Static | ZeroBOX

PE Compile Time

2013-08-22 20:00:11

PDB Path

notepad.pdb

PE Imphash

43a39bb2bf8e4b5d75b452af52201829

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00017364 0x00017400 6.53768538566
.data 0x00019000 0x0000282c 0x00001600 1.09314074498
.pdata 0x0001c000 0x00000660 0x00000800 4.446005584
.idata 0x0001d000 0x00001df0 0x00001e00 4.63170956961
.rsrc 0x0001f000 0x0001a000 0x00019800 7.35284404605
.reloc 0x00039000 0x00000128 0x00000200 3.5548316946

Resources

Name Offset Size Language Sub-language File type
MUI 0x0001f378 0x000000e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00037d70 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000381d8 0x000000bc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00038294 0x00000374 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x14001d000 RegQueryValueExW
0x14001d008 RegCreateKeyW
0x14001d010 RegCloseKey
0x14001d018 RegOpenKeyExW
0x14001d028 IsTextUnicode
0x14001d030 RegSetValueExW
Library KERNEL32.dll:
0x14001d040 UnmapViewOfFile
0x14001d048 FindNLSString
0x14001d050 GlobalAlloc
0x14001d058 GetLocalTime
0x14001d060 GetDateFormatW
0x14001d068 GetTimeFormatW
0x14001d070 GlobalLock
0x14001d078 GlobalUnlock
0x14001d080 GetUserDefaultUILanguage
0x14001d088 LocalReAlloc
0x14001d090 MultiByteToWideChar
0x14001d098 MapViewOfFile
0x14001d0a0 CreateFileMappingW
0x14001d0b0 SetEndOfFile
0x14001d0b8 DeleteFileW
0x14001d0c0 GetACP
0x14001d0c8 GetFileAttributesW
0x14001d0d0 WriteFile
0x14001d0d8 SetLastError
0x14001d0e0 WideCharToMultiByte
0x14001d0e8 GetLastError
0x14001d0f0 LocalSize
0x14001d0f8 GetFullPathNameW
0x14001d100 FoldStringW
0x14001d108 LocalUnlock
0x14001d110 LocalLock
0x14001d118 FormatMessageW
0x14001d120 FindClose
0x14001d128 FindFirstFileW
0x14001d130 lstrcmpW
0x14001d138 GetCurrentProcessId
0x14001d140 GetModuleHandleExW
0x14001d148 GetModuleFileNameW
0x14001d150 HeapSetInformation
0x14001d158 GetProcessHeap
0x14001d160 HeapFree
0x14001d168 GetProcAddress
0x14001d170 HeapAlloc
0x14001d178 GetTickCount
0x14001d180 GetSystemTimeAsFileTime
0x14001d188 GetCommandLineW
0x14001d190 lstrlenW
0x14001d198 MulDiv
0x14001d1a0 GetLocaleInfoW
0x14001d1a8 GlobalFree
0x14001d1b0 LocalAlloc
0x14001d1b8 CloseHandle
0x14001d1c0 ReadFile
0x14001d1c8 CreateFileW
0x14001d1d0 GetCurrentThreadId
0x14001d1d8 SetErrorMode
0x14001d1e0 lstrcmpiW
0x14001d1e8 LocalFree
0x14001d1f0 QueryPerformanceCounter
0x14001d1f8 GetModuleHandleW
0x14001d200 TerminateProcess
0x14001d208 Sleep
0x14001d210 GetStartupInfoW
0x14001d218 UnhandledExceptionFilter
0x14001d228 GetCurrentProcess
Library GDI32.dll:
0x14001d238 CreateDCW
0x14001d240 StartPage
0x14001d248 StartDocW
0x14001d250 SetAbortProc
0x14001d258 DeleteDC
0x14001d260 EndDoc
0x14001d268 AbortDoc
0x14001d270 EndPage
0x14001d278 GetTextMetricsW
0x14001d280 SetBkMode
0x14001d288 LPtoDP
0x14001d290 SetWindowExtEx
0x14001d298 SetViewportExtEx
0x14001d2a0 SetMapMode
0x14001d2a8 GetTextExtentPoint32W
0x14001d2b0 TextOutW
0x14001d2b8 EnumFontsW
0x14001d2c0 GetTextFaceW
0x14001d2c8 SelectObject
0x14001d2d0 DeleteObject
0x14001d2d8 CreateFontIndirectW
0x14001d2e0 GetDeviceCaps
Library USER32.dll:
0x14001d2f0 WinHelpW
0x14001d2f8 GetCursorPos
0x14001d300 ScreenToClient
0x14001d308 ChildWindowFromPoint
0x14001d310 GetParent
0x14001d318 GetWindowPlacement
0x14001d320 CharUpperW
0x14001d328 GetSystemMenu
0x14001d330 LoadAcceleratorsW
0x14001d338 SetWindowLongW
0x14001d340 RegisterWindowMessageW
0x14001d348 LoadCursorW
0x14001d350 CreateWindowExW
0x14001d358 SetWindowPlacement
0x14001d360 LoadImageW
0x14001d368 RegisterClassExW
0x14001d370 SetScrollPos
0x14001d378 InvalidateRect
0x14001d380 UpdateWindow
0x14001d388 GetWindowTextLengthW
0x14001d390 GetWindowLongW
0x14001d398 PeekMessageW
0x14001d3a0 GetWindowTextW
0x14001d3a8 EnableWindow
0x14001d3b0 CreateDialogParamW
0x14001d3b8 DrawTextExW
0x14001d3c0 GetDlgCtrlID
0x14001d3c8 SendDlgItemMessageW
0x14001d3d0 EndDialog
0x14001d3d8 GetDlgItemTextW
0x14001d3e0 SetDlgItemTextW
0x14001d3e8 CloseClipboard
0x14001d3f8 OpenClipboard
0x14001d400 GetMenuState
0x14001d408 SetWindowTextW
0x14001d410 UnhookWinEvent
0x14001d418 DispatchMessageW
0x14001d420 TranslateMessage
0x14001d428 TranslateAcceleratorW
0x14001d430 IsDialogMessageW
0x14001d438 GetMessageW
0x14001d440 SetWinEventHook
0x14001d448 CharNextW
0x14001d450 GetKeyboardLayout
0x14001d458 GetForegroundWindow
0x14001d460 MessageBeep
0x14001d468 DestroyWindow
0x14001d470 PostQuitMessage
0x14001d478 IsIconic
0x14001d480 LoadStringW
0x14001d488 SetActiveWindow
0x14001d490 SetCursor
0x14001d498 ReleaseDC
0x14001d4a0 GetDC
0x14001d4a8 ShowWindow
0x14001d4b0 GetClientRect
0x14001d4b8 CheckMenuItem
0x14001d4c0 MessageBoxW
0x14001d4c8 GetFocus
0x14001d4d0 LoadIconW
0x14001d4d8 DialogBoxParamW
0x14001d4e0 SetFocus
0x14001d4e8 GetSubMenu
0x14001d4f0 EnableMenuItem
0x14001d4f8 GetMenu
0x14001d500 PostMessageW
0x14001d508 MoveWindow
0x14001d510 SendMessageW
0x14001d518 DefWindowProcW
Library msvcrt.dll:
0x14001d528 _wtol
0x14001d530 memcpy
0x14001d538 memset
0x14001d540 _vsnwprintf
0x14001d548 strchr
0x14001d550 _commode
0x14001d558 iswctype
0x14001d560 _XcptFilter
0x14001d568 _amsg_exit
0x14001d570 __getmainargs
0x14001d578 __set_app_type
0x14001d580 ?terminate@@YAXXZ
0x14001d588 wcscmp
0x14001d590 _fmode
0x14001d598 _acmdln
0x14001d5a0 __C_specific_handler
0x14001d5a8 _initterm
0x14001d5b0 __setusermatherr
0x14001d5b8 _ismbblead
0x14001d5c0 _cexit
0x14001d5c8 _exit
0x14001d5d0 exit
Library COMDLG32.dll:
0x14001d5e0 GetOpenFileNameW
0x14001d5e8 GetSaveFileNameW
0x14001d5f0 ReplaceTextW
0x14001d5f8 FindTextW
0x14001d600 PageSetupDlgW
0x14001d608 ChooseFontW
0x14001d610 GetFileTitleW
0x14001d618 PrintDlgExW
0x14001d620 CommDlgExtendedError
Library SHELL32.dll:
0x14001d638 ShellAboutW
0x14001d640 DragQueryFileW
0x14001d648 SHAddToRecentDocs
0x14001d650 DragAcceptFiles
0x14001d658 DragFinish
Library WINSPOOL.DRV:
0x14001d668 OpenPrinterW
0x14001d670 ClosePrinter
0x14001d678 GetPrinterDriverW
Library ole32.dll:
0x14001d688 CoUninitialize
0x14001d690 CoInitializeEx
0x14001d698 CoCreateInstance
0x14001d6a0 CoTaskMemAlloc
0x14001d6a8 CoTaskMemFree
Library SHLWAPI.dll:
0x14001d6b8 SHStrDupW
0x14001d6c0 PathIsFileSpecW
Library ntdll.dll:
0x14001d700 RtlVirtualUnwind
0x14001d708 RtlLookupFunctionEntry
0x14001d710 RtlCaptureContext
0x14001d718 WinSqmAddToStream

!This program cannot be run in DOS mode.
rRich7
`.data
.pdata
.idata
@.rsrc
@.reloc
H WAVAWH
A_A^_
t$ UWATAVAWH
A_A^A\_]
UVWATAUAVAWH
@A_A^A]A\_^]
L$ SUVWH
WATAUAVAWH
A_A^A]A\_
9D$pvc
9D$pvg
9D$pvc
9D$pvg
9D$pvc
9D$pv`
D$pH9D$xt
A_A^A]A\_^]
0Hc\$`
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
u*9Q<|%
7'*=Y<
NtQuerySystemInformation
u&HcA<=
fD9$Gu
u&HcA<=
fD9$Cu
u&HcA<=
fD9$Gu
D9d$hv>H
D;L$hs
fD9$Au
fD9$Hu
fD9$Ku
fD9$Ou
uAVAUWVSH
[^_A]A^
AVAUWVSH
[^_A]A^
u HcB<=
H3E H3E
LA+F=l?
2Jj7S'yC
lFV<f/
B2CU'
HWbyh
ZoozUgY
CkI~qA
ig+R}!
}O:AJf
.X2J3,DB|zbMS
^I(n<AP7
d35y&`VWj
p WAVAWH
A_A^_
UVWAVAWH
A_A^_^]
WAVAWH
A_A^_
D$`+D$X9D$huXL
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
@A_A^A]A\_^]
UVWATAUAVAWH
@A_A^A]A\_^]
t$ WATAUAVAWH
L$x+T$t+L$p
A_A^A]A\_
UVWATAUAVAWH
HA_A^A]A\_^][
fD95S
x UATAUAVAWH
L$|f9=z:
9t$4t)95]F
A_A^A]A\]
x UATAUAVAWH
t=fA;@
t6fA;@
t$fA;@
A_A^A]A\]
LcA<E3
notepad.pdb

ew|>&=4_
^`i
`llh2''mk&ae_b]ga_YY&[ge'klk'aeY_[&bh_
NajlmYd9ddg[
DgY\DaZjYjq9
e]e[hq
Afl]jf]lGh]f9
@LLHJ=9<
Afl]jf]lGh]fMjd9
Afl]jf]lJ]Y\>ad]
Afl]jf]l;dgk]@Yf\d]
oafaf]l&\dd
ekn[jl&\dd
ntdll.dll
OLEAUT32.dll
COMCTL32.dll
SHLWAPI.dll
ole32.dll
WINSPOOL.DRV
SHELL32.dll
COMDLG32.dll
msvcrt.dll
USER32.dll
GDI32.dll
KERNEL32.dll
ADVAPI32.dll
RegQueryValueExW
RegCreateKeyW
RegCloseKey
RegOpenKeyExW
DuplicateEncryptionInfoFile
IsTextUnicode
RegSetValueExW
UnmapViewOfFile
FindNLSString
GlobalAlloc
GetLocalTime
GetDateFormatW
GetTimeFormatW
GlobalLock
GlobalUnlock
GetUserDefaultUILanguage
LocalReAlloc
MultiByteToWideChar
MapViewOfFile
CreateFileMappingW
GetFileInformationByHandle
SetEndOfFile
DeleteFileW
GetACP
GetFileAttributesW
WriteFile
SetLastError
WideCharToMultiByte
GetLastError
LocalSize
GetFullPathNameW
FoldStringW
LocalUnlock
LocalLock
FormatMessageW
FindClose
FindFirstFileW
lstrcmpW
GetCurrentProcessId
GetModuleHandleExW
GetModuleFileNameW
HeapSetInformation
GetProcessHeap
HeapFree
GetProcAddress
HeapAlloc
GetTickCount
GetSystemTimeAsFileTime
GetCommandLineW
lstrlenW
MulDiv
GetLocaleInfoW
GlobalFree
LocalAlloc
CloseHandle
ReadFile
CreateFileW
GetCurrentThreadId
SetErrorMode
lstrcmpiW
LocalFree
QueryPerformanceCounter
GetModuleHandleW
TerminateProcess
GetStartupInfoW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
CreateDCW
StartPage
StartDocW
SetAbortProc
DeleteDC
EndDoc
AbortDoc
EndPage
GetTextMetricsW
SetBkMode
LPtoDP
SetWindowExtEx
SetViewportExtEx
SetMapMode
GetTextExtentPoint32W
TextOutW
EnumFontsW
GetTextFaceW
SelectObject
DeleteObject
CreateFontIndirectW
GetDeviceCaps
WinHelpW
GetCursorPos
ScreenToClient
ChildWindowFromPoint
GetParent
GetWindowPlacement
CharUpperW
GetSystemMenu
LoadAcceleratorsW
SetWindowLongW
RegisterWindowMessageW
LoadCursorW
CreateWindowExW
SetWindowPlacement
LoadImageW
RegisterClassExW
SetScrollPos
InvalidateRect
UpdateWindow
GetWindowTextLengthW
GetWindowLongW
PeekMessageW
GetWindowTextW
EnableWindow
CreateDialogParamW
DrawTextExW
GetDlgCtrlID
SendDlgItemMessageW
EndDialog
GetDlgItemTextW
SetDlgItemTextW
CloseClipboard
IsClipboardFormatAvailable
OpenClipboard
GetMenuState
SetWindowTextW
UnhookWinEvent
DispatchMessageW
TranslateMessage
TranslateAcceleratorW
IsDialogMessageW
GetMessageW
SetWinEventHook
CharNextW
GetKeyboardLayout
GetForegroundWindow
MessageBeep
DestroyWindow
PostQuitMessage
IsIconic
LoadStringW
SetActiveWindow
SetCursor
ReleaseDC
ShowWindow
GetClientRect
CheckMenuItem
MessageBoxW
GetFocus
LoadIconW
DialogBoxParamW
SetFocus
GetSubMenu
EnableMenuItem
GetMenu
PostMessageW
MoveWindow
SendMessageW
DefWindowProcW
memcpy
memset
_vsnwprintf
strchr
_commode
iswctype
_XcptFilter
_amsg_exit
__getmainargs
__set_app_type
?terminate@@YAXXZ
wcscmp
_fmode
_acmdln
__C_specific_handler
_initterm
__setusermatherr
_ismbblead
_cexit
GetOpenFileNameW
GetSaveFileNameW
ReplaceTextW
FindTextW
PageSetupDlgW
ChooseFontW
GetFileTitleW
PrintDlgExW
CommDlgExtendedError
SHCreateItemFromParsingName
ShellAboutW
DragQueryFileW
SHAddToRecentDocs
DragAcceptFiles
DragFinish
OpenPrinterW
ClosePrinter
GetPrinterDriverW
CoUninitialize
CoInitializeEx
CoCreateInstance
CoTaskMemAlloc
CoTaskMemFree
SHStrDupW
PathIsFileSpecW
CreateStatusWindowW
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
WinSqmAddToStream
DDEA<::?6
GIIEA<;;?332,'
DNEE<<??>22+(&&&'3
SRRQPE@??>2,,('''',+233
SQRQPNNDDD??,((,(,,+33222',6
MNNEDDDDDI,2,,2233232,2,,2C+
@DIIIICCGIC3>3>2?2??2?C3G63G
?IIIIILILL?GC?CC>GGGG>GCC?C,
DIILOOO
CKGGGGGGDCCCCCGGG
LLLLLILKK
LLLLIIIILIC
p5-h-/z1~
~zxjhj
4+++*(
@?=,+/
===111*!
!!!!!!
'141133!/!(!(!""/""
414;;4
/2/22222////2
;;;;4;3423332
;;;;4:
jZZ \ZdZ^nN
~nnn^^TdUhUlWVkt
gQkQml
.(..%%!!!!!%0
3.r6x.3+,+.0+*!
|r8kr33.33m
xx8rrk3+
f_UUURTP
gbXOOLOZ[dbp
GXXXXXXXXXX
)KK1.-%
$KB>;88$
8KH11.%"
H>KKH;;8)$
;K631-."
(PMKH>;8))
)TE@330."
;LTMMK>;8+$
KHFE@330.
8VTMLH>;.(
(WVTMK>;8+
IDATx^
|8?99zEc
sCN $A
mem2KJ
}^=47"
tz80&a%
5eR@PahB
'2+8Ly
UE&c'O
:({?<#k
X&9Lx"
3A%$[w
q27:^u
H~bXGB
J{L6nD
`lX06,?
ieKe|A
,k<.KQ
oon;M=
|*+@F!
0y;:]Z
h;Z|?2
e &!h+
4J} ^t
C>_J*A
V&Xax)
2hb6YX
Jvz:OO
]I#!4!
?#Q@i(2YD
& 4 10O
84c%ez
xywSIpg
wf!>Tg
QV+ODc
>m5l-B
Gmqxg"
Hc^YF3
?,M.3G2
yT"F]g
YvSfyw/
bJYL^T
.WF"hB
6d@u`+
}x5Jbf
m;xDv)
!({.}Q0H!
V.xOx_T
o3noje
!@!$*B
Re.!D:
FZdQ&r
L-|9.
dB!dB!hB
Jx$7}H
%.!$-T
$)IA%:
,(S!Y(Cf
(@!h(d
u@ @p=
YuU8]&ldx
GsS!t"
vfql:>C
|LVz>FE@
9{8d93
APkP<&
B/XoX_
JN}<:5
<:KmJ*0
CG1\U
Ja\-6G
yz\yWlM~
[qA*68
VL `wZd~
y~qpz:
ycn3)io
P[a(,E
J!:+_m
,>d=MT
x8K{?3~4
M6W}6kY
B!U~8Hg
774_kki
,$4ida
4543!! B
yur:QNO[
MML%BBBQ
%s%c*.txt%c%s%c*.*%c
commdlg_FindReplace
commdlg_help
MainAcc
ntdll.dll
WinSta0
Default
Security-SPP-GenuineLocalStatus
Software\Microsoft\Notepad
lfEscapement
lfOrientation
lfWeight
lfItalic
lfUnderline
lfStrikeOut
lfCharSet
lfOutPrecision
lfClipPrecision
lfQuality
lfPitchAndFamily
lfFaceName
StatusBar
szHeader
szTrailer
iMarginTop
iMarginBottom
iMarginLeft
iMarginRight
iWindowPosX
iWindowPosY
iWindowPosDX
iWindowPosDY
/.SETUP
Lucida Console
Software\Microsoft\Notepad\DefaultFonts
fSaveWindowPositions
fMLE_is_broken
iPointSize
Notepad
HELP_ENTRY_ID_NOTEPAD_HELP
mshelp://windows/?id=5d18d5fb-e737-4a73-b6cc-dccc63720231
SlipUpAcc
Segoe UI Light
Segoe UI SemiBold
Segoe UI
[2taPG][
Segoe Pseudo
Meiryo UI
Malgun Gothic
Leelawadee UI
Microsoft YaHei UI
Microsoft JhengHei UI
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Notepad
FileVersion
6.3.9600.16384 (winblue_rtm.130821-1623)
InternalName
Notepad
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
NOTEPAD.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.3.9600.16384
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.