1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.
Virscan.org multi-engine scan report |
Behavior analysis report: Habo file analysis |
MD5:20a5c68e9a98c0409ead730db9891afd |
文件大小:5.58MB |
上传时间: 2014-09-22 10:36:30 (CST) |
Package names: |
Minimum operating environment: |
copyright: |
Behavior description: | 直接获取CPU时钟 |
details: | EAX = 0xb88fb89b, EDX = 0x00000038 |
Behavior description: | 查找文件 |
details: | FileName = C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscoreei.dll |
FileName = C:\Windows\Microsoft.NET\Framework\Upgrades.2.0.50727\mscoreei.dll | |
FileName = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorwks.dll | |
FileName = C:\Windows\Microsoft.NET\Framework\v4.0.40305\mscorwks.dll |
Behavior description: | 打开事件 |
details: | HookSwitchHookEnabledEvent |
Local\MSCTF.CtfActivated.Default1 | |
Local\MSCTF.AsmCacheReady.Default1 | |
Behavior description: | 检测自身是否被调试 |
details: | IsDebuggerPresent |
Behavior description: | 窗口信息 |
details: | Pid = 2612, Hwnd=0x2018a, Text = 确定, ClassName = Button. |
Pid = 2612, Hwnd=0x20186, Text = 若要运行此应用程序,您必须首先安装 .NET Framework 的以下版本之一: v4.0.30319 有关如何获取 .NET Framework 的适当版本的说明,请与应用程序发行者联系。, ClassName = Static. | |
Pid = 2612, Hwnd=0x3018c, Text = b70c.exe - .NET Framework 初始化错误, ClassName = #32770. | |
Behavior description: | 直接获取CPU时钟 |
details: | EAX = 0xb88fb89b, EDX = 0x00000038 |
Behavior description: | 打开互斥体 |
details: | Local\MSCTF.Asm.MutexDefault1 |