File details
File name: notepad.exe
Name: Notepad
Description: Microsoft® Windows® Operating System
Version: 5.1.2600.5877 (xpsp_sp3_qfe.090916-1338)
Product version: 5.1.2600.5877
Size: 213.5 KB
Original file name: NOTEPAD.EXE
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0180694938%
Privileged CPU:
0.0097503704%

User CPU:
0.00831912336119%

Privileged CPU time: 1109375 ms
Privileged CPU time /min: 0 ms
Context switches /sec:
22
 | Memory utilization averages |
Committed memory:
51.96 MB
Peak committed memory: 75.99 MB
Paged memory:
3.6 MB
Peak paged memory: 28.59 MB
Paged system memory:
102.02 KB
Non-paged system memory: 2.7 KB
Working set memory:
1.84 MB
Peak working set memory: 6.64 MB
Min working set memory: 560 KB
Private memory:
3.6 MB
Page faults:
2,278
Page faults /min: 0
 | Process I/O averages |
Total read operations:
6
Total read transfer: 408 Bytes
Total write operations:
13
Total write transfer: 1.16 KB
Total other operations:
487
Total other transfer: 3.36 KB
 | GUI Object Averages |
GDI objects:
32
USER objects:
21
Resources
Handle count average: 64
Thread count average: 1
Process details
Runs as (owner): User
Integrety level: Undefined
Windows platform: 32-bit
Process Command
"C:\WINDOWS\system32\NOTEPAD.EXE" C:\DOCUME~1\user\LocalS~1\Temp\7zO2FCB.tmp\README.txt
Shell open command details
Name: batfile
Command: NOTEPAD.EXE %1
Image hashes
MD5: 87048de5afe9a7c361551f28b6f9bc1e
SHA-1: 857fc5668d9ef68780e31b8e8e74df9070c59d3e
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.86730
File packed: No
Import Table
advapi32.dll

RegQueryValueExW
RegCloseKey
RegCreateKeyW
IsTextUnicode
RegQueryValueExA
RegOpenKeyExA
RegSetValueExW
comctl32.dll

comdlg32.dll

PageSetupDlgW
FindTextW
PrintDlgExW
ChooseFontW
GetFileTitleW
GetOpenFileNameW
ReplaceTextW
CommDlgExtendedError
GetSaveFileNameW
gdi32.dll

EndPage
AbortDoc
EndDoc
DeleteDC
StartPage
GetTextExtentPoint32W
CreateDCW
SetAbortProc
GetTextFaceW
TextOutW
StartDocW
EnumFontsW
GetStockObject
GetObjectW
GetDeviceCaps
CreateFontIndirectW
DeleteObject
GetTextMetricsW
SetBkMode
LPtoDP
SetWindowExtEx
SetViewportExtEx
SetMapMode
SelectObject
kernel32.dll

GetCurrentThreadId
GetTickCount
QueryPerformanceCounter
GetLocalTime
GetUserDefaultLCID
GetDateFormatW
GetTimeFormatW
GlobalLock
GlobalUnlock
GetFileInformationByHandle
CreateFileMappingW
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
LoadLibraryA
GetModuleHandleA
GetStartupInfoA
GlobalFree
GetLocaleInfoW
LocalFree
LocalAlloc
lstrlenW
LocalUnlock
CompareStringW
LocalLock
FoldStringW
CloseHandle
lstrcpyW
ReadFile
CreateFileW
lstrcmpiW
GetCurrentProcessId
GetProcAddress
GetCommandLineW
lstrcatW
FindClose
FindFirstFileW
GetFileAttributesW
lstrcmpW
MulDiv
lstrcpynW
LocalSize
GetLastError
WriteFile
SetLastError
WideCharToMultiByte
LocalReAlloc
FormatMessageW
GetUserDefaultUILanguage
SetEndOfFile
DeleteFileW
GetACP
UnmapViewOfFile
MultiByteToWideChar
MapViewOfFile
UnhandledExceptionFilter
msvcrt.dll
shell32.dll

DragFinish
DragQueryFileW
DragAcceptFiles
ShellAboutW
user32.dll

GetClientRect
SetCursor
ReleaseDC
GetDC
DialogBoxParamW
SetActiveWindow
GetKeyboardLayout
DefWindowProcW
DestroyWindow
MessageBeep
ShowWindow
GetForegroundWindow
IsIconic
GetWindowPlacement
CharUpperW
LoadStringW
LoadAcceleratorsW
GetSystemMenu
RegisterClassExW
LoadImageW
LoadCursorW
SetWindowPlacement
CreateWindowExW
GetDesktopWindow
GetFocus
LoadIconW
SetWindowTextW
PostQuitMessage
RegisterWindowMessageW
UpdateWindow
SetScrollPos
CharLowerW
PeekMessageW
EnableWindow
DrawTextExW
CreateDialogParamW
GetWindowTextW
GetSystemMetrics
MoveWindow
InvalidateRect
WinHelpW
GetDlgCtrlID
ChildWindowFromPoint
ScreenToClient
GetCursorPos
SendDlgItemMessageW
SendMessageW
CharNextW
CheckMenuItem
CloseClipboard
IsClipboardFormatAvailable
OpenClipboard
GetMenuState
EnableMenuItem
GetSubMenu
GetMenu
MessageBoxW
SetWindowLongW
GetWindowLongW
GetDlgItem
SetFocus
SetDlgItemTextW
wsprintfW
GetDlgItemTextW
EndDialog
GetParent
UnhookWinEvent
DispatchMessageW
TranslateMessage
TranslateAcceleratorW
IsDialogMessageW
PostMessageW
GetMessageW
SetWinEventHook
winspool.drv

GetPrinterDriverW
ClosePrinter
OpenPrinterW