VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
Safety rating:61
Behavior list
Basic Information
MD5:2c3e76d20e730d68590e15d99196f408
file type:EXE
Production company:
version:
Shell or compiler information:PACKER:UPX 0.89.6 - 1.02 / 1.05 - 1.24 -> Markus & Laszlo
Subfile information:rlpack_full_lzma_46048413dumpFile / 8a2baca50d4bd762267fdcae628c750c / EXE
Key behavior
Behavior description:检测自身是否被调试
details:N/A
Behavior description:隐藏指定窗口
details:[Window,Class] = [帮助,Button]
[Window,Class] = [完成,Button]
[Window,Class] = [,Static]
[Window,Class] = [,SysTabControl32]
Other behavior
Behavior description:检测自身是否被调试
details:N/A
Behavior description:窗口信息
details:Pid = 1652, Hwnd=0xa0198, Text = Fair Use for Windows Media, ClassName = Static.
Pid = 1652, Hwnd=0xd01a4, Text = 本程序将从 Media Player 中提取出个人标识信息 (解密许可证) 用于允许用户提高从正当途径获取的媒体文件的互操作性., ClassName = Static.
Pid = 1652, Hwnd=0xc01e8, Text = 恢复许可证, ClassName = Button.
Pid = 1652, Hwnd=0xa0196, Text = h, ClassName = Static.
Pid = 1652, Hwnd=0xb01be, Text = 没有载入许可证, ClassName = Static.
Pid = 1652, Hwnd=0xc01b4, Text = 许可证被恢复后, 这个页面将不再显示. 要返回这个页面, 请从文件选择页面选择“上一步”., ClassName = Static.
Pid = 1652, Hwnd=0xb0170, Text = 至少需要一个已激活许可文件的媒体文件. 某些系统中可能有多个标识信息集合 - 请尝试反复处理不同的许可文件., ClassName = Static.
Pid = 1652, Hwnd=0xd01c8, Text = < 上一步(&B), ClassName = Button.
Pid = 1652, Hwnd=0xc01c2, Text = 下一步(&N) >, ClassName = Button.
Pid = 1652, Hwnd=0xb01c6, Text = 完成, ClassName = Button.
Pid = 1652, Hwnd=0xb0184, Text = 取消, ClassName = Button.
Pid = 1652, Hwnd=0xa01aa, Text = 帮助, ClassName = Button.
Pid = 1652, Hwnd=0xd0166, Text = FairUse4WM 1.3fix-2, ClassName = #32770.
Behavior description:隐藏指定窗口
details:[Window,Class] = [帮助,Button]
[Window,Class] = [完成,Button]
[Window,Class] = [,Static]
[Window,Class] = [,SysTabControl32]
Behavior description:尝试打开调试器或监控软件的驱动设备对象
details:\??\SICE
\??\SIWVID
\??\NTICE
Abnormal crash
Behavior description:检测自身是否被调试
details:N/A
Behavior description:窗口信息
details:Pid = 1652, Hwnd=0xa0198, Text = Fair Use for Windows Media, ClassName = Static.
Pid = 1652, Hwnd=0xd01a4, Text = 本程序将从 Media Player 中提取出个人标识信息 (解密许可证) 用于允许用户提高从正当途径获取的媒体文件的互操作性., ClassName = Static.
Pid = 1652, Hwnd=0xc01e8, Text = 恢复许可证, ClassName = Button.
Pid = 1652, Hwnd=0xa0196, Text = h, ClassName = Static.
Pid = 1652, Hwnd=0xb01be, Text = 没有载入许可证, ClassName = Static.
Pid = 1652, Hwnd=0xc01b4, Text = 许可证被恢复后, 这个页面将不再显示. 要返回这个页面, 请从文件选择页面选择“上一步”., ClassName = Static.
Pid = 1652, Hwnd=0xb0170, Text = 至少需要一个已激活许可文件的媒体文件. 某些系统中可能有多个标识信息集合 - 请尝试反复处理不同的许可文件., ClassName = Static.
Pid = 1652, Hwnd=0xd01c8, Text = < 上一步(&B), ClassName = Button.
Pid = 1652, Hwnd=0xc01c2, Text = 下一步(&N) >, ClassName = Button.
Pid = 1652, Hwnd=0xb01c6, Text = 完成, ClassName = Button.
Pid = 1652, Hwnd=0xb0184, Text = 取消, ClassName = Button.
Pid = 1652, Hwnd=0xa01aa, Text = 帮助, ClassName = Button.
Pid = 1652, Hwnd=0xd0166, Text = FairUse4WM 1.3fix-2, ClassName = #32770.
Behavior description:隐藏指定窗口
details:[Window,Class] = [帮助,Button]
[Window,Class] = [完成,Button]
[Window,Class] = [,Static]
[Window,Class] = [,SysTabControl32]
Behavior description:尝试打开调试器或监控软件的驱动设备对象
details:\??\SICE
\??\SIWVID
\??\NTICE
Run screenshot
VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
中国反网络病毒联盟
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号