3961fdc95e467be2412e81a0571ba7a6

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2018-Jan-30 03:57:41
Detected languages English - United States
Comments For additional details, visit PortableApps.com
CompanyName PortableApps.com
FileDescription Notepad++ Portable
FileVersion 7.5.7.0
InternalName Notepad++ Portable
LegalCopyright 2007-2017 PortableApps.com, PortableApps.com Installer 3.5.8.0
LegalTrademarks PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFilename NotepadPlusPlusPortable_7.5.7.paf.exe
PortableApps.comAppID Notepad++Portable
PortableApps.comFormatVersion 3.5.8
PortableApps.comInstallerVersion 3.5.8.0
ProductName Notepad++ Portable
ProductVersion 7.5.7.0

Plugin Output

Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetFileSecurityW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: Rare Ideas.
Issuer: COMODO RSA Code Signing CA.
Suspicious VirusTotal score: 1/68 (Scanned on 2018-07-08 23:50:21) Antiy-AVL: Trojan/Win32.SGeneric

Hashes

MD5 3961fdc95e467be2412e81a0571ba7a6
SHA1 41276377e1acabdfad40117353611bbe8ff18875
SHA256 d7c23910e335729a89452060bf5f604d8c02d73aef3ed857d5268f61db3d2c8b
SHA3 cc61d6552f8d3f3335e4be6ed80b442cb92d03ee195c77fac1377e779c867de5
SSDeep 98304:05oPZ4PbCQKRuDpQkhw5Nbk1lVB5Wf3VXdWeYnywBup/fnxH0:052mThKRuikh69sV/m3VwywM5nxU
Imports Hash f6b8aa5eda0f635aadea6599807a6a47

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2018-Jan-30 03:57:41
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x6600
SizeOfInitializedData 0x22a00
SizeOfUninitializedData 0x800
AddressOfEntryPoint 0x000034A5 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x74000
SizeOfHeaders 0x400
Checksum 0x403422
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c267172bf13868b4198df8a473f100a7
SHA1 b9ef263ab78ea4d3a8c12d2156030ef19021d4d1
SHA256 56fec17bbf1b171ab899996f68d24507ed7f9696b342466df971f076d6e64e92
SHA3 2905b0ce77de81fb571c0fd68aa2dcf5a8dd61a920bfbcdba7364b26ed1d784b
VirtualSize 0x6409
VirtualAddress 0x1000
SizeOfRawData 0x6600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41622

.rdata

MD5 007eff248f0493620a3fd3f7cadc755b
SHA1 053cf2030c8b12be6566099fc7ec7260d79857ac
SHA256 1aaa21332007d8d037501b501b350ffcb92658b40afb8783dc581567672ed710
SHA3 113c8e92330afc6cd7dda1afa3302ff5425e9a76fca3a43e5fd12ee0e413bf9c
VirtualSize 0x138e
VirtualAddress 0x8000
SizeOfRawData 0x1400
PointerToRawData 0x6a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.14383

.data

MD5 8575fc5e872ca789611c386779287649
SHA1 919a09af848861c30a3d498fbd9e4ce73d81554a
SHA256 b70fa3c995d4a1b5857a8aae5777a06fedd497d9cc56c39d85a11f9251eb9e7a
SHA3 7fffa43fed28ae9478d15a213b61dc0bd510e9cfcc9f8ec36898aedb896b3524
VirtualSize 0x20358
VirtualAddress 0xa000
SizeOfRawData 0x600
PointerToRawData 0x7e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.0044

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 c5d2460186f7233c927e7db2dcc703c0e500b653ca82273b7bfad8045d85a470
VirtualSize 0x2c000
VirtualAddress 0x2b000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 92d0ed6e97a8eee550c940c41e1c8945
SHA1 747c2eb0060b915c6cce2ce985e96a4292389467
SHA256 2f579442f8d0e38687378224e18dcf78c905eb464af666215013fa967af1077e
SHA3 2835423e996e81592e0d6b9174e0a4b08ae17ffed532a3ab482c8ca7647f39d1
VirtualSize 0x1c6e0
VirtualAddress 0x57000
SizeOfRawData 0x1c800
PointerToRawData 0x8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.23639

Imports

KERNEL32.dll ExitProcess
SetFileAttributesW
Sleep
GetTickCount
CreateFileW
GetFileSize
GetModuleFileNameW
GetCurrentProcess
SetCurrentDirectoryW
GetFileAttributesW
SetEnvironmentVariableW
GetWindowsDirectoryW
GetTempPathW
GetCommandLineW
GetVersion
SetErrorMode
lstrlenW
lstrcpynW
CopyFileW
GetShortPathNameW
GlobalLock
CreateThread
GetLastError
CreateDirectoryW
CreateProcessW
RemoveDirectoryW
lstrcmpiA
GetTempFileNameW
WriteFile
lstrcpyA
MoveFileExW
lstrcatW
GetSystemDirectoryW
GetProcAddress
GetModuleHandleA
GetExitCodeProcess
WaitForSingleObject
lstrcmpiW
MoveFileW
GetFullPathNameW
SetFileTime
SearchPathW
CompareFileTime
lstrcmpW
CloseHandle
ExpandEnvironmentStringsW
GlobalFree
GlobalUnlock
GetDiskFreeSpaceW
GlobalAlloc
FindFirstFileW
FindNextFileW
DeleteFileW
SetFilePointer
ReadFile
FindClose
lstrlenA
MulDiv
MultiByteToWideChar
WideCharToMultiByte
GetPrivateProfileStringW
WritePrivateProfileStringW
FreeLibrary
LoadLibraryExW
GetModuleHandleW
USER32.dll GetSystemMenu
SetClassLongW
EnableMenuItem
IsWindowEnabled
SetWindowPos
GetSysColor
GetWindowLongW
SetCursor
LoadCursorW
CheckDlgButton
GetMessagePos
LoadBitmapW
CallWindowProcW
IsWindowVisible
CloseClipboard
SetClipboardData
EmptyClipboard
OpenClipboard
ScreenToClient
GetWindowRect
GetDlgItem
GetSystemMetrics
SetDlgItemTextW
GetDlgItemTextW
MessageBoxIndirectW
CharPrevW
CharNextA
wsprintfA
DispatchMessageW
PeekMessageW
ReleaseDC
EnableWindow
InvalidateRect
SendMessageW
DefWindowProcW
BeginPaint
GetClientRect
FillRect
DrawTextW
EndDialog
RegisterClassW
SystemParametersInfoW
CreateWindowExW
GetClassInfoW
DialogBoxParamW
CharNextW
ExitWindowsEx
DestroyWindow
GetDC
SetTimer
SetWindowTextW
LoadImageW
SetForegroundWindow
ShowWindow
IsWindow
SetWindowLongW
FindWindowExW
TrackPopupMenu
AppendMenuW
CreatePopupMenu
EndPaint
CreateDialogParamW
SendMessageTimeoutW
wsprintfW
PostQuitMessage
GDI32.dll SelectObject
SetBkMode
CreateFontIndirectW
SetTextColor
DeleteObject
GetDeviceCaps
CreateBrushIndirect
SetBkColor
SHELL32.dll SHGetSpecialFolderLocation
ShellExecuteExW
SHGetPathFromIDListW
SHBrowseForFolderW
SHGetFileInfoW
SHFileOperationW
ADVAPI32.dll AdjustTokenPrivileges
RegCreateKeyExW
RegOpenKeyExW
SetFileSecurityW
OpenProcessToken
LookupPrivilegeValueW
RegEnumValueW
RegDeleteKeyW
RegDeleteValueW
RegCloseKey
RegSetValueExW
RegQueryValueExW
RegEnumKeyW
COMCTL32.dll ImageList_Create
ImageList_AddMasked
ImageList_Destroy
#17
ole32.dll OleUninitialize
OleInitialize
CoTaskMemFree
CoCreateInstance

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x12524
Entropy 7.98277
Detected Filetype PNG graphic file
MD5 4101e7fe2d262454062666e4e181349a
SHA1 2d11959022789fb890225a7ba4b4eef5b489542d
SHA256 f696534ecddf1e182739c35ef50016755acd89c6ca949aeacac4856ffcdbd54e
SHA3 958868bcb2164b5f3f7ce6c9db9070194d6016f66de381dd70ebaaea8e0b875b

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
Entropy 5.1717
MD5 63737315ca446fd473b355e1970e8009
SHA1 bd2f7db66bbc397c4d7ee69c9a610fa49b107b8c
SHA256 1fc1a3b45127ff0484ac08249c3eceabbf884d0ce0ef8cd80d05705ac0756666
SHA3 a9e9468e3aae9d56b5b62a1fa7ea86ab1a3d7f0c819245ee9602d08e916455a0

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
Entropy 5.50995
MD5 685faa93596feb5c0b799bfa837be039
SHA1 7e877915e4754ef2a0318336c6b701b0db8a9a2a
SHA256 212a1a7d4b5ec6033bdcccce850adec537380656dbe8af65189a01d527361446
SHA3 87eb1ac73b80f26c46df8ebfeda0eea99e35cf5417692213ac4ffa55a1ea24fd

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
Entropy 5.70014
MD5 107ae50f721fca3a6e62b8371d61980c
SHA1 9dfaac4e2869cef0abe24a36edbcc855d6dad0b0
SHA256 b1aa4c4fd6e7892adf1452406f43dfddd90fa5525b7261addde6248663beab63
SHA3 d0886f70fcd513116c174ad7be787183131c7afa94e5eda2dfb0e212b7613d53

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
Entropy 5.6488
MD5 815675708dbbe0433a1376ac2dabe918
SHA1 48ed7e61ea400d5ef9da89609bd8a97bdc7ca797
SHA256 956b11a203a9191e11fb7472a4ffade4f853c80fbc8d7e0f34f6d6df85b724c4
SHA3 914e015eefa3fd696139328f7d71017315eb77a12f339fddfc2db87f98f97f8d

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
Entropy 6.01856
MD5 fdbd3aabee67dde60ca2b8fdfc03a7c6
SHA1 b893a80633e819ae28735dd39f025e726883c778
SHA256 523c147c0e633457f59ae45b8c3e85a674cbcf3cf0da669f6222b3cfec610b92
SHA3 f14ed51cf3bf048187d063d4da574c87b8cc610b8312ee925dc76a5b2cb0da4f

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
Entropy 5.66656
MD5 8aadc46c7cc360971241f917e1796326
SHA1 ea1db188814d5ff48e15908cef869107ed418222
SHA256 985d40950544c9018c46ab08afcb6464c5611ecdebee670a031cc4f9dfdeb993
SHA3 af35feb5593e7b60230f8dc1ad561abf2f8c8e7fadb975dd43605355764cad7b

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
Entropy 5.83657
MD5 20320b265fc9f3ab1751959cdb6db838
SHA1 a7083db2709454eef63fad58cab5d1896b8b37bb
SHA256 4d72060b6d82cb1e2c79117d972cb383cd87b3083b2baadb0c9abb65a03ae0d3
SHA3 b90222197b95b3f8af8ee5a234dc4f7b6f89d1445a808313b6be3bc685ad9092

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
Entropy 2.56193
MD5 db6dd0434da4d7cac564518725167e09
SHA1 a65a1367d7cd96450f089a8f8108239bbcea9f5b
SHA256 c50631fc1f8425a95fd1edcc8e730d339e193a38f18d42372c32847a5ad2c016
SHA3 61a5f863c9b12c78269bb13876ca9436a03828d0cc49cf4104d8c0c2bab2ee6f

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x200
Entropy 2.68372
MD5 583fb02149a19ffff54516cfd5edebd4
SHA1 9de29568e142e36811e4fc5130e60fdb78f3db06
SHA256 9dfacbe444e14cd17c5956afa713f043c2b1150d37868af1661b5bb848fee3f5
SHA3 e4996f23cc9633be3e7a1471406c465642fa04b05058ba4b61d8c529580c4a36

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
Entropy 2.91148
MD5 fa83652660409e90e0db9731ad2adb17
SHA1 0a8f0af67723c87fe26ccf676b8e19ec6357b4dc
SHA256 4a55bd714f5d50cd8eabba10e57f0618f1842717dcfa582d73a917b1933cd1d4
SHA3 8cdc23381c2115dc6057d4989e118528c84a56ff835728cfc712f0f9862e3d9c

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
Entropy 2.89887
MD5 663040d6315b1d6ce8c0334d182ed8fc
SHA1 ebcfff801a12fb8ad1200a4526fca8bd2c3e96cf
SHA256 cb3c86cbcb579244a6f819f9c1807a7e89b6e600982ec6ea0841fcdcb16a9efd
SHA3 4e64fd50994a8aba0536922c0f9d250b8bbecb4a173954f5e9a3e9fe84343f19

203

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
Entropy 2.84487
MD5 12402b54eddc39fa3dae283957b4eb4c
SHA1 beccbeac143c7c78d7271c20c73df7e797c6224b
SHA256 4017b96a65ef43c2d6781adc75b048ed8568f3068b81ee971154b90886766250
SHA3 ee98a44bfebe73cfa91db4a15ae02144e3f2689e710003a4e97d0f25bc3cf9ef

205

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x200
Entropy 2.95867
MD5 c14d7114c1c51ee3c9e2cb001f4ac472
SHA1 3cca25da6150a3b2c19d79c4a3c9666645b859be
SHA256 7f33b718205b0e5780ab19f8725288a7ebd3fbe429aae784db5c816d859fae74
SHA3 a9d17f483eb8000a6daf87d2abaae0be2a93b1960c63f33e489f7d25c7fe646e

206

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
Entropy 3.10966
MD5 1ffe62afd7fe045c34a23ea5c9c7eb22
SHA1 ac211007f1f7a65d868d6e9e658d5ff26dec9c8e
SHA256 184073a317c843cbe92b68cfacebcf5d73dedb538b3f79c048090f3ee5b614ff
SHA3 a9b9bbdd5988ef0360a8789c3c9681158cb2e8e91a17892a98438150078704f3

211

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
Entropy 3.06584
MD5 7ce8a17102daebb8d864cd1063e987d1
SHA1 072345a235d4947d36b53fd47da68e7e6a93fe62
SHA256 0fd40b240b9df8f2dece8947dabbebce898f12becca8e196136e4231efba2dc1
SHA3 1b81ee8b0c45d8d7922620e1359f5eddd48270f6292c4c96f132caf0c5decb97

303

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
Entropy 2.84487
MD5 12402b54eddc39fa3dae283957b4eb4c
SHA1 beccbeac143c7c78d7271c20c73df7e797c6224b
SHA256 4017b96a65ef43c2d6781adc75b048ed8568f3068b81ee971154b90886766250
SHA3 ee98a44bfebe73cfa91db4a15ae02144e3f2689e710003a4e97d0f25bc3cf9ef

305

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x200
Entropy 2.95867
MD5 c14d7114c1c51ee3c9e2cb001f4ac472
SHA1 3cca25da6150a3b2c19d79c4a3c9666645b859be
SHA256 7f33b718205b0e5780ab19f8725288a7ebd3fbe429aae784db5c816d859fae74
SHA3 a9d17f483eb8000a6daf87d2abaae0be2a93b1960c63f33e489f7d25c7fe646e

306

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
Entropy 3.10966
MD5 1ffe62afd7fe045c34a23ea5c9c7eb22
SHA1 ac211007f1f7a65d868d6e9e658d5ff26dec9c8e
SHA256 184073a317c843cbe92b68cfacebcf5d73dedb538b3f79c048090f3ee5b614ff
SHA3 a9b9bbdd5988ef0360a8789c3c9681158cb2e8e91a17892a98438150078704f3

311

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
Entropy 3.06584
MD5 7ce8a17102daebb8d864cd1063e987d1
SHA1 072345a235d4947d36b53fd47da68e7e6a93fe62
SHA256 0fd40b240b9df8f2dece8947dabbebce898f12becca8e196136e4231efba2dc1
SHA3 1b81ee8b0c45d8d7922620e1359f5eddd48270f6292c4c96f132caf0c5decb97

403

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
Entropy 2.84487
MD5 12402b54eddc39fa3dae283957b4eb4c
SHA1 beccbeac143c7c78d7271c20c73df7e797c6224b
SHA256 4017b96a65ef43c2d6781adc75b048ed8568f3068b81ee971154b90886766250
SHA3 ee98a44bfebe73cfa91db4a15ae02144e3f2689e710003a4e97d0f25bc3cf9ef

405

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x200
Entropy 2.95867
MD5 c14d7114c1c51ee3c9e2cb001f4ac472
SHA1 3cca25da6150a3b2c19d79c4a3c9666645b859be
SHA256 7f33b718205b0e5780ab19f8725288a7ebd3fbe429aae784db5c816d859fae74
SHA3 a9d17f483eb8000a6daf87d2abaae0be2a93b1960c63f33e489f7d25c7fe646e

406

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
Entropy 3.10966
MD5 1ffe62afd7fe045c34a23ea5c9c7eb22
SHA1 ac211007f1f7a65d868d6e9e658d5ff26dec9c8e
SHA256 184073a317c843cbe92b68cfacebcf5d73dedb538b3f79c048090f3ee5b614ff
SHA3 a9b9bbdd5988ef0360a8789c3c9681158cb2e8e91a17892a98438150078704f3

411

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
Entropy 3.06584
MD5 7ce8a17102daebb8d864cd1063e987d1
SHA1 072345a235d4947d36b53fd47da68e7e6a93fe62
SHA256 0fd40b240b9df8f2dece8947dabbebce898f12becca8e196136e4231efba2dc1
SHA3 1b81ee8b0c45d8d7922620e1359f5eddd48270f6292c4c96f132caf0c5decb97

503

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x118
Entropy 2.64541
MD5 44c009c9e1abc2355198b432965c61ef
SHA1 4c090f75f279e474a9ca4a07ac84935aa769b0dd
SHA256 85f659842e9aa525dc22d0ff4e18e14d4e4ccfc924d1fdfa03d50a0410e6c0d6
SHA3 ba588a09e931f6a3103a523da10e5ecb1d9962bae0436c6657ecd86a28a294a2

505

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x1f8
Entropy 2.72635
MD5 b413ed1b81e37e4b4eeddab8a7869fc6
SHA1 83139706f97c4c79f972d7324f111da8cad13ea8
SHA256 d951c0aff75a63e17cace239fc171e72c3c2f856809066549f83d973de7547ac
SHA3 6fe1203f998950b48a5f6007b4971dffa53ca14804ff4dbbbe70a12882fe2e6b

506

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf0
Entropy 3.04696
MD5 c7239ce55362dabbe3887e5fc4bdf5fe
SHA1 a2908207ffb889a12da3cbdbe7446e04b254e7ed
SHA256 012557f58e68234d4a88df0b713c59800f798ecce19dfd589d326b458dddcbd8
SHA3 dd33135f7a20e5b84fe1232c18cdc4b31cc539525bf04683903a257fd204e83a

511

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe6
Entropy 3.09674
MD5 30dab3583979c2008e8de9295ab7c36b
SHA1 186cd9560b358bbf8b523d1050573f22bb00264d
SHA256 8c64a2341dc473a7d8ab4956af589e9a7257c4f05a8dc229f862c16d49ba37e5
SHA3 787ad4c44460ff25a75e49d8520ef28e4da79649e07bb7ab0a9678920cbdda61

603

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x10c
Entropy 2.484
MD5 b21b5bb94f7cb7111620ebfb32534430
SHA1 d4fa9452937d98ccb59bdc96660d588a5183bba9
SHA256 eb6f4dac693c6249bb157ef5cfe6057af4088d7bacfce7089e13a85f0661389a
SHA3 a0d867a62de0edcee993f24476270c2fe2949d3ebdb3b16eab1859bc70820ce7

605

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x1ec
Entropy 2.62016
MD5 bc875863f57df58a7b9f8258b1caab04
SHA1 c5c80b03316a7a8e2360b285c51b052e8a0afec2
SHA256 9bba972d38ffe191155e695ba375581976b2c3e1828316b27dff01a2cd1a3096
SHA3 98b2d4227cb3af72a6650731220b262f147aacfc33bf6366fde623bb453fe5a4

606

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe4
Entropy 2.86295
MD5 cc0021533c65b44747600689ff5fbd43
SHA1 b1d1e4594f5ad7b08d56a25cdbe6d9b9378e482b
SHA256 ab1e3ad5b5d87630cb0f6a6671c10fe49d9c33839be0d5daeba89ec053dda92c
SHA3 36d154ec83d8bad82f4198f18fb58fb99d146595713f5a6e439fa9ec20244464

611

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xda
Entropy 2.92694
MD5 408a7443d8f432b28a248059d8669d1c
SHA1 c199828e8051a2825b1d5e216360eb57cd0b37f7
SHA256 4677979c1665998318fcb65b9a0c0b3dd9204c12dbddbd5e76df8822ed6e347a
SHA3 0e2cc75e1216c22216925ed7f5e346c299576a794e65cb664f4266273b79cf25

703

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
Entropy 2.84487
MD5 12402b54eddc39fa3dae283957b4eb4c
SHA1 beccbeac143c7c78d7271c20c73df7e797c6224b
SHA256 4017b96a65ef43c2d6781adc75b048ed8568f3068b81ee971154b90886766250
SHA3 ee98a44bfebe73cfa91db4a15ae02144e3f2689e710003a4e97d0f25bc3cf9ef

705

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x200
Entropy 2.95867
MD5 c14d7114c1c51ee3c9e2cb001f4ac472
SHA1 3cca25da6150a3b2c19d79c4a3c9666645b859be
SHA256 7f33b718205b0e5780ab19f8725288a7ebd3fbe429aae784db5c816d859fae74
SHA3 a9d17f483eb8000a6daf87d2abaae0be2a93b1960c63f33e489f7d25c7fe646e

706

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
Entropy 3.10966
MD5 1ffe62afd7fe045c34a23ea5c9c7eb22
SHA1 ac211007f1f7a65d868d6e9e658d5ff26dec9c8e
SHA256 184073a317c843cbe92b68cfacebcf5d73dedb538b3f79c048090f3ee5b614ff
SHA3 a9b9bbdd5988ef0360a8789c3c9681158cb2e8e91a17892a98438150078704f3

711

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
Entropy 3.06584
MD5 7ce8a17102daebb8d864cd1063e987d1
SHA1 072345a235d4947d36b53fd47da68e7e6a93fe62
SHA256 0fd40b240b9df8f2dece8947dabbebce898f12becca8e196136e4231efba2dc1
SHA3 1b81ee8b0c45d8d7922620e1359f5eddd48270f6292c4c96f132caf0c5decb97

803

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x10c
Entropy 2.47654
MD5 888fbcc92ebd6174786b32d45350005a
SHA1 ba4959d06247a07012fbca926691e2e709c7aa8f
SHA256 b98ac97ffc283bc465d34958c79f8a31480c0f98eb44c5e23977bee9ba52b703
SHA3 51ffc8ceffc7d9ebd6a71011df5813ca67823f1868f6450f923b34eb9bf8ef55

805

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x1ec
Entropy 2.62576
MD5 4429bc1da2cf5ffffaca57dfbeff9eaa
SHA1 65063c7c88ddfd422886554570c73793ea1bf2f9
SHA256 3f0bc1e0fc8d86dee74d2ed2e601ad0dfbd163bd38daeecdb3be5d4dfb00e54b
SHA3 67dd952e9f7c7654e23cc39f51170cd4fd0871ea6bfdff92dab463c50134d77d

806

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe4
Entropy 2.86626
MD5 8c69d2c81dd2d9050d0fa94df90ff16b
SHA1 cd71d904da747d7141e5abdde9363f7e240b26bd
SHA256 1a39a3aabdee2aa68c507c55ff37c38722b05b7f8bde66185a2462792381d8cd
SHA3 67c0826ece79f9796c7effa5aa2fac31548e8fcff18cdf24fc3975a1ed428770

811

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xda
Entropy 2.9304
MD5 2497a44fff8b76b5129662b60a617c85
SHA1 f73bd7c9caa4c1f7a0e4840d69b0accdc6d167a0
SHA256 a10617b39293152a65ad5c91ca4f35135845c7b785e3a582e58f6c8229045b85
SHA3 46c3b856906b45157ae0ccb395c5320fe986bc0110ebb60101400d65ee303d0f

903

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x110
Entropy 2.58011
MD5 088199de88ee4293982cec0b65748394
SHA1 ccce70fc022137c746dfb6bf52cd785b8675768d
SHA256 583b62d87b496612f7e10bf1da5113b8a4c83f0a2155184d03c0b2ec14fb5ed1
SHA3 4ae08f28c8d02ae88588914047346bcf4478166333f36a24f9b6898dcd8fa458

905

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x1f0
Entropy 2.68003
MD5 7a7689f6b4ee698d7998137f6178eae6
SHA1 64e8fd6be5e06b015072b4d94d7dee37a736b8d3
SHA256 af95e3210d7b97a9f8d6c028ad4f3155e20412b8452e12047313aa05e24f53d7
SHA3 96e281555148f20c0266728d7ca3da1b98f22394cd0571bdd7e89cb8a6097f92

906

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe8
Entropy 2.96511
MD5 c33758ab32a791644973dfd60cbf6034
SHA1 ee7eb0a27279d39a959f5d35b6dfd4c18c7123fa
SHA256 6e7bca0054a1785929747807906d8527c2c2a231ca5975d8ebb3a3f98353f129
SHA3 13ec863e01237ced6d350e96f1717e4c686241c1dfa2d10c30a4426e6f1caa69

911

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xde
Entropy 3.03655
MD5 2802ee53bc08ac9a2cfaed81b3d79d05
SHA1 b7faac6a14545ea9c03651f69ae27cce0e62b010
SHA256 65fb71b054977a55435f45bbcddddedaa1e1cf43fdd9fc230938d625c3f7edcd
SHA3 d63c4b5e91606527cedce5dc98f06b1e1e584a271c3353cf85672f2a5a77fce2

103 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x76
Entropy 2.80233
Detected Filetype Icon file
MD5 077bed48717c2f4c117c2938bfbabb0d
SHA1 57ac464d3ce37990dbc0562716ef30cbe94ca561
SHA256 e7f6ce7b7396ec12bb35f1bf818a988d4613ba8dc15a2f658e0861af8c84b4f8
SHA3 0cf2e66c8c21bc6c53259a90e7e72b6d33f6db56e2f39e1ff8735318a5f21c8d

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x59c
Entropy 3.39733
MD5 d722b082ea6dfcecf03f3c1215c3f22d
SHA1 ec3279ce5eebb81f894207db878280ac6afea47a
SHA256 1320fb4cc7891f6e49b52abd1d69df74209e3def6c48c1f2ea12945d648f1882
SHA3 180effec3c75cb0f26665c199bbe4735a9e7d14303a992cb1786afb7eecddebc

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x4e1
Entropy 5.28639
MD5 40083a41909a14bb74e83031a84d1de9
SHA1 4008ad464fa1d3e69c0969d6c340789da73dffb5
SHA256 53e8e75f74a3a45f14624aad04a6b4b09624b0e8adc8487ed62410729138cc70
SHA3 ed8d922fee31ebed81e151c5bf4a1c38deae1b899768869fbd3a54f19e840305

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 7.5.7.0
ProductVersion 7.5.7.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
Comments For additional details, visit PortableApps.com
CompanyName PortableApps.com
FileDescription Notepad++ Portable
FileVersion (#2) 7.5.7.0
InternalName Notepad++ Portable
LegalCopyright 2007-2017 PortableApps.com, PortableApps.com Installer 3.5.8.0
LegalTrademarks PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFilename NotepadPlusPlusPortable_7.5.7.paf.exe
PortableApps.comAppID Notepad++Portable
PortableApps.comFormatVersion 3.5.8
PortableApps.comInstallerVersion 3.5.8.0
ProductName Notepad++ Portable
ProductVersion (#2) 7.5.7.0
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xd26650e9
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 2
Total imports 165
Imports (VS2003 (.NET) build 4035) 15
48 (9044) 10
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[*] Warning: Section .ndata has a size of 0! [*] Warning: Section .ndata has a size of 0!