VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:6%Antivirus software(2/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2016-05-25 23:09:22 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 5
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 150725-1 4.7.4 2015-07-25 Found nothing 60
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 60
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 5
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 60
clamav 19861 0.97.5 2014-12-31 Found nothing 60
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 60
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 60
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 60
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 60
gdata 25.6694 25.6694 2016-05-25 Android.Trojan.Rootnik.AF 8
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 60
jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 40
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 60
kingsoft 2.1 2.1 2013-09-22 Android.TROJ.ijimu.mc.(kcloud) 4
mcafee 7638 5400.1158 2014-11-30 Found nothing 60
nod32 0920 3.0.21 2014-12-23 Found nothing 60
panda 9.05.01 9.05.01 2015-07-26 Found nothing 4
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 60
qh360 1.0.1 1.0.1 1.0.1 Found nothing 3
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 60
quickheal 14.00 14.00 2015-07-25 Found nothing 2
rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 1
sophos 5.08 3.55.0 2014-12-01 Found nothing 60
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 60
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 13
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 60
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 60
权限列表
许可名称 信息
android.permission.RECEIVE_USER_PRESENT
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
com.android.launcher.permission.INSTALL_SHORTCUT 创建快捷方式
android.permission.INTERNET 连接网络(2G或3G)
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.READ_EXTERNAL_STORAGE 读外部存储器(如:SD卡)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:87cdb281713cf1655c96b798dac45408
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:android.system.vold.v47
最低运行环境:Android 2.3, 2.3.1, 2.3.2
版权:Sun
关键行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 获取TickCount值
详情信息: TickCount = 1073166, SleepMilliseconds = 10.
TickCount = 1073181, SleepMilliseconds = 10.
TickCount = 1073197, SleepMilliseconds = 10.
TickCount = 1073213, SleepMilliseconds = 10.
TickCount = 1073228, SleepMilliseconds = 10.
TickCount = 1073244, SleepMilliseconds = 10.
TickCount = 1073260, SleepMilliseconds = 10.
TickCount = 1073275, SleepMilliseconds = 10.
TickCount = 1073291, SleepMilliseconds = 10.
TickCount = 1073306, SleepMilliseconds = 10.
TickCount = 1073322, SleepMilliseconds = 10.
TickCount = 1073338, SleepMilliseconds = 10.
TickCount = 1073353, SleepMilliseconds = 10.
TickCount = 1073369, SleepMilliseconds = 10.
TickCount = 1073385, SleepMilliseconds = 10.
进程行为
VirSCANVirSCAN
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 获取TickCount值
详情信息: TickCount = 1073166, SleepMilliseconds = 10.
TickCount = 1073181, SleepMilliseconds = 10.
TickCount = 1073197, SleepMilliseconds = 10.
TickCount = 1073213, SleepMilliseconds = 10.
TickCount = 1073228, SleepMilliseconds = 10.
TickCount = 1073244, SleepMilliseconds = 10.
TickCount = 1073260, SleepMilliseconds = 10.
TickCount = 1073275, SleepMilliseconds = 10.
TickCount = 1073291, SleepMilliseconds = 10.
TickCount = 1073306, SleepMilliseconds = 10.
TickCount = 1073322, SleepMilliseconds = 10.
TickCount = 1073338, SleepMilliseconds = 10.
TickCount = 1073353, SleepMilliseconds = 10.
TickCount = 1073369, SleepMilliseconds = 10.
TickCount = 1073385, SleepMilliseconds = 10.
文件行为
VirSCANVirSCAN
行为描述: 创建文件
详情信息: C:\Program Files\kele55\Install\kele.exe
行为描述: 设置特殊文件夹属性
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
C:\Documents and Settings\Administrator\Local Settings\History
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
C:\Documents and Settings\Administrator\Cookies
C:\Documents and Settings\Administrator\IETldCache
行为描述: 修改文件内容
详情信息: C:\Program Files\kele55\Install\kele.exe ---> Offset = 0
C:\Program Files\kele55\Install\kele.exe ---> Offset = 16384
C:\Program Files\kele55\Install\kele.exe ---> Offset = 32768
C:\Program Files\kele55\Install\kele.exe ---> Offset = 49152
C:\Program Files\kele55\Install\kele.exe ---> Offset = 65536
行为描述: 查找文件
详情信息: FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\Local Settings
FileName = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
FileName = C:\WINDOWS\system32\Ras\*.pbk
FileName = C:\Documents and Settings\Administrator\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
FileName = C:\Program Files\kele55\Install\kele.exe
FileName = C:\Documents and Settings\Administrator\My Documents
FileName = C:\Documents and Settings\All Users
FileName = C:\Documents and Settings\All Users\Documents
FileName = C:\Documents and Settings\Administrator\桌面
FileName = C:\Documents and Settings\All Users\桌面
FileName = C:\Program Files\kele55
FileName = C:\Program Files\kele55\Install
FileName = Files\kele55
行为描述: 创建可执行文件
详情信息: C:\Program Files\kele55\Install\kele.exe
网络行为
VirSCANVirSCAN
行为描述: 下载文件
详情信息: C:\Program Files\kele55\Install\kele.exe
行为描述: 连接指定站点
详情信息: InternetConnectA: ServerName = do****cn, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
InternetConnectA: ServerName = cj****om, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
InternetConnectA: ServerName = tg****om, PORT = 80, UserName = , Password = , hSession = 0x00cc0004, hConnect = 0x00cc0008, Flags = 0x00000000
InternetConnectA: ServerName = cj****om, PORT = 80, UserName = , Password = , hSession = 0x00cc000c, hConnect = 0x00cc0010, Flags = 0x00000000
行为描述: 打开HTTP连接
详情信息: InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT), hSession = 0x00cc0004
InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT), hSession = 0x00cc000c
行为描述: 建立到一个指定的套接字连接
详情信息: URL: do****cn, IP: **.133.40.**:80, SOCKET = 0x0000054c
URL: cj****om, IP: **.133.40.**:80, SOCKET = 0x000005e4
URL: cj****om, IP: **.133.40.**:80, SOCKET = 0x00000550
URL: tg****om, IP: **.133.40.**:80, SOCKET = 0x000004c0
URL: cj****om, IP: **.133.40.**:80, SOCKET = 0x000004bc
URL: cj****om, IP: **.133.40.**:80, SOCKET = 0x00000464
行为描述: 读取网络文件
详情信息: hFile = 0x00cc000c, BytesToRead =262144, BytesRead = 262144.
hFile = 0x00cc0014, BytesToRead =262144, BytesRead = 262144.
行为描述: 发送HTTP包
详情信息: GET /downcontainer/downLoad.do HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT) Host: do****cn Cache-Control: no-cache
GET /downloader/start?dlver=G1.0.0&pname=kele55&pver=0.0&cmdtype=0&cmdid=1&ad=0&oemid=0&fromurl=&webid= HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT) Host: cj****om Cache-Control: no-cache
GET /downloader/startdown?dlver=G1.0.0&pname=kele55&pver=0.0&cmdtype=0&cmdid=1&ad=0&oemid=0&fromurl=&webid= HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT) Host: cj****om Cache-Control: no-cache
HEAD /business/kele.exe HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT) Host: tg****om Content-Length: 0 Cache-Control: no-cache
GET /business/kele.exe HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT) Host: tg****om Cache-Control: no-cache
GET /downloader/downloadcomplete?dlver=G1.0.0&pname=kele55&pver=0.0&cmdtype=0&cmdid=1&ad=0&oemid=0&fromurl=&webid=&dltime=140 HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT) Host: cj****om Cache-Control: no-cache
GET /downloader/installcompletefail?dlver=G1.0.0&pname=kele55&pver=0.0&cmdtype=0&cmdid=1&ad=0&oemid=0&fromurl=&webid=&dltime=140&insttime=875&homepage=1&recinst=0 HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT) Host: cj****om Cache-Control: no-cache
行为描述: 打开HTTP请求
详情信息: HttpOpenRequestA: do****cn:80/downcontainer/download.do, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0xa4000100
HttpOpenRequestA: cj****om:80/downloader/start?dlver=g1.0.0&pname=kele55&pver=0.0&cmdtype=0&cmdid=1&ad=0&oemid=0&fromurl=&webid=, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0xa4000100
HttpOpenRequestA: cj****om:80/downloader/startdown?dlver=g1.0.0&pname=kele55&pver=0.0&cmdtype=0&cmdid=1&ad=0&oemid=0&fromurl=&webid=, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0xa4000100
HttpOpenRequestA: tg****om:80/business/kele.exe, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: HEAD, Referer: , Flags = 0xa4000100
HttpOpenRequestA: tg****om:80/business/kele.exe, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0xa4000100
HttpOpenRequestA: cj****om:80/downloader/downloadcomplete?dlver=g1.0.0&pname=kele55&pver=0.0&cmdtype=0&cmdid=1&ad=0&oemid=0&fromurl=&webid=&dltime=140, hConnect = 0x00cc0010, hRequest = 0x00cc0014, Verb: GET, Referer: , Flags = 0xa4000100
HttpOpenRequestA: cj****om:80/downloader/installcompletefail?dlver=g1.0.0&pname=kele55&pver=0.0&cmdtype=0&cmdid=1&ad=0&oemid=0&fromurl=&webid=&dltime=140&insttime=875&homepage=1&recinst=0, hConnect = 0x00cc0008, hRequest = 0x00cc000c, Verb: GET, Referer: , Flags = 0xa4000100
行为描述: 按名称获取主机地址
详情信息: GetAddrInfoW: do****cn
GetAddrInfoW: cj****om
GetAddrInfoW: tg****om
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
\REGISTRY\USER\S-*\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program Files\kele55\Install\kele.exe
行为描述: 删除注册表键值
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
Global\GirlShowSmallStationDownloadInstallTools
MSCTF.Shared.MUTEX.ELH
Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
RasPbFile
MSCTF.Shared.MUTEX.MHJ
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,Button]
[Window,Class] = [,#32770]
[Window,Class] = [锁定到任务栏,Static]
[Window,Class] = [可乐视频社区,#32770]
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
行为描述: 获取TickCount值
详情信息: TickCount = 1073166, SleepMilliseconds = 10.
TickCount = 1073181, SleepMilliseconds = 10.
TickCount = 1073197, SleepMilliseconds = 10.
TickCount = 1073213, SleepMilliseconds = 10.
TickCount = 1073228, SleepMilliseconds = 10.
TickCount = 1073244, SleepMilliseconds = 10.
TickCount = 1073260, SleepMilliseconds = 10.
TickCount = 1073275, SleepMilliseconds = 10.
TickCount = 1073291, SleepMilliseconds = 10.
TickCount = 1073306, SleepMilliseconds = 10.
TickCount = 1073322, SleepMilliseconds = 10.
TickCount = 1073338, SleepMilliseconds = 10.
TickCount = 1073353, SleepMilliseconds = 10.
TickCount = 1073369, SleepMilliseconds = 10.
TickCount = 1073385, SleepMilliseconds = 10.
行为描述: 调整进程token权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
行为描述: 窗口信息
详情信息: Pid = 2424, Hwnd=0x80326, Text = 可乐软件许可协议, ClassName = Static.
Pid = 2424, Hwnd=0xa030a, Text = 可乐视频社区, ClassName = Static.
Pid = 2424, Hwnd=0x6035e, Text = 查看", ClassName = Static.
Pid = 2424, Hwnd=0x40368, Text = "并进行安装, ClassName = Static.
Pid = 2424, Hwnd=0x90354, Text = 可乐视频社区, ClassName = #32770.
Pid = 2424, Hwnd=0x80324, Text = C:\Program Files\kele55, ClassName = Edit.
Pid = 2424, Hwnd=0x90320, Text = 启动房间, ClassName = Button.
Pid = 2424, Hwnd=0x60362, Text = 浏览, ClassName = Button.
Pid = 2424, Hwnd=0xa0322, Text = 开机启动, ClassName = Static.
Pid = 2424, Hwnd=0xb02f2, Text = 加载完成后启动, ClassName = Static.
Pid = 2424, Hwnd=0x60360, Text = 锁定到任务栏, ClassName = Static.
Pid = 2424, Hwnd=0x60356, Text = 可乐视频社区, ClassName = Static.
Pid = 2424, Hwnd=0x90350, Text = 主播上线提醒, ClassName = Static.
Pid = 2424, Hwnd=0x80312, Text = 可乐视频社区, ClassName = #32770.
Pid = 2424, Hwnd=0x902fc, Text = Button2, ClassName = Button.
行为描述: 可执行文件签名信息
详情信息: C:\Program Files\kele55\Install\kele.exe(签名验证: 未通过)
行为描述: 创建事件对象
详情信息: EventName = DINPUTWINMM
EventName = Global\userenv: User Profile setup event
EventName = MSCTF.SendReceive.Event.MHJ.IC
EventName = MSCTF.SendReceiveConection.Event.MHJ.IC
行为描述: 可执行文件MD5
详情信息: C:\Program Files\kele55\Install\kele.exe ---> fe1d0ee5901dd167ee9b28eece31786c
启动方式
VirSCANVirSCAN
名称 信息
android.system.vold.StartupReceiver 开机启动服务
android.system.vold.StartupReceiver 屏幕解锁启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.RECEIVE_USER_PRESENT
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
com.android.launcher.permission.INSTALL_SHORTCUT 创建快捷方式
android.permission.INTERNET 连接网络(2G或3G)
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.READ_EXTERNAL_STORAGE 读外部存储器(如:SD卡)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
服务列表
VirSCANVirSCAN
名称
android.system.vold.VoldService
android.system.vold.v47.rp.ibn217
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0x9927da16
META-INF/ANDROIDD.SF 0x9de8312
META-INF/ANDROIDD.RSA 0xd44ef79e
AndroidManifest.xml 0xdbee6a01
assets/s_s_kbhyxbxeyb 0x50b492d3
classes.dex 0x893994ff
res/drawable-hdpi-v4/ic_launcher.png 0x5f8a1eb4
resources.arsc 0x949e0c12
运行截图
VirSCANVirSCAN
VirSCAN