VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Basic Information

MD5: 34ca3309983b2e18b9b6fce7d6326d3d
file type: EXE
Production company: Lazy Creations
version: 2.8.9.0---2.8.9.0
Shell or compiler information: COMPILER:Microsoft Visual C# / Basic .NET

Key behavior

Behavior description: 直接获取CPU时钟
details: EAX = 0x118823e7, EDX = 0x0000003a

File behavior

Behavior description: 查找文件
details: FileName = C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscoreei.dll
FileName = C:\Windows\Microsoft.NET\Framework\Upgrades.2.0.50727\mscoreei.dll
FileName = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorwks.dll
FileName = C:\Windows\Microsoft.NET\Framework\v4.0.40305\mscorwks.dll

Other behavior

Behavior description: 打开事件
details: HookSwitchHookEnabledEvent
Local\MSCTF.CtfActivated.Default1
Local\MSCTF.AsmCacheReady.Default1
Behavior description: 检测自身是否被调试
details: IsDebuggerPresent
Behavior description: 窗口信息
details: Pid = 2528, Hwnd=0x3018a, Text = 确定, ClassName = Button.
Pid = 2528, Hwnd=0x20186, Text = 若要运行此应用程序,您必须首先安装 .NET Framework 的以下版本之一: v4.0.30319 有关如何获取 .NET Framework 的适当版本的说明,请与应用程序发行者联系。, ClassName = Static.
Pid = 2528, Hwnd=0x3018c, Text = b70c.exe - .NET Framework 初始化错误, ClassName = #32770.
Behavior description: 直接获取CPU时钟
details: EAX = 0x118823e7, EDX = 0x0000003a
Behavior description: 打开互斥体
details: Local\MSCTF.Asm.MutexDefault1

Run screenshot

VirSCAN