VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:0%Scanner(s) (0/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-03 08:05:22 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 3
antivir 1.9.2.0 1.9.159.0 7.11.182.198 Found nothing 14
antiy 114701 AVL141003 2014-10-04 Found nothing 5
arcavir 1.0 2011 2014-05-30 Found nothing 9
asquared 9.0.0.4157 9.0.0.4157 2014-07-30 Found nothing 1
avast 141102-0 4.7.4 2014-11-02 Found nothing 32
avg 2109/7906 10.0.1405 2014-10-17 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 3
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.57515 7.90123 2014-11-03 Found nothing 9
clamav 19571 0.97.5 2014-11-02 Found nothing 1
comodo 15023 5.1 2014-10-03 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-10-31 Found nothing 30
fortinet 23.108, 23.108 5.1.158 2014-11-03 Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-10-31 Found nothing 1
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 5
gdata 24.3819 24.3819 2014-08-29 Found nothing 7
hauri 2.73 2.73 2014-06-13 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-11-02 Found nothing 13
jiangmin 16.0.100 1.0.0.0 2014-07-28 Found nothing 13
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 20
kingsoft 2.1 2.1 2013-09-22 Found nothing 2
mcafee 7520 5400.1158 2014-08-04 Found nothing 8
nod32 0436 3.0.21 2014-09-18 Found nothing 1
panda 9.05.01 9.05.01 2014-06-15 Found nothing 3
pcc 11.252.05 9.500-1005 2014-11-02 Found nothing 1
qh360 1.0.1 1.0.1 1.0.1 Found nothing 12
qqphone 1.0.0.0 1.0.0.0 2014-11-03 Found nothing 1
quickheal 14.00 14.00 2014-06-14 Found nothing 2
rising 25.17.00.04 25.17.00.04 2014-06-02 Found nothing 1
sophos 5.04 3.51.0 2014-08-05 Found nothing 6
sunbelt 3.9.2589.2 3.9.2589.2 2014-06-13 Found nothing 1
symantec 20141028.001 1.3.0.24 2014-10-28 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2014-06-12 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-06-16 Found nothing 6
vba 3.12.26.3 3.12.26.3 2014-10-31 Found nothing 3
virusbuster 15.0.956.0 5.5.2.13 2014-11-02 Found nothing 14
权限列表
许可名称 信息
android.permission.READ_CONTACTS 读取联系人信息
文件信息
VirSCANVirSCAN
安全评分 :78
基本信息
VirSCANVirSCAN
MD5:8dd6ba94a339f771f3670ee4bb7c1941
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.jmk.healthlog
最低运行环境:Android 2.3.3, 2.3.4
版权:Mooney Unlimited
关键行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,#32770]
[Window,Class] = [Debug,#32770]
[Window,Class] = [您的产品 Setup,Afx:400000:3:10011:1900015:27018d]
[Window,Class] = [&Help,Button]
[Window,Class] = [,Button]
[Window,Class] = [,Auto-Suggest Dropdown]
行为描述: 按名称获取主机地址
详情信息: wpad.
hi.baidu.com
进程行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,#32770]
[Window,Class] = [Debug,#32770]
[Window,Class] = [您的产品 Setup,Afx:400000:3:10011:1900015:27018d]
[Window,Class] = [&Help,Button]
[Window,Class] = [,Button]
[Window,Class] = [,Auto-Suggest Dropdown]
行为描述: 按名称获取主机地址
详情信息: wpad.
hi.baidu.com
文件行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: Global\Cor_Private_IPCBlock_2060
Global\Cor_Public_IPCBlock_2060
Global\NLS_CodePage_936_3_2_0_0
Global\NLS_00000804_Exception_Table_3_2
Global\netfxcustomperfcounters.1.0.net clr networking
行为描述: 在系统敏感位置(如开始菜单等)释放链接或快捷方式
详情信息: C:\Documents and Settings\Administrator\「开始」菜单\程序\您的产品\ .lnk
C:\Documents and Settings\Administrator\「开始」菜单\程序\您的产品\果豆应用.lnk
C:\Documents and Settings\Administrator\「开始」菜单\程序\您的产品\卸载 您的产品.lnk
行为描述: 创建可执行文件
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_ir_sf7_temp_0\irsetup.exe
C:\WINDOWS\您的产品\uninstall.exe
C:\Program Files\您的产品\soft_5_1.exe
C:\Program Files\您的产品\GuoDou_1034_1231.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw7.tmp\DialogEx.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw7.tmp\System.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw7.tmp\Blowfish.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw7.tmp\Inetc.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw7.tmp\nsUnzip.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw7.tmp\nsArray.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw7.tmp\XML.dll
行为描述: 修改文件内容
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_ir_sf7_temp_0\irsetup.dat---> Offset = 12288
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_ir_sf7_temp_0\IRIMG1.JPG---> Offset = 8192
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_ir_sf7_temp_0\IRIMG2.JPG---> Offset = 12288
C:\WINDOWS\您的产品 Setup Log.txt---> Offset = 0
C:\Program Files\您的产品\Uninstall\uni4.tmp---> Offset = 12288
C:\Program Files\您的产品\Uninstall\uninstall.dat---> Offset = 65536
C:\Program Files\您的产品\Uninstall\uninstall.xml---> Offset = 0
C:\WINDOWS\您的产品 Setup Log.txt---> Offset = 879
C:\Documents and Settings\Administrator\「开始」菜单\程序\您的产品\ .lnk---> Offset = 0
C:\Documents and Settings\Administrator\「开始」菜单\程序\您的产品\果豆应用.lnk---> Offset = 0
C:\Program Files\您的产品\Uninstall\IRIMG1.JPG---> Offset = 0
C:\Program Files\您的产品\Uninstall\IRIMG2.JPG---> Offset = 0
C:\Documents and Settings\Administrator\「开始」菜单\程序\您的产品\卸载 您的产品.lnk---> Offset = 0
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw7.tmp\FrameImg.png---> Offset = 0
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsw7.tmp\bg.png---> Offset = 0
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
网络行为
VirSCANVirSCAN
行为描述: 连接指定站点
详情信息: InternetConnectA: ServerName = xml.tai69.com, PORT = 80
InternetConnectA: ServerName = xml2.tai69.com, PORT = 80
行为描述: 下载文件
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AAA.xml
行为描述: 读取网络文件
详情信息: hFile = 0x000001b8, BytesToRead =8192, BytesRead = 8192.
hFile = 0x000001c8, BytesToRead =8192, BytesRead = 8192.
行为描述: 打开HTTP请求
详情信息: HttpOpenRequestA: xml.tai69.com:80/config.php?v=1.01028, hConnect = 0x000001bc
HttpOpenRequestA: xml2.tai69.com:80/config.php?v=1.01028, hConnect = 0x000001c4
行为描述: 按名称获取主机地址
详情信息: wpad.
hi.baidu.com
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\DisplayName
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\NoModify
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\NoRepair
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\UninstallString
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\Publisher
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\URLInfoAbout
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\HelpLink
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\Contact
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\DisplayVersion
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\您的产品1.0\DisplayIcon
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: RasPbFile
Global\.net clr networking
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,#32770]
[Window,Class] = [Debug,#32770]
[Window,Class] = [您的产品 Setup,Afx:400000:3:10011:1900015:27018d]
[Window,Class] = [&Help,Button]
[Window,Class] = [,Button]
[Window,Class] = [,Auto-Suggest Dropdown]
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [#32770,]
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
行为描述: 窗口信息
详情信息: Pid = 1600, Hwnd=0xb01c6, Text = &Finish, ClassName = Button.
Pid = 1600, Hwnd=0xb0184, Text = &Cancel, ClassName = Button.
Pid = 1600, Hwnd=0xa01aa, Text = &Help, ClassName = Button.
Pid = 1600, Hwnd=0xb01b0, Text = < &Back, ClassName = Button.
Pid = 1600, Hwnd=0xd01c2, Text = 您的产品 Setup, ClassName = Afx:400000:3:10011:1900015:27018d.
Pid = 1852, Hwnd=0xd016c, Text = 目标文件夹, ClassName = Button.
Pid = 1852, Hwnd=0xd0174, Text = 所需空间: 1.8MB, ClassName = Static.
Pid = 1852, Hwnd=0xf0190, Text = 可用空间: 16.4GB, ClassName = Static.
Pid = 1852, Hwnd=0xf01b6, Text = C:\Program Files\GuoDou, ClassName = Edit.
Pid = 1852, Hwnd=0xb01e0, Text = 安装路径, ClassName = Static.
Pid = 1852, Hwnd=0xe01a6, Text = 加入自启动项, ClassName = Button(CheckBox).
Pid = 1852, Hwnd=0xd01be, Text = , ClassName = Button.
Pid = 1852, Hwnd=0xd0170, Text = , ClassName = Button(CheckBox).
Pid = 1852, Hwnd=0xe0198, Text = 果豆应用 1.01028 安装 , ClassName = #32770.
行为描述: 打开图片文件
详情信息: \DOCUME~1\ADMINI~1\LOCALS~1\Temp\_ir_sf7_temp_0\IRIMG1.JPG
\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_ir_sf7_temp_0\IRIMG2.JPG
\Program Files\您的产品\Uninstall\IRIMG1.JPG
\Program Files\您的产品\Uninstall\IRIMG2.JPG
动态列表行为
VirSCANVirSCAN
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
com.android.mms.transaction.SmsReceiverService
行为描述: 读取文件
详情信息: path:/proc/783/cmdline length:105
path:/proc/798/cmdline length:105
path:/proc/810/cmdline length:105
path:/proc/840/cmdline length:105
path:/proc/852/cmdline length:105
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/com.jmk.healthlog-1.apk
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
VirSCANVirSCAN
活动名 类型
.HealthLogActivity android.intent.action.MAIN
.HealthLogActivity android.intent.category.LAUNCHER
危险函数
VirSCANVirSCAN
函数名称 信息
ContentResolver;->query 读取联系人、短信等数据库
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.READ_CONTACTS 读取联系人信息
文件列表
VirSCANVirSCAN
文件名 校验码
res/drawable/doctor.png 0x72ac99ab
res/drawable/general.png 0x413bfe34
res/drawable/healthcross.png 0x32a0c874
res/drawable/ic_launcher.png 0xabcc960c
res/drawable/log.png 0x89c2d5e7
res/drawable/rx.png 0x3832c700
res/layout/main.xml 0x6f58c479
res/layout/medication_detail.xml 0x8e203f63
res/layout/medication_list.xml 0x30a239bd
res/layout/physicians_list.xml 0x95f99dd1
res/layout/records_detail.xml 0xf5d44a05
res/layout/records_list.xml 0xb9e1bd21
res/layout/records_simple.xml 0xb62abd9
res/layout/vitals_day_detail.xml 0x217f0b8b
res/layout/vitals_history.xml 0xb8d7d633
res/layout/vitals_time_detail.xml 0x72e28411
AndroidManifest.xml 0xd4e9b4c
resources.arsc 0x5a7e2e57
classes.dex 0xd436c455
META-INF/MANIFEST.MF 0xf59ce99b
META-INF/CERT.SF 0xbb67656a
META-INF/CERT.RSA 0xbcabce7c
运行截图
VirSCANVirSCAN
VirSCAN