vba32ldrgui.exe

Vba32 for Windows Vista

VIRUSBLOKADA ODO

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Vba32LoaderGUI’.
Publisher:
VirusBlokAda Ltd.  (signed by VIRUSBLOKADA ODO)

Product:
Vba32 for Windows Vista

Description:
Vba32 Loader GUI

Version:
3.12.4.1

MD5:
589bee23ba55349d80cf7fcda04eb1ca

SHA-1:
a5df2db2dddd8db2c7e5b2642d870fe92801d29d

SHA-256:
1e1561256f521c0181da16dbb9a3a139111109a12ae6c075745620f20e5467b2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 9:04:59 PM UTC  (today)

File size:
779.7 KB (798,400 bytes)

Product version:
3.12.4.1

Copyright:
Copyright (C) 1993 - 2009 by VirusBlokAda Ltd.

Original file name:
vba32ldrgui.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\vba32\vba32ldrgui.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/15/2014 3:00:00 AM

Valid to:
3/17/2015 2:59:59 AM

Subject:
CN=VIRUSBLOKADA ODO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=VIRUSBLOKADA ODO, L=Minsk, S=Minsk, C=BY

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
637B64CBDBA53F34B58DDBBEA4B5CFEA

File PE Metadata
Compilation timestamp:
2/12/2015 5:47:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
24576:7cgw0HvNaa4FMO6syAcye1xwFNANcbCFlSK796:b/OJbCFlSKA

Entry address:
0x3F88F

Entry point:
6A, 60, 68, E8, 7A, 45, 00, E8, 51, 13, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 49, ED, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, CC, F0, 44, 00, 8B, 4E, 10, 89, 0D, 90, 76, 46, 00, 8B, 46, 04, A3, 9C, 76, 46, 00, 8B, 56, 08, 89, 15, A0, 76, 46, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 94, 76, 46, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 94, 76, 46, 00, C1, E0, 08, 03, C2, A3, 98, 76, 46, 00, 33, F6, 56, 8B, 3D, A8, F2, 44, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
312 KB (319,488 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Vba32LoaderGUI

Command:
"C:\Program Files\vba32\vba32ldrgui.exe"


Scan vba32ldrgui.exe - Powered by Reason Core Security