VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:2%Scanner(s) (1/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-08 21:36:21 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 4
antivir 1.9.2.0 1.9.159.0 7.11.183.172 Found nothing 20
antiy 112612 AVL141106 2014-11-07 Found nothing 5
arcavir 1.0 2011 2014-05-30 Found nothing 8
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 141106-0 4.7.4 2014-11-06 Found nothing 26
avg 2109/8019 10.0.1405 2014-11-06 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 4
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.57607 7.90123 2014-11-07 Found nothing 6
clamav 19595 0.97.5 2014-11-07 Found nothing 1
comodo 15023 5.1 2014-11-07 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-10-31 Found nothing 36
fortinet 23.129, 23.129 5.1.158 2014-11-07 Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-11-07 Found nothing 1
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 7
gdata 24.4834 24.4834 2014-11-07 Found nothing 8
hauri 2.73 2.73 2014-11-07 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-11-07 Found nothing 14
jiangmin 16.0.100 1.0.0.0 2014-08-20 Found nothing 32
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 21
kingsoft 2.1 2.1 2013-09-22 Found nothing 5
mcafee 7520 5400.1158 2014-08-04 Found nothing 9
nod32 0436 3.0.21 2014-09-18 Found nothing 1
panda 9.05.01 9.05.01 2014-11-07 Found nothing 4
pcc 11.262.06 9.500-1005 2014-11-07 Found nothing 2
qh360 1.0.1 1.0.1 1.0.1 Found nothing 13
qqphone 1.0.0.0 1.0.0.0 2014-11-08 百度(a.spot.baidu.a) 2
quickheal 14.00 14.00 2014-11-07 Found nothing 2
rising 25.39.03.04 25.39.03.04 2014-11-06 Found nothing 1
sophos 5.04 3.51.0 2014-08-05 Found nothing 10
sunbelt 3.9.2595.2 3.9.2595.2 2014-11-06 Found nothing 2
symantec 20141104.004 1.3.0.24 2014-11-04 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
thehacker 6.8.0.5 6.8.0.5 2014-11-07 Found nothing 2
tws 17.47.17308 1.0.2.2108 2014-11-07 Found nothing 6
vba 3.12.26.3 3.12.26.3 2014-11-06 Found nothing 4
virusbuster 15.0.961.0 5.5.2.13 2014-11-07 Found nothing 15
权限列表
许可名称 信息
android.permission.CAMERA 访问照相机设备
android.permission.FLASHLIGHT 访问闪光灯
android.permission.DISABLE_KEYGUARD 禁用键盘锁
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.MOUNT_UNMOUNT_FILESYSTEMS 挂载、反挂载外部文件系统
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_COARSE_LOCATION 获取粗略的位置(通过wifi、基站)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
文件信息
VirSCANVirSCAN
安全评分 :74
基本信息
VirSCANVirSCAN
MD5:bf8b19c1ab0ecb886515b325c9acf501
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.totoro.flashlight
最低运行环境:Android 2.0
版权:
关键行为
VirSCANVirSCAN
行为描述: 按名称获取主机地址
详情信息: www.6jbox.iego.cn
网络行为
VirSCANVirSCAN
行为描述: 建立到一个指定的套接字连接
详情信息: 127.0.0.1:1040
127.0.0.1:1041
127.0.0.1:1042
127.0.0.1:1043
127.0.0.1:1044
127.0.0.1:1045
127.0.0.1:1046
127.0.0.1:1047
127.0.0.1:1048
127.0.0.1:1049
127.0.0.1:1050
127.0.0.1:1051
127.0.0.1:1052
127.0.0.1:1053
127.0.0.1:1054
行为描述: 按名称获取主机地址
详情信息: www.6jbox.iego.cn
注册表行为
VirSCANVirSCAN
行为描述: 删除注册表键
详情信息: \REGISTRY\MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\DW
行为描述: 删除注册表键值
详情信息: \REGISTRY\MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\DW\DWFileTreeRoot
异常崩溃
VirSCANVirSCAN
动态列表行为
VirSCANVirSCAN
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
com.android.mms.transaction.SmsReceiverService
行为描述: 读取文件
详情信息: path:/proc/783/cmdline length:105
path:/proc/799/cmdline length:105
path:/proc/811/cmdline length:105
path:/proc/841/cmdline length:105
path:/proc/852/cmdline length:105
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/com.totoro.flashlight-1.apk
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
VirSCANVirSCAN
活动名 类型
com.totoro.flashlight.MainActivity android.intent.action.MAIN
com.totoro.flashlight.MainActivity android.intent.category.LAUNCHER
危险函数
VirSCANVirSCAN
函数名称 信息
java/net/URL;->openConnection 连接URL
java/net/HttpURLConnection;->connect 连接URL
java/net/URLConnection;->connect 连接URL
Camera;->open 开启相机
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
LocationManager;->getLastKnownLocation 获取地址位置
android/app/NotificationManager;->notify 信息通知栏
HttpClient;->execute 请求远程服务器
广告信息
VirSCANVirSCAN
名称 信息
com.baidu 百度
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.CAMERA 访问照相机设备
android.permission.FLASHLIGHT 访问闪光灯
android.permission.DISABLE_KEYGUARD 禁用键盘锁
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.MOUNT_UNMOUNT_FILESYSTEMS 挂载、反挂载外部文件系统
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_COARSE_LOCATION 获取粗略的位置(通过wifi、基站)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
文件列表
VirSCANVirSCAN
文件名 校验码
res/layout/main.xml 0x8a8e151f
AndroidManifest.xml 0x27c3cf2a
resources.arsc 0x38089871
res/drawable-hdpi/ic_launcher.png 0x7a352cf5
res/drawable-hdpi/shou_off.png 0x3654b95a
res/drawable-hdpi/shou_on.png 0x532afdd3
res/drawable-hdpi/switch_off.png 0x37322024
res/drawable-hdpi/switch_on.png 0x902a16cb
res/drawable-ldpi/ic_launcher.png 0x7a352cf5
res/drawable-mdpi/ic_launcher.png 0x7a352cf5
res/drawable-xhdpi/ic_launcher.png 0x7a352cf5
classes.dex 0xbb459d7a
extra/__pasys_remote_banner.jar 0xf5cebf75
META-INF/MANIFEST.MF 0x8022e27a
META-INF/CERT.SF 0x187eedfe
META-INF/CERT.RSA 0x7d1dd19f
运行截图
VirSCANVirSCAN
VirSCAN