MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Packer / Compiler

Sections

Data Directory

StringTable 000004b0

VS_FIXEDFILEINFO

offsetsizetypecomment
057344EXE07/22/2007 02:33:05#
15c115HTM#
e000488610BINoverlay data past EOF#
Scanning the drive for archives:
1 file, 545954 bytes (534 KiB)


--
Type = 7z
Offset = 57628
Physical Size = 488326
Headers Size = 1712
Method = LZMA:1536k BCJ
Solid = +
Blocks = 2

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2012-12-07 16:27:02 ....A          565       334407  erunt/ERUNT.EXE.manifest
2013-04-21 07:09:45 ....A        37373               ask.bat
2013-04-21 21:31:54 ....A        15542               chrome.bat
2013-04-01 20:03:09 ....A         1825               delfolders.bat
2012-12-08 10:22:00 ....A          732               ev_clear.bat
2013-04-21 07:13:35 ....A       224236               firefox.bat
2012-12-08 10:50:23 ....A         1256               FWPolicy.bat
2013-05-06 22:18:44 ....A        14028               get.bat
2013-04-21 07:58:12 ....A        29803               iexplore.bat
2013-05-06 22:19:06 ....A        11837               JRT.bat
2013-01-15 20:45:43 ....A        14243               medfos.bat
2013-04-29 21:52:41 ....A        81579               misc.bat
2013-04-21 08:18:13 ....A         9763               modules.bat
2013-04-29 07:07:30 ....A        29565               prelim.bat
2013-04-03 10:54:40 ....A         5379               runvalues.bat
2013-04-21 08:21:14 ....A        13025               searchlnk.bat
2013-01-21 22:01:34 ....A         1040               TDL4.bat
2013-02-02 21:34:38 ....A          370               clean_shortcut.vbs
2012-12-07 16:27:02 ....A        31952               erunt/README.TXT
2013-01-23 21:52:12 ....A          100               sednewline.txt
2013-04-29 21:54:05 ....A        12866               badFOLDERS.cfg
2013-04-29 21:19:38 ....A          117               badFOLDERScom.cfg
2013-04-22 03:10:02 ....A          711               badFOLDERSstart.cfg
2013-03-31 03:35:37 ....A          168               badLNK.cfg
2013-04-29 21:51:56 ....A         3847               badvalues.cfg
2013-04-29 07:18:32 ....A          128               browsermngr_keys.cfg
2012-12-08 11:32:57 ....A           94               browsermngr_values.cfg
2013-04-29 07:19:37 ....A          174               CHRregkey_x64.cfg
2013-04-29 07:19:45 ....A          107               CHRregkey_x86.cfg
2013-04-29 21:18:32 ....A         3194               CHR_extensions.cfg
2013-04-21 07:24:55 ....A           38               defaultscope.cfg
2013-04-04 23:41:13 ....A          159               FFwhtlist.cfg
2013-04-22 23:41:31 ....A           86               IEwhtlst.cfg
2013-04-01 20:16:07 ....A         2655               REGhcr.cfg
2013-03-23 20:14:07 ....A           16               REGhkcu_and_hklm_allow.cfg
2013-05-06 22:18:08 ....A         1434               REGhkcu_and_hklm_software.cfg
2013-04-21 21:33:22 ....A          892               REGhkcu_software_appdatalow.cfg
2013-04-21 21:34:13 ....A         1870               REGhkcu_software_microsoft.cfg
2013-04-17 23:22:19 ....A        33349               REGhklm_software_classes.cfg
2013-03-11 22:06:04 ....A         6861               REGhklm_software_microsoft.cfg
2013-04-01 19:40:23 ....A         1816               REGhklm_software_wow6432node.cfg
2013-04-21 08:19:57 ....A          211               runvalues_x64.cfg
2013-04-21 08:15:02 ....A          129               runvalues_x86.cfg
2013-04-29 06:19:11 ....A         3078               askCLSID.dat
2013-04-29 07:13:31 ....A          488               askregkey_x64.dat
2013-04-29 07:14:02 ....A          260               askregkey_x86.dat
2013-04-29 07:16:07 ....A          424               askregvalue_x64.dat
2013-04-29 07:16:22 ....A          345               askregvalue_x86.dat
2013-04-29 07:16:34 ....A           22               askservices.dat
2013-03-30 00:47:16 ....A          118               badAPPINIT.dat
2013-04-29 21:13:52 ....A        20878               BHO_clsid.dat
2005-02-27 09:40:46 ....A        45056               CHOICE.DAT
2012-12-07 16:27:02 ....A        17920               CUT.DAT
2012-12-07 16:27:02 ....A          119               FFbrowsermngr.dat
2013-04-29 21:17:02 ....A         6614               FFextensions.dat
2012-12-07 16:27:02 ....A           75               FFplugins.dat
2013-04-29 21:51:25 ....A         3540               FFprefs.dat
2013-04-29 07:21:18 ....A          177               FFregkey_x64.dat
2013-04-29 07:21:28 ....A          109               FFregkey_x86.dat
2013-04-17 00:27:39 ....A         1351               FFXML.dat
2013-04-29 21:56:23 ....A          605               FFXPI.dat
2013-04-29 21:48:12 ....A         2278               FWCLSID.dat
2013-04-19 21:34:23 ....A          292               modules.dat
2013-01-23 22:19:43 ....A          178               moduleservices.dat
2012-12-14 20:36:09 ....A        43520               NIRCMD.DAT
2013-04-21 08:14:24 ....A           55               REGsetup.dat
2013-04-21 08:13:55 ....A          147               REGsetup2.dat
2010-10-21 10:15:22 ....A        98816               SED.DAT
2013-04-22 03:04:55 ....A         1720               services.dat
2013-02-01 00:13:58 ....A        57344               SHORTCUT.DAT
2012-12-07 16:27:02 ....A       163328               erunt/ERDNT.E_E
2012-12-07 16:27:02 ....A         2815               erunt/ERDNTDOS.LOC
2012-12-07 16:27:02 ....A         3275               erunt/ERDNTWIN.LOC
2012-12-07 16:27:02 ....A         4090               erunt/ERUNT.LOC
2012-12-07 16:27:02 ....A       157696       152207  erunt/ERUNT.EXE
2013-04-29 22:00:01 ....A            0            0  temp/null.txt
2013-05-06 22:17:37 D....            0            0  temp
2013-05-06 22:17:37 D....            0            0  erunt
------------------- ----- ------------ ------------  ------------------------
2013-05-06 22:19:06            1231868       486614  76 files, 2 folders
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

everything is OK