VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:0%Scanner(s) (0/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-03 09:01:52 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 4
antivir 1.9.2.0 1.9.159.0 7.11.182.198 Found nothing 14
antiy 110655 AVL141101 2014-11-02 Found nothing 5
arcavir 1.0 2011 2014-05-30 Found nothing 8
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 141102-0 4.7.4 2014-11-02 Found nothing 28
avg 2109/7906 10.0.1405 2014-10-17 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 2
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.57515 7.90123 2014-11-03 Found nothing 6
clamav 19571 0.97.5 2014-11-02 Found nothing 1
comodo 15023 5.1 2014-11-02 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-10-31 Found nothing 30
fortinet 23.108, 23.108 5.1.158 2014-11-03 Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-10-31 Found nothing 1
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 5
gdata 24.4740 24.4740 2014-11-03 Found nothing 8
hauri 2.73 2.73 2014-10-31 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-11-02 Found nothing 13
jiangmin 16.0.100 1.0.0.0 2014-08-20 Found nothing 31
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 19
kingsoft 2.1 2.1 2013-09-22 Found nothing 4
mcafee 7520 5400.1158 2014-08-04 Found nothing 8
nod32 0436 3.0.21 2014-09-18 Found nothing 1
panda 9.05.01 9.05.01 2014-11-02 Found nothing 5
pcc 11.252.05 9.500-1005 2014-11-02 Found nothing 1
qh360 1.0.1 1.0.1 1.0.1 Found nothing 13
qqphone 1.0.0.0 1.0.0.0 2014-11-03 Found nothing 1
quickheal 14.00 14.00 2014-11-01 Found nothing 2
rising 25.38.01.01 25.38.01.01 2014-10-28 Found nothing 1
sophos 5.04 3.51.0 2014-08-05 Found nothing 6
sunbelt 3.9.2595.2 3.9.2595.2 2014-11-01 Found nothing 1
symantec 20141028.001 1.3.0.24 2014-10-28 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2014-10-31 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-11-02 Found nothing 6
vba 3.12.26.3 3.12.26.3 2014-10-31 Found nothing 3
virusbuster 15.0.956.0 5.5.2.13 2014-11-02 Found nothing 14
权限列表
许可名称 信息
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.INTERNET 连接网络(2G或3G)
文件信息
VirSCANVirSCAN
安全评分 :73
基本信息
VirSCANVirSCAN
MD5:40d8c9febd5db73bffd2fe87a7ebfa3f
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.amnoon
最低运行环境:Android 2.3.3, 2.3.4
版权:amnoon
关键行为
VirSCANVirSCAN
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,TfrmFadeSplash]
进程行为
VirSCANVirSCAN
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,TfrmFadeSplash]
文件行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: Local\UrlZonesSM_Administrator
DfSharedHeapBDA23
\WINDOWS\system32\zh-cn\wshext.dll.mui
行为描述: 创建可执行文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\autorun.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\choice.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\cscript.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\hidcon.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\hs_message.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\instsrv.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\KMService.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\ospprearm.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\PortQry.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\srvany.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\osppc.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\apm3.tmp
行为描述: 修改文件内容
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\Start.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\slerror.xml---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\service.inf---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\ActOf.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\ActWin.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\ChkOf.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\ChkWin.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\KeyMngOf.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\KeyMngW.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\KMSIns.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\RearmOf.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\RearmW.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\Rest.cmd---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\Help.txt---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\ospp.vbs---> Offset = 0
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\Administrator\Local Settings\Temp\2.tmp\Start.cmd
其他行为
VirSCANVirSCAN
行为描述: 枚举窗口
详情信息: N/A
行为描述: 窗口信息
详情信息: Pid = 2080, Hwnd=0xb01de, Text = 是(&Y), ClassName = Button.
Pid = 2080, Hwnd=0xc01d6, Text = 否(&N), ClassName = Button.
Pid = 2080, Hwnd=0xc01c2, Text = 傠 徕ǐ?礅?酄? ìキ?€がōㄡ忄犫? , ClassName = Static.
Pid = 2080, Hwnd=0xd0166, Text = Activation Tool, ClassName = #32770.
Pid = 2172, Hwnd=0xc0184, Text = Activation Tool, ClassName = TfrmMain.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,TfrmFadeSplash]
行为描述: 创建互斥体
详情信息: Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
20141103020001-1486214174
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
动态列表行为
VirSCANVirSCAN
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
com.android.mms.transaction.SmsReceiverService
行为描述: 读取文件
详情信息: path:/proc/783/cmdline length:105
path:/proc/799/cmdline length:105
path:/proc/811/cmdline length:105
path:/proc/842/cmdline length:105
path:/proc/852/cmdline length:105
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/com.amnoon-1.apk
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
VirSCANVirSCAN
活动名 类型
.SupplicantActivity android.intent.action.MAIN
.SupplicantActivity android.intent.category.LAUNCHER
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.INTERNET 连接网络(2G或3G)
文件列表
VirSCANVirSCAN
文件名 校验码
res/drawable/amnoon.png 0xd3fd2471
res/layout/main.xml 0xc840e86c
AndroidManifest.xml 0x7852bc4d
resources.arsc 0xccea5c1e
res/drawable-hdpi/icon.png 0x40b8b2a2
res/drawable-ldpi/icon.png 0x159f0e12
res/drawable-mdpi/icon.png 0xcd7d6924
classes.dex 0x6131b7db
META-INF/MANIFEST.MF 0xac1fd0ca
META-INF/CERT.SF 0x16441757
META-INF/CERT.RSA 0x4004e89d
运行截图
VirSCANVirSCAN
VirSCAN