vba32ldrgui.exe

Vba32 for Windows Vista

VIRUSBLOKADA ODO

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Vba32LoaderGUI’.
Publisher:
VirusBlokAda Ltd.  (signed by VIRUSBLOKADA ODO)

Product:
Vba32 for Windows Vista

Description:
Vba32 Loader GUI

Version:
3.12.4.1

MD5:
75fbc7b83db436061ef9516dd7ba6659

SHA-1:
7ffa313b2946f3e496f5456cb1a416487563eaef

SHA-256:
264d4ce16aca80a031835d88616099e81ac576e017ae86bf6759a02d9bee095c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 4:31:21 AM UTC  (today)

File size:
765.9 KB (784,296 bytes)

Product version:
3.12.4.1

Copyright:
Copyright (C) 1993 - 2009 by VirusBlokAda Ltd.

Original file name:
vba32ldrgui.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\Program Files\vba32\vba32ldrgui.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2012 1:00:00 AM

Valid to:
2/22/2014 12:59:59 AM

Subject:
CN=VIRUSBLOKADA ODO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=VIRUSBLOKADA ODO, L=Minsk, S=BY, C=BY

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2DA05BBFA05778B979ACB88C01FF8E27

File PE Metadata
Compilation timestamp:
11/22/2012 8:53:27 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:XSDePaLRZ7zmceFZQdmqtlUoX7hXLyAcyeHxwFNANbN02+1Er9R+RR8Xz:iKU4QdTtyorhXLyAcyeHxwFNAN50v1Wx

Entry address:
0x3D49F

Entry point:
6A, 60, 68, 18, 5A, 45, 00, E8, 51, 13, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 89, F9, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 7C, D2, 44, 00, 8B, 4E, 10, 89, 0D, 28, 46, 46, 00, 8B, 46, 04, A3, 34, 46, 46, 00, 8B, 56, 08, 89, 15, 38, 46, 46, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 2C, 46, 46, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 2C, 46, 46, 00, C1, E0, 08, 03, C2, A3, 30, 46, 46, 00, 33, F6, 56, 8B, 3D, A0, D2, 44, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
304 KB (311,296 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Vba32LoaderGUI

Command:
"C:\Program Files\vba32\vba32ldrgui.exe"


Scan vba32ldrgui.exe - Powered by Reason Core Security