 60
    fortinet 50.473, 50.449, 50.305 5.4.247 2017-07-27 Found nothing 60
    fprot 4.6.2.117 6.5.1.5418 2016-02-05 Found nothing 60
    fsecure 2015-08-01-02 9.13 2015-08-01 Found nothing 60
    gdata 25.13563 25.13563 2017-07-27 Found nothing 13
    ikarus 1.06.01 V1.32.31.0 2016-11-28 Found nothing 60
    jiangmin 16.0.100 1.0.0.0 2017-07-25 Found nothing 2
    kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 60
    kingsoft 2.1 2.1 2017-07-26 Found nothing 5
    mcafee 8261 5400.1158 2016-08-18 Found nothing 60
    nod32 1777 3.0.21 2015-06-12 Found nothing 60
    panda 9.05.01 9.05.01 2017-07-26 Found nothing 4
    pcc 13.302.06 9.500-1005 2017-03-27 Found nothing 60
    qh360 1.0.1 1.0.1 1.0.1 Found nothing 5
    qqphone 1.0.0.0 1.0.0.0 2015-12-30 Found nothing 60
    quickheal 14.00 14.00 2017-07-26 Found nothing 3
    rising 26.28.00.01 26.28.00.01 2016-07-18 Found nothing 5
    sophos 5.32 3.65.2 2016-10-10 Found nothing 60
    symantec 20151230.005 1.3.0.24 2015-12-30 Found nothing 60
    tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
    thehacker 6.8.0.5 6.8.0.5 2017-07-24 Found nothing 3
    tws 17.47.17308 1.0.2.2108 2017-07-26 Found nothing 17
    vba 3.12.29.5 beta 3.12.29.5 beta 2017-07-25 Found nothing 60
    virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 60
    Heuristic/Suspicious Exact
    NOTICE: Results are not 100% accurate and can be reported as a false positive by some scannerswhen and if malware is found. Please judge these results for yourself.
  • 权限列表
    许可名称信息
    com.android.launcher.permission.INSTALL_SHORTCUT创建快捷方式
    android.permission.SET_WALLPAPER设置桌面壁纸
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
    android.permission.WRITE_EXTERNAL_STORAGE写外部存储器(如:SD卡)
    ACCESS_WIFI_STATE
    android.permission.ACCESS_WIFI_STATE读取wifi网络状态
    android.permission.ACCESS_COARSE_LOCATION获取粗略的位置(通过wifi、基站)
    android.permission.MOUNT_UNMOUNT_FILESYSTEMS挂载、反挂载外部文件系统
    android.permission.READ_PHONE_STATE读取电话状态
    android.permission.DISABLE_KEYGUARD禁用键盘锁
    android.permission.SYSTEM_ALERT_WINDOW显示系统窗口
    android.permission.ACCESS_WIFI_STATE.android.permission.READ_PHONE_STATE
    android.permission.INTERNET连接网络(2G或3G)
    android.permission.WRITE_SETTINGS读写系统设置项
    android.permission.CHANGE_WIFI_STATE改变WIFI连接状态
    android.permission.ACCESS_FINE_LOCATION获取精确的位置(通过GPS)
    android.permission.ACCESS_LOCATION_EXTRA_COMMANDS访问额外的定位指令
    com.android.launcher.permission.READ_SETTINGS读取快捷方式信息
    android.permission.ACCESS_NETWORK_STATE读取网络状态(2G或3G)
    android.permission.WAKE_LOCK手机屏幕关闭后后台进程仍运行
    android.permission.CHANGE_CONFIGURATION修改当前设置(如:本地化)
    android.permission.READ_SETTINGS
    android.permission.READ_EXTERNAL_STORAGE读外部存储器(如:SD卡)
  • 文件信息
    安全评分 :
    基本信息
    MD5:ebcec2fce8bb9e0fee4db319b2b956c8
    包名:com.zzbh
    最低运行环境:Android 2.2.x
    版权:E4A
    关键行为
    行为描述:设置特殊文件夹属性
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
    C:\Documents and Settings\Administrator\Local Settings\History
    C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
    C:\Documents and Settings\Administrator\Cookies
    C:\Documents and Settings\Administrator\IETldCache
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds Cache
    C:\Documents and Settings\Administrator\IECompatCache
    行为描述:直接获取CPU时钟
    详情信息:EAX = 0xfaabbf8f, EDX = 0x000000b5
    EAX = 0xfaabbfdb, EDX = 0x000000b5
    EAX = 0xfaabc027, EDX = 0x000000b5
    EAX = 0xfaabc073, EDX = 0x000000b5
    EAX = 0xfaabc0bf, EDX = 0x000000b5
    EAX = 0xfaabc10b, EDX = 0x000000b5
    EAX = 0xfaabc157, EDX = 0x000000b5
    EAX = 0xfaabc1a3, EDX = 0x000000b5
    EAX = 0xfaabc1ef, EDX = 0x000000b5
    EAX = 0xfaabc23b, EDX = 0x000000b5
    行为描述:获取窗口截图信息
    详情信息:Foreground window Info: HWND = 0x0001036a, DC = 0x0a010375.
    Foreground window Info: HWND = 0x00010364, DC = 0x01010055.
    Foreground window Info: HWND = 0x00010358, DC = 0x01010055.
    Foreground window Info: HWND = 0x0002036c, DC = 0x0a010375.
    Foreground window Info: HWND = 0x0002036a, DC = 0x0a010375.
    Foreground window Info: HWND = 0x0001035a, DC = 0x06010667.
    进程行为
    行为描述:创建进程
    详情信息:[0x00000b58]ImagePath = C:\Program Files\Internet Explorer\iexplore.exe, CmdLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
    [0x00000b80]ImagePath = C:\Program Files\Internet Explorer\iexplore.exe, CmdLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:2904 CREDAT:79873
    [0x00000c40]ImagePath = C:\Program Files\Internet Explorer\iexplore.exe, CmdLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:3052 CREDAT:79873
    行为描述:创建本地线程
    详情信息:TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2628, ThreadID = 2644, StartAddress = 77DC845A, Parameter = 00000000
    TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2628, ThreadID = 2832, StartAddress = 7C947EBB, Parameter = 00000000
    TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2628, ThreadID = 2836, StartAddress = 7C930230, Parameter = 00000000
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2912, StartAddress = 77DC845A, Parameter = 00000000
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2916, StartAddress = 7C947EBB, Parameter = 00000000
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2920, StartAddress = 7C930230, Parameter = 00000000
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2924, StartAddress = 7C949B6F, Parameter = 00000000
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2928, StartAddress = 77E56C7D, Parameter = 00196898
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2932, StartAddress = 5DE05ABD, Parameter = 00198A38
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2936, StartAddress = 5DE05BC0, Parameter = 00196928
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2940, StartAddress = 0122F74F, Parameter = 00000218
    TargetProcess: iexplore.exe, InheritedFromPID = 2904, ProcessID = 2944, ThreadID = 2976, StartAddress = 77DC845A, Parameter = 00000000
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2980, StartAddress = 77C0A341, Parameter = 003F6798
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2984, StartAddress = 77E56C7D, Parameter = 001B1DC0
    TargetProcess: iexplore.exe, InheritedFromPID = 2628, ProcessID = 2904, ThreadID = 2988, StartAddress = 769AE43B, Parameter = 001B4AA8
    文件行为
    行为描述:创建文件
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\dh[1].jb
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{69657BE2-721C-11E7-91C0-7B****28}.dat
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DF2B71.tmp
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6BA4129C-721C-11E7-91C0-7B****28}.dat
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{69657BE3-721C-11E7-91C0-7B****28}.dat
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DF7473.tmp
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\4399hs_com[1]
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\favicon[1].ico
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\yixun_com[1]
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DFB937.tmp
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{6BA4129D-721C-11E7-91C0-7B****28}.dat
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DFE01D.tmp
    行为描述:创建可执行文件
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
    行为描述:查找文件
    详情信息:FileName = C:\Documents and Settings\Administrator\Local Settings\Temp
    FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%
    FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe
    FileName = C:\Documents and Settings
    FileName = C:\Documents and Settings\Administrator
    FileName = C:\Documents and Settings\Administrator\Local Settings
    FileName = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
    FileName = C:\WINDOWS\system32\Ras\*.pbk
    FileName = C:\Documents and Settings\Administrator\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
    FileName = C:\Program Files\Internet Explorer\iexplore.exe
    FileName = C:\Program Files\Common Files\Adobe
    FileName = C:\Program Files\Common Files\Adobe\Acrobat
    FileName = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX
    FileName = C:\Program Files\Java
    FileName = C:\Program Files\Java\jre7
    行为描述:删除文件
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\dh[1].jb
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DF2B71.tmp
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DF7473.tmp
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\4399hs_com[1]
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\favicon[1].ico
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DFB937.tmp
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DFE01D.tmp
    行为描述:设置特殊文件夹属性
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
    C:\Documents and Settings\Administrator\Local Settings\History
    C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
    C:\Documents and Settings\Administrator\Cookies
    C:\Documents and Settings\Administrator\IETldCache
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds Cache
    C:\Documents and Settings\Administrator\IECompatCache
    行为描述:修改文件内容
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{69657BE2-721C-11E7-91C0-7B****28}.dat ---> Offset = 512
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{69657BE2-721C-11E7-91C0-7B****28}.dat ---> Offset = 0
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DF2B71.tmp ---> Offset = 16383
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DF2B71.tmp ---> Offset = 12288
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{69657BE2-721C-11E7-91C0-7B****28}.dat ---> Offset = 3072
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{69657BE2-721C-11E7-91C0-7B****28}.dat ---> Offset = 1536
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{69657BE3-721C-11E7-91C0-7B****28}.dat ---> Offset = 512
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{69657BE3-721C-11E7-91C0-7B****28}.dat ---> Offset = 0
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DF7473.tmp ---> Offset = 16383
    C:\Documents and Settings\Administrator\Local Settings\Temp\~DF7473.tmp ---> Offset = 12288
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{69657BE3-721C-11E7-91C0-7B****28}.dat ---> Offset = 3072
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{69657BE3-721C-11E7-91C0-7B****28}.dat ---> Offset = 1536
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6BA4129C-721C-11E7-91C0-7B****28}.dat ---> Offset = 512
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico ---> Offset = 0
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{6BA4129C-721C-11E7-91C0-7B****28}.dat ---> Offset = 0
    网络行为
    行为描述:下载文件
    详情信息:URLDownloadToFileW: http://ww****om/favicon.ico ---> C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
    行为描述:打开指定IE网页
    详情信息:http://ww****om
    http://ww****om/
    行为描述:连接指定站点
    详情信息:InternetConnectA: ServerName = dh****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
    WinHttpConnect: ServerName = im****om, PORT = 80, UserName = , Password = , hSession = 0x03833100, hConnect = 0x03833200, Flags = 0x00000000
    WinHttpConnect: ServerName = im****om, PORT = 80, UserName = , Password = , hSession = 0x03833100, hConnect = 0x03833300, Flags = 0x00000000
    InternetConnectA: ServerName = hu****om, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
    InternetConnectA: ServerName = ww****om, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
    InternetConnectA: ServerName = ur****om, PORT = 443, UserName = , Password = , hSession = 0x00cc0010, hConnect = 0x00cc0014, Flags = 0x00000200
    行为描述:打开HTTP连接
    详情信息:InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022), hSession = 0x00cc0004
    WinHttpOpen: UserAgent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5), hSession = 0x03833100
    InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0), hSession = 0x00cc0004
    InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489), hSession = 0x00cc0004
    InternetOpenA: UserAgent: VCSoapClient, hSession = 0x00cc0010
    行为描述:建立到一个指定的套接字连接
    详情信息:URL: dh****cn, IP: **.133.40.**:80, SOCKET = 0x00000344
    URL: im****om, IP: **.133.40.**:80, SOCKET = 0x0000036c
    URL: im****om, IP: **.133.40.**:80, SOCKET = 0x00000190
    URL: im****om, IP: **.133.40.**:80, SOCKET = 0x00000358
    URL: hu****om, IP: **.133.40.**:80, SOCKET = 0x00000190
    URL: ww****om, IP: **.133.40.**:80, SOCKET = 0x000004dc
    URL: ww****om, IP: **.133.40.**:80, SOCKET = 0x0000056c
    URL: ww****om, IP: **.133.40.**:80, SOCKET = 0x000004f0
    URL: ur****om, IP: **.133.40.**:443, SOCKET = 0x00000574
    URL: ww****om, IP: **.133.40.**:80, SOCKET = 0x0000044c
    URL: ww****om, IP: **.133.40.**:80, SOCKET = 0x00000588
    URL: ur****om, IP: **.133.40.**:443, SOCKET = 0x0000058c
    行为描述:读取网络文件
    详情信息:hFile = 0x00cc000c, BytesToRead =1024, BytesRead = 1024.
    hFile = 0x00cc000c, BytesToRead =4096, BytesRead = 4096.
    hFile = 0x00cc000c, BytesToRead =2048, BytesRead = 2048.
    hFile = 0x00cc0018, BytesToRead =4095, BytesRead = 4095.
    行为描述:发送HTTP包
    详情信息:GET /dh.jb HTTP/1.1 Referer: http://dh-cfg.liuxue789.cn/dh.jb Accept: */* Accept-Language: zh-cn Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) Host: dh****cn Cache-Control: no-cache
    GET /upload_pic/2017/7/24/4399_17574275981.jpg HTTP/1.1 Accept: */* Referer: http://imga4.5054399.com/upload_pic/2017/7/24/4399_17574275981.jpg Accept-Language: zh-cn User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1) Content-Type: application/x-www-form-urlencoded Host: im****om Connection: Keep-Alive
    GET /upload_pic/2017/7/25/4399_14142960001.jpg HTTP/1.1 Accept: */* Referer: http://imga4.5054399.com/upload_pic/2017/7/25/4399_14142960001.jpg Accept-Language: zh-cn User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1) Content-Type: application/x-www-form-urlencoded Host: im****om Connection: Keep-Alive
    GET /upload_pic/2017/7/20/4399_10551916190.jpg HTTP/1.1 Accept: */* Referer: http://imga3.5054399.com/upload_pic/2017/7/20/4399_10551916190.jpg Accept-Language: zh-cn User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1) Content-Type: application/x-www-form-urlencoded Host: im****om Connection: Keep-Alive
    GET /upload_pic/2017/7/13/4399_17011159372.jpg HTTP/1.1 Accept: */* Referer: http://imga3.5054399.com/upload_pic/2017/7/13/4399_17011159372.jpg Accept-Language: zh-cn User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1) Content-Type: application/x-www-form-urlencoded Host: im****om Connection: Keep-Alive
    GET /banben.txt HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0) Accept: */* Host: hu****om Cache-Control: no-cache
    GET / HTTP/1.1 Accept: */* Accept-Language: zh-cn User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Accept-Encoding: gzip, deflate Host: ww****om Connection: Keep-Alive
    GET /favicon.ico HTTP/1.1 Accept: */* Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: ww****om Connection: Keep-Alive
    GET / HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489) Host: ww****om Connection: Keep-Alive
    行为描述:打开HTTP请求
    详情信息:HttpOpenRequestA: dh****cn:80/dh.jb, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x80004010
    WinHttpOpenRequest: im****om:80/upload_pic/2017/7/24/4399_17574275981.jpg, hConnect = 0x03833200, hRequest = 0x03870000, Verb: GET, Referer: , Flags = 0x00000080
    WinHttpOpenRequest: im****om:80/upload_pic/2017/7/25/4399_14142960001.jpg, hConnect = 0x03833300, hRequest = 0x03870000, Verb: GET, Referer: , Flags = 0x00000080
    WinHttpOpenRequest: im****om:80/upload_pic/2017/7/20/4399_10551916190.jpg, hConnect = 0x03833200, hRequest = 0x03870000, Verb: GET, Referer: , Flags = 0x00000080
    WinHttpOpenRequest: im****om:80/upload_pic/2017/7/13/4399_17011159372.jpg, hConnect = 0x03833300, hRequest = 0x03870000, Verb: GET, Referer: , Flags = 0x00000080
    HttpOpenRequestA: hu****om:80/banben.txt, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x84000000
    HttpOpenRequestA: ww****om:80/, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400000
    HttpOpenRequestA: ww****om:80/favicon.ico, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00600010
    HttpOpenRequestA: ww****om:80/, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400010
    HttpOpenRequestA: ww****om:80/, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0x00400200
    HttpOpenRequestA: ur****om:443/urs.asmx?msurs-client-key=3jp/oc8qrlwrrczula4aaw%3d%3d&msurs-patented-lock=ye5cuv/btr8%3d, hConnect = 0x00cc0014, hRequest = 0x00cc0018, Verb: POST, Referer: , Flags = 0x04880300
    HttpOpenRequestA: ur****om:443/urs.asmx?msurs-client-key=yqv5rum3qyk6m7hhxdrxqq%3d%3d&msurs-patented-lock=f7dtbd%2bljjm%3d, hConnect = 0x00cc0014, hRequest = 0x00cc0018, Verb: POST, Referer: , Flags = 0x04880300
    行为描述:按名称获取主机地址
    详情信息:GetAddrInfoW: dh****cn
    GetAddrInfoW: im****om
    GetAddrInfoW: hu****om
    GetAddrInfoW: ww****om
    GetAddrInfoW: ur****om
    注册表行为
    行为描述:修改注册表
    详情信息:\REGISTRY\USER\S-*\Software\Microsoft\Multimedia\DrawDib\vga.drv 1920x973x32(BGR 0)
    \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
    \REGISTRY\USER\S-*\Software\Microsoft\Internet Explorer\Recovery\Active\{69657BE2-721C-11E7-91C0-7B****28}
    \REGISTRY\USER\S-*\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\0x00000000\{63800dac-e7ca-4df9-9a5c-20765055488d}\Enable
    \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0\win32\
    \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Count
    \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Time
    \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\LoadTime
    \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\LoadTimeCount
    \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore\Count
    \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore\Time
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\InprocServer32\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\InprocServer32\ThreadingModel
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB}\
    行为描述:删除注册表键值
    详情信息:\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
    \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
    行为描述:删除注册表键
    详情信息:\REGISTRY\USER\S-*\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\0x00000000\{63800dac-e7ca-4df9-9a5c-20765055488d}\
    \REGISTRY\USER\S-*\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\0x00000000\
    \REGISTRY\USER\S-*\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\
    \REGISTRY\USER\S-*\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\InprocServer32\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB}\InprocServer32\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBB}\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC}\InprocServer32\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBC}\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}\InprocServer32\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InprocServer32\
    \REGISTRY\USER\S-*_CLASSES\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\
    \REGISTRY\USER\S-*_CLASSES\JavaPlugin.1000\CLSID\
    其他行为
    行为描述:创建互斥体
    详情信息:RasPbFile
    CTF.LBES.MutexDefaultS-*
    CTF.Compart.MutexDefaultS-*
    CTF.Asm.MutexDefaultS-*
    CTF.Layouts.MutexDefaultS-*
    CTF.TMD.MutexDefaultS-*
    CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
    MSCTF.Shared.MUTEX.IOH
    Local\ZonesCounterMutex
    Local\ZoneAttributeCacheCounterMutex
    Local\ZonesCacheCounterMutex
    Local\ZonesLockedCacheCounterMutex
    Local\c:!documents and settings!administrator!ietldcache!
    MSCTF.Shared.MUTEX.IEK
    Local\!BrowserEmulation!SharedMemory!Mutex
    行为描述:创建事件对象
    详情信息:EventName = DINPUTWINMM
    EventName = Global\userenv: User Profile setup event
    EventName = MSCTF.SendReceiveConection.Event.IEK.IC
    EventName = MSCTF.SendReceive.Event.IEK.IC
    EventName = Isolation Signal Registry Event (69657BDF-721C-11E7-91C0-7B****28, 0)
    EventName = IE_EarlyTabStart_0xb5c
    EventName = Isolation Signal Registry Event (69657BE0-721C-11E7-91C0-7B****28, 0)
    EventName = Local\IEDDEExecuteEvent
    EventName = Local\RSS Eventing Event Event 00000b58
    EventName = Isolation Signal Registry Event (6BA41299-721C-11E7-91C0-7B****28, 0)
    EventName = IE_EarlyTabStart_0xbf0
    EventName = Isolation Signal Registry Event (6BA4129A-721C-11E7-91C0-7B****28, 0)
    EventName = MSCTF.SendReceive.Event.MFL.IC
    EventName = MSCTF.SendReceiveConection.Event.MFL.IC
    EventName = Global\crypt32LogoffEvent
    行为描述:打开互斥体
    详情信息:RasPbFile
    ShimCacheMutex
    Local\_!MSFTHISTORY!_
    Local\c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
    Local\c:!documents and settings!administrator!cookies!
    Local\c:!documents and settings!administrator!local settings!history!history.ie5!
    Local\WininetStartupMutex
    Local\WininetConnectionMutex
    Local\WininetProxyRegistryMutex
    Local\!IETld!Mutex
    Local\c:!documents and settings!administrator!ietldcache!
    Local\!BrowserEmulation!SharedMemory!Mutex
    CtfmonInstMutexDefaultS-*
    Local\RSS Eventing Connection Database Mutex 00000b58
    Local\c:!documents and settings!administrator!local settings!application data!microsoft!feeds cache!
    行为描述:查找指定窗口
    详情信息:NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
    NtUserFindWindowEx: [Class,Window] = [,]
    NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
    NtUserFindWindowEx: [Class,Window] = [,Microsoft Internet Explorer]
    NtUserFindWindowEx: [Class,Window] = [OleMainThreadWndClass,]
    NtUserFindWindowEx: [Class,Window] = [IEFrame,]
    NtUserFindWindowEx: [Class,Window] = [Static,]
    NtUserFindWindowEx: [Class,Window] = [MS_AutodialMonitor,]
    NtUserFindWindowEx: [Class,Window] = [MS_WebCheckMonitor,]
    行为描述:打开事件
    详情信息:HookSwitchHookEnabledEvent
    CTF.ThreadMIConnectionEvent.000007E8.00000000.00000010
    CTF.ThreadMarshalInterfaceEvent.000007E8.00000000.00000010
    MSCTF.SendReceiveConection.Event.IOH.IC
    MSCTF.SendReceive.Event.IOH.IC
    \SECURITY\LSA_AUTHENTICATION_INITIALIZED
    Global\SvcctrlStartEvent_A3752DX
    \INSTALLATION_SECURITY_HOLD
    Isolation Signal Registry Event (69657BDF-721C-11E7-91C0-7B****28, 0)
    MSFT.VSA.COM.DISABLE.2904
    MSFT.VSA.IEC.STATUS.6c736db0
    Isolation Signal Registry Event (69657BE0-721C-11E7-91C0-7B****28, 0)
    IE_EarlyTabStart_0xb5c
    _fCanRegisterWithShellService
    MSFT.VSA.COM.DISABLE.2944
    行为描述:调整进程token权限
    详情信息:SE_LOAD_DRIVER_PRIVILEGE
    行为描述:窗口信息
    详情信息:Pid = 2628, Hwnd=0x1036a, Text = 确定, ClassName = Button.
    Pid = 2628, Hwnd=0x1036c, Text = 魂殇辅助更名为金牌辅助, ClassName = Static.
    Pid = 2628, Hwnd=0x40368, Text = 信息:, ClassName = #32770.
    Pid = 2628, Hwnd=0x2036c, Text = 确定, ClassName = Button.
    Pid = 2628, Hwnd=0x2036a, Text = 取消, ClassName = Button.
    Pid = 2628, Hwnd=0x20372, Text = 发现最新版本,即将打开下载网站www.4399hs.com, ClassName = Static.
    Pid = 2628, Hwnd=0x60368, Text = 发现新版本, ClassName = #32770.
    Pid = 2628, Hwnd=0x10366, Text = 最新公告, ClassName = Button(GroupBox).
    Pid = 2628, Hwnd=0x10364, Text = 进度条卡住或一直提示【登录中】,请点击【网页管理】-【清理缓存】,然后点击【刷新游戏】即可, ClassName = Afx:400000:b:10011:1900015:0.
    Pid = 2628, Hwnd=0x1035c, Text = Tisp-版本信息, ClassName = Button(GroupBox).
    Pid = 2628, Hwnd=0x1035a, Text = 最新版本:, ClassName = Afx:400000:b:10011:1900015:0.
    Pid = 2628, Hwnd=0x10358, Text = 本地版本:1.9, ClassName = Afx:400000:b:10011:1900015:0.
    Pid = 2628, Hwnd=0x10356, Text = 更新内容, ClassName = Button(GroupBox).
    Pid = 2628, Hwnd=0x10354, Text = 辅助信息, ClassName = Button(GroupBox).
    Pid = 2628, Hwnd=0x10352, Text = 魂殇辅助已经通过腾讯电脑管家哈勃分析系统, ClassName = _EL_HyperLinker.
    行为描述:获取窗口截图信息
    详情信息:Foreground window Info: HWND = 0x0001036a, DC = 0x0a010375.
    Foreground window Info: HWND = 0x00010364, DC = 0x01010055.
    Foreground window Info: HWND = 0x00010358, DC = 0x01010055.
    Foreground window Info: HWND = 0x0002036c, DC = 0x0a010375.
    Foreground window Info: HWND = 0x0002036a, DC = 0x0a010375.
    Foreground window Info: HWND = 0x0001035a, DC = 0x06010667.
    行为描述:可执行文件签名信息
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico(签名验证: 未通过)
    行为描述:隐藏指定窗口
    详情信息:[Window,Class] = [,BrowserFrameGripperClass]
    [Window,Class] = [缩放级别,ToolbarWindow32]
    [Window,Class] = [,msctls_progress32]
    [Window,Class] = [,SysLink]
    [Window,Class] = [,Static]
    [Window,Class] = [文件大小未知,Static]
    [Window,Class] = [打开此类文件前总是询问(&W),Button]
    [Window,Class] = [发行者:,Static]
    [Window,Class] = [Windows Internet Explorer,IEFrame]
    [Window,Class] = [,UniversalSearchBand]
    [Window,Class] = [,TravelBand]
    [Window,Class] = [,CommandBarClass]
    [Window,Class] = [,ReBarWindow32]
    [Window,Class] = [,TabBandClass]
    [Window,Class] = [http://www.yixun.com/ - Windows Internet Explorer,IEFrame]
    行为描述:可执行文件MD5
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico ---> fe1d0ee5901dd167ee9b28eece31786c
    行为描述:直接获取CPU时钟
    详情信息:EAX = 0xfaabbf8f, EDX = 0x000000b5
    EAX = 0xfaabbfdb, EDX = 0x000000b5
    EAX = 0xfaabc027, EDX = 0x000000b5
    EAX = 0xfaabc073, EDX = 0x000000b5
    EAX = 0xfaabc0bf, EDX = 0x000000b5
    EAX = 0xfaabc10b, EDX = 0x000000b5
    EAX = 0xfaabc157, EDX = 0x000000b5
    EAX = 0xfaabc1a3, EDX = 0x000000b5
    EAX = 0xfaabc1ef, EDX = 0x000000b5
    EAX = 0xfaabc23b, EDX = 0x000000b5
    Activities
    活动名类型
    com.e4a.runtime.android.StartActivityandroid.intent.action.MAIN
    com.e4a.runtime.android.StartActivityandroid.intent.category.DEFAULT
    com.stub.stub01.Stub01android.intent.action.MAIN
    com.stub.stub01.Stub01android.intent.category.LAUNCHER
    com.e4a.runtime.android.mainActivityandroid.intent.action.MAIN
    com.e4a.runtime.android.mainActivityandroid.intent.category.DEFAULT
    com.tencent.tauth.AuthActivityandroid.intent.action.VIEW
    com.tencent.tauth.AuthActivityandroid.intent.category.DEFAULT
    com.tencent.tauth.AuthActivityandroid.intent.category.BROWSABLE
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivityandroid.intent.action.VIEW
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivityandroid.intent.category.DEFAULT
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivityandroid.intent.category.BROWSABLE
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivity2android.intent.action.VIEW
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivity2android.intent.category.DEFAULT
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivity2android.intent.category.BROWSABLE
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivity4android.intent.action.VIEW
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivity4android.intent.category.DEFAULT
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivity4android.intent.category.BROWSABLE
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivity5android.intent.action.VIEW
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivity5android.intent.category.DEFAULT
    com.e4a.runtime.components.impl.android.Ok百度视频类库.VideoViewPlayingActivity5android.intent.category.BROWSABLE
    com.tencent.smtt.sdk.VideoActivitycom.tencent.smtt.tbs.video.PLAY
    com.tencent.smtt.sdk.VideoActivityandroid.intent.category.DEFAULT
    危险函数
    函数名称信息
    getRuntime获取命令行环境
    java/lang/Runtime;->exec执行字符串命令
    权限列表
    许可名称信息
    com.android.launcher.permission.INSTALL_SHORTCUT创建快捷方式
    android.permission.SET_WALLPAPER设置桌面壁纸
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
    android.permission.WRITE_EXTERNAL_STORAGE写外部存储器(如:SD卡)
    ACCESS_WIFI_STATE
    android.permission.ACCESS_WIFI_STATE读取wifi网络状态
    android.permission.ACCESS_COARSE_LOCATION获取粗略的位置(通过wifi、基站)
    android.permission.MOUNT_UNMOUNT_FILESYSTEMS挂载、反挂载外部文件系统
    android.permission.READ_PHONE_STATE读取电话状态
    android.permission.DISABLE_KEYGUARD禁用键盘锁
    android.permission.SYSTEM_ALERT_WINDOW显示系统窗口
    android.permission.ACCESS_WIFI_STATE.android.permission.READ_PHONE_STATE
    android.permission.INTERNET连接网络(2G或3G)
    android.permission.WRITE_SETTINGS读写系统设置项
    android.permission.CHANGE_WIFI_STATE改变WIFI连接状态
    android.permission.ACCESS_FINE_LOCATION获取精确的位置(通过GPS)
    android.permission.ACCESS_LOCATION_EXTRA_COMMANDS访问额外的定位指令
    com.android.launcher.permission.READ_SETTINGS读取快捷方式信息
    android.permission.ACCESS_NETWORK_STATE读取网络状态(2G或3G)
    android.permission.WAKE_LOCK手机屏幕关闭后后台进程仍运行
    android.permission.CHANGE_CONFIGURATION修改当前设置(如:本地化)
    android.permission.READ_SETTINGS
    android.permission.READ_EXTERNAL_STORAGE读外部存储器(如:SD卡)
    服务列表
    名称
    com.stub.stub01.Stub03
    com.stub.stub02.Stub02
    com.stub.stub02.Stub03
    com.stub.stub05.Stub02
    Providers
    名字信息
    com.stub.stub02.Stub04
    文件列表
    文件名 校验码
    META-INF/MANIFEST.MF 0x40d3e417
    META-INF/_____.SF 0x1df8b843
    META-INF/_____.RSA 0x4f4c1e80
    AndroidManifest.xml 0x54d8f5e8
    assets/.appkey 0x65cd6e12
    assets/11970006ae4382ddab61.jpg 0xa43ec81a
    assets/133.png 0x9aa887dd
    assets/219.png 0xc83ff69e
    assets/225115455.png 0x954bfa6b
    assets/6.png 0x9c24ad01
    assets/6b0e81.png 0x99f119a2
    assets/82117.png 0x470ddb68
    assets/91.png 0x6f47f2de
    assets/E4Abanner201771514235.jpg 0x9ea31bb2
    assets/GO_dr.png 0xe3460e93
    assets/MG.png 0x69d4b1df
    assets/OT39f.jpg 0xc0f36898
    assets/TB.png 0x88a9608c
    assets/an1.png 0xf07068c0
    assets/anniu_laba_1.png 0xfec039ef
    assets/antenna.png 0xa919e135
    assets/banb5072754.png 0xc30c7240
    assets/beijing2.png 0xa747e112
    assets/bg_user_info.png 0x30b79247
    assets/button_quit_normal.png 0xbfc78bf
    assets/cljx1.png 0x654965c0
    assets/diaosi.png 0x4ed1adbe
    assets/essed.png 0x4b8d08e3
    assets/essed1.png 0xf139667
    assets/fanpai2.png 0x5fae2331
    assets/libjiagu.so 0x33ed92f2
    assets/libjiagu_ls.so 0xcc92cf74
    assets/libjiagu_x86.so 0xa0bd9b30
    assets/m_fw658.png 0x975e1e37
    assets/meitu2.png 0xf1f0a785
    assets/ssbuttom.png 0x4dd50c5c
    assets/t01d31280fe96aaa2ae.png 0x8a82424f
    assets/tim.jpg 0x8caf80da
    assets/timg.png 0xfe69a7dc
    assets/tongcyuepao.png 0x7847cad9
    assets/w01.jpg 0x33f00764
    assets/xllive_close_btn_normal.png 0xff3f4cad
    assets/youku2.png 0x6f64923
    assets/yyshenqu.png 0xfa06d05f
    assets/zhanqi.jpg 0xdf18e61f
    assets/zj.png 0x27247f73
    classes.dex 0xf13d7e74
    lib/armeabi/libcyberplayer-core.so 0xb98484e0
    lib/armeabi/libcyberplayer.so 0x2350af82
    lib/armeabi/liblbs.so 0xbe8edb00
    res/anim/dialog_scale_in.xml 0xd1205a18
    res/anim/dialog_scale_out.xml 0xe4110112
    res/anim/error_frame_in.xml 0x6dfac1ce
    res/anim/error_x_in.xml 0x75ae2b72
    res/anim/spinner.xml 0xc835ec9
    res/anim/success_bow_roate.xml 0x868ab202
    res/anim/success_mask_layout.xml 0x803af484
    res/drawable-hdpi/custom_img.jpg 0x5180fa2a
    res/drawable-hdpi/cyberplayer_listbtn_normal.png 0xa2be03dc
    res/drawable-hdpi/cyberplayer_listbtn_pressed.png 0x21de95cb
    res/drawable-hdpi/cyberplayer_next_play.png 0x4dbc08ae
    res/drawable-hdpi/cyberplayer_next_play_disable.png 0xd9509e6a
    res/drawable-hdpi/cyberplayer_next_play_pressed.png 0xecd2fb3a
    res/drawable-hdpi/cyberplayer_play_media.png 0x7825fccf
    res/drawable-hdpi/cyberplayer_play_media_disable.png 0xd06ad4ea
    res/drawable-hdpi/cyberplayer_play_media_pressed.png 0x754abc4d
    res/drawable-hdpi/cyberplayer_retreat_media.png 0xc1863e71
    res/drawable-hdpi/cyberplayer_retreat_media_disable.png 0x105d69ea
    res/drawable-hdpi/cyberplayer_retreat_media_pressed.png 0x107d406d
    res/drawable-hdpi/cyberplayer_seekbar_background.png 0x470141ee
    res/drawable-hdpi/cyberplayer_seekbar_background_normal.9.png 0xb682f96c
    res/drawable-hdpi/cyberplayer_seekbar_background_process.9.png 0x525e50fe
    res/drawable-hdpi/cyberplayer_seekbar_background_sound_normal.9.png 0xf670f95b
    res/drawable-hdpi/cyberplayer_seekbar_background_sound_process.9.png 0x5e8b1ec9
    res/drawable-hdpi/cyberplayer_seekbar_cache.png 0x273eb0ec
    res/drawable-hdpi/cyberplayer_seekbar_normal.png 0x60b412f3
    res/drawable-hdpi/cyberplayer_seekbar_ratio.png 0x8ec16bd1
    res/drawable-hdpi/cyberplayer_seekbar_ratio_white.png 0xa7a8ded9
    res/drawable-hdpi/cyberplayer_stop_media.png 0x6395a790
    res/drawable-hdpi/cyberplayer_stop_media_disable.png 0xbaafc338
    res/drawable-hdpi/cyberplayer_stop_media_pressed.png 0x520b1252
    res/drawable-hdpi/cyberplayer_subtitle_setting.png 0xdd3621e6
    res/drawable-hdpi/cyberplayer_subtitle_setting_disable.png 0xcb77113f
    res/drawable-hdpi/cyberplayer_subtitle_setting_pressed.png 0x9a0a6625
    res/drawable-hdpi/cyberplayer_switch_subtitle.png 0xe91d219b
    res/drawable-hdpi/cyberplayer_switch_subtitle_disable.png 0x4f852d8c
    res/drawable-hdpi/cyberplayer_switch_subtitle_pressed.png 0xf6580cd6
    res/drawable-hdpi/cyberplayer_take_snapshot.png 0xab8e7fd5
    res/drawable-hdpi/cyberplayer_take_snapshot_disable.png 0x234d73be
    res/drawable-hdpi/cyberplayer_take_snapshot_pressed.png 0x241205e
    res/drawable-hdpi/cyberplayer_textbtn_background_blue.9.png 0x84105c73
    res/drawable-hdpi/cyberplayer_titlebar_return.png 0xaafad296
    res/drawable-hdpi/cyberplayer_volumebar_background.9.png 0xd4992489
    res/drawable-hdpi/ic_episode_titlebar_videoplayer.png 0xc4f1ae6b
    res/drawable-hdpi/ic_episode_titlebar_videoplayer_disable.png 0xaba89ad2
    res/drawable-hdpi/ic_episode_titlebar_videoplayer_pressed.png 0x4b8d08e3
    res/drawable-hdpi/ic_next_play.png 0x719162df
    res/drawable-hdpi/ic_next_play_pressed.png 0x1da89f5
    res/drawable-hdpi/ic_play_media.png 0xe1efa842
    res/drawable-hdpi/ic_play_media_disable.png 0xd06ad4ea
    res/drawable-hdpi/ic_play_media_pressed.png 0x369158f9
    res/drawable-hdpi/ic_retreat_media.png 0x62ad09c7
    res/drawable-hdpi/ic_retreat_media_disable.png 0x105d69ea
    res/drawable-hdpi/ic_retreat_media_pressed.png 0x9e62fb86
    res/drawable-hdpi/ic_stop_media.png 0x5e106da4
    res/drawable-hdpi/ic_stop_media_pressed.png 0x101fb9db
    res/drawable-hdpi/ic_zoom_in_btn_videoplayer.png 0x986da792
    res/drawable-hdpi/ic_zoom_in_btn_videoplayer_disable.png 0x590e0a34
    res/drawable-hdpi/ic_zoom_in_btn_videoplayer_pressed.png 0xea9b5ca1
    res/drawable-hdpi/ic_zoom_out_btn_videoplayer.png 0xa25660f0
    res/drawable-hdpi/ic_zoom_out_btn_videoplayer_disable.png 0x1489a84c
    res/drawable-hdpi/ic_zoom_out_btn_videoplayer_pressed.png 0x722558a6
    res/drawable-hdpi/mo_shang_1.png 0x8ab606b3
    res/drawable-hdpi/mo_xia_1.png 0x7cc1ef0d
    res/drawable-hdpi/progress_custom_bg.xml 0x9444c7
    res/drawable-xhdpi/bookmark_expand_icon.png 0x6639221b
    res/drawable-xhdpi/bookmark_icon_folder.png 0xae8b5d6b
    res/drawable-xhdpi/bookmark_unexpand_icon.png 0xf6e40be6
    res/drawable-xhdpi/btn_style_alert_dialog_button_normal.9.png 0x19f80729
    res/drawable-xhdpi/btn_style_alert_dialog_button_pressed.9.png 0xca61388e
    res/drawable-xhdpi/btn_style_alert_dialog_cancel_normal.9.png 0x2baa5f01
    res/drawable-xhdpi/btn_style_alert_dialog_special_normal.9.png 0xfb7979e3
    res/drawable-xhdpi/btn_style_alert_dialog_special_pressed.9.png 0x4d13cbda
    res/drawable-xhdpi/download_bookmark_toolbar_delete.png 0x3a7249be
    res/drawable-xhdpi/download_toolbar_backward.png 0xa3e23cfd
    res/drawable-xhdpi/ic_action_search.png 0x3294aee3
    res/drawable-xhdpi/menu_exit.png 0x2983d8b8
    res/drawable-xhdpi/mo_shang.png 0x9c8a8e1d
    res/drawable-xhdpi/mo_xia.png 0x33a6a99b
    res/drawable-xhdpi/mo_zhong.png 0x5784734e
    res/drawable-xhdpi/ok_win101.xml 0x68dd54c
    res/drawable-xhdpi/ok_win101_1.png 0xc18f6c93
    res/drawable-xhdpi/ok_win10_1.png 0x3f2da75e
    res/drawable-xhdpi/ok_win10_10.png 0xf1b2f71e
    res/drawable-xhdpi/ok_win10_11.png 0xbb91fe35
    res/drawable-xhdpi/ok_win10_12.png 0x8e59419e
    res/drawable-xhdpi/ok_win10_13.png 0x583476b6
    res/drawable-xhdpi/ok_win10_14.png 0x7e6d87da
    res/drawable-xhdpi/ok_win10_15.png 0x9c5fd291
    res/drawable-xhdpi/ok_win10_16.png 0xda091058
    res/drawable-xhdpi/ok_win10_17.png 0xabd11b0b
    res/drawable-xhdpi/ok_win10_18.png 0x7d50df6d
    res/drawable-xhdpi/ok_win10_19.png 0xedd4f106
    res/drawable-xhdpi/ok_win10_2.png 0x8c31996e
    res/drawable-xhdpi/ok_win10_20.png 0xc2062a6
    res/drawable-xhdpi/ok_win10_21.png 0x7b988fc4
    res/drawable-xhdpi/ok_win10_22.png 0xb429d99c
    res/drawable-xhdpi/ok_win10_23.png 0x8e25fefa
    res/drawable-xhdpi/ok_win10_24.png 0x8f107ff3
    res/drawable-xhdpi/ok_win10_25.png 0x23650567
    res/drawable-xhdpi/ok_win10_26.png 0x7c5fadae
    res/drawable-xhdpi/ok_win10_27.png 0xf9812dff
    res/drawable-xhdpi/ok_win10_28.png 0x353d2aef
    res/drawable-xhdpi/ok_win10_29.png 0xd6403544
    res/drawable-xhdpi/ok_win10_3.png 0x30d49bea
    res/drawable-xhdpi/ok_win10_30.png 0x4fd184fe
    res/drawable-xhdpi/ok_win10_31.png 0xae4fcca7
    res/drawable-xhdpi/ok_win10_32.png 0x1811001f
    res/drawable-xhdpi/ok_win10_33.png 0xf1647bbe
    res/drawable-xhdpi/ok_win10_34.png 0xee51f09b
    res/drawable-xhdpi/ok_win10_35.png 0xd4560822
    res/drawable-xhdpi/ok_win10_36.png 0xf2f61c5
    res/drawable-xhdpi/ok_win10_37.png 0x8c34a715
    res/drawable-xhdpi/ok_win10_38.png 0x54f98dd1
    res/drawable-xhdpi/ok_win10_39.png 0x5b69bac3
    res/drawable-xhdpi/ok_win10_4.png 0x9042ed2
    res/drawable-xhdpi/ok_win10_40.png 0x5204a48e
    res/drawable-xhdpi/ok_win10_41.png 0x562d4ca1
    res/drawable-xhdpi/ok_win10_42.png 0xfbb04908
    res/drawable-xhdpi/ok_win10_43.png 0x96e3309e
    res/drawable-xhdpi/ok_win10_44.png 0x583476b6
    res/drawable-xhdpi/ok_win10_45.png 0x5af76e72
    res/drawable-xhdpi/ok_win10_46.png 0xdf187d2f
    res/drawable-xhdpi/ok_win10_47.png 0x72bf0510
    res/drawable-xhdpi/ok_win10_48.png 0x8c77307a
    res/drawable-xhdpi/ok_win10_49.png 0x7d50df6d
    res/drawable-xhdpi/ok_win10_5.png 0x1e969f02
    res/drawable-xhdpi/ok_win10_50.png 0x93a5e64e
    res/drawable-xhdpi/ok_win10_51.png 0x84db4127
    res/drawable-xhdpi/ok_win10_52.png 0xf2b97805
    res/drawable-xhdpi/ok_win10_53.png 0x9816bea0
    res/drawable-xhdpi/ok_win10_54.png 0xa397d7dd
    res/drawable-xhdpi/ok_win10_55.png 0x8f107ff3
    res/drawable-xhdpi/ok_win10_56.png 0x5819d596
    res/drawable-xhdpi/ok_win10_57.png 0xb37a1fd1
    res/drawable-xhdpi/ok_win10_58.png 0xd02da4a6
    res/drawable-xhdpi/ok_win10_59.png 0x353d2aef
    res/drawable-xhdpi/ok_win10_6.png 0xf8a63f04
    res/drawable-xhdpi/ok_win10_60.png 0xf3901052
    res/drawable-xhdpi/ok_win10_61.png 0xb7a2ff0e
    res/drawable-xhdpi/ok_win10_62.png 0xdc899480
    res/drawable-xhdpi/ok_win10_63.png 0x1811001f
    res/drawable-xhdpi/ok_win10_64.png 0x89777e6b
    res/drawable-xhdpi/ok_win10_65.png 0x6ec37229
    res/drawable-xhdpi/ok_win10_66.png 0xd849beaa
    res/drawable-xhdpi/ok_win10_67.png 0x3bad2405
    res/drawable-xhdpi/ok_win10_68.png 0x726b7b15
    res/drawable-xhdpi/ok_win10_69.png 0xe59993a2
    res/drawable-xhdpi/ok_win10_7.png 0xb5d1e2f4
    res/drawable-xhdpi/ok_win10_70.png 0xd1b58aa5
    res/drawable-xhdpi/ok_win10_71.png 0xa97f2961
    res/drawable-xhdpi/ok_win10_72.png 0xb79aa5b7
    res/drawable-xhdpi/ok_win10_73.png 0xbec3199d
    res/drawable-xhdpi/ok_win10_74.png 0xf52b6e9b
    res/drawable-xhdpi/ok_win10_75.png 0xc4a38d7f
    res/drawable-xhdpi/ok_win10_8.png 0xb6af5baf
    res/drawable-xhdpi/ok_win10_9.png 0x90a86d8c
    res/drawable-xhdpi/p_phone_account_back_small.png 0x44fcca81
    res/drawable-xhdpi/p_phone_account_back_small_caidan.png 0x6fd891c7
    res/drawable-xhdpi/p_phone_account_back_small_jietu.png 0x49f38474
    res/drawable-xhdpi/p_phone_account_back_small_selected.png 0xc7fcf407
    res/drawable-xhdpi/p_phone_account_back_small_selected_caidan.png 0xd1dec9c3
    res/drawable-xhdpi/p_phone_account_back_small_selected_jietu.png 0x97df35a6
    res/drawable-xhdpi/pause_btn_cai_apy_style.xml 0xbd832477
    res/drawable-xhdpi/pause_btn_caidan_apy_style.xml 0x848c54c1
    res/drawable-xhdpi/pause_btn_fanhui_apy_style.xml 0xd7b6e514
    res/drawable-xhdpi/pause_btn_fenx_apy_style.xml 0xb71c029
    res/drawable-xhdpi/pause_btn_hou_apy_style.xml 0x7e67beeb
    res/drawable-xhdpi/pause_btn_jietu_apy_style.xml 0x24efa2c5
    res/drawable-xhdpi/pause_btn_jin2_apy_style.xml 0xea739e23
    res/drawable-xhdpi/pause_btn_jin_apy_style.xml 0xbc375192
    res/drawable-xhdpi/pause_btn_qi_apy_style.xml 0xbd832477
    res/drawable-xhdpi/pause_btn_quan_apy_style.xml 0xc7379034
    res/drawable-xhdpi/pause_btn_shoc_apy_style.xml 0x5034ff
    res/drawable-xhdpi/pause_btn_shocz_apy_style.xml 0x690bec82
    res/drawable-xhdpi/pause_btn_suo1_apy_style.xml 0x80a7a783
    res/drawable-xhdpi/pause_btn_suo_apy_style.xml 0x8c8a8cdf
    res/drawable-xhdpi/pause_btn_ting_apy_style.xml 0xbbf569ae
    res/drawable-xhdpi/pause_btn_xiazai_apy_style.xml 0x7db3915
    res/drawable-xhdpi/pause_btn_zan_apy_style.xml 0x8f82bf62
    res/drawable-xhdpi/play_ctrl_battery.png 0x17f7be70
    res/drawable-xhdpi/play_ctrl_battery1.png 0x3aef9f86
    res/drawable-xhdpi/play_ctrl_battery2.png 0x2ca1eba9
    res/drawable-xhdpi/player_landscape_btn_paopao_normal.png 0xe9597c12
    res/drawable-xhdpi/player_landscape_btn_paopao_pressed.png 0xd822ef8d
    res/drawable-xhdpi/player_landscape_download_normal.png 0x6a357a7d
    res/drawable-xhdpi/player_landscape_download_pressed.png 0x1549bd49
    res/drawable-xhdpi/player_landscape_more_normal.png 0x41dc98c1
    res/drawable-xhdpi/player_landscape_more_pressed.png 0x574b1438
    res/drawable-xhdpi/player_landscape_next_normal.png 0x98d1268f
    res/drawable-xhdpi/player_landscape_next_normal_1.png 0x8c07631c
    res/drawable-xhdpi/player_landscape_next_normals.png 0x15ae1191
    res/drawable-xhdpi/player_landscape_next_pressed.png 0x41f5238c
    res/drawable-xhdpi/player_landscape_next_pressed_1.png 0xa127802
    res/drawable-xhdpi/player_landscape_next_presseds.png 0x6355b68f
    res/drawable-xhdpi/player_landscape_screen_off_normal.png 0x9d608819
    res/drawable-xhdpi/player_landscape_screen_off_pressed.png 0xd5da8283
    res/drawable-xhdpi/player_landscape_screen_on_noraml.png 0x48dded46
    res/drawable-xhdpi/player_landscape_screen_on_pressed.png 0xf96e4c3b
    res/drawable-xhdpi/player_landscape_share_normal.png 0x5bfc76c
    res/drawable-xhdpi/player_landscape_share_pressed.png 0xcd6ce27f
    res/drawable-xhdpi/qiyi_sdk_play_portrait_btn_pause_normal.png 0x76d2e07a
    res/drawable-xhdpi/qiyi_sdk_play_portrait_btn_pause_pressed.png 0x4d66850a
    res/drawable-xhdpi/qiyi_sdk_play_portrait_btn_player_normal.png 0x15ad3d8b
    res/drawable-xhdpi/qiyi_sdk_play_portrait_btn_player_pressed.png 0x39b765be
    res/drawable-xhdpi/quan_mg_233.png 0xd6c795ee
    res/drawable-xhdpi/quan_mg_234.png 0x8da844cd
    res/drawable-xhdpi/round_46px_1071539_easyicon.png 0x18cf53b0
    res/drawable-xhdpi/round_48px_1071539_easyicon.png 0xc24a6722
    res/drawable-xhdpi/toast_collect.png 0x960bb6c9
    res/drawable-xhdpi/toast_collectz.png 0xa5fc1274
    res/drawable-xhdpi/toast_uncollect.png 0x1a1382d4
    res/drawable-xhdpi/toast_uncollectz.png 0x5a76eab6
    res/drawable-xhdpi/yanse_baise.png 0xc1df8226
    res/drawable-xhdpi/yanse_baisu.png 0x1da031d2
    res/drawable-xhdpi/yanse_huhuise.png 0xbf5ef6c1
    res/drawable-xhdpi/yanse_huise.png 0xd8256c99
    res/drawable/a16.png 0xa306990a
    res/drawable/aa.png 0xb4e4753e
    res/drawable/ad_indicator_selected.png 0x3c90412a
    res/drawable/bb.png 0x4e325f24
    res/drawable/blue_button_background.xml 0x667588f4
    res/drawable/btn_cancel_pressed.9.png 0x313fe0e9
    res/drawable/btn_style_alert_dialog_button.xml 0x52659ee6
    res/drawable/btn_style_alert_dialog_cancel.xml 0x4f4a85de
    res/drawable/btn_style_alert_dialog_special.xml 0x4b1b230e
    res/drawable/caidan_btn_style.xml 0xe7d7fc0b
    res/drawable/caidian_lie_style.xml 0xa3e3b0d5
    res/drawable/caidian_lies_style.xml 0x3db6e9fa
    res/drawable/cc.png 0xaf709172
    res/drawable/confirm_dialog_bg.xml 0x1d967bfa
    res/drawable/confirm_dialog_cancel_selector.xml 0x2182fcde
    res/drawable/confirm_dialog_ok_selector.xml 0x838435db
    res/drawable/dialog_background.xml 0x4fd129b
    res/drawable/e4alistview_new_message.png 0x1cdc5409
    res/drawable/emoticon_pager_select_normal.png 0xd4b3274c
    res/drawable/error_center_x.xml 0x1381f6c6
    res/drawable/error_circle.xml 0x4f7dd542
    res/drawable/fancircle_banner_cover.png 0x635e2d55
    res/drawable/gray_button_background.xml 0x49ead617
    res/drawable/hou.png 0x356ecd7c
    res/drawable/icon.png 0xcf32f060
    res/drawable/jzsb.png 0xeff0c8d8
    res/drawable/jzz.png 0x104eb37c
    res/drawable/moren.png 0x8a1f4b00
    res/drawable/next_btn_style.xml 0x9256b93
    res/drawable/ok_win10.xml 0xab668da9
    res/drawable/ound_easyicon.png 0x9d7c819f
    res/drawable/pause_btn_style.xml 0x5f41ec0f
    res/drawable/play_btn_style.xml 0x9598de68
    res/drawable/player_landscape_more_normal.png 0xcf66ec96
    res/drawable/player_landscape_more_press.png 0x38397897
    res/drawable/pre_btn_style.xml 0x6ec1b373
    res/drawable/progress_custom_bg.xml 0x9444c7
    res/drawable/qcloud_player_icon_audio_vol.png 0x73be6b62
    res/drawable/qcloud_player_icon_brightness.png 0x3e7ba87b
    res/drawable/qian.png 0xf69d578
    res/drawable/qian1.png 0x48e5c8c6
    res/drawable/red_button_background.xml 0x8b2a8fda
    res/drawable/seekbar_define2_style.xml 0x9a2329d5
    res/drawable/seekbar_define_style.xml 0xe0e89bb0
    res/drawable/seekbar_thumb.xml 0x870d60a9
    res/drawable/spinner_1.png 0x3ced7ec2
    res/drawable/spinner_10.png 0x467437da
    res/drawable/spinner_11.png 0x8221323d
    res/drawable/spinner_12.png 0xa695d39b
    res/drawable/spinner_2.png 0xb3d08bb5
    res/drawable/spinner_3.png 0xfaa5365b
    res/drawable/spinner_4.png 0x50c9309b
    res/drawable/spinner_5.png 0x113a2b04
    res/drawable/spinner_6.png 0x32024394
    res/drawable/spinner_7.png 0xd4414c95
    res/drawable/spinner_8.png 0x31039f6
    res/drawable/spinner_9.png 0x191cc91e
    res/drawable/success_bow.xml 0x6cb0041
    res/drawable/success_circle.xml 0x8889b17f
    res/drawable/vive_yuanxing.xml 0x9d33c26e
    res/drawable/warning_circle.xml 0x95a6aa47
    res/drawable/warning_sigh.xml 0xd0915a0
    res/drawable/zidingyi_anniu_style.xml 0x2599177f
    res/drawable/zidingyi_anniu_style1.xml 0x6a27679b
    res/drawable/zidingyi_anniu_style2.xml 0x78b519ce
    res/layout/alert_dialog.xml 0xae2eece4
    res/layout/canduanxiang.xml 0x5eff05cf
    res/layout/confirm_dialog.xml 0xce3096de
    res/layout/controllerplayinging.xml 0x8930a5db
    res/layout/controllerplayingok.xml 0x4acafd5a
    res/layout/controllerplayingok_apy.xml 0x7da6a54c
    res/layout/controllerplayingok_apy2.xml 0xc917979a
    res/layout/layout.xml 0xb6ec2eca
    res/layout/layout_tab.xml 0xd7250613
    res/layout/layout_tab_bj.xml 0x9e41efbc
    res/layout/layout_tab_bottom.xml 0xc63ab38d
    res/layout/layout_tab_left.xml 0xd35ea748
    res/layout/layout_tab_right.xml 0xccf86a89
    res/layout/layout_tab_segment.xml 0xa955c683
    res/layout/layout_tab_top.xml 0xd99c7e4c
    res/layout/loading_dialog.xml 0x3bcd2adb
    res/layout/progress_custom.xml 0xc84bbe74
    res/layout/prom_dialog.xml 0xe67c76f1
    res/layout/refresh_layout.xml 0xf3571654
    resources.arsc 0x8518b9e1
    运行截图
    VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号