933b53a44e49709193a3304d45c70176

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2008-Apr-13 18:35:51
Detected languages English - United States
Debug artifacts notepad.pdb
CompanyName Microsoft Corporation
FileDescription Notepad
FileVersion 5.1.2600.5512 (xpsp.080413-2105)
InternalName Notepad
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename NOTEPAD.EXE
ProductName Microsoft® Windows® Operating System
ProductVersion 5.1.2600.5512

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious The PE is possibly packed. Section .text is both writable and executable.
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegQueryValueExW
  • RegCloseKey
  • RegCreateKeyW
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegSetValueExW
Malicious VirusTotal score: 13/70 (Scanned on 2019-12-12 07:23:38) CMC: Trojan.Win32.Diple!O
Sangfor: Malware
CrowdStrike: win/malicious_confidence_90% (W)
Cyren: W32/Patched.AZ.gen!Eldorado
Symantec: ML.Attribute.HighConfidence
APEX: Malicious
Invincea: heuristic
Trapmine: malicious.high.ml.score
FireEye: Generic.mg.933b53a44e497091
Ikarus: Virus.Win32.Heur
F-Prot: W32/Patched.AZ.gen!Eldorado
Acronis: suspicious
Cybereason: malicious.7d03c4

Hashes

MD5 933b53a44e49709193a3304d45c70176
SHA1 e9325927d03c4b8e262b36d045272be42ad72e3e
SHA256 33d9fa4332ff3211e305d61b20765ab4f784e67b1d8600aa6cff54bca5566820
SHA3 d44c4bef8393b9fb4ccbcd6313019b5cf5e2ec1f1e5d955f7631060d1c8cd079
SSDeep 1536:bPwOnbNQKLjWDyy1o5I0foMJUEbooPRrKKReFX3:b9NQKPWDyDI0fFJltZrpReFX3
Imports Hash 6fe25ed74b214298e440bdb980709c44

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2008-Apr-13 18:35:51
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 7.1
SizeOfCode 0x7800
SizeOfInitializedData 0xa600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000739D (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x9000
ImageBase 0x1000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 5.1
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x14000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x40000
SizeofStackCommit 0x11000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 debcf7299d2aac29b3bca84abd1d18dd
SHA1 0da899fd9ae0f1d59392265994e2294bd3b5df37
SHA256 c94df9d6d20e0d2df90da16ed1495bfc681a8e4f5bfc7988ab0fc1ebb3c03b98
SHA3 10b1a7631ef1ca263e7dad3a700dc91849ff12d9d1237e2e3676781d4588d677
VirtualSize 0x7748
VirtualAddress 0x1000
SizeOfRawData 0x7800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.27751

.data

MD5 3fd82fcc3cf0c0692e0e466248ee3fbf
SHA1 73304225b866a642e29cc3b5c57e3c0161e35680
SHA256 87cbb581163f3aabe62312722180512fe26f49215afb0b1e06933bc1ce9a20b2
SHA3 14e451dc4d287b24c2a5a65154c07643f267aef06f1ea81f4fac9e70d40a7cc9
VirtualSize 0x1ba8
VirtualAddress 0x9000
SizeOfRawData 0x800
PointerToRawData 0x7c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.14857

.rsrc

MD5 950dd279a78aefe8be9ae8b129dd928e
SHA1 bc492bbb0a486c1cbca88422a55b130ce4ba2181
SHA256 016fbb0630579443d6df8981515afabdd2edd448c0924065d76aa3618d0a1858
SHA3 3207bd2e681a7fb2d084ab5a59178b0b21deab9ba436dd457e324771f50667ef
VirtualSize 0x8948
VirtualAddress 0xb000
SizeOfRawData 0x8a00
PointerToRawData 0x8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.40888

Imports

comdlg32.dll PageSetupDlgW
FindTextW
PrintDlgExW
ChooseFontW
GetFileTitleW
GetOpenFileNameW
ReplaceTextW
CommDlgExtendedError
GetSaveFileNameW
SHELL32.dll DragFinish
DragQueryFileW
DragAcceptFiles
ShellAboutW
WINSPOOL.DRV GetPrinterDriverW
ClosePrinter
OpenPrinterW
COMCTL32.dll CreateStatusWindowW
msvcrt.dll _XcptFilter
_exit
_c_exit
time
localtime
_cexit
iswctype
_except_handler3
_wtol
wcsncmp
_snwprintf
exit
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
wcsncpy
ADVAPI32.dll RegQueryValueExW
RegCloseKey
RegCreateKeyW
IsTextUnicode
RegQueryValueExA
RegOpenKeyExA
RegSetValueExW
KERNEL32.dll GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetLocalTime
GetUserDefaultLCID
GetDateFormatW
GetTimeFormatW
GlobalLock
GlobalUnlock
GetFileInformationByHandle
CreateFileMappingW
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
LoadLibraryA
GetModuleHandleA
GetStartupInfoA
GlobalFree
GetLocaleInfoW
LocalFree
LocalAlloc
lstrlenW
LocalUnlock
CompareStringW
LocalLock
FoldStringW
CloseHandle
lstrcpyW
ReadFile
CreateFileW
lstrcmpiW
GetCurrentProcessId
GetProcAddress
GetCommandLineW
lstrcatW
FindClose
FindFirstFileW
GetFileAttributesW
lstrcmpW
MulDiv
lstrcpynW
LocalSize
GetLastError
WriteFile
SetLastError
WideCharToMultiByte
LocalReAlloc
FormatMessageW
GetUserDefaultUILanguage
SetEndOfFile
DeleteFileW
GetACP
UnmapViewOfFile
MultiByteToWideChar
MapViewOfFile
UnhandledExceptionFilter
GDI32.dll EndPage
AbortDoc
EndDoc
DeleteDC
StartPage
GetTextExtentPoint32W
CreateDCW
SetAbortProc
GetTextFaceW
TextOutW
StartDocW
EnumFontsW
GetStockObject
GetObjectW
GetDeviceCaps
CreateFontIndirectW
DeleteObject
GetTextMetricsW
SetBkMode
LPtoDP
SetWindowExtEx
SetViewportExtEx
SetMapMode
SelectObject
USER32.dll GetClientRect
SetCursor
ReleaseDC
GetDC
DialogBoxParamW
SetActiveWindow
GetKeyboardLayout
DefWindowProcW
DestroyWindow
MessageBeep
ShowWindow
GetForegroundWindow
IsIconic
GetWindowPlacement
CharUpperW
LoadStringW
LoadAcceleratorsW
GetSystemMenu
RegisterClassExW
LoadImageW
LoadCursorW
SetWindowPlacement
CreateWindowExW
GetDesktopWindow
GetFocus
LoadIconW
SetWindowTextW
PostQuitMessage
RegisterWindowMessageW
UpdateWindow
SetScrollPos
CharLowerW
PeekMessageW
EnableWindow
DrawTextExW
CreateDialogParamW
GetWindowTextW
GetSystemMetrics
MoveWindow
InvalidateRect
WinHelpW
GetDlgCtrlID
ChildWindowFromPoint
ScreenToClient
GetCursorPos
SendDlgItemMessageW
SendMessageW
CharNextW
CheckMenuItem
CloseClipboard
IsClipboardFormatAvailable
OpenClipboard
GetMenuState
EnableMenuItem
GetSubMenu
GetMenu
MessageBoxW
SetWindowLongW
GetWindowLongW
GetDlgItem
SetFocus
SetDlgItemTextW
wsprintfW
GetDlgItemTextW
EndDialog
GetParent
UnhookWinEvent
DispatchMessageW
TranslateMessage
TranslateAcceleratorW
IsDialogMessageW
PostMessageW
GetMessageW
SetWinEventHook

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.52715
MD5 e88b5bfeb06f7815ef84920fc87b5792
SHA1 fcd8b7fd2f462333888a5305c8307c0c53022a89
SHA256 0924c3158065aa6efa74c7b32d70b2638f937a6f48d636953b6be0f441f0a3ef
SHA3 69096bd995da80c931a0a2595d4ef3477c76e30c6bb3cf0a0ae1590da90fa665

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.80159
MD5 b7ad807c28c59fe218bd7974a01c3e79
SHA1 3926aa5e67e20715b7890f0b8c6ab4e038afa8bc
SHA256 4b541efde7773192a061a1f1904e93a94cb86a02306a9ebb2b9ed37c2d658d11
SHA3 fda881b9b97c7677f6ec9d751aa2691927b6a4888f3a834fdc8c7b46c2b8bcc4

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.71967
MD5 6f25021efef65e3bdd83fc1bd2615864
SHA1 233edfbe5f6619ce3d3b40eefd4936c0c93e2e75
SHA256 0c37181983d83509d18d0934d606a8bdcf30ca3edd647ddcaf50ebddf9ad0e88
SHA3 6d70857004ebe9d0dd53fc74b8de6d3bca13e773963a8c8ee2c619f2b168b55e

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.72769
MD5 18c27563276e9cc50d132e91c2539870
SHA1 9f74f35e3dd05c6874b15684c85144d273a9755f
SHA256 6e3022dd86cb7f7ee57b28299c408cf75299aa716501cacaa75d8c690bf34006
SHA3 f554245a89d6f22911fb45ad62412a469075ce7584a64cfdea7ac80dc0cb1b0d

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.559
MD5 4cd04d76788cc9f338983cfc79e57bb5
SHA1 43efd05c2079cddd83762c706927ddf3a1d7f0ca
SHA256 ce975c94e304113b8e507a9841e8706ad2eaf17637b2ee7139522c35af278067
SHA3 f8229b0a6749be04403ada14ecd61b29975f63be945bf83cefe84beddf67d5fb

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.1602
MD5 9640063dd931253265dbc1e19be360e1
SHA1 de7d1a6062f245d187be9c5e903294ee88a81c22
SHA256 302989d0a33a08a2aab155e6cb3ec012bef9d6d00e94871de29ed8d4bb62ab05
SHA3 bd9e78ca52e46a72f8aec2717323c7476a2a5167de97d900a07ab5352e6f5dcd

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.16689
MD5 f1eb7c939c4100647d4018863bca80fc
SHA1 15768e85be3d863af6c56118463e80f9ed6d3c03
SHA256 539241168aea0932be7176e84ae24c967aa039fd6538d6e58dd7322aeb631476
SHA3 2f26b6877d3e6ee61fa139f6b59467415a2dc4a24aac7cc02a2afca75f902268

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.52728
MD5 3f8fa1d9633b7dd242b1f96ab859694f
SHA1 38156e56f96a63db5962ded60bd7d9b36a245936
SHA256 5f1cc9ffc67b508318cee92b2bf0a0b9b32fe383eb10ce05b0c0b43d746bea00
SHA3 6be6d3e8b65233681ff2bef187b1396b26faa15c11c995e539a9995f71c248de

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33377
MD5 1503bddd982672ba3bf4cbf4537af543
SHA1 b0f36c8dbbe81ef106e8ed91979466488274ee91
SHA256 7e7c7f709e62d8827d00a33e1fc3e274cdfa41b32c38b7a83390ccc3aded8fc7
SHA3 c92e638dccbc72cb2ae450a94b4de66e54dc659f1dc8012b5b06b518990d114b

1 (#2)

Type RT_MENU
Language English - United States
Codepage UNKNOWN
Size 0x342
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21934
MD5 2c7beb0ffe84063c1f0a760658b98961
SHA1 30f2f06b0d7626bdc2da23bc36fa9da2cea56397
SHA256 84ecd556138f8b30bd5fe9b7887fddf1d344a70e72031915e0b7823ae9b1ba87
SHA3 2c0b85f02cfcfc19fe4bd034202f795e5a87f75a597c01d98db51f0473f9248d

NPENCODINGDIALOG

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x7e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.99139
MD5 328364a55c2d01b826345c96bb58f4e0
SHA1 e6d0ef5aa46a056ee48aa329f6f3d897fdce96d0
SHA256 adf24a8045c4426776c5e06e0cc9ecb7c296a270aeb039d3a98f85e6b959fd97
SHA3 7a85925f5f33dfef3d98c311763a6b97c8a10ae68c6f8af7292763dd4fcdafc1

11

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xd6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04151
MD5 b1a95d2e952c8606cb9e15702cbc3b03
SHA1 072e876ee5b478777b15bb99cb8829dc4a2b946c
SHA256 bd335009b35f9c83d76e11eae7e92e2e8fbb157746c904fc7cf8438994f36d7f
SHA3 22717fe1bcf7672f70333d68b95ea2d9802504d1f37696f06ab0408d5c8b46a4

12

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x43e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46026
MD5 6c85b82126244f7771d22812df0ca83d
SHA1 c4f32d75795e2696730f820558918b245617d9c7
SHA256 8f1ce0c64f333104a5b80b606a5c54df4de26bccca4bef5d98938266daf5c336
SHA3 de7ede490872843880de9737ac3a9eba0d26ea601d2312c11fabb619da272541

14

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xde
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20226
MD5 ce5e40d98d28af2697fa057b684ba9c3
SHA1 0b610053fee51207b80634c627aca2116b869473
SHA256 e1814585a2269a12791438cd2610acb989bcd873999859d7d90c0dadd2914960
SHA3 840fc4e01087ac1b52bb4ba255779205abcd954db1063d1d8ab9e207f21acb3d

1 (#3)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x7fe
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22864
MD5 224d06fdd47d02bd63fa8ff7ca002b6f
SHA1 9bdc2fb999b64d3933866ef11d848fd9b47a9887
SHA256 112d2059c46836baedd1b95a48b3447b2174a983bcdee50a37a3626424a691c8
SHA3 b76befbf62a1e808a5b195ef1df6cf4131f8f415170614e3991d89c05d6a3058

2 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x704
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32759
MD5 f4f7c2544af7fa49952de896c67d45e0
SHA1 91461ee58ffa3d65a2cc6a0ba89c8020e0c494ad
SHA256 b17902ff379b97841b6916869f4676cb7c872dd379f6055244b254dee5f4418d
SHA3 4ccf340179ad26921295bbbbb283dc7fcc35bc65dced35bd6cdf3fa1ae2d6af3

3 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47185
MD5 c0e5eaa1c5f4b9d441bac061a4d2ed24
SHA1 dd4381157551202b2d98a32e383dde73e743e4e7
SHA256 37e320205493f5177b3b248fc7d9f772a70351899f7a67e3bed62519125fcb89
SHA3 e5333f1f358205d92daca77beb30fabd13650064b9185d3da8068b1b78250503

30

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x3a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.64738
MD5 f4731947668105f6afdb7458cf259b65
SHA1 78db1c02fe72b43de2450a32d5d9359c1a1f9f32
SHA256 8d246ee6dce873aabc79fd524ec7f46cf2512dbd7f17ebb43cd9acc1d2c34f61
SHA3 160056220a51a9703b70b9fcae5aad7b5bf8badf99dddf83eb076c4c5d87d0cd

MAINACC

Type RT_ACCELERATOR
Language English - United States
Codepage UNKNOWN
Size 0x88
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76645
MD5 74245f277c5a26e130a6bb24b573f157
SHA1 cacb132119774253ef8b6df78e7cb693dced67ad
SHA256 751524eb55938f044ce30c1165264dfc98ed5abb23e66de8c83b04c2f173a82d
SHA3 53f5f2cdebab799f5df5af491c38150b00819f96f62d4245f21a6b3855ef128b

SLIPUPACC

Type RT_ACCELERATOR
Language English - United States
Codepage UNKNOWN
Size 0xa8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76164
MD5 283fb5931b0ae47385a1be47f4f7d477
SHA1 4d27a1290cb5b7f8bb842f7ae3a93123cbdd68aa
SHA256 de73777705d07552f21e35a47f0bc0d6f89443a947a1883e51725ddd9db304c3
SHA3 d5e8b6c681b98ea72bcb9723113c597dd4507fed93d3724ee454b34e6ab55ff4

2 (#3)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.89097
Detected Filetype Icon file
MD5 a6469ac97a109b7c2bc1bf3020168af3
SHA1 53f3b4b4b61af9cde9de74a33fbc492c71f7660c
SHA256 ca82878ac6f8f5d26249f03257b496eebf06e2d20e02349a0b871bf92766535c
SHA3 15f2850e54173ca36462fa901e1019404484e4da82f3668cb938a5e593f2ed53

1 (#4)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x360
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.58154
MD5 a9c75e7308146f21d4671474005c466b
SHA1 f0dadc39f8441f53eb5d2b0ab66c44edd1c42a21
SHA256 6a149076191c6b24fbec5f4cd21fd95d04ea4361408c53c75c7cff9251dcdb55
SHA3 2423052b134c0b2d7e5de5daf644f6eef73bffbfd8df91ed286e99d21e13dcfd

1 (#5)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x29e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.87297
MD5 69b2da99d1ad0010a9de7ecf37178c5a
SHA1 19851037ea6058696f700ee0361e587148607cc0
SHA256 5c1f3a8e510335856575234287bd63786c53d0ea277098d3b792d9e84748815b
SHA3 67c64371d1c3ee415c1cda404084292c7e28e7f78c2e99ffb61311e70dc2e334

String Table contents

Cannot open the %% file.
Make sure a disk is in the drive you specified.
Cannot find the %% file.
Do you want to create a new file?
The text in the %% file has changed.
Do you want to save the changes?
Untitled
- Notepad
Cannot find "%%"
Not enough memory available to complete this operation. Quit one or more applications to increase available memory, and then try again.
The %% file is too large for Notepad.
Use another editor to edit the file.
Notepad
Failed to Initialize File Dialogs. Change the Filename and try again.
Failed to Initialize Print Dialogs. Make sure that your printer is connected properly and use Control Panel to verify that the printer is configured properly.
Cannot print the %% file. Be sure that your printer is connected properly and use Control Panel to verify that the printer is configured properly.
Not a valid file name.
Cannot create the %% file.
Make sure that the path and filename are correct.
Cannot carry out the Word Wrap command because there is too much text in the file.
%%
notepad.hlp
&f
Page &p
Text Documents (*.txt)
All Files
Open
Save As
You cannot quit Windows because the Save As dialog
box in Notepad is open. Switch to Notepad, close this
dialog box, and then try quitting Windows again.
Cannot access your printer.
Be sure that your printer is connected properly and use Control Panel to verify that the printer is configured properly.
%%
You do not have permission to open this file. See the owner of the file or an administrator to obtain permission.
%%
This file contains characters in Unicode format which will be lost if you save this file as an ANSI encoded text file. To keep the Unicode information, click Cancel below and then select one of the Unicode options from the Encoding drop down list. Continue?
Page too small to print one line.
Try printing using smaller font.
Common Dialog error (0x%04x)
Notepad - Goto Line
Line number out of range
ANSI
Unicode
Unicode big endian
UTF-8
Page %d
Ln %d, Col %d
Compressed,
Encrypted,
Hidden,
Offline,
ReadOnly,
System,
File
fFpPtTdDcCrRlL
Text Document

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 5.1.2600.5512
ProductVersion 5.1.2600.5512
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Notepad
FileVersion (#2) 5.1.2600.5512 (xpsp.080413-2105)
InternalName Notepad
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename NOTEPAD.EXE
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 5.1.2600.5512
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2008-Apr-13 18:35:51
Version 0.0
SizeofData 36
AddressOfRawData 0x18f0
PointerToRawData 0xcf0
Referenced File notepad.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1009604
SEHandlerTable 0x1001920
SEHandlerCount 1

RICH Header

XOR Key 0xf235e4a8
Unmarked objects 0
ASM objects (VS2003 (.NET) build 4035) 1
C++ objects (VS2003 (.NET) build 4035) 1
Imports (VS2003 (.NET) build 4035) 19
Total imports 203
94 (VS2003 (.NET) build 4035) 1
C objects (VS2003 (.NET) build 4035) 23
Linker (VS2003 (.NET) build 4035) 1

Errors