VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
Safety rating:55
Behavior list
Basic Information
MD5:fb271916c7988325640fd118734c1a63
file type:EXE
Production company:KAKA GAME SOFT
version:10.5.7.221---10, 5, 7, 221
Shell or compiler information:
Subfile information:Audition.exe / 1f881fd38737bc20579a0c46f5d90bcd / EXE
au56.acv / 7dd3658a3dd3f813142fd4e7b5590e1d / Unknown
onmi.dll / 79c27c4b4523cc53fdb590d4bab5dcfc / DLL
ij1l6.dll / 2ceaa153326be85738b131bc43fff582 / DLL
FontLoader.ldr / c38b50fff14873cae17fd6612b6e4747 / DLL
ij1l7.dll / 8bc4833608a1dd90c45331a1b92c11da / DLL
Bezier.fnt / 2e649bc30521bc0dcd23e4f1be7fdced / Unknown
TblPtLst.bin / 56c91b70d83fe012f48451d5cf4b2c54 / Unknown
login_w.DDS / bfd026b122e5983d2be5ea2c3bf0804f / Unknown
fmode.dll / 2f1f02dddea29e713f4bca6e14b1c998 / DLL
wmvl.dll / e46c84cba2090fb620de813a3c96ece4 / DLL
ijl15.dll / 909bd84bf2e9bc198d083f519d8888b8 / DLL
Chinese.loc / 405603297c84836137d6321bb1605698 / Unknown
br0011.tbm / e4800c5459b00afbbbbd34132b9974fe / Unknown
intro.jpg / df32b0f95c278dad3aab6e3756ed4bf4 / Unknown
123.gif / 0fc81735d89eed03c667f57edef6febf / Unknown
popup_01.jpg / 1bf53cf87516939642c4b16abe49bccd / Unknown
TaskKeyHookCN.dll / 0da46133e7fa3f400395c849ba0c03cb / DLL
imejpn_right.dds / adef049ab1a941dc24cd85936a4a3f9e / Unknown
Key behavior
Behavior description:探测 Virtual PC是否存在
details:N/A
Behavior description:尝试打开调试器或监控软件的驱动设备对象
details:\??\SICE
\??\SIWVID
\??\NTICE
Behavior description:获取TickCount值
details:TickCount = 5367690, SleepMilliseconds = 50.
TickCount = 5367721, SleepMilliseconds = 50.
TickCount = 5367737, SleepMilliseconds = 50.
TickCount = 5367768, SleepMilliseconds = 50.
TickCount = 5367784, SleepMilliseconds = 50.
TickCount = 5367846, SleepMilliseconds = 50.
TickCount = 5368534, SleepMilliseconds = 50.
TickCount = 5368565, SleepMilliseconds = 50.
TickCount = 5372393, SleepMilliseconds = 50.
TickCount = 5372409, SleepMilliseconds = 50.
Behavior description:查询注册表_检测虚拟机相关
details:\REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
\REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
Behavior description:查找指定内核模块
details:lstrcmpiA: ntice.sys <------> ntkrnlpa.exe Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> hal.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> KDCOM.DLL Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BOOTVID.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ACPI.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> WMILIB.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> pci.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> isapnp.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> compbatt.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BATTC.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> intelide.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> PCIIDEX.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> MountMgr.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ftdisk.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> dmload.sys Des: SoftICE驱动
Behavior description:查找反病毒常用工具窗口
details:NtUserFindWindowEx: [Class,Window] = [OLLYDBG,]
NtUserFindWindowEx: [Class,Window] = [GBDYLLO,]
NtUserFindWindowEx: [Class,Window] = [pediy06,]
NtUserFindWindowEx: [Class,Window] = [FilemonClass,]
NtUserFindWindowEx: [Class,Window] = [,File Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
NtUserFindWindowEx: [Class,Window] = [,Process Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [RegmonClass,]
NtUserFindWindowEx: [Class,Window] = [,Registry Monitor - Sysinternals: www.sysinternals.com]
Process behavior
Behavior description:创建本地线程
details:TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3760, StartAddress = 005DF1D3, Parameter = 0073F25F
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3764, StartAddress = 005DF1D3, Parameter = 0073FCF5
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3768, StartAddress = 005DF1D3, Parameter = 00740DC3
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3772, StartAddress = 005DF1D3, Parameter = 00741950
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3776, StartAddress = 005DF1D3, Parameter = 0074254A
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3780, StartAddress = 005DF1D3, Parameter = 00743076
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3784, StartAddress = 005DF1D3, Parameter = 00743B64
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3788, StartAddress = 005DF1D3, Parameter = 0074464F
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3792, StartAddress = 005DF1D3, Parameter = 0074883D
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3796, StartAddress = 005DF1D3, Parameter = 0074993D
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3800, StartAddress = 005DF1D3, Parameter = 0074AAFF
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3804, StartAddress = 005DF1D3, Parameter = 0074BB08
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3808, StartAddress = 005DF1D3, Parameter = 0074CB1F
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3812, StartAddress = 005DF1D3, Parameter = 0074DBEB
TargetProcess: %temp%\****.exe, InheritedFromPID = 1944, ProcessID = 3728, ThreadID = 3816, StartAddress = 005DF1D3, Parameter = 0074ECDB
Behavior description:枚举进程
details:N/A
Registry behavior
Behavior description:查询注册表_检测虚拟机相关
details:\REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
\REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion
Other behavior
Behavior description:探测 Virtual PC是否存在
details:N/A
Behavior description:创建互斥体
details:RasPbFile
CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
Behavior description:创建事件对象
details:EventName = DINPUTWINMM
EventName = Global\userenv: User Profile setup event
Behavior description:打开事件
details:HookSwitchHookEnabledEvent
Behavior description:查找指定窗口
details:NtUserFindWindowEx: [Class,Window] = [18467-41,]
Behavior description:尝试打开调试器或监控软件的驱动设备对象
details:\??\SICE
\??\SIWVID
\??\NTICE
Behavior description:搜索kernel32.dll基地址
details:Instruction Address = 0x005e0a05
Behavior description:获取光标位置
details:CursorPos = (71,18468), SleepMilliseconds = 50.
Behavior description:窗口信息
details:Pid = 588, Hwnd=0x80358, Text = 确定, ClassName = Button.
Pid = 588, Hwnd=0xd035e, Text = 取消, ClassName = Button.
Pid = 588, Hwnd=0x1802fe, Text = "0x7c8017ee" 指令引用的 "0xcccc0018" 内存。该内存不能为 "read"。 要终止程序,请单击“确定”。 要调试程序,请单击“取消”。, ClassName = Static.
Pid = 588, Hwnd=0x802da, Text = %temp%\****.exe - 应用程序错误, ClassName = #32770.
Behavior description:获取TickCount值
details:TickCount = 5367690, SleepMilliseconds = 50.
TickCount = 5367721, SleepMilliseconds = 50.
TickCount = 5367737, SleepMilliseconds = 50.
TickCount = 5367768, SleepMilliseconds = 50.
TickCount = 5367784, SleepMilliseconds = 50.
TickCount = 5367846, SleepMilliseconds = 50.
TickCount = 5368534, SleepMilliseconds = 50.
TickCount = 5368565, SleepMilliseconds = 50.
TickCount = 5372393, SleepMilliseconds = 50.
TickCount = 5372409, SleepMilliseconds = 50.
Behavior description:打开互斥体
details:DBWinMutex
RasPbFile
Behavior description:查找指定内核模块
details:lstrcmpiA: ntice.sys <------> ntkrnlpa.exe Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> hal.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> KDCOM.DLL Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BOOTVID.dll Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ACPI.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> WMILIB.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> pci.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> isapnp.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> compbatt.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> BATTC.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> intelide.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> PCIIDEX.SYS Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> MountMgr.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> ftdisk.sys Des: SoftICE驱动
lstrcmpiA: ntice.sys <------> dmload.sys Des: SoftICE驱动
Behavior description:查找反病毒常用工具窗口
details:NtUserFindWindowEx: [Class,Window] = [OLLYDBG,]
NtUserFindWindowEx: [Class,Window] = [GBDYLLO,]
NtUserFindWindowEx: [Class,Window] = [pediy06,]
NtUserFindWindowEx: [Class,Window] = [FilemonClass,]
NtUserFindWindowEx: [Class,Window] = [,File Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [PROCMON_WINDOW_CLASS,]
NtUserFindWindowEx: [Class,Window] = [,Process Monitor - Sysinternals: www.sysinternals.com]
NtUserFindWindowEx: [Class,Window] = [RegmonClass,]
NtUserFindWindowEx: [Class,Window] = [,Registry Monitor - Sysinternals: www.sysinternals.com]
Run screenshot
VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
中国反网络病毒联盟
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号