vba32ldrgui.exe

Vba32 for Windows Vista

VIRUSBLOKADA ODO

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Vba32LoaderGUI’.
Publisher:
VirusBlokAda Ltd.  (signed by VIRUSBLOKADA ODO)

Product:
Vba32 for Windows Vista

Description:
Vba32 Loader GUI

Version:
3.12.4.1

MD5:
5229656575780b66de28ae7041107d2c

SHA-1:
fbb220fbfcea3e3445bf98d7e0a0c63ab8230771

SHA-256:
a392a9e84ba1ce69b2a25746158359d5e5522aee048166fef85b2b3c1b964b65

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 4:13:54 AM UTC  (today)

File size:
785.9 KB (804,776 bytes)

Product version:
3.12.4.1

Copyright:
Copyright (C) 1993 - 2009 by VirusBlokAda Ltd.

Original file name:
vba32ldrgui.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\vba32\vba32ldrgui.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2012 2:00:00 AM

Valid to:
2/22/2014 1:59:59 AM

Subject:
CN=VIRUSBLOKADA ODO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=VIRUSBLOKADA ODO, L=Minsk, S=BY, C=BY

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2DA05BBFA05778B979ACB88C01FF8E27

File PE Metadata
Compilation timestamp:
10/9/2012 9:41:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
24576:bHOUx/fvps+yAcyelxwFNAN+nWIshIKFl7:1pp/nNshIKL

Entry address:
0x415EF

Entry point:
6A, 60, 68, 48, A2, 45, 00, E8, 51, 13, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 49, EE, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 80, 12, 45, 00, 8B, 4E, 10, 89, 0D, C0, 96, 46, 00, 8B, 46, 04, A3, CC, 96, 46, 00, 8B, 56, 08, 89, 15, D0, 96, 46, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, C4, 96, 46, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, C4, 96, 46, 00, C1, E0, 08, 03, C2, A3, C8, 96, 46, 00, 33, F6, 56, 8B, 3D, A4, 12, 45, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
320 KB (327,680 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Vba32LoaderGUI

Command:
"C:\Program Files\vba32\vba32ldrgui.exe"


Scan vba32ldrgui.exe - Powered by Reason Core Security