VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

   File information

Virscan.org multi-engine scan report
Behavior analysis report:         Habo file analysis

Basic Information

MD5:9757e990f4170ef5accfdd929691d08f
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
Package names:
Minimum operating environment:
copyright:

Key behavior

Behavior description: 查询注册表_检测虚拟机相关
details: \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
Behavior description: 设置线程上下文
details: C:\Documents and Settings\Administrator\Local Settings\%temp%\1456771189.453118.exe

Process behavior

Behavior description: 创建本地线程
details: N/A
Behavior description: 进程退出
details: N/A
Behavior description: 设置线程上下文
details: C:\Documents and Settings\Administrator\Local Settings\%temp%\1456771189.453118.exe
Behavior description: 枚举进程
details: N/A

Registry behavior

Behavior description: 查询注册表_检测虚拟机相关
details: \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion

Other behavior

Behavior description: 创建互斥体
details: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.ELH
MSCTF.Shared.MUTEX.AKB
Behavior description: 查找指定窗口
details: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
Behavior description: 创建事件对象
details: EventName = MSCTF.SendReceive.Event.AKB.IC
EventName = MSCTF.SendReceiveConection.Event.AKB.IC
Behavior description: 窗口信息
details: Pid = 1344, Hwnd=0x202a6, Text = 确定, ClassName = Button.
Pid = 1344, Hwnd=0x202cc, Text = 运行该程序需要授权文件(泰迪勋章墙.key), ClassName = Static.
Pid = 1344, Hwnd=0x202a2, Text = Safengine, ClassName = #32770.
Pid = 1344, Hwnd=0x302a6, Text = 确定, ClassName = Button.
Pid = 1344, Hwnd=0x302cc, Text = 该授权文件的机器码与本机不匹配。 本机机器码:1+LKtQAIAgDDBgMAAAECAwQFBgfF5Op/OJiK9A== (按CTRL+V粘帖), ClassName = Static.
Pid = 1344, Hwnd=0x302a2, Text = Safengine, ClassName = #32770.
Behavior description: 直接操作物理设备
details: \??\PhysicalDrive0