VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Basic Information

MD5: 5f21bf6f376edca69842a6e5142f62c0
file type: zip
Production company:
version:
Shell or compiler information: COMPILER:Microsoft Visual C++ v6.0 DLL *
{$lang.habo.subfile_info}>: PrimaIR.exe / dcdf78800f430e0489948e029dc0be55 / EXE
PrimaIR.exe / dcdf78800f430e0489948e029dc0be55 / EXE

Key behavior

Behavior description: 直接获取CPU时钟
details: EAX = 0x3bc62825, EDX = 0x0000003c
EAX = 0x3e7927a1, EDX = 0x0000003c
EAX = 0x4e54c327, EDX = 0x0000003c
EAX = 0x85aa32cb, EDX = 0x0000003c
EAX = 0x8ae50184, EDX = 0x0000003c
EAX = 0xc7753f95, EDX = 0x0000003c

File behavior

Behavior description: 创建文件
details: C:\Users\Administrator\AppData\Local\Temp\ILIST-6B14A549.tmp
C:\Users\Administrator\AppData\Local\Temp\ICACHE-3AF5A474.tmp
C:\Users\Administrator\AppData\Local\Temp\ILIST-1B408A49.tmp
C:\Users\Administrator\AppData\Local\Temp\ICACHE-6DDC996F.tmp
C:\Users\Administrator\AppData\Local\Temp\ILIST-2FECBF30.tmp
C:\Users\Administrator\AppData\Local\Temp\ICACHE-7FB8BDF2.tmp
Behavior description: 删除文件
details: C:\Users\Administrator\AppData\Local\Temp\ILIST-6B14A549.tmp
C:\Users\Administrator\AppData\Local\Temp\ICACHE-3AF5A474.tmp
C:\Users\Administrator\AppData\Local\Temp\ILIST-1B408A49.tmp
C:\Users\Administrator\AppData\Local\Temp\ICACHE-6DDC996F.tmp
C:\Users\Administrator\AppData\Local\Temp\ILIST-2FECBF30.tmp
C:\Users\Administrator\AppData\Local\Temp\ICACHE-7FB8BDF2.tmp
Behavior description: 查找文件
details: FileName = C:\Users\Administrator\AppData\Local\%temp%\b70c.exe_7zdump\PrimaIR.zh-CN
FileName = C:\Users\Administrator\AppData\Local\%temp%\b70c.exe_7zdump\PrimaIR.zh-Hans
FileName = C:\Users\Administrator\AppData\Local\%temp%\b70c.exe_7zdump\PrimaIR.zh
FileName = C:\Users\Administrator\AppData\Local\%temp%\b70c.exe_7zdump\PrimaIR.en-US
FileName = C:\Users\Administrator\AppData\Local\%temp%\b70c.exe_7zdump\PrimaIR.en
FileName = C:\Users\Administrator\AppData\Local\%temp%\b70c.exe_7zdump\PrimaIR.CHS
FileName = C:\Users\Administrator\AppData\Local\%temp%\b70c.exe_7zdump\PrimaIR.CH
FileName = C:\Users\Administrator\AppData\Local\%temp%\b70c.exe_7zdump\*.*

Registry behavior

Behavior description: 修改注册表
details: \REGISTRY\USER\S-*\Software\Microsoft\Multimedia\DrawDib\vga.drv 1920x973x32(BGR 0)

Other behavior

Behavior description: 检测自身是否被调试
details: IsDebuggerPresent
Behavior description: 隐藏指定窗口
details: [Window,Class] = [,ComboLBox]
Behavior description: 直接获取CPU时钟
details: EAX = 0x3bc62825, EDX = 0x0000003c
EAX = 0x3e7927a1, EDX = 0x0000003c
EAX = 0x4e54c327, EDX = 0x0000003c
EAX = 0x85aa32cb, EDX = 0x0000003c
EAX = 0x8ae50184, EDX = 0x0000003c
EAX = 0xc7753f95, EDX = 0x0000003c
Behavior description: 查找指定窗口
details: NtUserFindWindowEx: [Class,Window] = [msctls_updown32,]
Behavior description: 打开事件
details: HookSwitchHookEnabledEvent
Global\TermSrvReadyEvent
\KernelObjects\MaximumCommitCondition
Global\SvcctrlStartEvent_A3752DX
Local\MSCTF.CtfActivated.Default1
Local\MSCTF.AsmCacheReady.Default1
Behavior description: 窗口信息
details: Pid = 2776, Hwnd=0x201f6, Text = sckbCopyStandard, ClassName = TsCheckBox.
Pid = 2776, Hwnd=0x20210, Text = Create Subfolders, ClassName = TsRadioGroup.
Pid = 2776, Hwnd=0x20264, Text = Off, ClassName = TsGroupButton.
Pid = 2776, Hwnd=0x30224, Text = Picture Year\Picture Month\Picture Date, ClassName = TsGroupButton.
Pid = 2776, Hwnd=0x30214, Text = Picture Year\Picture Date, ClassName = TsGroupButton.
Pid = 2776, Hwnd=0x3021c, Text = Picture Year\Picture Month, ClassName = TsGroupButton.
Pid = 2776, Hwnd=0x3021a, Text = Picture Date, ClassName = TsGroupButton.
Pid = 2776, Hwnd=0x2020e, Text = Jpeg, ClassName = TsComboBox.
Pid = 2776, Hwnd=0x40164, Text = .jpg, ClassName = TsComboBox.
Pid = 2776, Hwnd=0x301ee, Text = Jpeg, ClassName = TsComboBox.
Pid = 2776, Hwnd=0x30160, Text = Display only thumbnails, ClassName = TsCheckBox.
Pid = 2776, Hwnd=0x201f4, Text = File format, ClassName = TsRadioGroup.
Pid = 2776, Hwnd=0x4015c, Text = Tiff, ClassName = TsGroupButton.
Pid = 2776, Hwnd=0x201f0, Text = Jpeg, ClassName = TsGroupButton.
Pid = 2776, Hwnd=0x30174, Text = Auto Doc. feeder, ClassName = TsCheckBox.
Behavior description: 打开互斥体
details: Local\MSCTF.Asm.MutexDefault1

Run screenshot

VirSCAN