VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Basic Information

MD5: d1eeda6b37ce470d9743532a4d0a4c4f
file type: EXE
Production company: Cheney.小风
version: 1.1.9.9---1.1.9.9
Shell or compiler information: COMPILER:.NET executable -> Microsoft *

Key behavior

Behavior description: 直接获取CPU时钟
details: EAX = 0x41387e1a, EDX = 0x00000039

File behavior

Behavior description: 查找文件
details: FileName = C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscoreei.dll
FileName = C:\Windows\Microsoft.NET\Framework\Upgrades.2.0.50727\mscoreei.dll
FileName = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorwks.dll
FileName = C:\Windows\Microsoft.NET\Framework\v4.0.40305\mscorwks.dll

Other behavior

Behavior description: 打开事件
details: HookSwitchHookEnabledEvent
Local\MSCTF.CtfActivated.Default1
Local\MSCTF.AsmCacheReady.Default1
Behavior description: 检测自身是否被调试
details: IsDebuggerPresent
Behavior description: 窗口信息
details: Pid = 2528, Hwnd=0x3018a, Text = 确定, ClassName = Button.
Pid = 2528, Hwnd=0x20186, Text = 若要运行此应用程序,您必须首先安装 .NET Framework 的以下版本之一: v4.0.30319 有关如何获取 .NET Framework 的适当版本的说明,请与应用程序发行者联系。, ClassName = Static.
Pid = 2528, Hwnd=0x4018c, Text = b70c.exe - .NET Framework 初始化错误, ClassName = #32770.
Behavior description: 直接获取CPU时钟
details: EAX = 0x41387e1a, EDX = 0x00000039
Behavior description: 打开互斥体
details: Local\MSCTF.Asm.MutexDefault1

Run screenshot

VirSCAN