Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2010-Aug-26 15:22:36 |
Detected languages |
English - United States
|
Debug artifacts |
c:\bld_area\NMR_r1.5_42\bin\bin.iru\NPE.pdb
|
CompanyName | Symantec Corporation |
FileDescription | Norton Power Eraser |
FileVersion | 1.5.0.42 |
InternalName | NMR |
LegalCopyright | Copyright (c) 1997-2010 Symantec Corporation |
OriginalFilename | NPE.exe |
ProductName | Norton Power Eraser |
ProductVersion | 1.5 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig2(h) MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to Blowfish Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE is possibly a dropper. |
Resource 10001 is possibly compressed or encrypted.
Resource 10100 detected as a PE Executable. Resource 10101 detected as a PE Executable. Resource 10200 detected as a PE Executable. Resource 10201 detected as a PE Executable. |
Info | The PE is digitally signed. |
Signer: Symantec Corporation
Issuer: VeriSign Class 3 Code Signing 2004 CA |
Safe | VirusTotal score: 0/65 (Scanned on 2019-02-23 00:17:34) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2010-Aug-26 15:22:36 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x372e00 |
SizeOfInitializedData | 0x1ff400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00311B7A (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x374000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x57b000 |
SizeOfHeaders | 0x400 |
Checksum | 0x57a066 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WINHTTP.dll |
WinHttpSendRequest
WinHttpReceiveResponse WinHttpQueryDataAvailable WinHttpReadData WinHttpCrackUrl WinHttpSetOption WinHttpSetStatusCallback WinHttpGetProxyForUrl WinHttpSetCredentials WinHttpTimeFromSystemTime WinHttpAddRequestHeaders WinHttpOpenRequest WinHttpCloseHandle WinHttpConnect WinHttpQueryHeaders WinHttpOpen |
---|---|
NETAPI32.dll |
NetUseGetInfo
NetApiBufferFree NetShareGetInfo |
PSAPI.DLL |
EnumProcesses
|
WS2_32.dll |
#16
#23 #52 #8 #21 #9 #3 #19 #1 #22 #18 #56 #4 #111 #12 #55 WSAStringToAddressW #115 #116 #57 WSAAddressToStringW #112 #51 #15 #11 |
WINTRUST.dll |
CryptCATAdminCalcHashFromFileHandle
CryptCATAdminReleaseCatalogContext CryptCATAdminEnumCatalogFromHash CryptCATCatalogInfoFromContext CryptCATAdminReleaseContext CryptCATAdminAcquireContext WinVerifyTrust |
CRYPT32.dll |
CryptVerifyMessageSignature
CertFreeCertificateContext CertCompareIntegerBlob CryptMemFree CertNameToStrW CertVerifyValidityNesting CryptMemRealloc CryptMemAlloc CryptDecodeObjectEx CertFindExtension CertGetIntendedKeyUsage CertGetIssuerCertificateFromStore CertCompareCertificate CertDuplicateCertificateContext CertAddCertificateContextToStore CertCreateCertificateContext CertCloseStore CryptMsgOpenToDecode CryptMsgClose CryptMsgUpdate CryptMsgGetParam CryptMsgControl CertOpenStore CertGetNameStringW |
DNSAPI.dll |
DnsFree
DnsQuery_W |
KERNEL32.dll |
InterlockedExchangeAdd
SetUnhandledExceptionFilter ReleaseMutex CreateMutexW OpenMutexW ReleaseSemaphore CreateSemaphoreW MapViewOfFileEx GetSystemTime GetVolumeNameForVolumeMountPointW SetFileAttributesW DeviceIoControl SetFilePointerEx InterlockedCompareExchange CreateWaitableTimerW QueueUserWorkItem GetPrivateProfileSectionW CompareStringA QueryDosDeviceW LoadLibraryA GetSystemDirectoryA GetLogicalDriveStringsW BackupRead BackupWrite CompareFileTime GetVolumeInformationW FindFirstFileExW GetModuleFileNameA FormatMessageA ReadProcessMemory LCMapStringW LCMapStringA CreateMutexA CreateFileMappingA FlushViewOfFile GetThreadLocale GetVersionExA GetCurrencyFormatW SetThreadLocale CreateEventA IsProcessorFeaturePresent GetLocaleInfoA FindResourceA MulDiv TlsSetValue InterlockedExchange GlobalSize GlobalAlloc GlobalLock GlobalUnlock WaitForMultipleObjectsEx WaitForMultipleObjects CreateEventW ResetEvent SetEvent DuplicateHandle HeapReAlloc VirtualAlloc HeapSize VirtualFree GetCurrentThread GetVersionExW GetSystemInfo lstrcpyW SetEndOfFile GetFileSize FlushFileBuffers ReadFile CreateThread ExitThread TerminateThread ResumeThread IsDebuggerPresent Sleep GetShortPathNameW GetLongPathNameW GetCurrentDirectoryW GetCommandLineW OutputDebugStringW WriteFile SetFilePointer TerminateProcess GetSystemTimeAsFileTime GetLocalTime RemoveDirectoryW MoveFileExW FindNextFileW FindFirstFileW FindClose lstrlenA GetSystemDirectoryW GetProcAddress LoadLibraryW GlobalFree DeleteFileW FileTimeToLocalFileTime SystemTimeToFileTime GetLocaleInfoW GetNumberFormatW GetTimeFormatW GetDateFormatW GetDriveTypeW OpenProcess GetCurrentProcessId Process32NextW ProcessIdToSessionId Process32FirstW CreateToolhelp32Snapshot ExpandEnvironmentStringsW GetSystemDefaultLangID HeapFree GetProcessHeap HeapAlloc GetCurrentProcess WTSGetActiveConsoleSessionId GetExitCodeThread FileTimeToSystemTime GetFileTime UnmapViewOfFile MapViewOfFile CreateFileMappingW GetFileSizeEx CreateFileW CompareStringW LocalFree LocalLock FormatMessageW LocalAlloc WaitForSingleObject CloseHandle GetTickCount WideCharToMultiByte LockResource SetErrorMode GetCurrentThreadId CreateDirectoryW DeleteCriticalSection InitializeCriticalSection GetModuleFileNameW GetModuleHandleW FindResourceW LoadResource SizeofResource GetLastError EnterCriticalSection RaiseException LeaveCriticalSection lstrcmpiW lstrlenW FindResourceExW GetFileAttributesW FreeLibrary GetUserDefaultUILanguage GetSystemDefaultUILanguage GetEnvironmentStrings FreeEnvironmentStringsA SetEnvironmentVariableA WriteConsoleW GetConsoleOutputCP WriteConsoleA SetStdHandle TlsGetValue TlsFree TlsAlloc SetLastError AllocConsole FlushInstructionCache HeapDestroy RtlUnwind VirtualProtect VirtualQuery ExitProcess DeleteFileA MoveFileA GetTimeFormatA GetDateFormatA CreateProcessA GetCPInfo GetStringTypeW GetStdHandle HeapCreate GetACP GetOEMCP IsValidCodePage FreeEnvironmentStringsW LoadLibraryExW GetExitCodeProcess CreatePipe GetStringTypeA IsValidLocale EnumSystemLocalesA GetUserDefaultLCID CreateFileA GetFileAttributesA InitializeCriticalSectionAndSpinCount GetModuleHandleA GetConsoleMode GetConsoleCP GetTimeZoneInformation QueryPerformanceCounter GetStartupInfoA GetFileType SetHandleCount GetEnvironmentStringsW MultiByteToWideChar InterlockedDecrement InterlockedIncrement GetTempPathA GetTempFileNameA GetComputerNameA UnhandledExceptionFilter SetWaitableTimer GetStartupInfoW |
USER32.dll |
IsWindow
wsprintfW GetDesktopWindow GetSystemMenu GetMenuItemCount EnableMenuItem CharNextW PostMessageW SendMessageW DestroyWindow GetCursorPos TrackPopupMenu LoadIconW DestroyIcon RegisterWindowMessageW CopyRect IsClipboardFormatAvailable OpenClipboard GetClipboardData CloseClipboard DrawIconEx GetGuiResources SetWindowLongW GetWindowLongW DefWindowProcW CallWindowProcW SystemParametersInfoW SetWindowPos ShowWindow EnableWindow GetFocus SetFocus SetClipboardData EmptyClipboard KillTimer RedrawWindow RegisterClassExW GetClassInfoExW LoadCursorW CreateWindowExW CallNextHookEx SetWindowsHookExW UnhookWindowsHookEx GetActiveWindow GetDialogBaseUnits CreateDialogIndirectParamW DialogBoxIndirectParamW AdjustWindowRectEx GetClientRect GetParent GetWindowRect GetMonitorInfoW MonitorFromWindow GetWindow SetTimer SetWindowTextW FlashWindow CountClipboardFormats GetWindowThreadProcessId EndDialog GetMenuState PostMessageA MessageBoxA LoadCursorA RegisterClassExA RegisterClassA UnregisterClassA RegisterClassW UnregisterClassW RegisterWindowMessageA ReleaseDC BeginPaint EndPaint FillRect SendMessageA SetCapture GetCapture ReleaseCapture ClientToScreen GetWindowLongA GetDlgCtrlID UpdateWindow GetSysColor GetAsyncKeyState GetKeyState GetWindowDC InflateRect OffsetRect GetClassLongA DefWindowProcA GetScrollInfo GetDoubleClickTime ScreenToClient WindowFromPoint InvalidateRect MoveWindow GetWindowPlacement IsWindowEnabled SetWindowsHookExA GetUpdateRect DrawTextA PeekMessageA CreateCursor SetCursor LoadCursorFromFileA NotifyWinEvent IsWindowVisible GetWindowTextW SetWindowLongA IsChild CreateWindowExA SetActiveWindow GetDC SystemParametersInfoA SetScrollInfo BeginDeferWindowPos DeferWindowPos EndDeferWindowPos ScrollDC ValidateRect ScrollWindowEx SetForegroundWindow GetKeyboardLayout CreateCaret DestroyCaret SetCaretPos SendMessageTimeoutA RegisterClipboardFormatW EnumClipboardFormats LoadStringW MapWindowPoints GetSystemMetrics PostQuitMessage ExitWindowsEx CharPrevW DispatchMessageW MessageBeep DrawFrameControl GetSysColorBrush DrawEdge DrawTextW InvertRect GetIconInfo CreateIconFromResourceEx GetCaretBlinkTime AnimateWindow MsgWaitForMultipleObjectsEx PeekMessageW GetMessageW TranslateMessage DispatchMessageA IsWindowUnicode GetMessageA |
ADVAPI32.dll |
MakeAbsoluteSD
ControlTraceW RegOpenKeyExW RegQueryValueExW RegCloseKey GetTraceLoggerHandle GetTraceEnableLevel IsTextUnicode GetTraceEnableFlags RegisterTraceGuidsW UnregisterTraceGuids RegDeleteKeyW RegQueryInfoKeyW RegEnumKeyExW RegSetValueExW RegCreateKeyExW RegDeleteValueW ImpersonateLoggedOnUser OpenProcessToken GetUserNameA RevertToSelf GetTokenInformation LookupAccountSidW ConvertSidToStringSidW GetLengthSid SetTokenInformation DuplicateTokenEx CreateProcessAsUserW ConvertStringSidToSidW InitializeSecurityDescriptor CreateWellKnownSid SetEntriesInAclW SetSecurityDescriptorOwner SetSecurityDescriptorGroup SetSecurityDescriptorDacl FreeSid AllocateAndInitializeSid SetNamedSecurityInfoW OpenThreadToken RegEnumValueW LookupPrivilegeValueW AdjustTokenPrivileges StartServiceW CloseServiceHandle OpenServiceW OpenSCManagerW DuplicateToken CopySid IsValidSid GetSidSubAuthority InitializeSid GetSidLengthRequired CheckTokenMembership CreateServiceW ReadEncryptedFileRaw CloseEncryptedFileRaw OpenEncryptedFileRawW WriteEncryptedFileRaw CryptReleaseContext CryptAcquireContextW GetSecurityDescriptorControl GetSecurityDescriptorSacl GetSecurityDescriptorDacl GetSecurityDescriptorGroup GetSecurityDescriptorOwner MakeSelfRelativeSD GetSecurityDescriptorLength ConvertStringSecurityDescriptorToSecurityDescriptorW InitializeAcl AddAce GetAclInformation GetAce TraceMessage |
SHELL32.dll |
ShellExecuteW
SHParseDisplayName SHOpenFolderAndSelectItems SHBrowseForFolderW SHGetPathFromIDListW SHGetSpecialFolderPathA ShellExecuteExW SHGetSpecialFolderPathW SHGetFolderPathA SHGetFileInfoW DragQueryFileW ShellExecuteExA SHGetFolderPathW #680 |
ole32.dll |
OleRun
StgCreateStorageEx StgOpenStorageEx PropVariantClear PropVariantCopy CoCreateGuid StringFromGUID2 OleSaveToStream GetHGlobalFromStream CreateStreamOnHGlobal ReleaseStgMedium RevokeDragDrop RegisterDragDrop OleInitialize OleLoadFromStream CoUninitialize CoInitializeEx CoInitializeSecurity CoCreateInstance CoTaskMemRealloc CoTaskMemAlloc CoTaskMemFree |
OLEAUT32.dll |
#20
#19 #77 #15 #21 #148 #22 #40 #411 #23 #16 #150 #149 #11 #8 #9 #2 #184 #185 #6 #277 #200 #27 #4 #24 |
SHLWAPI.dll |
PathSkipRootW
PathFindExtensionW UrlCanonicalizeW PathRemoveFileSpecW PathRemoveBackslashW PathIsUNCServerW PathAppendW SHDeleteEmptyKeyW SHDeleteKeyW PathIsUNCW PathIsFileSpecW PathAddBackslashW |
WININET.dll |
HttpOpenRequestA
InternetErrorDlg HttpSendRequestA InternetOpenA InternetQueryOptionA InternetOpenW InternetSetOptionA InternetGetLastResponseInfoA InternetConnectA HttpQueryInfoA InternetCombineUrlA InternetCloseHandle HttpOpenRequestW HttpAddRequestHeadersW HttpSendRequestW InternetReadFile InternetConnectW |
OLEACC.dll |
AccessibleObjectFromWindow
LresultFromObject |
IMM32.dll |
ImmAssociateContextEx
ImmGetCompositionStringW ImmNotifyIME ImmGetContext ImmAssociateContext ImmReleaseContext ImmIsIME ImmSetCandidateWindow |
WINMM.dll |
timeGetTime
timeKillEvent PlaySoundA timeSetEvent timeGetDevCaps |
WTSAPI32.dll |
WTSQueryUserToken
|
USERENV.dll |
GetAllUsersProfileDirectoryW
UnloadUserProfile |
IPHLPAPI.DLL |
GetAdaptersInfo
|
VERSION.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoW |
RPCRT4.dll |
UuidCreateSequential
|
GDI32.dll |
GetObjectA
SetBkColor SetTextColor CreateSolidBrush SetWindowOrgEx GetViewportExtEx GetWindowExtEx GetMapMode LPtoDP BitBlt DeleteDC SelectObject RestoreDC SetLayout CreateCompatibleDC EndDoc IntersectClipRect StartDocA GetDeviceCaps StartPage EndPage SetTextAlign GetTextAlign TextOutA TextOutW GetPixel RoundRect RectVisible CreatePen CreatePatternBrush GetTextExtentExPointW Rectangle SetBkMode CreateBitmap SetPixel SetBrushOrgEx CreateHatchBrush GetTextExtentPoint32A PatBlt GetTextExtentPoint32W GetWindowOrgEx DPtoLP SetWindowExtEx SetViewportExtEx SetStretchBltMode StretchDIBits GetDIBits StretchBlt CreateDIBSection CreateDIBPatternBrushPt EnumFontFamiliesExW AddFontMemResourceEx EnumFontFamiliesExA CreateFontA SetMapMode SetViewportOrgEx GetStockObject DeleteObject GetTextMetricsA GetGlyphOutlineW GetKerningPairsA CreateCompatibleBitmap CreateRectRgnIndirect CombineRgn ExcludeClipRect GetClipBox SaveDC GetCurrentObject |
COMDLG32.dll |
GetOpenFileNameW
GetSaveFileNameW PrintDlgA |
COMCTL32.dll |
ImageList_DrawEx
ImageList_GetImageInfo ImageList_GetIconSize |
urlmon.dll |
FindMimeFromData
|
Unknown |
Norton Power Eraser |
Checking for New Version |
Checking for updates... |
Gathering load points: |
Examining load points: |
Processing data... |
Evaluating file: |
Removing item: |
Submitting item: |
Processing scan results... |
Restoring item: |
Error Aborting... |
Saving Remediation Event... |
Deleting History Item... |
Warning, Reputation Info Not Available... |
Optical drives cannot be scanned. |
Invalid directory specified |
Folder Path cannot exceed 220 characters. Please choose another folder. |
Aggressive mode should only be used after all other options to clean up your system have been tried. Are you sure you want to scan in Aggressive mode? |
Norton Power Eraser |
Your computer is still infected. If you wait to restart, the threats may not be removed. Are you sure you want to restart later? |
EN |
Process |
Service |
File |
Registry Key |
Registry Value |
Unspecified |
Driver |
Service |
Process |
LSP |
Network Plugin |
Shortcut |
Autorun File |
Startup Item |
BHO |
Browser Toolbar |
Browser Plugin |
Shell Extension |
Explorer Plugin |
DNS Entry |
Network Settings |
File |
System Settings |
Directory |
www.norton.com/smr2011 |
http://security.symantec.com/pfb/pFeedback_form.asp?go=pfb&products=NMR&versions=1.5.0.x&oslocale=ENU# |
<h1 >FILE INSIGHT</h1> |
<ul titlearea> |
<li> |
<div> |
<img type="icon" filename="%s" /> |
<h3 id="filename" fileorpath>%s</h3> |
<span><a id="appcard_locatefile" href="#">Locate this file</a></span> |
</div> |
</li> |
</ul> |
<div overflowHandler> |
<ul blinds> |
<li FileDetails> |
<div class="caption"> |
<div class="captionHeader"> |
<h3 id="appcardreputationdetails">Reputation Details</h3> |
</div> |
</div> |
<div class="details" tabindex=-1> |
<div general> |
<label>Signature: </label> |
<div id="signature" fileorpath>%s</div> |
<label>Installed:</label> |
<div id="installed" >%s</div> |
<div>Startup Item: <span id="startup"></span></div> |
</div> |
<ul id="trustlevel" what> |
<li> |
<h3 id="prevalence" ></h3> |
<label prevalencelabel>%s</label> |
</li> |
<li> |
<h3 id="age" ></h3> |
<label agelabel>%s</label> |
</li> |
<li> |
<h3 id="trust"></h3> |
<label></label><br/> |
</li> |
</ul> |
</div> |
</li> |
<li SideEffects> |
<div class="caption"> |
<div class="captionHeader"> |
<h3 id="appcardthreatdetails">Threat Details</h3> |
</div> |
<p fileorpath> |
</p> |
</div> |
<div id="appcardurl" class="details" tabindex=-1> |
<div url fileorpath> |
<ul url="">%s</ul> |
<p></p> |
</div> |
</div> |
</li> |
</ul> |
</div> |
Number of users in the Norton Community that have used this file: <em>Unknown</em> |
<em>Fewer than 10 users</em> in the Norton Community have used this file. |
<em>Fewer than 100 users</em> in the Norton Community have used this file. |
<em>Hundreds of users</em> in the Norton Community have used this file. |
<em>Thousands of users</em> in the Norton Community have used this file. |
<em>Tens of thousands</em> of users in the Norton Community have used this file. |
<em>Hundreds of thousands</em> of users in the Norton Community have used this file. |
<em>Millions of users</em> in the Norton Community have used this file. |
This file release is currently <em>not known.</em> |
This file was released <em>less than 1 week ago.</em> |
This file was released <em>more than 7 days ago.</em> |
This file was released <em>more than 31 days ago.</em> |
Warning: |
Error: |
Selected directory may contain critical files. <br>Are you sure that you would like to proceed? |
YES |
NO |
Log file for this session does not exist |
Log can not be viewed |
Specified log location is not valid |
http://security.symantec.com/nbrt/?ssdcat=221&lcid=1033&origin=unk&env=production&tooltype=NMR |
If you delete the log history you will not be able to undo any previous fix sessions. Are you sure you want to delete the log history? |
This program supports Windows XP, Windows Vista, and Windows 7. You are attempting to run this program on an unsupported operating system. |
The Fix or Undo you ran is incomplete. Please restart your computer to complete the process. |
You must be logged in as an administrator to run Norton Power Eraser. |
System Restore point cannot be created. |
System Restore point cannot be created because the Windows System Restore Service is stopped. Use the Administrative Tools in your Control Panel to start System Restore Service and try again. |
The definitions needed for the scan are corrupt. Restart the scan to download new definitions. |
The definitions needed for the scan could not be downloaded. Please try again later. |
Norton Power Eraser has experienced an engine failure. Please download a new copy. |
Cannot undo this session. |
Cannot undo this session. |
The definitions needed for the scan could not be downloaded. Please try again later. |
The scan cannot run because Norton Power Eraser cannot access the Symantec server. Check your network connection or try again later. |
Unspecified error |
Cannot undo this session. The original location of these files no longer exists. |
Select the folder you want to scan, and then click Ok. |
Select the folder you want to save your logs to, and then click Ok. |
risks removed |
View |
This file may not be malicious. We recommend removal only if a Remote Scan determines that the file is bad. |
Are you sure you want to continue? |
%s at %s |
Not Available |
All files have already been sent for Remote Scan |
Files will be sent to Symantec Servers for analysis. Are you sure you want to remote scan this item? |
All files will be sent to Symantec Servers for analysis. Are you sure you want to remote scan all the items? |
<thead><tr><th class="tablerisk">teststring</th><th class="tabletype"></th><th class="tablemode"></th><th class="tabledeepscan"><a id="deepscanallfileslink" href="#" >Scan all files</a><div><span text></span><widget type="info" align=6><menu class="popup"><p></p></menu></widget></div></th> <th><button id="itemcheckbox_normal_checkall" type="checkbox" %hs > </button><span class="tablefix">Q</span><widget type="info" align="6" ><menu class="popup" ><p>text</p></menu></widget></th></tr></thead><tbody id="tablebody"></tbody> |
http://liveupdate.symantec.com/upgrade/NMR/English/NMR.txt |
This file may not be malicious. |
Are you sure you want to remove this item? |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.5.0.42 |
ProductVersion | 1.5.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Symantec Corporation |
FileDescription | Norton Power Eraser |
FileVersion (#2) | 1.5.0.42 |
InternalName | NMR |
LegalCopyright | Copyright (c) 1997-2010 Symantec Corporation |
OriginalFilename | NPE.exe |
ProductName | Norton Power Eraser |
ProductVersion (#2) | 1.5 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Aug-26 15:22:36 |
Version | 0.0 |
SizeofData | 68 |
AddressOfRawData | 0x3e0240 |
PointerToRawData | 0x3df440 |
Referenced File | c:\bld_area\NMR_r1.5_42\bin\bin.iru\NPE.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x81f990 |
SEHandlerTable | 0x7e2f80 |
SEHandlerCount | 2794 |
XOR Key | 0xdd0540b5 |
---|---|
Unmarked objects | 0 |
150 (20413) | 5 |
ASM objects (VS2008 SP1 build 30729) | 71 |
C++ objects (VS2008 build 21022) | 5 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 8 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 57 |
Total imports | 750 |
C objects (VS2008 SP1 build 30729) | 310 |
C objects (VS2003 (.NET) build 3077) | 21 |
ASM objects (VS2012 build 50727 / VS2005 build 50727) | 55 |
Unmarked objects (#2) | 230 |
C++ objects (VS2008 SP1 build 30729) | 347 |
138 (VS2008 SP1 build 30729) | 344 |
Linker (VS2008 build 21022) | 1 |
151 | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |