| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-13 18:08:17 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
D:\dbs\el\omr\Target\x64\ship\postc2r\x-none\onenotem.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Send to OneNote Tool |
| FileVersion | 16.0.19822.20182 |
| InternalName | QuickLauncher |
| LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFilename | OneNoteM.exe |
| ProductName | Microsoft OneNote |
| ProductVersion | 16.0.19822.20182 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .c2r |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Windows Code Signing PCA 2024 |
| Safe | VirusTotal score: 0/72 (Scanned on 2026-04-14 18:29:13) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2026-Apr-13 18:08:17 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x2dc00 |
| SizeOfInitializedData | 0x6b800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000002BCF0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xa4000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xa6d71 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| AppVIsvSubsystems64.dll |
#1
|
|---|---|
| KERNEL32.dll |
CreateActCtxW
ActivateActCtx SetLastError EnterCriticalSection GetCommandLineW GetCurrentProcess GetModuleHandleExW OutputDebugStringA GetModuleFileNameW LeaveCriticalSection FindActCtxSectionStringW InitializeCriticalSectionEx WaitForSingleObject GetCurrentThreadId GetVersionExW DeactivateActCtx OpenProcess CreateEventW QueryActCtxW Sleep GetLastError GlobalSize SetEvent GlobalAlloc GlobalFree CloseHandle RaiseException LoadLibraryW HeapCompact DecodePointer GetProcAddress GlobalLock DeleteCriticalSection GetProcessHeap CreateProcessW FreeLibrary LocaleNameToLCID SetProcessWorkingSetSize CreateFileMappingW GlobalUnlock RegisterApplicationRestart LoadLibraryExW SetUnhandledExceptionFilter CreateMutexW ReleaseMutex OpenFileMappingW UnmapViewOfFile MapViewOfFile EncodePointer TlsAlloc FlsFree TlsFree CompareStringEx GetLocaleInfoEx MultiByteToWideChar WideCharToMultiByte GetUserDefaultLocaleName IsValidCodePage FileTimeToSystemTime GetStringTypeExW HeapFree HeapAlloc GetCurrentProcessId GetSystemTimeAsFileTime TerminateProcess GetModuleFileNameA GetShortPathNameA FindResourceW SizeofResource LoadResource GetModuleHandleW LockResource LoadLibraryExA IsDebuggerPresent OutputDebugStringW AcquireSRWLockExclusive VirtualQuery VirtualProtect GetSystemInfo InitOnceComplete InitOnceBeginInitialize AcquireSRWLockShared ReleaseSRWLockShared GetFileInformationByHandleEx AreFileApisANSI GetFileAttributesExW FindNextFileW FindFirstFileExW FindFirstFileW FindClose CreateFileW FormatMessageA WakeAllConditionVariable SleepConditionVariableSRW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter IsProcessorFeaturePresent QueryPerformanceCounter InitializeSListHead GetStartupInfoW LocalFree ReleaseSRWLockExclusive |
| OLEAUT32.dll |
LoadRegTypeLib
VariantInit LoadTypeLib SysFreeString SysAllocString SysStringLen |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| VCRUNTIME140.dll |
__current_exception_context
__current_exception memset memmove wcschr _purecall __C_specific_handler_noexcept _CxxThrowException memcpy memcmp wcsstr __std_exception_copy __std_exception_destroy __C_specific_handler __std_terminate |
| MSVCP140.dll |
_Thrd_id
_Mtx_lock _Mtx_init_in_situ ?_Throw_Cpp_error@std@@YAXH@Z ?_Syserror_map@std@@YAPEBDH@Z ?_Winerror_map@std@@YAHH@Z ?_Xout_of_range@std@@YAXPEBD@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Xbad_alloc@std@@YAXXZ _Mtx_unlock |
| api-ms-win-crt-heap-l1-1-0.dll |
free
_set_new_mode malloc |
| api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vsnwprintf_s
__stdio_common_vswprintf_s __p__commode _set_fmode |
| api-ms-win-crt-runtime-l1-1-0.dll |
abort
_invoke_watson terminate _seh_filter_exe _crt_atexit _register_onexit_function _initialize_onexit_table _register_thread_local_exe_atexit_callback _c_exit _cexit _set_app_type _exit exit _initterm_e _initterm _get_narrow_winmain_command_line _initialize_narrow_environment _configure_narrow_argv |
| api-ms-win-crt-string-l1-1-0.dll |
wcscat_s
wcsncpy_s wcsncat_s wcscpy_s wcscmp isdigit _wcsicmp wcsnlen |
| api-ms-win-crt-math-l1-1-0.dll |
_fdclass
log10 round floor _dclass pow __setusermatherr |
| api-ms-win-crt-convert-l1-1-0.dll |
_wtoi
_i64tow_s |
| api-ms-win-crt-locale-l1-1-0.dll |
___lc_codepage_func
_configthreadlocale __initialize_lconv_for_unsigned_char |
| ADVAPI32.dll (delay-loaded) |
RegQueryValueExW
RegOpenKeyExW RegSetValueExW RegCreateKeyExW RegCloseKey ReportEventW RegisterEventSourceW DeregisterEventSource EventWriteTransfer EventRegister EventUnregister EventSetInformation RegGetValueW |
| Attributes | 0x1 |
|---|---|
| Name | ADVAPI32.dll |
| ModuleHandle | 0x7d710 |
| DelayImportAddressTable | 0x87000 |
| DelayImportNameTable | 0x72808 |
| BoundDelayImportTable | 0 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 16.0.19822.20182 |
| ProductVersion | 16.0.19822.20182 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | Microsoft Corporation |
| FileDescription | Send to OneNote Tool |
| FileVersion (#2) | 16.0.19822.20182 |
| InternalName | QuickLauncher |
| LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFilename | OneNoteM.exe |
| ProductName | Microsoft OneNote |
| ProductVersion (#2) | 16.0.19822.20182 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-13 18:08:17 |
| Version | 0.0 |
| SizeofData | 280 |
| AddressOfRawData | 0x747d0 |
| PointerToRawData | 0x737d0 |
| Referenced File | D:\dbs\el\omr\Target\x64\ship\postc2r\x-none\onenotem.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-13 18:08:17 |
| Version | 576.35719 |
| SizeofData | 4 |
| AddressOfRawData | 0x748e8 |
| PointerToRawData | 0x738e8 |
| StartAddressOfRawData | 0x140071ed0 |
|---|---|
| EndAddressOfRawData | 0x14007201c |
| AddressOfIndex | 0x14007dd44 |
| AddressOfCallbacks | 0x14002f788 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x000000014002C520
0x000000014002C590 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14007b040 |
| GuardCFCheckFunctionPointer | 5368903176 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x48f22590 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 16 |
| Imports (35207) | 6 |
| ASM objects (35207) | 4 |
| C objects (35207) | 10 |
| ASM objects (33136) | 3 |
| C objects (33136) | 8 |
| C objects (CVTCIL) (33136) | 2 |
| Imports (33136) | 5 |
| Total imports | 594 |
| C++ objects (35207) | 48 |
| C++ objects (LTCG) (35214) | 242 |
| Resource objects (35214) | 1 |
| 151 | 1 |
| Linker (35214) | 1 |
No comments yet.