VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
Safety rating:84
Behavior list
Basic Information
MD5:a19c8dd5f19d4aedd1556ad60b099bcd
Package names:myc.phone.PhoneInfo
Minimum operating environment:Android 1.5
copyright:
Key behavior
Behavior description:修改注册表_启动项
details:\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\c:\monitor\sample.exe
Process behavior
Behavior description:隐藏窗口创建进程
details:ImagePath = c:\windows\system32\taskmgr.exe, CmdLine = "c:\windows\system32\taskmgr.exe"
Behavior description:创建进程
details:ImagePath = C:\WINDOWS\system32\taskmgr.exe, CmdLine = "C:\WINDOWS\system32\taskmgr.exe"
File behavior
Behavior description:写权限映射文件
details:Global\Cor_Private_IPCBlock_v4_300
Global\Cor_SxSPublic_IPCBlock_300
\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
\WINDOWS\system32\zh-cn\ieframe.dll.mui
Local\UrlZonesSM_Administrator
Registry behavior
Behavior description:修改注册表
details:\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\GDIPlus\FontCachePath
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
Behavior description:修改注册表_启动项
details:\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\c:\monitor\sample.exe
Other behavior
Behavior description:创建互斥体
details:Local\ZonesCounterMutex
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
SHIMLIB_LOG_MUTEX
NTShell Taskman Startup Mutex
Behavior description:查找指定窗口
details:NtUserFindWindowEx: [Class,Window] = [,Windows 任务管理器]
Behavior description:窗口信息
details:Pid = 300, Hwnd=0xb0184, Text = ->, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xa01aa, Text = 9, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xb01b0, Text = 8, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xa018c, Text = 7, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xe016e, Text = 6, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xa0198, Text = 5, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xd01a4, Text = 4, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xc01e8, Text = 3, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xa0196, Text = 2, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xb01be, Text = 1, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xc01b4, Text = No micro:, ClassName = WindowsForms10.STATIC.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xb0164, Text = Unlock, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
Pid = 300, Hwnd=0xd01c8, Text = Multi.Lock.1 by aswen001, ClassName = WindowsForms10.Window.8.app.0.2bf8098_r21_ad1.
Behavior description:获取系统权限
details:SE_LOAD_DRIVER_PRIVILEGE
Dynamic list behavior
Behavior description:启动服务
details:com.android.musicfx.Compatibility$Service
com.android.mms.transaction.SmsReceiverService
Behavior description:读取文件
details:path:/proc/758/cmdline length:105
path:/proc/760/cmdline length:105
path:/proc/772/cmdline length:105
path:/proc/774/cmdline length:105
path:/proc/783/cmdline length:105
path:/proc/798/cmdline length:105
path:/proc/810/cmdline length:105
path:/proc/840/cmdline length:105
path:/proc/851/cmdline length:105
Behavior description:类加载
details:path:/system/app/PicoTts.apk
path:/system/app/MusicFX.apk
path:/system/framework/am.jar
path:/data/app/myc.phone.PhoneInfo-1.apk
Behavior description:初始化Intent
details:Ljava/lang/String;=android.intent.action.VIEW
Behavior description:激活Activity
details:act=android.intent.action.VIEW cmp=com.android.settings/.TestingSettings
Behavior description:写入文件
details:path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
Activities
Activity nameTypes of
.PhoneInfoActivityandroid.intent.action.MAIN
.PhoneInfoActivityandroid.intent.category.LAUNCHER
File List
file name Check code
res/drawable/icon.png 0xcdefa6c3
AndroidManifest.xml 0xc69b78e3
resources.arsc 0xc736b7d
classes.dex 0xa44fe60e
META-INF/MANIFEST.MF 0xeb773e64
META-INF/CERT.SF 0x8eff5d7a
META-INF/CERT.RSA 0x7e49d36
Run screenshot
VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
中国反网络病毒联盟
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号