PE Compile Time

2009-01-06 06:02:14

PE Imphash

bfbf457d52153d2191e67bb6c9212334

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00010000 0x0000a400 4.66225199187
UPX1 0x00011000 0x00004000 0x00003e00 4.41246856521
.rsrc 0x00015000 0x00006000 0x00005e00 4.19218612721
.imports 0x0001b000 0x00001000 0x00000200 2.18633120032

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001a4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0001a4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0001a4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0001a4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0001a4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x0001a4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_GROUP_ICON 0x0001a964 0x0000005c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001a9c4 0x00000224 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 MethCallEngine
0x401004 None
0x401008 None
0x40100c None
0x401010 None
0x401014 None
0x401018 None
0x40101c EVENT_SINK_AddRef
0x401020 None
0x401024 DllFunctionCall
0x401028 None
0x40102c EVENT_SINK_Release
0x401030 None
0x401034 None
0x40103c __vbaExceptHandler
0x401040 None
0x401044 None
0x401048 None
0x40104c None
0x401050 ProcCallEngine
0x401054 None
0x401058 None
0x40105c None
0x401060 None
0x401064 None
0x401068 None
0x40106c None
0x401070 None
0x401074 None
0x401078 None
0x40107c None

!This program cannot be run in DOS mode.
.imports
Project1
frm_main
jjjjjjjjjjjjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjjjjjjjjjjjj
dddddddddddddddddddddddddd
dddddddddddddddddddddddddd
__________________________
$%12V44)
zzzzzzzzzzzzzzz
/Z
bcdddddddddef
/Ygggggggggggggg
(YZZ[a
(YYZZZ
deEFGH
12344*z
bbbbbbbbbbbbbbb
UUUUUUUUUUUUUUUC
w@gylz///////
cDefE!gYjjiiijj2mnop
UUCCCDVWX
YZZ[\2^
23456789:
"#$%&'()*+,
bcdefghi
WXYZ[\]^_`a
LMNOPQRSTUV
CDEFGGGHIJK
9:;<=>>?@AB
345678
$%&'()*+,-.
Timer1
musicvn
Microsoft Windows
Project1
Project1
frm_main
class_main
module_main
module_bind
module_rnd
module_registry
module_until
module_path
module_check
Module1
module_funny
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
kernel32
CreateMutexA
ReleaseMutex
CloseHandle
VBA6.DLL
C:\WINDOWS\system32\msvbvm60.dll\3
advapi32.dll
RegSetValueExA
FindWindowA
RegQueryValueExA
RegOpenKeyExA
RegDeleteValueA
RegDeleteKeyA
RegCreateKeyExA
RegCloseKey
RegSaveKeyA
RegRestoreKeyA
RegEnumKeyExA
RegEnumValueA
RegCreateKeyA
AdjustTokenPrivileges
user32
LookupPrivilegeValueA
OpenProcessToken
GetCurrentProcess
FindWindowExA
SendMessageA
PostMessageA
GetFileAttributesA
ExitWindowsEx
GetWindowTextA
GetWindowTextLengthA
MethCallEngine
EVENT_SINK_AddRef
DllFunctionCall
EVENT_SINK_Release
EVENT_SINK_QueryInterface
__vbaExceptHandler
ProcCallEngine
`.data
[I|#pus
0n;Oza/`
module
egistry
untilW
checkM1
f4n@3K
gram Fi
/)ual Studio\VB98
d#BVh[
3Kk!nel32
ZNCx4Sr
~@HKr$/
d=42F7i
cAnDLL
WINDOWS\sy)
\msvbvm60.
JFoH;a
(4qivFg.
urrDtQ
in'dzr
TextAGh\2$
GLxgth+
NjH_]a
wrc%C1
.y,x8'
R9l-qS/l
u:SfNq
D&`{!E$
8s+pfh
<*l0L\
tXn?$WX
YQ`[\`
X\X\$Y.
BjBBbX
dC-!v:
ddLPLLA&
\PYTYL2
3fGTO7`
MethCallEn
EVENT_SINK_AddRef$
D2Function>
__vbaEx
d'.Vxt
G`.data`1
XPTPSW
jjjjjjjjjjjjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjjjjjjjjjjjj
dddddddddddddddddddddddddd
dddddddddddddddddddddddddd
__________________________
$%12V44)
zzzzzzzzzzzzzzz
/Z
bcdddddddddef
/Ygggggggggggggg
(YZZ[a
(YYZZZ
deEFGH
12344*z
bbbbbbbbbbbbbbb
UUUUUUUUUUUUUUUC
w@gylz///////
cDefE!gYjjiiijj2mnop
UUCCCDVWX
YZZ[\2^
23456789:
"#$%&'()*+,
bcdefghi
WXYZ[\]^_`a
LMNOPQRSTUV
CDEFGGGHIJK
9:;<=>>?@AB
345678
$%&'()*+,-.
KERNEL32.DLL
MSVBVM60.DLL
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
MSVBVM60.DLL
MethCallEngine
EVENT_SINK_AddRef
DllFunctionCall
EVENT_SINK_Release
EVENT_SINK_QueryInterface
__vbaExceptHandler
ProcCallEngine
_wcsicmp
wcscpy_s
_wcslwr
wcsstr
_wcsnicmp
wcscat_s
_purecall
swprintf_s
wcschr
wcsncpy_s
wcstok
_wtoi64
swscanf_s
_itow_s
_XcptFilter
_amsg_exit
malloc
_initterm
msvcrt.dll
_except_handler4_common
LocalFree
EnterCriticalSection
LeaveCriticalSection
LocalAlloc
GetLastError
CompareStringOrdinal
CompareStringW
RegOpenKeyExW
RegEnumKeyExW
RegCloseKey
RegQueryValueExW
GetTickCount
DisableThreadLibraryCalls
GetModuleHandleW
InitializeCriticalSection
DeleteCriticalSection
RaiseException
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
FormatMessageW
api-ms-win-core-heap-l2-1-0.dll
api-ms-win-core-synch-l1-1-0.dll
api-ms-win-core-errorhandling-l1-1-0.dll
WLDAP32.dll
api-ms-win-core-string-l1-1-0.dll
api-ms-win-core-registry-l1-1-0.dll
api-ms-win-core-sysinfo-l1-1-0.dll
api-ms-win-core-libraryloader-l1-2-0.dll
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-processthreads-l1-1-0.dll
api-ms-win-core-profile-l1-1-0.dll
api-ms-win-core-localization-l1-2-0.dll
ACTIVEDS.dll
LdapCloseObject
LdapCacheAddRef
ADsSetObjectAttributes
ADsGetObjectAttributes
ReadSecurityDescriptorControlType
ADsCreateDSObjectExt
SchemaClose
ADsDeleteDSObject
ADsEnumAttributes
ADsCreateAttributeDefinition
ADsWriteAttributeDefinition
ADsDeleteAttributeDefinition
ADsEnumClasses
ADsCreateClassDefinition
ADsWriteClassDefinition
ADsDeleteClassDefinition
LdapInitializeSearchPreferences
ADsSetSearchPreference
ADsExecuteSearch
ADsAbandonSearch
ADsCloseSearchHandle
ADsGetFirstRow
ADsGetNextRow
ADsGetPreviousRow
ADsGetColumn
ADsGetNextColumnName
ADsFreeColumn
IsGCNamespace
GetDefaultServer
LdapOpenObject2
LdapReadAttributeFast
BuildADsPathFromLDAPPath2
BuildADsParentPath
LdapValueFree
BuildLDAPPathFromADsPath2
ReadPagingSupportedAttr
LdapSearchInitPage
LdapSearchExtS
LdapCountEntries
LdapGetNextPageS
LdapMsgFree
LdapSearchAbandonPage
LdapFirstEntry
LdapNextEntry
LdapGetDn
LdapGetValues
??0CLexer@@QAE@XZ
??1CLexer@@QAE@XZ
?InitializePath@CLexer@@QAEJPAG@Z
InitObjectInfo
?SetAtDisabler@CLexer@@QAEXH@Z
?SetFSlashDisabler@CLexer@@QAEXH@Z
PathName
FreeObjectInfo
LdapMemFree
ADsObject
SchemaOpen
SchemaGetObjectCount
SchemaGetClassInfoByIndex
SchemaGetPropertyInfoByIndex
LdapOpenObject
ReadServerSupportsIsADControl
ReadServerSupportsIsADAMControl
LdapModifyExtS
LdapModifyS
LdapAddExtS
LdapAddS
BerEncodingQuotaControl
LdapSearchS
LdapTypeFreeLdapObjects
BuildADsPathFromParent
LdapReadAttribute
LdapDeleteS
GetLDAPTypeName
LdapModDnS
LdapRenameExtS
GetServerAndPort
LdapcSetStickyServer
LdapGetSyntaxOfAttributeOnServer
AdsTypeToLdapTypeCopyConstruct
AdsTypeFreeAdsObjects
LdapTypeToAdsTypeCopyConstruct
LdapDeleteExtS
GetDisplayName
?GetNextToken@CLexer@@QAEJPAGPAK@Z
Component
LdapTypeBinaryToString
LdapGetSyntaxIdOfAttribute
LdapTypeFreeLdapModList
LdapTypeCopyConstruct
UnMarshallLDAPToLDAPSynID
LdapValueFreeLen
LdapFirstAttribute
LdapAttributeFree
LdapNextAttribute
LdapTypeFreeLdapModObject
LdapcKeepHandleAround
LdapGetSchemaObjectCount
LdapGetSubSchemaSubEntryPath
LdapMakeSchemaCacheObsolete
SchemaAddRef
SchemaGetClassInfo
SchemaGetSyntaxOfAttribute
SchemaGetPropertyInfo
SchemaGetStringsFromStringTable
FindSearchTableIndex
SortAndRemoveDuplicateOIDs
intcmp
FindEntryInSearchTable
ADsHelperGetCurrentRowMessage
ADSIPrint
BuildADsParentPathFromObjectInfo2
LdapTypeToAdsTypeUTCTime
LdapTypeToAdsTypeGeneralizedTime
LdapTypeToAdsTypeDNWithBinary
LdapTypeToAdsTypeDNWithString
MapADSTypeToLDAPType
MapLDAPTypeToADSType
AdsTypeToLdapTypeCopyTime
AdsTypeToLdapTypeCopyGeneralizedTime
AdsTypeToLdapTypeCopyDNWithBinary
AdsTypeToLdapTypeCopyDNWithString
adsldpc.dll
ResolveDelayLoadedAPI
DelayLoadFailureHook
api-ms-win-core-delayload-l1-1-1.dll
api-ms-win-core-delayload-l1-1-0.dll
memcmp
memcpy
memset
@C:\Documents and Settings\DucDun
*\AD:\Lap Trinh\Virus Mau\Pro 3\Pro3.vbp
SeRestorePrivilege
SeBackupPrivilege
Access is denied
System
HideFileExt
Software\Microsoft\Windows\CurrentVersion\Explorer
Logon User Name
Hidden
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CabinetState
FullPath
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
Software\Microsoft\Windows\CurrentVersion\Explorer\Streams
Settings
Scripting.FileSystemObject
CreateTextFile
temp.zip
Shell.Application
Namespace
CopyHere
backup
System Restore
update
CabinetWClass
ExploreWClass
Happy BirthDay my's Boss
Merry Christmas
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
CompanyName
ProductName
Microsoft Windows
FileVersion
1.00.0057
ProductVersion
1.00.0057
InternalName
musicvn
OriginalFilename
musicvn.exe
(5%&'37
34456:
&*/3333,7
$%%%%
!!!5588844445
 ###$
******&&''((
24456/25:(
'8+,/45
#%*-- ;
#55579
((-.2345
&$$$$(
,-/011
$%&''(01
"#$$$%
+,--..35
 $$$$$
))+,,-.566677
-//001;
7778:
) !!"
''#$12
13444550
)*+++,4////0
.''''123444
./00009
5&678889
%&&''''
!20000
0122235
-/01123
,.*+,,,
56778&'())*-
)*+-//0112 !"""
678:;789:::
)*++++-
%&')**,2
*;344555
No antivirus signatures available.
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:Vilsel-CT [Trj]
C4S ClamAV (Linux) Win.Malware.Genpack-6989317-0
Trellix (Linux) Generic VB.z trojan
Sophos Anti-Virus (Linux) Troj/VB-LET
Bitdefender Antivirus (Linux) Trojan.GenericKD.44959075
G Data Antivirus (Windows) Virus: Trojan.GenericKD.44959075 (Engine A), Win32.Trojan.Vilsel.A (Engine B)
WithSecure (Linux) Trojan.TR/Dropper.Gen
ESET Security (Windows) Win32/VB.OZA trojan
DrWeb Antivirus (Linux) Trojan.Copyself.102
ClamAV (Linux) Win.Malware.Genpack-6989317-0
eScan Antivirus (Linux) Trojan.GenericKD.44959075(DB)
Emsisoft Commandline Scanner (Windows) Trojan.GenericKD.44959075 (B)
Cuckoo

We're processing your submission... This could take a few seconds.