VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:3%Antivirus software(1/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2017-07-03 02:38:51 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 2.0 1970-01-01 Found nothing 5
asquared 9.0.0.4799 9.0.0.4799 2015-03-08 Found nothing 1
avast 170303-1 4.7.4 2017-03-03 Found nothing 60
avg 2109/14122 10.0.1405 2017-06-29 Found nothing 60
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 5
baidusd 1.0 1.0 2017-03-22 Found nothing 1
bitdefender 7.58879 7.90123 2015-01-16 Found nothing 60
clamav 23506 0.97.5 2017-06-25 Found nothing 60
drweb 5.0.2.3300 5.0.1.1 2017-06-18 Found nothing 60
fortinet 49.915, 49.796 5.4.247 2017-07-03 Found nothing 60
fprot 4.6.2.117 6.5.1.5418 2016-02-05 Found nothing 60
fsecure 2015-08-01-02 9.13 2015-08-01 Found nothing 60
gdata 25.13180 25.13180 2017-07-03 Found nothing 11
ikarus 1.06.01 V1.32.31.0 2016-11-28 Found nothing 60
jiangmin 16.0.100 1.0.0.0 2017-07-01 Found nothing 2
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 60
kingsoft 2.1 2.1 2017-07-02 Found nothing 3
mcafee 8261 5400.1158 2016-08-18 Found nothing 60
nod32 1777 3.0.21 2015-06-12 Found nothing 60
panda 9.05.01 9.05.01 2017-07-01 Found nothing 4
pcc 13.302.06 9.500-1005 2017-03-27 Found nothing 60
qh360 1.0.1 1.0.1 1.0.1 Found nothing 4
qqphone 1.0.0.0 1.0.0.0 2015-12-30 Found nothing 60
quickheal 14.00 14.00 2017-07-01 Android.BaiduProtect.A (PUP) 3
rising 26.28.00.01 26.28.00.01 2016-07-18 Found nothing 1
sophos 5.32 3.65.2 2016-10-10 Found nothing 60
symantec 20151230.005 1.3.0.24 2015-12-30 Found nothing 60
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2017-06-27 Found nothing 1
tws 17.47.17308 1.0.2.2108 2017-07-01 Found nothing 14
vba 3.12.29.5 beta 3.12.29.5 beta 2017-06-30 Found nothing 60
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 60
权限列表
许可名称 信息
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.CALL_PHONE 拨打电话
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.INTERNET 连接网络(2G或3G)
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:b9edfe8f30fdc7f31055ddb656273610
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.dt.call
最低运行环境:Android 2.2.x
版权:androidkiller
关键行为
VirSCANVirSCAN
行为描述: 屏蔽窗口关闭消息
详情信息: hWnd = 0x001b02b6, Text = *********k07*********, ClassName = #32770.
行为描述: 修改注册表_系统防火墙可信进程列表
详情信息: \REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe
行为描述: 获取TickCount值
详情信息: TickCount = 5428235, SleepMilliseconds = 1.
TickCount = 5428251, SleepMilliseconds = 1.
TickCount = 5428266, SleepMilliseconds = 1.
TickCount = 5428282, SleepMilliseconds = 1.
TickCount = 5428297, SleepMilliseconds = 1.
TickCount = 5428313, SleepMilliseconds = 1.
TickCount = 5428329, SleepMilliseconds = 1.
TickCount = 5428344, SleepMilliseconds = 1.
TickCount = 5428360, SleepMilliseconds = 1.
TickCount = 5428391, SleepMilliseconds = 1.
TickCount = 5428407, SleepMilliseconds = 1.
TickCount = 5428422, SleepMilliseconds = 1.
TickCount = 5428438, SleepMilliseconds = 1.
TickCount = 5428454, SleepMilliseconds = 1.
TickCount = 5428469, SleepMilliseconds = 1.
进程行为
VirSCANVirSCAN
行为描述: 屏蔽窗口关闭消息
详情信息: hWnd = 0x001b02b6, Text = *********k07*********, ClassName = #32770.
行为描述: 修改注册表_系统防火墙可信进程列表
详情信息: \REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe
行为描述: 获取TickCount值
详情信息: TickCount = 5428235, SleepMilliseconds = 1.
TickCount = 5428251, SleepMilliseconds = 1.
TickCount = 5428266, SleepMilliseconds = 1.
TickCount = 5428282, SleepMilliseconds = 1.
TickCount = 5428297, SleepMilliseconds = 1.
TickCount = 5428313, SleepMilliseconds = 1.
TickCount = 5428329, SleepMilliseconds = 1.
TickCount = 5428344, SleepMilliseconds = 1.
TickCount = 5428360, SleepMilliseconds = 1.
TickCount = 5428391, SleepMilliseconds = 1.
TickCount = 5428407, SleepMilliseconds = 1.
TickCount = 5428422, SleepMilliseconds = 1.
TickCount = 5428438, SleepMilliseconds = 1.
TickCount = 5428454, SleepMilliseconds = 1.
TickCount = 5428469, SleepMilliseconds = 1.
文件行为
VirSCANVirSCAN
行为描述: 查找文件
详情信息: FileName = C:\Documents and Settings\Administrator\Application Data\Tencent
FileName = C:\Documents and Settings\Administrator\Application Data\Tencent\QQ
FileName = C:\Documents and Settings\Administrator\Application Data\Tencent\QQ\STemp
FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\桌面
FileName = C:\Documents and Settings\Administrator\桌面\k07.lnk
FileName = C:\Documents and Settings\Administrator\桌面\k07.lnk\*.*
网络行为
VirSCANVirSCAN
行为描述: 建立到一个指定的套接字连接
详情信息: IP: **.14.187.**:17951, SOCKET = 0x000002dc
IP: **.14.187.**:17951, SOCKET = 0x000002e4
IP: **.199.192.**:17951, SOCKET = 0x000002ec
IP: **.14.187.**:17951, SOCKET = 0x000002ec
IP: **.199.188.**:17951, SOCKET = 0x000002ec
IP: **.199.192.**:17951, SOCKET = 0x000002f0
IP: **.199.188.**:17951, SOCKET = 0x000002f0
IP: **.14.187.**:17951, SOCKET = 0x000002f0
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表_系统防火墙可信进程列表
详情信息: \REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.ELH
行为描述: 创建事件对象
详情信息: EventName = DINPUTWINMM
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
行为描述: 获取TickCount值
详情信息: TickCount = 5428235, SleepMilliseconds = 1.
TickCount = 5428251, SleepMilliseconds = 1.
TickCount = 5428266, SleepMilliseconds = 1.
TickCount = 5428282, SleepMilliseconds = 1.
TickCount = 5428297, SleepMilliseconds = 1.
TickCount = 5428313, SleepMilliseconds = 1.
TickCount = 5428329, SleepMilliseconds = 1.
TickCount = 5428344, SleepMilliseconds = 1.
TickCount = 5428360, SleepMilliseconds = 1.
TickCount = 5428391, SleepMilliseconds = 1.
TickCount = 5428407, SleepMilliseconds = 1.
TickCount = 5428422, SleepMilliseconds = 1.
TickCount = 5428438, SleepMilliseconds = 1.
TickCount = 5428454, SleepMilliseconds = 1.
TickCount = 5428469, SleepMilliseconds = 1.
行为描述: 调整进程token权限
详情信息: SE_DEBUG_PRIVILEGE
SE_LOAD_DRIVER_PRIVILEGE
行为描述: 屏蔽窗口关闭消息
详情信息: hWnd = 0x001b02b6, Text = *********k07*********, ClassName = #32770.
行为描述: 打开事件
详情信息: HookSwitchHookEnabledEvent
_fCanRegisterWithShellService
CTF.ThreadMIConnectionEvent.000007B4.00000000.00000053
CTF.ThreadMarshalInterfaceEvent.000007B4.00000000.00000053
MSCTF.SendReceiveConection.Event.ELH.IC
MSCTF.SendReceive.Event.ELH.IC
行为描述: 调用Sleep函数
详情信息: [1]: MilliSeconds = 1.
[2]: MilliSeconds = 1.
[3]: MilliSeconds = 1.
[4]: MilliSeconds = 1.
[5]: MilliSeconds = 1.
[6]: MilliSeconds = 1.
[7]: MilliSeconds = 1.
[8]: MilliSeconds = 1.
[9]: MilliSeconds = 1.
[10]: MilliSeconds = 1.
行为描述: 打开互斥体
详情信息: ShimCacheMutex
Activities
VirSCANVirSCAN
活动名 类型
com.dt.call.SplashActivity android.intent.action.MAIN
com.dt.call.SplashActivity android.intent.category.LAUNCHER
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.CALL_PHONE 拨打电话
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.INTERNET 连接网络(2G或3G)
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
服务列表
VirSCANVirSCAN
名称
com.test.load.LoadService
Providers
VirSCANVirSCAN
名称 信息
com.test.load.LoadService
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0xc84dc157
META-INF/ANDROIDK.SF 0x23a212f9
META-INF/ANDROIDK.RSA 0x2bcb837b
assets/load_setting 0x83dc20c8
res/drawable-hdpi-v4/ic_launcher.png 0x53d08ae
res/drawable-hdpi-v4/logo.png 0x29dd82c4
res/drawable-mdpi-v4/ic_launcher.png 0xb76f8e32
res/drawable-xhdpi-v4/ic_launcher.png 0x5f58f4d5
res/drawable-xxhdpi-v4/ic_launcher.png 0xce43d39a
res/layout/act_loopcall.xml 0x24aeb8e4
res/layout/act_singlecall.xml 0x32875781
res/layout/act_splash.xml 0x65cba72b
res/layout/itemview_callloop.xml 0x3673467a
res/layout/load_dialogview.xml 0x8279b8df
res/menu/main.xml 0x1d494ad2
res/raw/load_setting 0x90c60a99
resources.arsc 0x458a88d
AndroidManifest.xml 0x600e91cb
assets/baiduprotect1.jar 0xe4e9e5e7
lib/ 0x0
lib/armeabi/ 0x0
lib/armeabi/libbaiduprotect.so 0x9b82e023
lib/x86/ 0x0
lib/x86/libbaiduprotect.so 0x8b034d3c
assets/libbaiduprotect_x86.so 0x7081c2e1
classes.dex 0x43fac0dd
运行截图
VirSCANVirSCAN
VirSCAN