VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:9%Antivirus software(3/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2019-01-16 10:47:25 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 1
avast 18.4.3895.0 18.4.3895.0 2019-01-16 Found nothing 46
avg 10.0.1405 10.0.1405 2019-01-16 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 1
baidusd 1.0 1.0 2018-06-21 Found nothing 1
bitdefender 7.141118 7.141118 2019-01-16 Found nothing 6
clamav 25158 0.97.5 2018-11-27 Found nothing 1
drweb 5.0.2.3300 5.0.1.1 2019-01-09 Found nothing 9
emsisoft 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
fortinet 1.000, 65.634, 65.492, 65.516 5.4.247 2019-01-16 Found nothing 1
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 1
fsecure 2015-08-01-02 9.13 2019-01-16 Found nothing 8
gdata 25.20180 25.20180 2019-01-14 Found nothing 11
ikarus 5.01.02 V1.32.39.0 2019-01-15 Found nothing 12
jiangmin 16.0.100 1.0.0.0 2017-03-30 Found nothing 4
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 20
kingsoft 2.1 2.1 2013-09-22 Found nothing 27
mcafee 8974 5400.1158 2018-08-03 Found nothing 12
nod32 8699 3.0.21 2019-01-13 a variant of Android/AdDisplay.Dowgin.GT application 1
panda 9.05.01 9.05.01 2017-03-30 Found nothing 3
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 2
qh360 1.0.1 1.0.1 2018-06-20 Adware.Android.Gen 3
qqphone 2.0.0.0 2.0.0.0 2018-09-25 a.gray.AdsPushAttack 1
quickheal 14.00 14.00 2018-08-07 Found nothing 3
rising 4545 4545 2019-01-15 Found nothing 1
sophos 4.62 3.16.1 2016-09-20 Found nothing 10
symantec 20151230.005 1.3.0.24 2015-12-30 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2017-03-30 Found nothing 1
tws 17.47.17308 1.0.2.2108 2019-01-15 Found nothing 6
vba 3.12.29.3 beta 3.12.29.3 beta 2016-09-19 Found nothing 3
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 3
权限列表
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.REQUEST_INSTALL_PACKAGES
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
com.android.launcher.permission.UNINSTALL_SHORTCUT 删除快捷方式
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
com.android.launcher.permission.INSTALL_SHORTCUT 创建快捷方式
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:dbbbe5a7b46f39f5a033a61627e1a4b2
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:eir.rjl.wrj
最低运行环境:Android 4.0, 4.0.1, 4.0.2
版权:dyfkd
文件行为
VirSCANVirSCAN
行为描述: 查找文件
详情信息: FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.zh-CN
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.zh-Hans
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.zh
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.CHS
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.CH
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
ArmStrong
MSCTF.Shared.MUTEX.IOH
MSCTF.Shared.MUTEX.MHK
行为描述: 创建事件对象
详情信息: EventName = MSCTF.SendReceive.Event.MHK.IC
EventName = MSCTF.SendReceiveConection.Event.MHK.IC
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
NtUserFindWindowEx: [Class,Window] = [OleMainThreadWndClass,]
行为描述: 窗口信息
详情信息: Pid = 2680, Hwnd=0x10340, Text = 系统信息, ClassName = TGroupBox.
Pid = 2680, Hwnd=0x10342, Text = KMS模式, ClassName = TComboBox.
Pid = 2680, Hwnd=0x10346, Text = 一键永久激活Windows和Office, ClassName = TButton.
Pid = 2680, Hwnd=0x40336, Text = OEM8, ClassName = TArmStrongForm.
行为描述: 打开事件
详情信息: HookSwitchHookEnabledEvent
CTF.ThreadMIConnectionEvent.000007E8.00000000.0000000F
CTF.ThreadMarshalInterfaceEvent.000007E8.00000000.0000000F
MSCTF.SendReceiveConection.Event.IOH.IC
MSCTF.SendReceive.Event.IOH.IC
行为描述: 枚举窗口
详情信息: N/A
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
行为描述: 打开互斥体
详情信息: ShimCacheMutex
Activities
VirSCANVirSCAN
活动名 类型
com.example.kongdemo.MainActivity android.intent.action.MAIN
com.example.kongdemo.MainActivity android.intent.category.LAUNCHER
危险函数
VirSCANVirSCAN
函数名称 信息
java/net/URL;->openConnection 连接URL
java/net/HttpURLConnection;->connect 连接URL
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
TelephonyManager;->getSimSerialNumber 获取SIM序列号
getRuntime 获取命令行环境
java/lang/Runtime;->exec 执行字符串命令
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.REQUEST_INSTALL_PACKAGES
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
com.android.launcher.permission.UNINSTALL_SHORTCUT 删除快捷方式
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
com.android.launcher.permission.INSTALL_SHORTCUT 创建快捷方式
服务列表
VirSCANVirSCAN
名称
com.ag.cupk.etnx
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0xaeadc34b
META-INF/ZHY.SF 0xa7cc0ee7
META-INF/ZHY.RSA 0x9b502d88
AndroidManifest.xml 0xc8afa94f
classes.dex 0x960b1060
res/drawable-hdpi-v4/ic_launcher.png 0xf248df62
res/drawable-mdpi-v4/ic_launcher.png 0x6a84dfd9
res/drawable-xhdpi-v4/ic_launcher.png 0xa227fc8a
res/drawable-xxhdpi-v4/ic_launcher.png 0x2a4a99d1
res/layout/activity_main.xml 0x960066de
res/menu/main.xml 0x5cd6e58
resources.arsc 0xa7789dc2
运行截图
VirSCANVirSCAN
VirSCAN