1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
Safety rating:72 |
Behavior list |
Basic Information | |
---|---|
MD5: | f85e5c381497f90c11699d9eb9a02112 |
file type: | EXE |
Production company: | Microsoft |
version: | 1.0.0.0---1.0.0.0 |
Shell or compiler information: | COMPILER:Microsoft Visual C++ 6.0 [Overlay] |
Key behavior | |
---|---|
Behavior description: | 写权限映射文件 |
details: | CiceroSharedMemDefaultS-* |
Behavior description: | 隐藏指定窗口 |
details: | [Window,Class] = [,_EL_Timer] |
Process behavior | |
---|---|
Behavior description: | 枚举进程 |
details: | N/A |
File behavior | |
---|---|
Behavior description: | 写权限映射文件 |
details: | CiceroSharedMemDefaultS-* |
Behavior description: | 创建可执行文件 |
details: | C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\krnln.fnr |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\eAPI.fne | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\iext.fnr | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\spec.fne | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\shell.fne | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\ascaris.dll | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\shlwapi.dll | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\jedata.dll | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\imm32.dll | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\imedllhost09.ime | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\E_N40005\AntiOpenProcess.dll | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\%temp%\AntiOpenProcess.dll | |
Behavior description: | 查找文件 |
details: | FileName = AntiOpenProcess.dll |
Other behavior | |
---|---|
Behavior description: | 创建互斥体 |
details: | CTF.LBES.MutexDefaultS-* |
CTF.Compart.MutexDefaultS-* | |
CTF.Asm.MutexDefaultS-* | |
CTF.Layouts.MutexDefaultS-* | |
CTF.TMD.MutexDefaultS-* | |
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-* | |
Behavior description: | 隐藏指定窗口 |
details: | [Window,Class] = [,_EL_Timer] |
Run screenshot |
---|
![]() |