File Name | BulletsPassView.exe |
File Type |
PE32+ executable (GUI) x86-64, for MS Windows
|
Scanner Version | 1.0.221.174 |
Database Version | 2025-07-24 10:00:31 UTC |
Malware family: Gen
Hash Type | Value | Action |
---|---|---|
MD5 |
7f31636f9b74ab93a268f5a473066053
|
|
SHA1 |
22544df33b80b9da3f91946cacb706805a5a992d
|
|
SHA256 |
e71cda5e7c018f18aefcdfbce171cfeee7b8d556e5036d8b8f0864efc5f2156b
|
|
SHA512 |
d979ade4d1c427a43e60b58cd4292994b59f9da0e10366bbf0a7e05ec55e55ca06a7b835d551de41d3067029e2c94f4227152e066d84a65726ba48406b49752b
|
|
ImpHash |
569268acae49b073e0ccf59bb9d69615
|
Icon |
Hash: ed7b8f319493d429121fe167aa85b9f8
Fuzzy: 6fd4461de724a0a4b31ffb15b323a41c dHash: 21d6f8d0f0f0c401 |
Image Base | 0x140000000 |
Entry Point | 0x14000f6b0 |
Compilation Time | 2015-03-01 14:02:26 |
Checksum | 0x00021d24 (Actual: 0x00021d24) |
OS Version | 4.0 |
PEiD Signatures |
PE32+ executable (GUI) x86-64, for MS Windows
|
PDB Path | c:\Projects\VS2005\BulletsPassView\x64\Release\BulletsPassView.pdb |
Digital Signature | OK |
Imports |
10 libraries
msvcrt, COMCTL32, VERSION, KERNEL32, USER32, GDI32, comdlg32, SHELL32, ole32, OLEAUT32 |
Exports | 0 functions |
Resources | 21 Resources |
Sections | 5 Sections |
CompanyName | NirSoft |
FileDescription | BulletsPassView |
FileVersion | 1.32 |
InternalName | BulletsPassView |
LegalCopyright | Copyright © 2010 - 2015 Nir Sofer |
OriginalFilename | BulletsPassView.exe |
ProductName | BulletsPassView |
ProductVersion | 1.32 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
60,115 bytes | 60,416 bytes | 6.11 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
28E80448BB33962FA10943EE64015440 |
.rdata |
0x00010000 |
15,898 bytes | 16,384 bytes | 4.64 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
E11EAC02B6C17CBE8E330ACFA6BCA5AA |
.data |
0x00014000 |
6,384 bytes | 1,024 bytes | 2.94 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D6006D12B88A4152B49DDE0F4384F8AA |
.pdata |
0x00016000 |
2,592 bytes | 3,072 bytes | 4.30 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
178286FB0FF796D9832390159A70D456 |
.rsrc |
0x00017000 |
10,232 bytes | 10,240 bytes | 4.13 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0F5D457F2EB154C3CC788589A8804446 |
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_CURSOR | 1 | 308 bytes | |
RT_BITMAP | 3 | 1,432 bytes | |
RT_ICON | 2 | 1,040 bytes | |
RT_MENU | 3 | 2,298 bytes | |
RT_DIALOG | 4 | 1,896 bytes | |
RT_STRING | 3 | 694 bytes | |
RT_ACCELERATOR | 1 | 96 bytes | |
RT_GROUP_CURSOR | 1 | 20 bytes | |
RT_GROUP_ICON | 1 | 34 bytes | |
RT_VERSION | 1 | 744 bytes | |
RT_MANIFEST | 1 | 364 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Virtool.Win64.Gen.vb without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system