ceeb38b4b5df96a08fcd66031b4962cd

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2009-Sep-16 10:53:23
Detected languages English - United States
Debug artifacts notepad.pdb
CompanyName Microsoft Corporation
FileDescription Notepad
FileVersion 5.1.2600.5877 (xpsp_sp3_qfe.090916-1338)
InternalName Notepad
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename NOTEPAD.EXE
ProductName Microsoft® Windows® Operating System
ProductVersion 5.1.2600.5877

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegQueryValueExW
  • RegCloseKey
  • RegCreateKeyW
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegSetValueExW
Suspicious VirusTotal score: 2/68 (Scanned on 2021-06-20 05:01:51) Paloalto: generic.ml
Webroot: W32.Sality.Gen

Hashes

MD5 ceeb38b4b5df96a08fcd66031b4962cd
SHA1 ec3dc6369719adee93231d5aceed6b794af9a34f
SHA256 df3086477c84084fd749e3b6536c0c970b4f6a9a3de798314dedafbb1d527160
SHA3 f042d1d39c5a800bb8631d6d999762227c27ccd540e0611ed6818679116799f5
SSDeep 384:uFUt5wa1QSDyF1d8Gnx8xCpJwS9prvn+lfDc9VrSWzYWaw3:eA5wnYe5xldTL+Fg3V3
Imports Hash 6fe25ed74b214298e440bdb980709c44

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2009-Sep-16 10:53:23
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 7.1
SizeOfCode 0x7800
SizeOfInitializedData 0xa600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000739D (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x9000
ImageBase 0x1000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 5.1
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x14000
SizeOfHeaders 0x400
Checksum 0x13033
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x40000
SizeofStackCommit 0x11000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 faeec120252b1a5c671f344e4cfdc45a
SHA1 1117cc97d507dabc27e5d3d78338091cb73794f0
SHA256 d0a892d6a42874c56cfc582f03f7b10bb9519f8f7086e8f0b80f38df6ad97503
SHA3 187b0fd7a52a953e766d7e2f8a994c8c11f1f5aecb30b69946a2392906ed708c
VirtualSize 0x7748
VirtualAddress 0x1000
SizeOfRawData 0x7800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 3.454

.data

MD5 59b11093edc57f2e8289b98e6335baaf
SHA1 3b3e51a7850f01b096e164ba641680857a294aac
SHA256 194bd1c4227dd3dcc2e45922a40e681fc905f24266620bb377e05a3d7f563a3d
SHA3 6266fd5e67e0857ef96eba8b815654e8d6d21b4ef0ce0b952663e95a52440d94
VirtualSize 0x1ba8
VirtualAddress 0x9000
SizeOfRawData 0x800
PointerToRawData 0x7c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.15248

.rsrc

MD5 8da6a0b4a41cb796b77f149a93a43676
SHA1 53973f42537c058d4122616d39bd8edeb00cbce1
SHA256 f08a484d1a0b11ee71316a8e238e3ce628f165cc7d7e7af13e2fda2516aead2f
SHA3 cb1272fc6a522cf951304ad5e921bc6dbfcc11e32036c233e84459b9c7937500
VirtualSize 0x8958
VirtualAddress 0xb000
SizeOfRawData 0x8a00
PointerToRawData 0x8400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.56934

Imports

comdlg32.dll PageSetupDlgW
FindTextW
PrintDlgExW
ChooseFontW
GetFileTitleW
GetOpenFileNameW
ReplaceTextW
CommDlgExtendedError
GetSaveFileNameW
SHELL32.dll DragFinish
DragQueryFileW
DragAcceptFiles
ShellAboutW
WINSPOOL.DRV GetPrinterDriverW
ClosePrinter
OpenPrinterW
COMCTL32.dll CreateStatusWindowW
msvcrt.dll _XcptFilter
_exit
_c_exit
time
localtime
_cexit
iswctype
_except_handler3
_wtol
wcsncmp
_snwprintf
exit
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
wcsncpy
ADVAPI32.dll RegQueryValueExW
RegCloseKey
RegCreateKeyW
IsTextUnicode
RegQueryValueExA
RegOpenKeyExA
RegSetValueExW
KERNEL32.dll GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetLocalTime
GetUserDefaultLCID
GetDateFormatW
GetTimeFormatW
GlobalLock
GlobalUnlock
GetFileInformationByHandle
CreateFileMappingW
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
LoadLibraryA
GetModuleHandleA
GetStartupInfoA
GlobalFree
GetLocaleInfoW
LocalFree
LocalAlloc
lstrlenW
LocalUnlock
CompareStringW
LocalLock
FoldStringW
CloseHandle
lstrcpyW
ReadFile
CreateFileW
lstrcmpiW
GetCurrentProcessId
GetProcAddress
GetCommandLineW
lstrcatW
FindClose
FindFirstFileW
GetFileAttributesW
lstrcmpW
MulDiv
lstrcpynW
LocalSize
GetLastError
WriteFile
SetLastError
WideCharToMultiByte
LocalReAlloc
FormatMessageW
GetUserDefaultUILanguage
SetEndOfFile
DeleteFileW
GetACP
UnmapViewOfFile
MultiByteToWideChar
MapViewOfFile
UnhandledExceptionFilter
GDI32.dll EndPage
AbortDoc
EndDoc
DeleteDC
StartPage
GetTextExtentPoint32W
CreateDCW
SetAbortProc
GetTextFaceW
TextOutW
StartDocW
EnumFontsW
GetStockObject
GetObjectW
GetDeviceCaps
CreateFontIndirectW
DeleteObject
GetTextMetricsW
SetBkMode
LPtoDP
SetWindowExtEx
SetViewportExtEx
SetMapMode
SelectObject
USER32.dll GetClientRect
SetCursor
ReleaseDC
GetDC
DialogBoxParamW
SetActiveWindow
GetKeyboardLayout
DefWindowProcW
DestroyWindow
MessageBeep
ShowWindow
GetForegroundWindow
IsIconic
GetWindowPlacement
CharUpperW
LoadStringW
LoadAcceleratorsW
GetSystemMenu
RegisterClassExW
LoadImageW
LoadCursorW
SetWindowPlacement
CreateWindowExW
GetDesktopWindow
GetFocus
LoadIconW
SetWindowTextW
PostQuitMessage
RegisterWindowMessageW
UpdateWindow
SetScrollPos
CharLowerW
PeekMessageW
EnableWindow
DrawTextExW
CreateDialogParamW
GetWindowTextW
GetSystemMetrics
MoveWindow
InvalidateRect
WinHelpW
GetDlgCtrlID
ChildWindowFromPoint
ScreenToClient
GetCursorPos
SendDlgItemMessageW
SendMessageW
CharNextW
CheckMenuItem
CloseClipboard
IsClipboardFormatAvailable
OpenClipboard
GetMenuState
EnableMenuItem
GetSubMenu
GetMenu
MessageBoxW
SetWindowLongW
GetWindowLongW
GetDlgItem
SetFocus
SetDlgItemTextW
wsprintfW
GetDlgItemTextW
EndDialog
GetParent
UnhookWinEvent
DispatchMessageW
TranslateMessage
TranslateAcceleratorW
IsDialogMessageW
PostMessageW
GetMessageW
SetWinEventHook

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.52715
MD5 e88b5bfeb06f7815ef84920fc87b5792
SHA1 fcd8b7fd2f462333888a5305c8307c0c53022a89
SHA256 0924c3158065aa6efa74c7b32d70b2638f937a6f48d636953b6be0f441f0a3ef
SHA3 69096bd995da80c931a0a2595d4ef3477c76e30c6bb3cf0a0ae1590da90fa665

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.46296
MD5 ca781c8b5025a3be42c31c65844ea84b
SHA1 69d2d7d91ef319b5e1bf699ba934e71e95c8b9f1
SHA256 12f7d758b0a0bd650c99cf520376457b0d1ca988678c8e01cd72e68631d9900a
SHA3 bad1e2aeceb3c50cfa9e75689d914eea3d139df5032bc04d691ecff578041a7b

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 982079681d7ad12766abc44f06946f3e
SHA1 50f73ed0787bf5911bb907e487efbc84a9714e48
SHA256 250f52cb2d6f1966a29f6ac771fa1cd185b8f8531396c8a4026c0fe635617e0c
SHA3 b8805d45012d79cfa8bb45e23c9b4a4421cd91538d569e58437efa0f545cf4d4

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 0d3a12fd3f68decc694da04b57e61d8c
SHA1 f73d4d591f6ef0b2b04fc90d2e840329f7590743
SHA256 ee0352f75df1009fa6f5eaf323a1ed55c127cc679ac6b9de70b1b3f8dc9ece76
SHA3 42ec79da319d9c0b1f8ee21fbb28002d15857d9af0c8a1f2db5e41f6c5e23c88

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 28f8d082df931688124f25f23c688904
SHA1 2f057655ecdd3ab25cfe985714e270786ce16cae
SHA256 4e7a8c59942ff527ff680aa88cc66bb8c8e7b6c02a018bc85ba36794e278670f
SHA3 99f004163a598b6df87372bd9b7d5e7704dbfdf7cfb3ec96da9e31c0275f7465

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a42b23f1c58701e073db2e9de0b27333
SHA1 f22232cbadff165ceb212527a6d77124312d0688
SHA256 e253c6a87bdd62e771c0ef1b9850dbc9523c51408ca282f994d3530dbbad9b11
SHA3 bc93a26ac3218cac12b89fa3242b509e44b087d2c22a54d9a47c63692dc8dc57

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 5f47a9d9640cc99d066c5784ba9df434
SHA1 816875cae3e19301f90358469c53cdd91d33af34
SHA256 559eb05d39a8e243be3e4b051e94f6572a487cc6f90c4847f333d61fe887b28d
SHA3 fc26364868396d506e74e7070d46e4704b69e6b1a2a50ac14c10542c18892e76

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 90d19bb4d7b1bd1f5622b062bc0891cf
SHA1 91510007472b7a3315cedbda969a5be3b5cde65d
SHA256 6389684b4c4ad12dc53c8cbbce4cf65f283c8fb4d8b98d90df7485a9424873fa
SHA3 d14149dadcdecf72a0be141f3642cceaf76d53cdf92bc5558735d47dd9b03805

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 7e1b34650fb04bc15a494a1d712cffee
SHA1 43e1808e4308baf093556946552f4fabc05278d8
SHA256 3731b0a75ab19d96b774da62d37eccacd517c6593af20aa66525dc0b951cdba9
SHA3 79a9c096a1a56ae4f98f1e8ad4c44fa5c08e5d98e745898df9031e3b3a13c46c

1 (#2)

Type RT_MENU
Language English - United States
Codepage UNKNOWN
Size 0x342
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 4f00b32a70c5d829f8199614fe56af64
SHA1 ff2afa238f88ce8cdb4430fe578c58823cd6d752
SHA256 e3833793f7412667cdbe15693f5dc4994934d1a6695392f8bebb74f985658256
SHA3 d29d8fe88ca0e638a6ec97821958f04163b3f7ca115b19dd336d726188ee060b

NPENCODINGDIALOG

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x7e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.84925
MD5 20885affa1182d8cd88f49c3af80bed3
SHA1 33dd5495aca99af5d5f715891f3adb47f0d8351d
SHA256 6dfd9392cc67bf54e019735f508bccf364b1918aa2887c890a943931d75a0ffc
SHA3 08a8d5cdf54445d8909388544ad4aa81a2691edd90df2ecd56176e19a250e685

11

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xd6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 30746881da58fa0e6b7786a056bda009
SHA1 f4565ca843e75c0e587840ee39a2528ec3df0fd6
SHA256 36b0a196916432bd5807bf323358d61475e8dcb318f637a7350e2e3d767afa5f
SHA3 7f4983f8800424eaf302f6f9899f7707f37366eb58dc568e0310d0639a3d0376

12

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x43e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46026
MD5 6c85b82126244f7771d22812df0ca83d
SHA1 c4f32d75795e2696730f820558918b245617d9c7
SHA256 8f1ce0c64f333104a5b80b606a5c54df4de26bccca4bef5d98938266daf5c336
SHA3 de7ede490872843880de9737ac3a9eba0d26ea601d2312c11fabb619da272541

14

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xde
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20226
MD5 ce5e40d98d28af2697fa057b684ba9c3
SHA1 0b610053fee51207b80634c627aca2116b869473
SHA256 e1814585a2269a12791438cd2610acb989bcd873999859d7d90c0dadd2914960
SHA3 840fc4e01087ac1b52bb4ba255779205abcd954db1063d1d8ab9e207f21acb3d

1 (#3)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x7fe
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22864
MD5 224d06fdd47d02bd63fa8ff7ca002b6f
SHA1 9bdc2fb999b64d3933866ef11d848fd9b47a9887
SHA256 112d2059c46836baedd1b95a48b3447b2174a983bcdee50a37a3626424a691c8
SHA3 b76befbf62a1e808a5b195ef1df6cf4131f8f415170614e3991d89c05d6a3058

2 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x704
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32759
MD5 f4f7c2544af7fa49952de896c67d45e0
SHA1 91461ee58ffa3d65a2cc6a0ba89c8020e0c494ad
SHA256 b17902ff379b97841b6916869f4676cb7c872dd379f6055244b254dee5f4418d
SHA3 4ccf340179ad26921295bbbbb283dc7fcc35bc65dced35bd6cdf3fa1ae2d6af3

3 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47185
MD5 c0e5eaa1c5f4b9d441bac061a4d2ed24
SHA1 dd4381157551202b2d98a32e383dde73e743e4e7
SHA256 37e320205493f5177b3b248fc7d9f772a70351899f7a67e3bed62519125fcb89
SHA3 e5333f1f358205d92daca77beb30fabd13650064b9185d3da8068b1b78250503

30

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x3a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.64738
MD5 f4731947668105f6afdb7458cf259b65
SHA1 78db1c02fe72b43de2450a32d5d9359c1a1f9f32
SHA256 8d246ee6dce873aabc79fd524ec7f46cf2512dbd7f17ebb43cd9acc1d2c34f61
SHA3 160056220a51a9703b70b9fcae5aad7b5bf8badf99dddf83eb076c4c5d87d0cd

MAINACC

Type RT_ACCELERATOR
Language English - United States
Codepage UNKNOWN
Size 0x88
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 256abfbb6883823718eaf33f62510d6a
SHA1 9a8c7efca7e5aefbcbb86a9ad6cffa0df3704bfc
SHA256 b707241545a346265aab1ffb32ff64b55bf8f8dc1b56a46ef33ce3d15db11d33
SHA3 e772c9cf9eb9c991cdfcf125001b454fdbc0a95f188d1b4c844aa032ad6e075e

SLIPUPACC

Type RT_ACCELERATOR
Language English - United States
Codepage UNKNOWN
Size 0xa8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 27418f9aeb0fae483bcf13272efe6310
SHA1 9a28ce8233f1be05276f787e06f872f7dd49f8ed
SHA256 e3c2af35d1dfc500e16f826a071cc311bf55003a3de77de7ea3376c6b6fa2857
SHA3 befaebb14926b3bc6d3330ea240dc2f202a15ddebd0ac4f50a0195d7928acf5f

2 (#3)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x84
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 e7633aa6a479bbbe82dbe794126bbeca
SHA1 1df5935d4cd349ac78102af001ced100f31449b1
SHA256 115bad14f1c9f2c027a84de21b107015722cb76be8d0abf3760ad8e00d6c24a5
SHA3 7e635de280c13637362a6c51f69da3bf92829ab013f4a2e087cc043f761f00b6

1 (#4)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x370
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.59161
MD5 eaea297dbe0b5a94b4a95f30bb8d76d3
SHA1 9261dc1095cd107af74b5b2a9c94836939e28fc8
SHA256 7f926cc644e51f8e7452111189a6cd69e9974de3669e05fcb99e3fbffba5a286
SHA3 f7594da88e01270eea55a2467667856ccd602644da84ae10bc51636138ea498d

1 (#5)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x29e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.87297
MD5 69b2da99d1ad0010a9de7ecf37178c5a
SHA1 19851037ea6058696f700ee0361e587148607cc0
SHA256 5c1f3a8e510335856575234287bd63786c53d0ea277098d3b792d9e84748815b
SHA3 67c64371d1c3ee415c1cda404084292c7e28e7f78c2e99ffb61311e70dc2e334

String Table contents

Cannot open the %% file.
Make sure a disk is in the drive you specified.
Cannot find the %% file.
Do you want to create a new file?
The text in the %% file has changed.
Do you want to save the changes?
Untitled
- Notepad
Cannot find "%%"
Not enough memory available to complete this operation. Quit one or more applications to increase available memory, and then try again.
The %% file is too large for Notepad.
Use another editor to edit the file.
Notepad
Failed to Initialize File Dialogs. Change the Filename and try again.
Failed to Initialize Print Dialogs. Make sure that your printer is connected properly and use Control Panel to verify that the printer is configured properly.
Cannot print the %% file. Be sure that your printer is connected properly and use Control Panel to verify that the printer is configured properly.
Not a valid file name.
Cannot create the %% file.
Make sure that the path and filename are correct.
Cannot carry out the Word Wrap command because there is too much text in the file.
%%
notepad.hlp
&f
Page &p
Text Documents (*.txt)
All Files
Open
Save As
You cannot quit Windows because the Save As dialog
box in Notepad is open. Switch to Notepad, close this
dialog box, and then try quitting Windows again.
Cannot access your printer.
Be sure that your printer is connected properly and use Control Panel to verify that the printer is configured properly.
%%
You do not have permission to open this file. See the owner of the file or an administrator to obtain permission.
%%
This file contains characters in Unicode format which will be lost if you save this file as an ANSI encoded text file. To keep the Unicode information, click Cancel below and then select one of the Unicode options from the Encoding drop down list. Continue?
Page too small to print one line.
Try printing using smaller font.
Common Dialog error (0x%04x)
Notepad - Goto Line
Line number out of range
ANSI
Unicode
Unicode big endian
UTF-8
Page %d
Ln %d, Col %d
Compressed,
Encrypted,
Hidden,
Offline,
ReadOnly,
System,
File
fFpPtTdDcCrRlL
Text Document

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 5.1.2600.5877
ProductVersion 5.1.2600.5877
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Notepad
FileVersion (#2) 5.1.2600.5877 (xpsp_sp3_qfe.090916-1338)
InternalName Notepad
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename NOTEPAD.EXE
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 5.1.2600.5877
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2009-Sep-16 10:53:23
Version 0.0
SizeofData 36
AddressOfRawData 0x18f0
PointerToRawData 0xcf0
Referenced File notepad.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1009604
SEHandlerTable 0x1001920
SEHandlerCount 1

RICH Header

XOR Key 0xf235e4a8
Unmarked objects 0
ASM objects (VS2003 (.NET) build 4035) 1
C++ objects (VS2003 (.NET) build 4035) 1
Imports (VS2003 (.NET) build 4035) 19
Total imports 203
94 (VS2003 (.NET) build 4035) 1
C objects (VS2003 (.NET) build 4035) 23
Linker (VS2003 (.NET) build 4035) 1

Errors