VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:0%Scanner(s) (0/39)found malware!
Behavior analysis report:         Habo file analysis
Time: 2014-11-03 22:19:23 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
ahnlab 9.9.9 9.9.9 2013-05-28 Found nothing 4
antivir 1.9.2.0 1.9.159.0 7.11.182.198 Found nothing 56
antiy 114701 AVL141003 2014-10-04 Found nothing 5
arcavir 1.0 2011 2014-05-30 Found nothing 18
asquared 9.0.0.4157 9.0.0.4157 2014-07-30 Found nothing 1
avast 141102-0 4.7.4 2014-11-02 Found nothing 56
avg 2109/7906 10.0.1405 2014-10-17 Found nothing 1
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 31
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.57515 7.90123 2014-11-03 Found nothing 16
clamav 19571 0.97.5 2014-11-02 Found nothing 1
comodo 15023 5.1 2014-10-03 Found nothing 3
ctch 4.6.5 5.3.14 2013-12-01 Found nothing 3
drweb 5.0.2.3300 5.0.1.1 2014-10-31 Found nothing 58
fortinet 23.108, 23.108 5.1.158 2014-11-03 Found nothing 12
fprot 4.6.2.117 6.5.1.5418 2014-10-31 Found nothing 12
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 25
gdata 24.3819 24.3819 2014-08-29 Found nothing 9
hauri 2.73 2.73 2014-06-13 Found nothing 1
ikarus 1.06.01 V1.32.31.0 2014-11-02 Found nothing 60
jiangmin 16.0.100 1.0.0.0 2014-07-28 Found nothing 14
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 56
kingsoft 2.1 2.1 2013-09-22 Found nothing 2
mcafee 7520 5400.1158 2014-08-04 Found nothing 35
nod32 0436 3.0.21 2014-09-18 Found nothing 2
panda 9.05.01 9.05.01 2014-06-15 Found nothing 3
pcc 11.252.05 9.500-1005 2014-11-02 Found nothing 10
qh360 1.0.1 1.0.1 1.0.1 Found nothing 2
qqphone 1.0.0.0 1.0.0.0 2014-11-03 Found nothing 2
quickheal 14.00 14.00 2014-06-14 Found nothing 2
rising 25.17.00.04 25.17.00.04 2014-06-02 Found nothing 2
sophos 5.04 3.51.0 2014-08-05 Found nothing 49
sunbelt 3.9.2589.2 3.9.2589.2 2014-06-13 Found nothing 1
symantec 20141028.001 1.3.0.24 2014-10-28 Found nothing 1
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 8
thehacker 6.8.0.5 6.8.0.5 2014-06-12 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-06-16 Found nothing 4
vba 3.12.26.3 3.12.26.3 2014-10-31 Found nothing 23
virusbuster 15.0.956.0 5.5.2.13 2014-11-02 Found nothing 56
权限列表
许可名称 信息
android.permission.CAMERA 访问照相机设备
android.permission.FLASHLIGHT 访问闪光灯
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_COARSE_LOCATION 获取粗略的位置(通过wifi、基站)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.VIBRATE 允许设备震动
com.android.launcher.permission.INSTALL_SHORTCUT 创建快捷方式
android.permission.CHANGE_NETWORK_STATE 变更网络状态
android.permission.EXPAND_STATUS_BAR 操控状态栏
android.permission.FORCE_STOP_PACKAGES
android.permission.INSTALL_PACKAGES 安装应用
android.permission.DELETE_PACKAGES 删除应用
android.permission.CHANGE_COMPONENT_ENABLED_STATE 变更组件状态
文件信息
VirSCANVirSCAN
安全评分 :81
基本信息
VirSCANVirSCAN
MD5:4dc23ce570593305f4bc6c30841d4c27
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:edu.light.shoudian
最低运行环境:Android 2.2.x
版权:Android
关键行为
VirSCANVirSCAN
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,Button]
[Window,Class] = [Copyright NeoSmart Technologies 2011,Static]
[Window,Class] = [Copyright NeoSmart Technologies 2011 ,Static]
[Window,Class] = [,Static]
文件行为
VirSCANVirSCAN
行为描述: 创建可执行文件
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\InstallOptions.dll
行为描述: 修改文件内容
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 0
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 36
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\modern-wizard.bmp---> Offset = 49152
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 124
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 33
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 43
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 60
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 277
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 323
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 378
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 386
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 398
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 225
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 347
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\ioSpecial.ini---> Offset = 714
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
其他行为
VirSCANVirSCAN
行为描述: 窗口信息
详情信息: Pid = 404, Hwnd=0xc01d6, Text = &Next >, ClassName = Button.
Pid = 404, Hwnd=0xd01c8, Text = Cancel, ClassName = Button.
Pid = 404, Hwnd=0xa018c, Text = Copyright NeoSmart Technologies 2011 , ClassName = Static.
Pid = 404, Hwnd=0xe016e, Text = Copyright NeoSmart Technologies 2011, ClassName = Static.
Pid = 404, Hwnd=0xb01ce, Text = Welcome to the EasyBCD 2.2 Setup Wizard, ClassName = Static.
Pid = 404, Hwnd=0xd01ac, Text = This wizard will guide you through the installation of EasyBCD 2.2. It is recommended that you close all other applications be, ClassName = Static.
Pid = 404, Hwnd=0xd0166, Text = EasyBCD 2.2 Setup, ClassName = #32770.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,Button]
[Window,Class] = [Copyright NeoSmart Technologies 2011,Static]
[Window,Class] = [Copyright NeoSmart Technologies 2011 ,Static]
[Window,Class] = [,Static]
行为描述: 打开图片文件
详情信息: \DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsb7.tmp\modern-wizard.bmp
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
危险行为
VirSCANVirSCAN
行为描述: 执行系统命令
详情信息: chmod 777 /data/data/edu.light.shoudian/files/libprovider.jar
动态列表行为
VirSCANVirSCAN
行为描述: 启动服务
详情信息: com.android.musicfx.Compatibility$Service
com.android.mms.transaction.SmsReceiverService
行为描述: 读取文件
详情信息: path:/data/data/edu.light.shoudian/files/libprovider.jar length:9
path:/data/data/edu.light.shoudian/files/libprovider.jar length:22
path:/data/data/edu.light.shoudian/files/libprovider.jar length:94
path:/data/data/edu.light.shoudian/files/libprovider.jar length:7
path:/proc/783/cmdline length:105
path:/proc/799/cmdline length:105
path:/proc/811/cmdline length:105
path:/proc/841/cmdline length:105
path:/proc/852/cmdline length:105
path:/proc/895/cmdline length:105
path:/proc/897/cmdline length:105
行为描述: 类加载
详情信息: path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/edu.light.shoudian-1.apk
path:/data/data/edu.light.shoudian/files/libprovider.jar
行为描述: 执行系统命令
详情信息: chmod 777 /data/data/edu.light.shoudian/files/libprovider.jar
行为描述: 初始化Intent
详情信息: Ljava/lang/String;=com.android.daemon.system.ApolloService
Ljava/lang/String;=com.mobsafetguard.systemprivelges.IsystemprivelgesService
行为描述: 写入文件
详情信息: path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/edu.light.shoudian/files/libprovider.jar length:78
path:/data/data/edu.light.shoudian/files/libprovider.jar length:58
path:/data/data/edu.light.shoudian/files/libprovider.jar length:54
path:/data/data/edu.light.shoudian/files/libprovider.jar length:59
path:/data/data/edu.light.shoudian/files/libprovider.jar length:60
path:/data/data/edu.light.shoudian/files/libprovider.jar length:42
path:/data/data/edu.light.shoudian/files/libprovider.jar length:49
path:/data/data/edu.light.shoudian/files/libprovider.jar length:53
path:/data/data/edu.light.shoudian/files/libprovider.jar length:45
path:/data/data/edu.light.shoudian/files/libprovider.jar length:51
path:/data/data/edu.light.shoudian/files/libprovider.jar length:51
path:/data/data/edu.light.shoudian/files/libprovider.jar length:53
path:/data/data/edu.light.shoudian/files/libprovider.jar length:54
path:/data/data/edu.light.shoudian/files/libprovider.jar length:60
path:/data/data/edu.light.shoudian/files/libprovider.jar length:50
path:/data/data/edu.light.shoudian/files/libprovider.jar length:53
path:/data/data/edu.light.shoudian/files/libprovider.jar length:49
path:/data/data/edu.light.shoudian/files/libprovider.jar length:44
path:/data/data/edu.light.shoudian/files/libprovider.jar length:48
path:/data/data/edu.light.shoudian/files/libprovider.jar length:50
path:/data/data/edu.light.shoudian/files/libprovider.jar length:56
path:/data/data/edu.light.shoudian/files/libprovider.jar length:55
path:/data/data/edu.light.shoudian/files/libprovider.jar length:53
path:/data/data/edu.light.shoudian/files/libprovider.jar length:62
path:/data/data/edu.light.shoudian/files/libprovider.jar length:57
path:/data/data/edu.light.shoudian/files/libprovider.jar length:59
path:/data/data/edu.light.shoudian/files/libprovider.jar length:53
path:/data/data/edu.light.shoudian/files/libprovider.jar length:54
path:/data/data/edu.light.shoudian/files/libprovider.jar length:53
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
VirSCANVirSCAN
活动名 类型
edu.light.shoudian.NIKPiLeRq android.intent.action.MAIN
edu.light.shoudian.NIKPiLeRq android.intent.category.LAUNCHER
com.android.daemon.system.ApolloActivityPopup com.android.daemon.system.ApolloActivityPopup
com.android.daemon.system.ApolloActivityPopup android.intent.category.DEFAULT
com.android.daemon.system.ApolloActivityPopup1 com.android.daemon.system.ApolloActivityPopup1
com.android.daemon.system.ApolloActivityPopup1 android.intent.category.DEFAULT
com.android.daemon.system.ApolloEngineerModeActivity com.android.daemon.system.EngineerMode
com.android.daemon.system.ApolloEngineerModeActivity android.intent.category.DEFAULT
com.android.daemon.system.ApolloSesameActivity com.android.daemon.system.ApolloSesameActivity
com.android.daemon.system.ApolloSesameActivity android.intent.category.DEFAULT
危险函数
VirSCANVirSCAN
函数名称 信息
ContentResolver;->query 读取联系人、短信等数据库
android/app/NotificationManager;->notify 信息通知栏
getRuntime 获取命令行环境
java/lang/Runtime;->exec 执行字符串命令
Camera;->open 开启相机
启动方式
VirSCANVirSCAN
名称 信息
com.android.daemon.system.ApolloBootReceiver 开机启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.CAMERA 访问照相机设备
android.permission.FLASHLIGHT 访问闪光灯
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_COARSE_LOCATION 获取粗略的位置(通过wifi、基站)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.VIBRATE 允许设备震动
com.android.launcher.permission.INSTALL_SHORTCUT 创建快捷方式
android.permission.CHANGE_NETWORK_STATE 变更网络状态
android.permission.EXPAND_STATUS_BAR 操控状态栏
android.permission.FORCE_STOP_PACKAGES
android.permission.INSTALL_PACKAGES 安装应用
android.permission.DELETE_PACKAGES 删除应用
android.permission.CHANGE_COMPONENT_ENABLED_STATE 变更组件状态
服务列表
VirSCANVirSCAN
名称
com.android.daemon.system.ApolloService
com.android.daemon.system.ApolloDaemonService
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0x77fe27ab
META-INF/CERT.SF 0x77ac1211
META-INF/CERT.RSA 0x9413418c
AndroidManifest.xml 0x2e8b5309
assets/libprovider.jar 0x2542c7d4
classes.dex 0x93010e4f
res/drawable/ic_launcher.png 0x32778f98
res/drawable/ledoff.png 0xc369676
res/drawable/ledon.png 0xf7f3f0ed
res/drawable/lightoff.png 0xc00f9176
res/drawable/skin_light.png 0x3fd3897c
res/layout/activity_lightscreen.xml 0x54a553cb
res/layout/activity_main.xml 0x852d61cf
res/layout/ps_notification_1.xml 0x492895b8
res/layout/ps_notification_2.xml 0x9ab6f0ad
res/layout/ps_notification_3.xml 0xa2177ce0
res/raw/sound.ogg 0xf22dbcff
resources.arsc 0x53594f8e
运行截图
VirSCANVirSCAN
VirSCAN