VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

   File information

Virscan.org multi-engine scan report
Behavior analysis report:         Habo file analysis

Basic Information

MD5:e07170906928be8a1c1f67bac5153e38
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
Package names:
Minimum operating environment:
copyright:

Key behavior

Behavior description: 探测 Virtual PC是否存在
details: N/A
Behavior description: 查询注册表_检测虚拟机相关
details: \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
Behavior description: 尝试打开调试器或监控软件的驱动设备对象
details: \??\SICE
\??\SIWVID
\??\NTICE
Behavior description: 获取TickCount值
details: TickCount = 1074846, SleepMilliseconds = 50.
TickCount = 1074878, SleepMilliseconds = 50.
TickCount = 1074925, SleepMilliseconds = 50.
TickCount = 1074940, SleepMilliseconds = 50.

Process behavior

Behavior description: 创建本地线程
details: TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 1844, StartAddress = 0073ECBB, Parameter = 007A81CE
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 556, StartAddress = 0073ECBB, Parameter = 007A8CFB
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 1772, StartAddress = 0073ECBB, Parameter = 007A9D11
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 1008, StartAddress = 0073ECBB, Parameter = 007AA74E
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 1860, StartAddress = 0073ECBB, Parameter = 007AB298
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 888, StartAddress = 0073ECBB, Parameter = 007AC89B
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 1560, StartAddress = 0073ECBB, Parameter = 007AD3C2
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 896, StartAddress = 0073ECBB, Parameter = 007AEAB5
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 1400, StartAddress = 0073ECBB, Parameter = 007B168C
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 284, StartAddress = 0073ECBB, Parameter = 007B2704
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 412, StartAddress = 0073ECBB, Parameter = 007B36D3
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 1356, StartAddress = 0073ECBB, Parameter = 007B45F9
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 912, StartAddress = 0073ECBB, Parameter = 007B5731
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 1360, StartAddress = 0073ECBB, Parameter = 007B68B2
TargetProcess: 彩虹云点播 V14.6正式版.exe, InheritedFromPID = 1944, ProcessID = 1280, ThreadID = 1384, StartAddress = 0073ECBB, Parameter = 007B78DE

Registry behavior

Behavior description: 查询注册表_检测虚拟机相关
details: \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion

Other behavior

Behavior description: 探测 Virtual PC是否存在
details: N/A
Behavior description: 创建互斥体
details: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.ELH
Behavior description: 创建事件对象
details: EventName = DINPUTWINMM
Behavior description: 查找指定窗口
details: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
Behavior description: 尝试打开调试器或监控软件的驱动设备对象
details: \??\SICE
\??\SIWVID
\??\NTICE
Behavior description: 搜索kernel32.dll基地址
details: Instruction Address = 0x0073f8f1
Behavior description: 窗口信息
details: Pid = 1280, Hwnd=0x9032c, Text = 确定, ClassName = Button.
Pid = 1280, Hwnd=0xa0302, Text = Sorry, this application cannot run under a Virtual Machine, ClassName = Static.
Pid = 1280, Hwnd=0x9033e, Text = Themida, ClassName = #32770.
Behavior description: 获取TickCount值
details: TickCount = 1074846, SleepMilliseconds = 50.
TickCount = 1074878, SleepMilliseconds = 50.
TickCount = 1074925, SleepMilliseconds = 50.
TickCount = 1074940, SleepMilliseconds = 50.