VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
Safety rating:75
Behavior list
Basic Information
MD5:3abeb1ce7569c3e9dac552370b050afc
file type:Cab
Production company:Microsoft Corporation
version:12.0.6732.5000---12.0.6732.5000
Shell or compiler information:
Subfile information:excel-x-none.xml / 180bd62bb30871f3567eecd6b2f29ee8 / Unknown
supplementaleula_officeclient_ca-es.txt / 4fc5b44adb88d5658c3d09b133e78b2e / Unknown
supplementaleula_officeclient_sr-cyrl-cs.txt / 4ccf3624b015d4be1e48c531de46d3b3 / Unknown
excel-x-none.msp / big file / Compound
supplementaleula_officeclient_ru-ru.txt / a619f8cc8329717081d1826cc9d09b99 / Unknown
supplementaleula_officeclient_uk-ua.txt / 13d02eb325e7091031722edb35c036f1 / Unknown
supplementaleula_officeclient_es-es.txt / 4773bd7964f43009384497a6bf035056 / Unknown
supplementaleula_officeclient_fr-fr.txt / 992be346b1d6e2fe679cb208c7278e54 / Unknown
supplementaleula_officeclient_th-th.txt / b9fa1b150aa2d06f0c5b959501169e97 / Unknown
supplementaleula_officeclient_pt-br.txt / 3a16e76a42235eaca1cfe40e14fe9255 / Unknown
supplementaleula_officeclient_hr-hr.txt / 37af8e88762720379d5616d98f67cad0 / Unknown
supplementaleula_officeclient_tr-tr.txt / c5813ce615bfc642c63a81707ef20f0d / Unknown
supplementaleula_officeclient_en-us.txt / 72cff0ff3553ea3c7c387dd9343e2ece / Unknown
supplementaleula_officeclient_sr-latn-cs.txt / caee6b93b95a57a4d796c0374644dd58 / Unknown
supplementaleula_officeclient_cs-cz.txt / 111b3ca8e6c3993ef40a606d00eb1bce / Unknown
supplementaleula_officeclient_de-de.txt / 61ff0e5ff5b030a38cf31e50b852061c / Unknown
supplementaleula_officeclient_it-it.txt / b336457097427a0fdabad299582f0293 / Unknown
supplementaleula_officeclient_kk-kz.txt / 808e2640551be2099580c1f9629a35af / Unknown
supplementaleula_officeclient_pl-pl.txt / cd17501a66aa396838185ad44cfe683f / Unknown
Key behavior
Behavior description:屏蔽窗口关闭消息
details:hWnd = 0x000202a4, Text = Microsoft Office Excel 2007 安全更新 (KB3085615) 32 位版本 , ClassName = #32770.
Process behavior
Behavior description:创建本地线程
details:N/A
Behavior description:进程退出
details:N/A
Behavior description:枚举进程
details:N/A
File behavior
Behavior description:创建文件
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\OWP4.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\opatchinstall(1).log
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\OWP4.tmp\eula.txt
Behavior description:删除文件
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\OWP4.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\OWP4.tmp\eula.txt
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\OWP4.tmp\eula.txt-newfile
Behavior description:修改文件内容
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\OWP4.tmp\eula.txt---> Offset = 0
Behavior description:查找文件
details:FileName = C:\*.*
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\OWP4.tmp
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\OWP4.tmp\*.*
Other behavior
Behavior description:查找指定窗口
details:NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
Behavior description:窗口信息
details:Pid = 2184, Hwnd=0x202a8, Text = 单击此处接受《Microsoft 软件许可条款》(&A)。, ClassName = Button(CheckBox).
Pid = 2184, Hwnd=0x202cc, Text = 继续(&C), ClassName = Button.
Pid = 2184, Hwnd=0x202b4, Text = 请注意:Microsoft Corporation(或 Microsoft Corporation 在您所在地的关联公司)现授予您本补充程序的许可证。您可以随 Microsoft 2007 , ClassName = Edit.
Pid = 2184, Hwnd=0x202b2, Text = 若要继续安装,必须接受《Microsoft 软件许可条款》。, ClassName = Static.
Pid = 2184, Hwnd=0x202a4, Text = Microsoft Office Excel 2007 安全更新 (KB3085615) 32 位版本 , ClassName = #32770.
Pid = 2184, Hwnd=0x10328, Text = 是(&Y), ClassName = Button.
Pid = 2184, Hwnd=0x1032a, Text = 否(&N), ClassName = Button.
Pid = 2184, Hwnd=0x1032c, Text = 是否确定要取消安装?, ClassName = Static.
Pid = 2184, Hwnd=0x10326, Text = Microsoft Office Excel 2007 安全更新 (KB3085615) 32 位版本 , ClassName = #32770.
Behavior description:创建事件对象
details:EventName = MSCTF.SendReceiveConection.Event.MII.IC
EventName = MSCTF.SendReceive.Event.MII.IC
EventName = ShellCopyEngineRunning
EventName = Global\crypt32LogoffEvent
EventName = Global\userenv: User Profile setup event
EventName = ShellCopyEngineFinished
Behavior description:创建互斥体
details:CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.ELH
MSCTF.Shared.MUTEX.MII
Behavior description:屏蔽窗口关闭消息
details:hWnd = 0x000202a4, Text = Microsoft Office Excel 2007 安全更新 (KB3085615) 32 位版本 , ClassName = #32770.
Run screenshot
VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
Translated by Keith Miller, United States
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号