VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:20%Scanner(s) (8/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-04 00:19:44 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 4
antivir 1.9.2.0 1.9.159.0 7.11.182.198 Found nothing 14
antiy 110655 AVL141101 2014-11-02 Found nothing 5
arcavir 1.0 2011 2014-05-30 Found nothing 8
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 141102-0 4.7.4 2014-11-02 Found nothing 18
avg 2109/7906 10.0.1405 2014-10-17 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 4
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.57515 7.90123 2014-11-03 Android.Trojan.SmsSpy.ES 7
clamav 19571 0.97.5 2014-11-02 Found nothing 1
comodo 15023 5.1 2014-11-02 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2014-10-31 Found nothing 29
fortinet 23.108, 23.108 5.1.158 2014-11-03 Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-10-31 Found nothing 1
fsecure 2014-04-02-01 9.13 2014-04-02 Trojan:Android/Fakeinst.IT 1
gdata 24.4740 24.4740 2014-11-03 Android.Trojan.SmsSpy.ES 7
hauri 2.73 2.73 2014-10-31 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-11-02 Trojan.AndroidOS.SMForw 13
jiangmin 16.0.100 1.0.0.0 2014-08-20 Found nothing 31
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 20
kingsoft 2.1 2.1 2013-09-22 Android.Troj.Bqspy.yd.(kcloud) 3
mcafee 7520 5400.1158 2014-08-04 Found nothing 8
nod32 0436 3.0.21 2014-09-18 a variant of Android/TrojanSMS.Agent.APO trojan 1
panda 9.05.01 9.05.01 2014-11-02 Found nothing 4
pcc 11.252.05 9.500-1005 2014-11-02 Found nothing 1
qh360 1.0.1 1.0.1 1.0.1 Found nothing 13
qqphone 1.0.0.0 1.0.0.0 2014-11-03 Found nothing 1
quickheal 14.00 14.00 2014-11-01 Android.SmsThief.AO 2
rising 25.38.01.01 25.38.01.01 2014-10-28 Found nothing 1
sophos 5.04 3.51.0 2014-08-05 Andr/SmsSpy-BH 6
sunbelt 3.9.2595.2 3.9.2595.2 2014-11-01 Found nothing 1
symantec 20141028.001 1.3.0.24 2014-10-28 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2014-10-31 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-11-02 Found nothing 6
vba 3.12.26.3 3.12.26.3 2014-10-31 Found nothing 3
virusbuster 15.0.956.0 5.5.2.13 2014-11-02 Found nothing 14
权限列表
许可名称 信息
android.permission.WRITE_SMS 写短信
android.permission.SEND_SMS 发送短信
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_SMS 读取短信
android.permission.RECEIVE_SMS 监控接收短信
文件信息
VirSCANVirSCAN
安全评分 :74
基本信息
VirSCANVirSCAN
MD5:3a0a667dfb03e1bfc0633884737bb097
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.oliuyht.iujyhtgr.m
最低运行环境:
版权:r3q1we
关键行为
VirSCANVirSCAN
行为描述: 跨进程写入数据
详情信息: TargetProcess = vbc.exe, WriteAddress = 0x00400000, Size = 1024
TargetProcess = vbc.exe, WriteAddress = 0x00401000, Size = 580096
TargetProcess = vbc.exe, WriteAddress = 0x0048f000, Size = 6656
TargetProcess = vbc.exe, WriteAddress = 0x00491000, Size = 15872
TargetProcess = vbc.exe, WriteAddress = 0x00495000, Size = 0
TargetProcess = vbc.exe, WriteAddress = 0x0049d000, Size = 16896
TargetProcess = vbc.exe, WriteAddress = 0x004a2000, Size = 0
TargetProcess = vbc.exe, WriteAddress = 0x004a3000, Size = 512
TargetProcess = vbc.exe, WriteAddress = 0x004a4000, Size = 35840
TargetProcess = vbc.exe, WriteAddress = 0x004ad000, Size = 17408
TargetProcess = vbc.exe, WriteAddress = 0x7ffde008, Size = 4
行为描述: 设置线程上下文
详情信息: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe
行为描述: 修改注册表_启动项
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\CryptedFile
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\DarkComet RAT
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit
进程行为
VirSCANVirSCAN
行为描述: 跨进程写入数据
详情信息: TargetProcess = vbc.exe, WriteAddress = 0x00400000, Size = 1024
TargetProcess = vbc.exe, WriteAddress = 0x00401000, Size = 580096
TargetProcess = vbc.exe, WriteAddress = 0x0048f000, Size = 6656
TargetProcess = vbc.exe, WriteAddress = 0x00491000, Size = 15872
TargetProcess = vbc.exe, WriteAddress = 0x00495000, Size = 0
TargetProcess = vbc.exe, WriteAddress = 0x0049d000, Size = 16896
TargetProcess = vbc.exe, WriteAddress = 0x004a2000, Size = 0
TargetProcess = vbc.exe, WriteAddress = 0x004a3000, Size = 512
TargetProcess = vbc.exe, WriteAddress = 0x004a4000, Size = 35840
TargetProcess = vbc.exe, WriteAddress = 0x004ad000, Size = 17408
TargetProcess = vbc.exe, WriteAddress = 0x7ffde008, Size = 4
行为描述: 设置线程上下文
详情信息: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe
行为描述: 修改注册表_启动项
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\CryptedFile
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\DarkComet RAT
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit
文件行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: Global\Cor_Private_IPCBlock_1748
Global\Cor_Public_IPCBlock_1748
Global\NLS_00000804_Exception_Table_3_2
Local\UrlZonesSM_Administrator
行为描述: 创建可执行文件
详情信息: C:\Documents and Settings\Administrator\My Documents\DCSCMIN\IMDCSC.exe
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\Administrator\My Documents\DCSCMIN\IMDCSC.exe
行为描述: 修改注册表_启动项
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\CryptedFile
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\DarkComet RAT
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: myyyyyy
Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
行为描述: 窗口信息
详情信息: Pid = 1748, Hwnd=0xb01de, Text = 确定, ClassName = Button.
Pid = 1748, Hwnd=0xc01d6, Text = loooool, ClassName = Static.
行为描述: 获取系统权限
详情信息: SE_CHANGE_NOTIFY_PRIVILEGE
SE_SECURITY_PRIVILEGE
SE_BACKUP_PRIVILEGE
SE_RESTORE_PRIVILEGE
SE_SYSTEMTIME_PRIVILEGE
SE_SHUTDOWN_PRIVILEGE
SE_REMOTE_SHUTDOWN_PRIVILEGE
SE_TAKE_OWNERSHIP_PRIVILEGE
SE_DEBUG_PRIVILEGE
SE_SYSTEM_ENVIRONMENT_PRIVILEGE
SE_SYSTEM_PROFILE_PRIVILEGE
SE_PROF_SINGLE_PROCESS_PRIVILEGE
SE_INC_BASE_PRIORITY_PRIVILEGE
SE_LOAD_DRIVER_PRIVILEGE
SE_CREATE_PAGEFILE_PRIVILEGE
动态列表行为
VirSCANVirSCAN
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
行为描述: 读取文件
详情信息: path:/proc/783/cmdline length:105
path:/proc/798/cmdline length:105
path:/proc/810/cmdline length:105
path:/proc/840/cmdline length:105
path:/proc/851/cmdline length:105
path:/proc/863/cmdline length:105
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/com.oliuyht.iujyhtgr.m-1.apk
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
VirSCANVirSCAN
活动名 类型
com.fef.xre.MainActivity android.intent.action.MAIN
com.fef.xre.MainActivity android.intent.category.LAUNCHER
com.fef.xre.ljrjvc android.intent.action.VIEW
com.fef.xre.ljrjvc android.intent.action.DELETE
com.fef.xre.ljrjvc android.intent.category.DEFAULT
危险函数
VirSCANVirSCAN
函数名称 信息
SmsManager;->sendTextMessage 发送普通短信
启动方式
VirSCANVirSCAN
名称 信息
com.fef.xre.kigdgc 监控短信(收到短信)启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.WRITE_SMS 写短信
android.permission.SEND_SMS 发送短信
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_SMS 读取短信
android.permission.RECEIVE_SMS 监控接收短信
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0x328df64b
META-INF/ANDROID_.SF 0x1712470
META-INF/ANDROID_.RSA 0xc150e834
lib/armeabi/libAPKProtect.so 0x75806fcf
res/drawable/qqq.png 0xcc6ba7dd
res/layout/activity_main.xml 0x23ac2b25
res/layout/main.xml 0x6b7ee4cd
res/xml/xyz.xml 0xc5fc3a86
AndroidManifest.xml 0x520ce08
classes.dex 0xfbeccd45
resources.arsc 0x84e3efbe
运行截图
VirSCANVirSCAN
VirSCAN