VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
Safety rating:55
Behavior list
Basic Information
MD5:46ded010c962db3174ea8e939fee7f8e
file type:EXE
Production company:
version:
Shell or compiler information:PACKER:UPolyX v0.5
Key behavior
Behavior description:探测 Virtual PC是否存在
details:N/A
Behavior description:查询注册表_检测虚拟机相关
details:\REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
\REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
Behavior description:尝试打开调试器或监控软件的驱动设备对象
details:\??\SICE
\??\SIWVID
\??\NTICE
Behavior description:获取TickCount值
details:TickCount = 5353940, SleepMilliseconds = 50.
TickCount = 5353971, SleepMilliseconds = 50.
TickCount = 5355878, SleepMilliseconds = 50.
TickCount = 5356159, SleepMilliseconds = 50.
TickCount = 5356253, SleepMilliseconds = 50.
Behavior description:直接获取CPU时钟
details:N/A
Behavior description:查找指定内核模块
details:lstrcmpiA: ntice.sys <------> ntkrnlpa.exe Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> hal.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> KDCOM.DLL Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BOOTVID.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ACPI.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> WMILIB.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> pci.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> isapnp.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> compbatt.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BATTC.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> intelide.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> PCIIDEX.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> MountMgr.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ftdisk.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> dmload.sys Des: SoftICE驱动
Behavior description:查找反病毒常用工具窗口
details:NtUserFindWindowEx: [Class,Window] = [OLLYDBG,]
NtUserFindWindowEx: [Class,Window] = [GBDYLLO,]
NtUserFindWindowEx: [Class,Window] = [pediy06,]
NtUserFindWindowEx: [Class,Window] = [FilemonClass,]
NtUserFindWindowEx: [Class,Window] = [,File Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
NtUserFindWindowEx: [Class,Window] = [,Process Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [RegmonClass,]
NtUserFindWindowEx: [Class,Window] = [,Registry Monitor - Sysinternals: www.sysinternals.com]
Process behavior
Behavior description:创建本地线程
details:TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 164, StartAddress = 009474A7, Parameter = 00AD4BC2
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 1996, StartAddress = 009474A7, Parameter = 00AD560E
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 444, StartAddress = 009474A7, Parameter = 00AD6760
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 252, StartAddress = 009474A7, Parameter = 00AD716F
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 1012, StartAddress = 009474A7, Parameter = 00AD7BB5
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 1360, StartAddress = 009474A7, Parameter = 00AD9C1B
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 1372, StartAddress = 009474A7, Parameter = 00ADA7BB
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 556, StartAddress = 009474A7, Parameter = 00ADB492
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 764, StartAddress = 009474A7, Parameter = 00ADE105
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 1004, StartAddress = 009474A7, Parameter = 00ADF00C
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 1856, StartAddress = 009474A7, Parameter = 00ADFFD0
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 1140, StartAddress = 009474A7, Parameter = 00AE1085
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 2044, StartAddress = 009474A7, Parameter = 00AE2187
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 468, StartAddress = 009474A7, Parameter = 00AE30E1
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 672, ThreadID = 124, StartAddress = 009474A7, Parameter = 00AE4127
Behavior description:枚举进程
details:N/A
Registry behavior
Behavior description:查询注册表_检测虚拟机相关
details:\REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
\REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
Other behavior
Behavior description:探测 Virtual PC是否存在
details:N/A
Behavior description:创建事件对象
details:EventName = DINPUTWINMM
Behavior description:打开互斥体
details:DBWinMutex
Behavior description:查找指定窗口
details:NtUserFindWindowEx: [Class,Window] = [18467-41,]
Behavior description:尝试打开调试器或监控软件的驱动设备对象
details:\??\SICE
\??\SIWVID
\??\NTICE
Behavior description:搜索kernel32.dll基地址
details:Instruction Address = 0x00947a58
Behavior description:获取TickCount值
details:TickCount = 5353940, SleepMilliseconds = 50.
TickCount = 5353971, SleepMilliseconds = 50.
TickCount = 5355878, SleepMilliseconds = 50.
TickCount = 5356159, SleepMilliseconds = 50.
TickCount = 5356253, SleepMilliseconds = 50.
Behavior description:直接获取CPU时钟
details:N/A
Behavior description:查找指定内核模块
details:lstrcmpiA: ntice.sys <------> ntkrnlpa.exe Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> hal.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> KDCOM.DLL Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BOOTVID.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ACPI.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> WMILIB.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> pci.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> isapnp.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> compbatt.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BATTC.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> intelide.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> PCIIDEX.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> MountMgr.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ftdisk.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> dmload.sys Des: SoftICE驱动
Behavior description:查找反病毒常用工具窗口
details:NtUserFindWindowEx: [Class,Window] = [OLLYDBG,]
NtUserFindWindowEx: [Class,Window] = [GBDYLLO,]
NtUserFindWindowEx: [Class,Window] = [pediy06,]
NtUserFindWindowEx: [Class,Window] = [FilemonClass,]
NtUserFindWindowEx: [Class,Window] = [,File Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
NtUserFindWindowEx: [Class,Window] = [,Process Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [RegmonClass,]
NtUserFindWindowEx: [Class,Window] = [,Registry Monitor - Sysinternals: www.sysinternals.com]
Run screenshot
VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
中国反网络病毒联盟
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号