VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
Safety rating:60
Behavior list
Basic Information
MD5:40a959a037277e282eb3da5914432cd7
file type:Nsis
Production company:PortableAppC.com
version:7.2.9.3634---7.2.9.3634
Shell or compiler information:
Subfile information:stream.dll / c00cd082e5fc4da786fb14c57b623493 / DLL
XLUE.dll / 8c3305acac1874a8e64bdb52006c4f9f / DLL
layout.xar / b27817e797eb8a8383531ff7c50ef15e / Unknown
layout.xar / 62e02dc9e5d899fb1abfb271a599deb4 / Unknown
VipService.dll / 5a39e45312bd23436ce4147f659faf78 / DLL
Thunder.exe / 32aa181cb4078318892cf31aa95128d7 / EXE
DownloadKernel.dll / 4c7ae78d7660733e56ef1179e6bbae00 / DLL
emule_kernel.dll / b9e54cfd7b516091c36d8667933b778c / DLL
bt_kernel.dll / 3e71aee0e2538f6df38e446180d6b40d / DLL
p2sp.dll / 25e61c92dafd7c4bd95be64c1c5f2421 / DLL
default.zip / d957dd52af2c801976a4e7145a4d0dc3 / zip
asyn_download_interface.dll / 7ed5ccb0162cc844de2e1c0cc4a81784 / DLL
p2p.dll / 5ed0a5bc02429cbbe7f8c67d63cd0ce8 / DLL
XLGraphic.dll / fc965c919ce65b22e480fc274b95c0dc / DLL
7z.dll / eba842a88eae56951f9dca8ca811372d / DLL
DapCtrl.dll / 0d4f61f2baeacacff2774c766c5a57ab / DLL
XlBrowserAddinKernel.dll / 851b4aa2976041eba87c1a312c1ed755 / DLL
ptl.dll / 0cba44819ca48cc149c039d5a1a8cd22 / DLL
XBrowser.exe / 36d065bbc16dcbf43e031f670bb82854 / EXE
Key behavior
Behavior description:屏蔽窗口关闭消息
details:hWnd = 0x0007029e, Text = Thunder Portable | PortableAppC.com | David Pi , ClassName = #32770.
Process behavior
Behavior description:创建本地线程
details:N/A
Behavior description:枚举进程
details:N/A
File behavior
Behavior description:创建文件
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nse4.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nse5.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\System.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\FindProcDLL.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\modern-wizard.bmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\modern-header.bmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\InstallOptions.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\w7tbp.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\ThunderPortable.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\help.txt
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\AppInfo\appicon.ico
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\AppInfo\appicon_16.png
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\AppInfo\appicon_32.png
Behavior description:创建可执行文件
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\System.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\FindProcDLL.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\InstallOptions.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\w7tbp.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\ThunderPortable.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\DefaultData\Addins\Community\Community.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\DefaultData\Addins\Community\XLCPAddinManager.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\DefaultData\Addins\VipService\VipService.dll
Behavior description:覆盖已有文件
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nse5.tmp
Behavior description:查找文件
details:FileName = C:\DOCUME~1
FileName = C:\Documents and Settings\ADMINI~1
FileName = C:\Documents and Settings\Administrator\LOCALS~1
FileName = C:\Documents and Settings\Administrator\Local Settings\Temp
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp
FileName = C:\Documents and Settings\Administrator\PortableApps\*.*
FileName = C:\PortableApps
FileName = D:\PortableApps
FileName = X:\PortableApps
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1
FileName = C:\DOCUME~1\ADMINI~1
Behavior description:删除文件
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nse4.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp
Behavior description:修改文件内容
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 0
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 74
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\modern-wizard.bmp---> Offset = 49152
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 250
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\modern-header.bmp---> Offset = 16384
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 68
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 88
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 122
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 556
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 602
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 712
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 728
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 752
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 452
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\ioSpecial.ini---> Offset = 650
Other behavior
Behavior description:创建互斥体
details:CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.ELH
MSCTF.Shared.MUTEX.AHN
MSCTF.Shared.MUTEX.INJ
Behavior description:创建事件对象
details:EventName = Global\userenv: User Profile setup event
EventName = MSCTF.SendReceive.Event.AHN.IC
EventName = MSCTF.SendReceiveConection.Event.AHN.IC
EventName = Global\crypt32LogoffEvent
EventName = MSCTF.SendReceive.Event.INJ.IC
EventName = MSCTF.SendReceiveConection.Event.INJ.IC
Behavior description:查找指定窗口
details:NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [#32770,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
NtUserFindWindowEx: [Class,Window] = [OleMainThreadWndClass,]
Behavior description:获取系统权限
details:SE_LOAD_DRIVER_PRIVILEGE
Behavior description:屏蔽窗口关闭消息
details:hWnd = 0x0007029e, Text = Thunder Portable | PortableAppC.com | David Pi , ClassName = #32770.
Behavior description:窗口信息
details:Pid = 3452, Hwnd=0x202a4, Text = 下一步(&N) >, ClassName = Button.
Pid = 3452, Hwnd=0x202a6, Text = 取消(&C), ClassName = Button.
Pid = 3452, Hwnd=0x302bc, Text = PortableAppC.com - PortableApps Made in China? , ClassName = Static.
Pid = 3452, Hwnd=0x202d4, Text = PortableAppC.com - PortableApps Made in China?, ClassName = Static.
Pid = 3452, Hwnd=0x202c6, Text = Thunder Portable, ClassName = Static.
Pid = 3452, Hwnd=0x302da, Text = 这个安装向导将引导您便携式安装 Thunder Portable。 如果您要升级一个旧版本的 Thunder Portable,请先关闭它。 请放心,安装过程中, ClassName = Static.
Pid = 3452, Hwnd=0x7029e, Text = Thunder Portable | PortableAppC.com | David Pi, ClassName = #32770.
Pid = 3452, Hwnd=0x402da, Text = 自定义, ClassName = ComboBox.
Pid = 3452, Hwnd=0x302ca, Text = 选定安装的组件: , ClassName = Static.
Pid = 3452, Hwnd=0x202ae, Text = 所需空间: 26.7MB, ClassName = Static.
Pid = 3452, Hwnd=0x202aa, Text = 勾选你想要安装的组件,并解除勾选你不希望安装的组件。 单击 [下一步(N)] 继续。, ClassName = Static.
Pid = 3452, Hwnd=0x702c0, Text = 描述, ClassName = Button(GroupBox).
Pid = 3452, Hwnd=0x502ce, Text = 移动你的鼠标指针到组件之上,便可见到它的描述。, ClassName = Static.
Pid = 3452, Hwnd=0x202a4, Text = 安装(&I), ClassName = Button.
Pid = 3452, Hwnd=0x602ce, Text = C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable, ClassName = Edit.
Behavior description:可执行文件签名信息
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\System.dll(签名验证: 未通过)
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\FindProcDLL.dll(签名验证: 未通过)
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\InstallOptions.dll(签名验证: 未通过)
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\w7tbp.dll(签名验证: 未通过)
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\ThunderPortable.exe(签名验证: 未通过)
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\DefaultData\Addins\Community\Community.dll(签名验证: 通过)
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\DefaultData\Addins\Community\XLCPAddinManager.dll(签名验证: 通过)
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\DefaultData\Addins\VipService\VipService.dll(签名验证: 未通过)
Behavior description:隐藏指定窗口
details:[Window,Class] = [,Button]
[Window,Class] = [PortableAppC.com - PortableApps Made in China®,Static]
[Window,Class] = [PortableAppC.com - PortableApps Made in China® ,Static]
[Window,Class] = [,Static]
[Window,Class] = [,ComboLBox]
[Window,Class] = [,Auto-Suggest Dropdown]
Behavior description:可执行文件MD5
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\System.dll ---> bf712f32249029466fa86756f5546950
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\FindProcDLL.dll ---> 6f73b00aef6c49eac62128ef3eca677e
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\InstallOptions.dll ---> 89351a0a6a89519c86c5531e20dab9ea
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\w7tbp.dll ---> 9a3031cc4cef0dba236a28eecdf0afb5
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\ThunderPortable.exe ---> f84c4c9d4eff2fb770ca2feb95b5c81d
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\DefaultData\Addins\Community\Community.dll ---> 2181b87fa20aaefb45188f3cd7a4a372
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\DefaultData\Addins\Community\XLCPAddinManager.dll ---> 8d3bf48c26b140bb6d9e1e505d312145
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\ThunderPortable\App\DefaultData\Addins\VipService\VipService.dll ---> 5a39e45312bd23436ce4147f659faf78
Behavior description:加载新释放的文件
details:Image: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\System.dll.
Image: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\FindProcDLL.dll.
Image: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\InstallOptions.dll.
Image: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsj6.tmp\w7tbp.dll.
Run screenshot
VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号