1, 你可以上传任何文件,但是文件的尺寸不能超过20兆。
2, 我们支持RAR或ZIP格式的自动解压缩,但压缩文件中不能包含超过20个文件。
3, 我们可以识别并检测密码为 'infected' 或 'virus' 的压缩文件包。
4, 如果您的浏览器无法上传文件,请下载Virscan Uploader进行上传。
MD5:3c03562b5af9ed347614053d459d7778 |
文件大小:5.58MB |
上传时间: 2014-09-22 10:36:30 (CST) |
包名: |
最低运行环境: |
版权: |
行为描述: | 写权限映射文件 |
详细信息: | CiceroSharedMemDefaultS-1-5-21-1482476501-1645522239-1417001333-500 |
MSCTF.MarshalInterface.FileMap.EGJ..JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.B.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.C.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.D.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.E.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.F.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.G.JHLIG | |
MSCTF.MarshalInterface.FileMap.MHJ..DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.B.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.C.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.D.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.E.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.F.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.G.DJMIG | |
行为描述: | 隐藏指定窗口 |
详细信息: | [Window,Class] = [You must restart your computer to complete the rollback of the software.,Static] |
[Window,Class] = [&Restart,Button] | |
[Window,Class] = [,Auto-Suggest Dropdown] |
行为描述: | 写权限映射文件 |
详细信息: | CiceroSharedMemDefaultS-1-5-21-1482476501-1645522239-1417001333-500 |
MSCTF.MarshalInterface.FileMap.EGJ..JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.B.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.C.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.D.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.E.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.F.JHLIG | |
MSCTF.MarshalInterface.FileMap.EGJ.G.JHLIG | |
MSCTF.MarshalInterface.FileMap.MHJ..DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.B.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.C.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.D.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.E.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.F.DJMIG | |
MSCTF.MarshalInterface.FileMap.MHJ.G.DJMIG | |
行为描述: | 创建可执行文件 |
详细信息: | C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\.ba1\wixstdba.dll |
行为描述: | 修改文件内容 |
详细信息: | C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\.ba1\thm.xml---> Offset = 0 |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\.ba1\thm.wxl---> Offset = 0 | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\.ba1\logo.png---> Offset = 0 | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\.ba1\license.rtf---> Offset = 0 | |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\.ba1\BootstrapperApplicationData.xml---> Offset = 0 |
行为描述: | 创建互斥体 |
详细信息: | CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 |
CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 | |
CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 | |
CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 | |
CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500 | |
CTF.TimListCache.FMPDefaultS-1-5-21-1482476501-1645522239-1417001333-500MUTEX.DefaultS-1-5-21-1482476501-1645522239-1417001333-500 | |
MSCTF.Shared.MUTEX.AEH | |
MSCTF.Shared.MUTEX.EGJ | |
MSCTF.Shared.MUTEX.MHJ | |
行为描述: | 查找指定窗口 |
详细信息: | NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,] |
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,] | |
行为描述: | 隐藏指定窗口 |
详细信息: | [Window,Class] = [You must restart your computer to complete the rollback of the software.,Static] |
[Window,Class] = [&Restart,Button] | |
[Window,Class] = [,Auto-Suggest Dropdown] | |
行为描述: | 窗口信息 |
详细信息: | Pid = 2176, Hwnd=0x40252, Text = Setup Help, ClassName = Static. |
Pid = 2176, Hwnd=0x301be, Text = /install | /repair | /uninstall | /layout [directory] - installs, repairs, uninstalls or creates a complete local copy of the , ClassName = Static. | |
Pid = 2176, Hwnd=0x301c0, Text = &Close, ClassName = Button. | |
Pid = 2176, Hwnd=0x301c6, Text = MICROSOFT SOFTWARE LICENSE TERMS MICROSOFT VISUAL C++ 2012 RUNTIME LIBRARIES These license terms are an agreement between Micr, ClassName = RichEdit20W. | |
Pid = 2176, Hwnd=0x301d0, Text = I &agree to the license terms and conditions, ClassName = Button(CheckBox). | |
Pid = 2176, Hwnd=0x501ae, Text = &Options, ClassName = Button. | |
Pid = 2176, Hwnd=0x30228, Text = &Install, ClassName = Button. | |
Pid = 2176, Hwnd=0x301ca, Text = &Close, ClassName = Button. | |
Pid = 2176, Hwnd=0x301e6, Text = Setup Options, ClassName = Static. | |
Pid = 2176, Hwnd=0x3022c, Text = Install location:, ClassName = Static. | |
Pid = 2176, Hwnd=0x501bc, Text = &Browse, ClassName = Button. | |
Pid = 2176, Hwnd=0x40246, Text = &OK, ClassName = Button. | |
Pid = 2176, Hwnd=0x50216, Text = &Cancel, ClassName = Button. | |
Pid = 2176, Hwnd=0x4021e, Text = Setup Progress, ClassName = Static. | |
Pid = 2176, Hwnd=0x50210, Text = Processing:, ClassName = Static. |