MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Packer / Compiler

Sections

Data Directory

StringTable 000004b0

VS_FIXEDFILEINFO

offsetsizetypecomment
057344EXE07/22/2007 02:33:05#
e000488610BINoverlay data past EOF#
Type = 7z
Method = LZMA BCJ
Solid = +
Blocks = 2
Physical Size = 488326
Headers Size = 1712
Offset = 57628

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2012-12-07 20:27:02 ....A          565       334407  erunt/ERUNT.EXE.manifest
2013-04-21 11:09:45 ....A        37373               ask.bat
2013-04-22 01:31:54 ....A        15542               chrome.bat
2013-04-02 00:03:09 ....A         1825               delfolders.bat
2012-12-08 14:22:00 ....A          732               ev_clear.bat
2013-04-21 11:13:35 ....A       224236               firefox.bat
2012-12-08 14:50:23 ....A         1256               FWPolicy.bat
2013-05-07 02:18:44 ....A        14028               get.bat
2013-04-21 11:58:12 ....A        29803               iexplore.bat
2013-05-07 02:19:06 ....A        11837               JRT.bat
2013-01-16 00:45:43 ....A        14243               medfos.bat
2013-04-30 01:52:41 ....A        81579               misc.bat
2013-04-21 12:18:13 ....A         9763               modules.bat
2013-04-29 11:07:30 ....A        29565               prelim.bat
2013-04-03 14:54:40 ....A         5379               runvalues.bat
2013-04-21 12:21:14 ....A        13025               searchlnk.bat
2013-01-22 02:01:34 ....A         1040               TDL4.bat
2013-02-03 01:34:38 ....A          370               clean_shortcut.vbs
2012-12-07 20:27:02 ....A        31952               erunt/README.TXT
2013-01-24 01:52:12 ....A          100               sednewline.txt
2013-04-30 01:54:05 ....A        12866               badFOLDERS.cfg
2013-04-30 01:19:38 ....A          117               badFOLDERScom.cfg
2013-04-22 07:10:02 ....A          711               badFOLDERSstart.cfg
2013-03-31 07:35:37 ....A          168               badLNK.cfg
2013-04-30 01:51:56 ....A         3847               badvalues.cfg
2013-04-29 11:18:32 ....A          128               browsermngr_keys.cfg
2012-12-08 15:32:57 ....A           94               browsermngr_values.cfg
2013-04-29 11:19:37 ....A          174               CHRregkey_x64.cfg
2013-04-29 11:19:45 ....A          107               CHRregkey_x86.cfg
2013-04-30 01:18:32 ....A         3194               CHR_extensions.cfg
2013-04-21 11:24:55 ....A           38               defaultscope.cfg
2013-04-05 03:41:13 ....A          159               FFwhtlist.cfg
2013-04-23 03:41:31 ....A           86               IEwhtlst.cfg
2013-04-02 00:16:07 ....A         2655               REGhcr.cfg
2013-03-24 00:14:07 ....A           16               REGhkcu_and_hklm_allow.cfg
2013-05-07 02:18:08 ....A         1434               REGhkcu_and_hklm_software.cfg
2013-04-22 01:33:22 ....A          892               REGhkcu_software_appdatalow.cfg
2013-04-22 01:34:13 ....A         1870               REGhkcu_software_microsoft.cfg
2013-04-18 03:22:19 ....A        33349               REGhklm_software_classes.cfg
2013-03-12 02:06:04 ....A         6861               REGhklm_software_microsoft.cfg
2013-04-01 23:40:23 ....A         1816               REGhklm_software_wow6432node.cfg
2013-04-21 12:19:57 ....A          211               runvalues_x64.cfg
2013-04-21 12:15:02 ....A          129               runvalues_x86.cfg
2013-04-29 10:19:11 ....A         3078               askCLSID.dat
2013-04-29 11:13:31 ....A          488               askregkey_x64.dat
2013-04-29 11:14:02 ....A          260               askregkey_x86.dat
2013-04-29 11:16:07 ....A          424               askregvalue_x64.dat
2013-04-29 11:16:22 ....A          345               askregvalue_x86.dat
2013-04-29 11:16:34 ....A           22               askservices.dat
2013-03-30 04:47:16 ....A          118               badAPPINIT.dat
2013-04-30 01:13:52 ....A        20878               BHO_clsid.dat
2005-02-27 12:40:46 ....A        45056               CHOICE.DAT
2012-12-07 20:27:02 ....A        17920               CUT.DAT
2012-12-07 20:27:02 ....A          119               FFbrowsermngr.dat
2013-04-30 01:17:02 ....A         6614               FFextensions.dat
2012-12-07 20:27:02 ....A           75               FFplugins.dat
2013-04-30 01:51:25 ....A         3540               FFprefs.dat
2013-04-29 11:21:18 ....A          177               FFregkey_x64.dat
2013-04-29 11:21:28 ....A          109               FFregkey_x86.dat
2013-04-17 04:27:39 ....A         1351               FFXML.dat
2013-04-30 01:56:23 ....A          605               FFXPI.dat
2013-04-30 01:48:12 ....A         2278               FWCLSID.dat
2013-04-20 01:34:23 ....A          292               modules.dat
2013-01-24 02:19:43 ....A          178               moduleservices.dat
2012-12-15 00:36:09 ....A        43520               NIRCMD.DAT
2013-04-21 12:14:24 ....A           55               REGsetup.dat
2013-04-21 12:13:55 ....A          147               REGsetup2.dat
2010-10-21 14:15:22 ....A        98816               SED.DAT
2013-04-22 07:04:55 ....A         1720               services.dat
2013-02-01 04:13:58 ....A        57344               SHORTCUT.DAT
2012-12-07 20:27:02 ....A       163328               erunt/ERDNT.E_E
2012-12-07 20:27:02 ....A         2815               erunt/ERDNTDOS.LOC
2012-12-07 20:27:02 ....A         3275               erunt/ERDNTWIN.LOC
2012-12-07 20:27:02 ....A         4090               erunt/ERUNT.LOC
2012-12-07 20:27:02 ....A       157696       152207  erunt/ERUNT.EXE
2013-04-30 02:00:01 ....A            0            0  temp/null.txt
2013-05-07 02:17:37 D....            0            0  temp
2013-05-07 02:17:37 D....            0            0  erunt
------------------- ----- ------------ ------------  ------------------------
                               1231868       486614  76 files, 2 folders
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

everything is OK