Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2012-Apr-01 15:42:02 |
Detected languages |
English - United States
|
CompanyName | Microsoft Corporation |
FileDescription | Notepad |
FileVersion | 5.00.2140.1 |
InternalName | Notepad |
LegalCopyright | Copyright (C) Microsoft Corp. 1981-1999 |
OriginalFilename | NOTEPAD.EXE |
ProductName | Microsoft(R) Windows (R) 2000 Operating System |
ProductVersion | 5.00.2140.1 |
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Suspicious | The PE is possibly packed. |
Unusual section name found: .g7
Unusual section name found: .g6 Unusual section name found: .g5 Unusual section name found: .g4 Unusual section name found: .g3 Unusual section name found: .g2 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. | 2 bytes of data starting at offset 0x25227. |
Info | The PE is digitally signed. |
Signer: UBLZtyA7ZCIkZc8
Issuer: UBLZtyA7ZCIkZc8 |
Malicious | VirusTotal score: 59/70 (Scanned on 2019-11-19 18:54:37) |
DrWeb:
Trojan.PWS.Multi.471
MicroWorld-eScan: Gen:Variant.Razy.164359 FireEye: Generic.mg.000cbb278e4f0194 CAT-QuickHeal: TrojanPWS.Zbot.Gen McAfee: PWS-Zbot.gen.beu Zillya: Trojan.Kryptik.Win32.926876 K7AntiVirus: Spyware ( 003919791 ) Alibaba: Packed:Win32/Krap.5a25a3ec K7GW: Spyware ( 003919791 ) CrowdStrike: win/malicious_confidence_100% (W) TrendMicro: TROJ_FAKEAV.SMFW BitDefenderTheta: Gen:NN.ZexaF.32251.jO1@a0FBIddi F-Prot: W32/Zbot.DQ.gen!Eldorado Symantec: Packed.Generic.406 ESET-NOD32: a variant of Win32/Kryptik.ADLV TrendMicro-HouseCall: TROJ_FAKEAV.SMFW TotalDefense: Win32/Fareit.A!generic Avast: Win32:Karagany Kaspersky: Packed.Win32.Krap.iu BitDefender: Gen:Variant.Razy.164359 NANO-Antivirus: Trojan.Win32.Multi.uyhgc Paloalto: generic.ml AegisLab: Hacktool.Win32.Krap.lKMc Endgame: malicious (high confidence) Sophos: Troj/Zbot-DHN Comodo: TrojWare.Win32.Kryptik.ADKA@4nqnb0 F-Secure: Trojan.TR/Spy.Zbot.dpttnma Baidu: Win32.Adware.Kryptik.b VIPRE: Trojan.Win32.Reveton.ca (v) Invincea: heuristic McAfee-GW-Edition: PWS-Zbot.gen.beu Fortinet: W32/ZBOT.HL!tr Trapmine: malicious.high.ml.score Emsisoft: Gen:Variant.Razy.164359 (B) Ikarus: Trojan.Win32.Yakes Cyren: W32/Zbot.DQ.gen!Eldorado Jiangmin: Trojan/Generic.zblu Webroot: W32.Infostealer.Zeus Avira: TR/Spy.Zbot.dpttnma MAX: malware (ai score=100) Antiy-AVL: Trojan[Packed]/Win32.Krap Arcabit: Trojan.Razy.D28207 ZoneAlarm: Packed.Win32.Krap.iu Microsoft: PWS:Win32/Fareit AhnLab-V3: Dropper/Win32.Injector.R23007 Acronis: suspicious VBA32: BScope.Malware-Cryptor.SB.01798 ALYac: Gen:Variant.Razy.164359 Ad-Aware: Gen:Variant.Razy.164359 Cylance: Unsafe APEX: Malicious Rising: Spyware.Zbot!8.16B (TFE:1:O1uYTXJ9E5O) Yandex: TrojanSpy.ZBot.Gen!Pac.29 SentinelOne: DFI - Malicious PE GData: Gen:Variant.Razy.164359 AVG: Win32:Karagany Cybereason: malicious.78e4f0 Panda: Trj/Genetic.gen Qihoo-360: Win32/Trojan.cfa |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 10 |
TimeDateStamp | 2012-Apr-01 15:42:02 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x18600 |
SizeOfInitializedData | 0xc600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001400 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1a000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x2c000 |
SizeOfHeaders | 0x400 |
Checksum | 0x2b01f |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
VirtualAlloc
CreateFileA GetWindowsDirectoryA LoadLibraryA GetProcAddress lstrcatA SetStdHandle CommConfigDialogA LeaveCriticalSection _lopen GetAtomNameW CompareFileTime ReadConsoleA GetCurrentThread FindResourceExA lstrcmpA GlobalAddAtomW GlobalFix DisconnectNamedPipe CancelDeviceWakeupRequest FreeConsole GlobalFree OpenEventA IsBadHugeReadPtr SetConsoleCP FindAtomW ScrollConsoleScreenBufferA LocalUnlock SetFileApisToOEM FoldStringA GetCommConfig SystemTimeToTzSpecificLocalTime FindVolumeMountPointClose GetThreadPriorityBoost RtlFillMemory GetConsoleAliasExesA EnumSystemCodePagesW CancelIo FindFirstVolumeMountPointW DeleteFileA DosDateTimeToFileTime EnumCalendarInfoA RtlMoveMemory FindResourceW GetCurrentDirectoryW FindNextVolumeMountPointW CreateSemaphoreA FindFirstFileExA SetVolumeMountPointA AllocConsole ReadConsoleOutputW GetCalendarInfoA GetWindowsDirectoryW ResetWriteWatch LoadLibraryExA ReadConsoleInputA Thread32First ReadConsoleOutputA GetPrivateProfileSectionNamesW GetThreadContext SetProcessAffinityMask GetDiskFreeSpaceExW CreateWaitableTimerW GetVolumePathNameA QueueUserAPC WriteConsoleInputW GetDiskFreeSpaceW PrepareTape SetConsoleCtrlHandler GetFileSizeEx lstrcpyn GetLocaleInfoW GetDateFormatW SuspendThread GetPrivateProfileStringW SetThreadIdealProcessor GetBinaryType InterlockedExchangeAdd GetShortPathNameA GetConsoleAliasExesW FindFirstVolumeA AddAtomA MultiByteToWideChar GetCalendarInfoW Beep WriteConsoleOutputW _llseek ReplaceFileW _hwrite EnumSystemLanguageGroupsW GetTapePosition WriteProfileStringW GetPriorityClass GetStartupInfoW EnumTimeFormatsA MoveFileWithProgressW GetComputerNameW LocalFileTimeToFileTime AddAtomW WaitNamedPipeW SetTapePosition GetNamedPipeHandleStateA SetComputerNameExA ReadProcessMemory FormatMessageW EraseTape ExpandEnvironmentStringsW GetCompressedFileSizeW GlobalDeleteAtom BackupRead lstrcpy BackupWrite GetLogicalDriveStringsA GetSystemWindowsDirectoryW GetCurrentConsoleFont BuildCommDCBW SetCalendarInfoA SetProcessShutdownParameters GetTimeFormatA WriteProcessMemory VerifyVersionInfoA SwitchToFiber FreeEnvironmentStringsW CopyFileExW SetDefaultCommConfigW EnumSystemLocalesW GetProfileStringA lstrcpynA WriteFileEx LockResource GetComputerNameExW RemoveDirectoryW CreateHardLinkA SetEvent HeapAlloc GetLocalTime FillConsoleOutputCharacterW GetVersionExA CreateFileW SetWaitableTimer MapUserPhysicalPagesScatter GetFileAttributesW CreateFileMappingA GetPrivateProfileStructW HeapDestroy DeleteTimerQueue GetSystemWindowsDirectoryA FindFirstVolumeMountPointA ProcessIdToSessionId SetThreadPriority GetThreadPriority FindNextFileA IsProcessorFeaturePresent IsBadReadPtr GlobalFindAtomA GetFileTime GetSystemDefaultLCID SetEndOfFile IsBadStringPtrA VerLanguageNameW EnumDateFormatsW QueryInformationJobObject MapViewOfFile GetSystemPowerStatus GetPrivateProfileStringA SetCommTimeouts DefineDosDeviceW DisableThreadLibraryCalls GetSystemInfo GetLongPathNameW GetModuleHandleA FillConsoleOutputCharacterA GetVolumeNameForVolumeMountPointW SetFileApisToANSI FlushInstructionCache GetSystemTime WaitForDebugEvent |
---|---|
USER32.dll |
BeginPaint
GetClientRect EndPaint PostQuitMessage DefWindowProcA LoadIconA LoadCursorA CreateWindowExA RegisterClassExA LoadAcceleratorsA GetScrollRange DragDetect GetWindowModuleFileNameW DestroyIcon DefFrameProcW EnumThreadWindows DdeDisconnect GetMenuItemCount GetMessageA EnumPropsW ClipCursor DdeEnableCallback SetWindowTextW SetScrollRange AttachThreadInput DispatchMessageA GetOpenClipboardWindow TrackMouseEvent SwapMouseButton InsertMenuW DrawTextExW DlgDirListW GetDialogBaseUnits IsDlgButtonChecked SetSystemCursor CharUpperA SetCursor TranslateAcceleratorA SendMessageCallbackW EnableMenuItem CloseClipboard DdeFreeDataHandle SetParent GetKeyNameTextW PostThreadMessageA TileChildWindows RedrawWindow MessageBeep DrawAnimatedRects GetClassInfoA DrawCaption EnumDisplayMonitors EnumDisplayDevicesW EndDeferWindowPos LoadCursorFromFileA GetUpdateRect DdeConnect MapVirtualKeyW GetKeyNameTextA ValidateRect RemovePropW DdeQueryStringW DrawStateA SetWindowPlacement SendNotifyMessageW LockSetForegroundWindow CharUpperW GetKeyboardType GetUserObjectSecurity GetDlgItem CopyImage GetDlgItemInt WindowFromPoint CharToOemW GetDoubleClickTime OemToCharW WINNLSGetEnableStatus DdePostAdvise GetNextDlgGroupItem RegisterHotKey GetDlgCtrlID IsCharLowerW GetGUIThreadInfo CascadeChildWindows GetMenu SetUserObjectInformationA GetNextDlgTabItem OemKeyScan DdeNameService CopyIcon CharPrevA IsDialogMessageW GetAltTabInfoW PaintDesktop DialogBoxIndirectParamA BlockInput LoadBitmapW IsWindowUnicode IMPGetIMEA IsMenu EnumClipboardFormats EnumPropsExW GetForegroundWindow OpenDesktopA SystemParametersInfoW GetWindowPlacement GetWindowContextHelpId EndDialog SetMenuItemInfoA ChangeDisplaySettingsA BroadcastSystemMessage GetLastActivePopup VkKeyScanExW IsCharUpperW BringWindowToTop DrawIconEx GetActiveWindow DdeImpersonateClient InternalGetWindowText SendMessageTimeoutW UserHandleGrantAccess CopyRect SetClipboardViewer GetWindowTextLengthW UpdateLayeredWindow CallWindowProcA GetKeyboardLayoutNameW CharLowerA GetGuiResources RegisterDeviceNotificationW IsWindowEnabled AppendMenuW PeekMessageW SetLayeredWindowAttributes SetPropW IsCharAlphaNumericW SystemParametersInfoA UnhookWinEvent SetMenu CreatePopupMenu ShowScrollBar GetDlgItemTextA HiliteMenuItem GetMenuItemInfoW SwitchDesktop mouse_event IsWindowVisible SetMenuInfo RegisterWindowMessageA ToUnicode DefFrameProcA SetThreadDesktop GetMouseMovePointsEx DestroyAcceleratorTable PostThreadMessageW EnumWindows GetInputDesktop DlgDirListComboBoxW wvsprintfA SetTimer LookupIconIdFromDirectory MapVirtualKeyA DestroyCaret IsHungAppWindow CreateDialogIndirectParamA GetWindowWord SendInput UnregisterClassA GetCaretBlinkTime DlgDirSelectComboBoxExA |
GDI32.dll |
CreateEnhMetaFileA
Rectangle MoveToEx LineTo CloseEnhMetaFile PlayEnhMetaFile DeleteEnhMetaFile GetStockObject |
msvcrt.dll |
memcpy
|
COMDLG32.dll |
ReplaceTextA
ChooseColorW GetFileTitleW PageSetupDlgA CommDlgExtendedError PrintDlgExA PageSetupDlgW ChooseColorA GetFileTitleA ChooseFontW GetSaveFileNameW GetOpenFileNameA GetSaveFileNameA ChooseFontA FindTextA ReplaceTextW FindTextW PrintDlgW GetOpenFileNameW PrintDlgExW PrintDlgA |
ADVAPI32.dll |
RegOpenKeyExW
|
ole32.dll |
STGMEDIUM_UserMarshal
CoGetInterfaceAndReleaseStream CreateItemMoniker OleLoad OleCreateDefaultHandler SetDocumentBitStg OleBuildVersion OleConvertIStorageToOLESTREAMEx OleConvertIStorageToOLESTREAM CoDeactivateObject GetConvertStg RevokeDragDrop CoRegisterChannelHook CoQueryProxyBlanket GetClassFile CoGetObjectContext DllDebugObjectRPCHook OleLoadFromStream IsEqualGUID HICON_UserFree OleSetMenuDescriptor WdtpInterfacePointer_UserFree OleCreateMenuDescriptor CoGetInstanceFromIStorage HPALETTE_UserUnmarshal SNB_UserFree CoDosDateTimeToFileTime CoGetCallerTID CoDisconnectObject OleGetAutoConvert OleCreateStaticFromData CoTreatAsClass CoRegisterMallocSpy StgCreateDocfileOnILockBytes CoTestCancel CoTaskMemRealloc OleTranslateAccelerator CoInitializeWOW PropVariantClear OleQueryLinkFromData CreateClassMoniker CoGetObject PropStgNameToFmtId OleUninitialize CoIsHandlerConnected HBRUSH_UserUnmarshal CoFreeUnusedLibraries CLIPFORMAT_UserSize OleNoteObjectVisible OleDoAutoConvert CoMarshalHresult ReadStringStream CreateDataCache GetHGlobalFromStream HMETAFILE_UserUnmarshal HPALETTE_UserMarshal OleCreateLinkFromData CoCancelCall OleRegGetMiscStatus StringFromIID CoGetPSClsid HBITMAP_UserUnmarshal DllGetClassObjectWOW StgConvertVariantToProperty HACCEL_UserUnmarshal WriteOleStg OleRun CoEnableCallCancellation UtConvertDvtd32toDvtd16 CoRegisterSurrogateEx CoAddRefServerProcess CoReleaseMarshalData CoCreateGuid HDC_UserFree WriteClassStg WdtpInterfacePointer_UserMarshal HBRUSH_UserFree CoSuspendClassObjects HACCEL_UserSize CoCopyProxy OleDestroyMenuDescriptor CoFreeAllLibraries CoRegisterPSClsid CLIPFORMAT_UserMarshal OleRegEnumFormatEtc CoCreateInstanceEx CoGetStandardMarshal CoFileTimeToDosDateTime OleCreateFromData CLSIDFromProgID StringFromCLSID StgOpenPropStg HMENU_UserUnmarshal CoQueryReleaseObject OleCreate GetRunningObjectTable CoFileTimeNow CoReleaseServerProcess WriteClassStm CoSwitchCallContext SNB_UserUnmarshal CoGetCurrentProcess CoInstall StgConvertPropertyToVariant HMETAFILE_UserMarshal OleCreateLinkFromDataEx CoLoadLibrary OleGetClipboard CoGetMalloc HGLOBAL_UserMarshal HBITMAP_UserFree OleInitialize CreateBindCtx CoInitialize HWND_UserSize CoRegisterMessageFilter CreateObjrefMoniker OpenOrCreateStream StgCreateStorageEx CLIPFORMAT_UserFree HPALETTE_UserFree HDC_UserSize PropVariantCopy OleIsRunning HMETAFILE_UserSize CoInitializeEx GetHookInterface ReadOleStg OleGetIconOfClass HGLOBAL_UserUnmarshal CoGetApartmentID CreatePointerMoniker StgOpenStorageOnILockBytes MonikerRelativePathTo UtGetDvtd16Info HBITMAP_UserMarshal CoGetCallContext |
OLEAUT32.dll |
#259
#43 #226 #117 #196 #100 #244 #71 #18 #198 #47 #291 #213 #293 #281 #222 #30 #155 #128 #133 #163 #42 #208 #237 #131 #48 #283 #172 #285 #221 #81 #307 #304 #136 #211 #51 #108 #230 #23 #94 #159 #422 #306 #224 #288 #284 #219 #57 #402 #61 #210 #13 #26 #315 #200 #134 #215 #290 #31 #318 #187 #147 #280 #188 #8 #278 #87 #171 #246 #254 #308 #45 #99 #6 #10 #267 #240 #277 #58 #9 #35 #109 #270 #303 #33 #174 #272 #413 #297 #412 #143 #241 #298 #92 #264 #218 #127 #190 #424 #299 #286 #235 #313 #103 #106 #273 #205 #414 #83 #85 #239 #120 #330 #193 #66 #140 #135 #93 #253 #74 #247 #250 #88 #238 #266 #332 #331 #217 #36 #138 #114 #421 #123 #53 #276 #258 #310 #223 #234 #199 #256 #169 #212 #292 #173 #411 #137 #5 #91 #101 #251 #260 |
COMCTL32.dll |
#16
ImageList_GetIconSize GetMUILanguage FlatSB_GetScrollProp _TrackMouseEvent ImageList_Draw ImageList_Remove DestroyPropertySheetPage FlatSB_GetScrollPos ImageList_SetDragCursorImage FlatSB_SetScrollRange FlatSB_ShowScrollBar CreateToolbarEx #6 #2 ImageList_Duplicate ImageList_SetBkColor ImageList_Read FlatSB_GetScrollInfo ImageList_Replace #5 ImageList_SetOverlayImage CreatePropertySheetPageA FlatSB_SetScrollProp ImageList_Copy CreatePropertySheetPageW UninitializeFlatSB ImageList_DrawEx ImageList_GetDragImage CreateStatusWindowW DrawStatusTextW #7 ImageList_GetBkColor FlatSB_SetScrollPos ImageList_DrawIndirect FlatSB_EnableScrollBar ImageList_SetImageCount PropertySheetA ImageList_DragMove #3 InitializeFlatSB ImageList_DragLeave CreateStatusWindow ImageList_AddIcon ImageList_LoadImageA #15 ImageList_Merge ImageList_DragShowNolock ImageList_EndDrag PropertySheet #14 ImageList_DragEnter CreatePropertySheetPage FlatSB_SetScrollInfo ImageList_LoadImageW ImageList_GetImageRect InitMUILanguage PropertySheetW #4 ImageList_ReplaceIcon #13 ImageList_AddMasked ImageList_Write ImageList_SetFilter ImageList_SetIconSize ImageList_BeginDrag InitCommonControlsEx ImageList_Create ImageList_GetIcon ImageList_GetImageInfo |
Cannot open the %% file. |
Make sure a disk is in the drive you specified. |
Cannot find the %% file. |
Do you want to create a new file\? |
The %% file already exists. |
Do you want to overwrite it\? |
The text in the %% file has changed. |
Do you want to save the changes\? |
Untitled |
- Notepad |
Cannot find "%%" |
Not enough memory available to complete this operation. Quit one or more applications to increase available memory, and then try again. |
The %% file is too large for Notepad. |
Use another editor to edit the file. |
Notepad |
Failed to Initialize File Dialogs. Change the Filename and try again. |
Failed to Initialize Print Dialogs. Make sure that your printer is connected properly and use Control Panel to verify that the printer is configured properly. |
Cannot print the %% file. Be sure that your printer is connected properly and use Control Panel to verify that the printer is configured properly. |
Not a valid file name. |
Cannot create the %% file. |
Make sure that the path and filename are correct. |
Cannot carry out the Word Wrap command because there is too much text in the file. |
%% |
\*.txt |
notepad.hlp |
The Margin values are not correct. Either they are not numeric characters or they don\'t fit the dimensions of the page. Try either entering a number or decreasing the margins. |
&f |
Page &p |
fFpPtTdDcCrRlL |
Cannot open the %% file. |
Cannot print the file because it can\'t be found or is currently being used by another application. Be sure that the path and filename are correct, or wait until the application is finished, and then try again |
Text Documents (*.txt) |
All Files |
Open |
Save As |
You cannot quit Windows because the Save As dialog |
box in Notepad is open. Switch to Notepad, close this |
dialog box, and then try quitting Windows again. |
Cannot access your printer. |
Be sure that your printer is connected properly and use Control Panel to verify that the printer is configured properly. |
%% |
You do not have permission to open this file. See the owner of the file or an administrator to obtain permission. |
%% |
This file contains characters in Unicode format which will be lost if you save this file as a text document. To keep the Unicode information, select the Unicode encoding in the Save As dialog box. Continue\? |
Page too small to print one line. |
Try printing using smaller font. |
Common Dialog error (0x%04x) |
Notepad - Goto Line |
Line number out of range |
ANSI |
Unicode |
Unicode big endian |
UTF-8 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 5.0.2140.1 |
ProductVersion | 5.0.2140.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Notepad |
FileVersion (#2) | 5.00.2140.1 |
InternalName | Notepad |
LegalCopyright | Copyright (C) Microsoft Corp. 1981-1999 |
OriginalFilename | NOTEPAD.EXE |
ProductName | Microsoft(R) Windows (R) 2000 Operating System |
ProductVersion (#2) | 5.00.2140.1 |
Resource LangID | English - United States |
---|