VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
Safety rating:81
Behavior list
Behavior analysis report:         Threatbook file behavior analysis report
Basic Information
MD5:af5f4c9277231e88c615d96d4e09febf
file type:EXE
Production company:Microsoft Corporation
version:11.0.5510.0---11.0.5510
Shell or compiler information:COMPILER:Microsoft Visual C++ 7.0 Method2 [调试] [Overlay]
File behavior
Behavior description:修改文件内容
details:C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Setup Log File.Log---> Offset = 822
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Setup Log File.Log---> Offset = 843
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Setup Log File.Log---> Offset = 862
Registry behavior
Behavior description:删除注册表键
details:\REGISTRY\MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining\ChainedInstalls\-1001
\REGISTRY\MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining\ChainedInstalls
\REGISTRY\MACHINE\SOFTWARE\Microsoft\MSSetup_Chaining
Other behavior
Behavior description:窗口信息
details:Pid = 1460, Hwnd=0xb016a, Text = 确定, ClassName = Button.
Pid = 1460, Hwnd=0xc01d6, Text = 设置文件 c:\monitor\FILES\SETUP\sample.INI 丢失或无效。请确认该文件存在并且可以访问。, ClassName = Static.
Pid = 1460, Hwnd=0xd0166, Text = Microsoft Office 安装程序, ClassName = #32770.
Behavior description:创建互斥体
details:Global\{0BB25CA4-59F4-4cf4-B8D2-CD935D8520DB}
Run screenshot
VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
Translated by Keith Miller, United States
中国反网络病毒联盟
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号