PE Compile Time

2009-01-06 06:02:14

PE Imphash

bfbf457d52153d2191e67bb6c9212334

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00012000 0x00011a00 4.20625959766
.rsrc 0x00013000 0x00002000 0x00002000 7.52929785384

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00012308 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x00012308 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x00012308 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x00012308 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x00012308 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_ICON 0x00012308 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1088
RT_GROUP_ICON 0x00012770 0x0000005c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000127d0 0x00000224 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 MethCallEngine
0x401004 None
0x401008 None
0x40100c None
0x401010 None
0x401014 None
0x401018 None
0x40101c EVENT_SINK_AddRef
0x401020 None
0x401024 DllFunctionCall
0x401028 None
0x40102c EVENT_SINK_Release
0x401030 None
0x401034 None
0x40103c __vbaExceptHandler
0x401040 None
0x401044 None
0x401048 None
0x40104c None
0x401050 ProcCallEngine
0x401054 None
0x401058 None
0x40105c None
0x401060 None
0x401064 None
0x401068 None
0x40106c None
0x401070 None
0x401074 None
0x401078 None
0x40107c None

!This program cannot be run in DOS mode.
PEC2^O
Project1
frm_main
jjjjjjjjjjjjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjjjjjjjjjjjj
dddddddddddddddddddddddddd
dddddddddddddddddddddddddd
__________________________
$%12V44)
zzzzzzzzzzzzzzz
/Z
bcdddddddddef
/Ygggggggggggggg
(YZZ[a
(YYZZZ
deEFGH
12344*z
bbbbbbbbbbbbbbb
UUUUUUUUUUUUUUUC
w@gylz///////
cDefE!gYjjiiijj2mnop
UUCCCDVWX
YZZ[\2^
23456789:
"#$%&'()*+,
bcdefghi
WXYZ[\]^_`a
LMNOPQRSTUV
CDEFGGGHIJK
9:;<=>>?@AB
345678
$%&'()*+,-.
Timer1
musicvn
Microsoft Windows
Project1
Project1
frm_main
class_main
module_main
module_bind
module_rnd
module_registry
module_until
module_path
module_check
Module1
module_funny
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
kernel32
CreateMutexA
ReleaseMutex
CloseHandle
VBA6.DLL
C:\WINDOWS\system32\msvbvm60.dll\3
advapi32.dll
RegSetValueExA
FindWindowA
RegQueryValueExA
RegOpenKeyExA
RegDeleteValueA
RegDeleteKeyA
RegCreateKeyExA
RegCloseKey
RegSaveKeyA
RegRestoreKeyA
RegEnumKeyExA
RegEnumValueA
RegCreateKeyA
AdjustTokenPrivileges
user32
LookupPrivilegeValueA
OpenProcessToken
GetCurrentProcess
FindWindowExA
SendMessageA
PostMessageA
GetFileAttributesA
ExitWindowsEx
GetWindowTextA
GetWindowTextLengthA
MSVBVM60.DLL
MethCallEngine
EVENT_SINK_AddRef
DllFunctionCall
EVENT_SINK_Release
EVENT_SINK_QueryInterface
__vbaExceptHandler
ProcCallEngine
jjjjjjjjjjjjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjjjjjjjjjjjj
dddddddddddddddddddddddddd
dddddddddddddddddddddddddd
__________________________
$%12V44)
zzzzzzzzzzzzzzz
/Z
bcdddddddddef
/Ygggggggggggggg
(YZZ[a
(YYZZZ
deEFGH
12344*z
bbbbbbbbbbbbbbb
UUUUUUUUUUUUUUUC
w@gylz///////
cDefE!gYjjiiijj2mnop
UUCCCDVWX
YZZ[\2^
23456789:
"#$%&'()*+,
bcdefghi
WXYZ[\]^_`a
LMNOPQRSTUV
CDEFGGGHIJK
9:;<=>>?@AB
345678
$%&'()*+,-.
kernel32.dll
LoadLibraryA
GetProcAddress
VirtualAlloc
VirtualFree
iM5AFu(
M*wbax`
z7M0rK
vhuIALC
FVXgGOQwq1Z@T
{@ sJs}
LJ^NK]
J0F]~t
K@ZTLP
a~qJO3V
UbS\vsEB
}>K<y:G)
YLKqO`oF
/.-,+*8
GetModup
$R)"B-
pSy(5+
i(-*_^
\qAbR?
CpJK~@
fdb;u}
@xHVBW
ZLh]5oM
on 8er
%os5/l
USQWVR
Z^_Y[]
!This program cannot be run in DOS mode.
PEC2^O
PECompact2
9^D8Zq8
u2ymaJ.
F15U^$
zX8hUd!
t7#sIx
k>)WeT
@uN]Uf
&,:BeA
4By*8w
#0TH&g
f18&C:
W+Jf*w4p@iI
^Y6=Ql
\A"pV~R
|_pR(T
9k^&q-
vJWCgr/f5
mAYUox,_|
kernel32.dll
LoadLibraryA
GetProcAddress
VirtualAlloc
VirtualFree
iM5AFu(
M*wbax`
z7M0rK
vhuIALC
FVXgGOQwq1Z@T
{@ sJs}
LJ^NK]
J0F]~t
K@ZTLP
a~qJO3V
UbS\vsEB
}>K<y:G)
YLKqO`oF
/.-,+*8
GetModup
$R)"B-
pSy(5+
i(-*_^
\qAbR?
CpJK~@
fdb;u}
@xHVBW
ZLh]5oM
on 8er
%os5/l
USQWVR
Z^_Y[]
@C:\Documents and Settings\DucDun
*\AD:\Lap Trinh\Virus Mau\Pro 3\Pro3.vbp
SeRestorePrivilege
SeBackupPrivilege
Access is denied
System
HideFileExt
Software\Microsoft\Windows\CurrentVersion\Explorer
Logon User Name
Hidden
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CabinetState
FullPath
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoFolderOptions
Software\Microsoft\Windows\CurrentVersion\Explorer\Streams
Settings
Scripting.FileSystemObject
CreateTextFile
temp.zip
Shell.Application
Namespace
CopyHere
backup
System Restore
update
CabinetWClass
ExploreWClass
Happy BirthDay my's Boss
Merry Christmas
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
CompanyName
ProductName
Microsoft Windows
FileVersion
1.00.0057
ProductVersion
1.00.0057
InternalName
musicvn
OriginalFilename
musicvn.exe
(5%&'37
34456:
&*/3333!,
2#((((1111
(5%&'37
34456:
&*/3333!,
2#((((1111
!!#779
,./1224589;/
11289!";
112389;
!!-//0
No antivirus signatures available.
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:Vilsel-CT [Trj]
C4S ClamAV (Linux) Win.Malware.Genpack-6989317-0
Trellix (Linux) Generic VB.z trojan
Sophos Anti-Virus (Linux) Troj/VB-LET
Bitdefender Antivirus (Linux) Trojan.Generic.4385790
G Data Antivirus (Windows) Virus: Trojan.Generic.4385790 (Engine A), Win32.Trojan.Vilsel.A (Engine B)
WithSecure (Linux) Trojan.TR/Crypt.XPACK.Gen
ESET Security (Windows) Win32/VB.OZA trojan
DrWeb Antivirus (Linux) Trojan.Copyself.102
ClamAV (Linux) Win.Malware.Genpack-6989317-0
eScan Antivirus (Linux) Trojan.Generic.4385790(DB)
Kaspersky Standard (Windows) Trojan.Win32.Vilsel.loy
Emsisoft Commandline Scanner (Windows) Trojan.Generic.4385790 (B)
Cuckoo

We're processing your submission... This could take a few seconds.