VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

   File information

Virscan.org multi-engine scan report
Behavior analysis report:         Habo file analysis

Basic Information

MD5:fcd5417570f720a2da4181d228128d45
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
Package names:bbbbbs.ggtgggtged.rgggtt
Minimum operating environment:Android 2.2.x
copyright:Android

Key behavior

Behavior description: 设置特殊文件夹属性
details: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016050920160510
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds Cache

Process behavior

Behavior description: 创建本地线程
details: TargetProcess: iexplore.exe, InheritedFromPID = 3024, ProcessID = 3068, ThreadID = 3196, StartAddress = 6359727B, Parameter = 002591C8
TargetProcess: iexplore.exe, InheritedFromPID = 3024, ProcessID = 3068, ThreadID = 3200, StartAddress = 77E56C7D, Parameter = 0026F878
TargetProcess: iexplore.exe, InheritedFromPID = 3024, ProcessID = 3068, ThreadID = 3220, StartAddress = 4AEA7456, Parameter = 00000000
TargetProcess: iexplore.exe, InheritedFromPID = 3024, ProcessID = 3068, ThreadID = 3224, StartAddress = 6359727B, Parameter = 03614820
TargetProcess: iexplore.exe, InheritedFromPID = 3024, ProcessID = 3068, ThreadID = 3284, StartAddress = 5DE05A52, Parameter = 031555E0
TargetProcess: iexplore.exe, InheritedFromPID = 3024, ProcessID = 3068, ThreadID = 3320, StartAddress = 6359727B, Parameter = 00275BA8
TargetProcess: iexplore.exe, InheritedFromPID = 3024, ProcessID = 3068, ThreadID = 3328, StartAddress = 6359727B, Parameter = 00275C48

File behavior

Behavior description: 创建文件
details: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016050920160510\index.dat
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\dnserrordiagoff[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\noConnect[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\background_gradient[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\down[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\favcenter[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\tools[2]
Behavior description: 覆盖已有文件
details: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\dnserrordiagoff[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\ErrorPageTemplate[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\noConnect[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\background_gradient[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\down[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\favcenter[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\tools[2]
Behavior description: 删除文件
details: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\dnserrordiagoff[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\ErrorPageTemplate[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\errorPageStrings[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\httpErrorPagesScripts[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\noConnect[3]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\bullet[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\background_gradient[2]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\down[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\favcenter[3]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\tools[1]
Behavior description: 修改文件内容
details: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016050920160510\index.dat ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\dnserrordiagoff[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\ErrorPageTemplate[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\errorPageStrings[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\httpErrorPagesScripts[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6TLOMATB\noConnect[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\bullet[2] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\background_gradient[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\down[2] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1OS62RY\favcenter[1] ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IUKHR8T2\tools[2] ---> Offset = 0
Behavior description: 设置特殊文件夹属性
details: C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012016050920160510
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Feeds Cache

Network behavior

Behavior description: 打开HTTP连接
details: InternetOpenA: UserAgent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; KB974489), hSession = 0x00cc0004

Registry behavior

Behavior description: 修改注册表
details: \REGISTRY\MACHINE\SOFTWARE\Microsoft\Internet Explorer\Default MHTML Editor\Last
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016050920160510\CachePath
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016050920160510\CachePrefix
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016050920160510\CacheLimit
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016050920160510\CacheOptions
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016050920160510\CacheRepair
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Count
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Time
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\LoadTime
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\LoadTimeCount
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
Behavior description: 删除注册表键值
details: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
Behavior description: 删除注册表键
details: \REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012015082520150826\

Other behavior

Behavior description: 创建互斥体
details: Local\!PrivacIE!SharedMemory!Mutex
SmartScreen_UrsCacheMutex_2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2High_S-*
Local\c:!documents and settings!administrator!local settings!history!history.ie5!mshist012016050920160510!
Local\c:!documents and settings!administrator!local settings!application data!microsoft!feeds cache!
RasPbFile
MSIMGSIZECacheMutex
Behavior description: 创建事件对象
details: EventName = Global\crypt32LogoffEvent
EventName = DINPUTWINMM
EventName = Global\userenv: User Profile setup event
Behavior description: 查找指定窗口
details: NtUserFindWindowEx: [Class,Window] = [MS_AutodialMonitor,]
NtUserFindWindowEx: [Class,Window] = [MS_WebCheckMonitor,]
Behavior description: 隐藏指定窗口
details: [Window,Class] = [缩放级别,ToolbarWindow32]
[Window,Class] = [,msctls_progress32]
Behavior description: 窗口信息
details: Pid = 3024, Hwnd=0x702c0, Text = 导航栏, ClassName = WorkerW.
Pid = 3024, Hwnd=0x102de, Text = 地址组合控制, ClassName = ToolbarWindow32.
Pid = 3024, Hwnd=0x102e2, Text = 页面控制, ClassName = ToolbarWindow32.
Pid = 3024, Hwnd=0x102f2, Text = 搜索..., ClassName = Edit.
Pid = 3024, Hwnd=0x102f6, Text = 搜索组合控制, ClassName = ToolbarWindow32.
Pid = 3024, Hwnd=0x102f8, Text = 搜索控制, ClassName = ToolbarWindow32.
Pid = 3024, Hwnd=0x10312, Text = 命令栏, ClassName = ToolbarWindow32.
Pid = 3024, Hwnd=0x1030a, Text = 收藏夹命令栏, ClassName = ToolbarWindow32.
Pid = 3024, Hwnd=0x102fe, Text = LinksBand, ClassName = LinksBandClass.
Pid = 3024, Hwnd=0x10306, Text = 收藏夹栏, ClassName = ToolbarWindow32.
Pid = 3024, Hwnd=0x10302, Text = 添加到收藏夹栏, ClassName = ToolbarWindow32.
Pid = 3068, Hwnd=0x10328, Text = ITBarHost, ClassName = InternetToolbarHost.
Pid = 3068, Hwnd=0x1032a, Text = 菜单栏, ClassName = WorkerW.
Pid = 3068, Hwnd=0x1033c, Text = 缩放级别, ClassName = ToolbarWindow32.

Activities

com.phone2.stop.activity.MainActivity android.intent.action.MAIN
com.phone2.stop.activity.MainActivity android.intent.category.LAUNCHER
com.phone2.stop.activity.DeleteActivity android.intent.action.DELETE
com.phone2.stop.activity.DeleteActivity android.intent.category.DEFAULT

Dangerous function

ContentResolver;->delete 删除短信、联系人
ContentResolver;->query 读取联系人、短信等数据库
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
java/net/URL;->openConnection 连接URL

Startup mode

com.phone.stop.receiver.BootReceiver 开机启动服务
com.phone.stop.receiver.SMSReceiver 监控短信(收到短信)启动服务
com.phone.stop.receiver.MyDeviceAdminReceiver

Permission list

android.permission.RECEIVE_WAP_PUSH 接收wap push信息
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
android.permission.MODIFY_AUDIO_SETTINGS 修改声音设置
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.RECEIVE_USER_PRESENT
android.permission.READ_CONTACTS 读取联系人信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.READ_SMS 读取短信
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.VIBRATE 允许设备震动
android.permission.RECEIVE_SMS 监控接收短信
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
android.permission.WRITE_SMS 写短信
android.permission.SEND_SMS 发送短信
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态

Service list

com.phone.stop6.service.SecondService
com.phone.stop6.service.BootService
com.phone.stop6.service.SmsService

File List

META-INF/MANIFEST.MF
META-INF/CERT.SF
META-INF/CERT.RSA
AndroidManifest.xml
mimetypes.default
dsn.mf
javamail.pop3.provider
res/layout/activity_main.xml
mailcap.default
javamail.default.providers
javamail.default.address.map
javamail.smtp.address.map
res/layout/activity_aa.xml
javamail.smtp.provider
javamail.charset.map
res/drawable-hdpi/icon.png
res/drawable-hdpi/app_logo.png
javamail.imap.provider
resources.arsc
res/xml/devicepolicymanager_permission.xml
classes.dex
mailcap