MZ Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 52 65  |........!..L.!Re|
00000010: 71 75 69 72 65 20 57 69  6e 64 6f 77 73 0d 0a 24  |quire Windows..$|

PE Header

Packer / Compiler

Sections

Data Directory

StringTable 000004b0

VS_FIXEDFILEINFO

offsetsizetypecomment
091136EXE06/27/2010 07:06:38#
15c115HTM#
16400925125BINoverlay data past EOF#
Scanning the drive for archives:
1 file, 1016261 bytes (993 KiB)


--
Type = 7z
Offset = 91470
Physical Size = 924791
Headers Size = 2298
Method = LZMA:21 BCJ
Solid = +
Blocks = 2

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2012-12-08 07:27:02 ....A          565       770286  erunt/ERUNT.EXE.manifest
2014-04-06 05:12:38 ....A        29635               ask.bat
2014-04-06 05:12:44 ....A        13963               chrome.bat
2014-04-06 05:12:51 ....A         1813               delfolders.bat
2013-07-10 00:21:16 ....A           85               delorphans.bat
2014-04-06 05:13:01 ....A          719               ev_clear.bat
2014-04-06 05:13:06 ....A       152733               firefox.bat
2014-04-06 05:13:11 ....A         1226               FWPolicy.bat
2014-04-06 05:51:21 ....A        15919               get.bat
2014-04-06 05:13:18 ....A        31401               iexplore.bat
2014-04-06 05:14:37 ....A        10161               JRT.bat
2014-04-06 05:14:43 ....A        18670               medfos.bat
2014-04-06 05:14:49 ....A       154678               misc.bat
2014-04-06 05:14:54 ....A         8104               modules.bat
2014-04-06 05:14:59 ....A        39458               prelim.bat
2014-04-06 05:30:02 ....A         9516               runvalues.bat
2014-04-06 05:15:07 ....A        24738               searchlnk.bat
2014-04-06 05:15:13 ....A         1230               TDL4.bat
2013-02-03 12:34:40 ....A          370               clean_shortcut.vbs
2014-04-06 04:31:19 ....A           13               currentmd5.txt
2012-12-08 07:27:02 ....A        31952               erunt/README.TXT
2013-01-24 12:52:14 ....A          100               sednewline.txt
2013-09-02 00:20:59 ....A          144               appinit64_null.reg
2013-08-29 02:30:41 ....A          132               appinit_null.reg
2013-10-15 23:14:27 ....A          414               CHR_open_x64.reg
2013-10-15 23:19:59 ....A          402               CHR_open_x86.reg
2013-08-22 03:41:47 ....A          386               datamngr_del.reg
2013-10-15 23:13:50 ....A          388               FF_open_x64.reg
2013-10-15 23:19:21 ....A          376               FF_open_x86.reg
2013-10-15 23:15:19 ....A          388               IE_open_x64.reg
2013-10-15 23:22:54 ....A          388               IE_open_x86.reg
2014-04-06 04:26:20 ....A        18307               badFOLDERS.cfg
2013-10-06 06:30:34 ....A          119               badFOLDERScom.cfg
2014-03-23 21:19:41 ....A         1007               badFOLDERSstart.cfg
2014-02-04 05:57:38 ....A          221               badLNK.cfg
2014-03-23 21:20:12 ....A         4583               badvalues.cfg
2013-04-29 22:18:34 ....A          128               browsermngr_keys.cfg
2012-12-09 02:32:58 ....A           94               browsermngr_values.cfg
2013-04-29 22:19:38 ....A          174               CHRregkey_x64.cfg
2013-04-29 22:19:46 ....A          107               CHRregkey_x86.cfg
2014-03-23 21:20:48 ....A         6866               CHR_extensions.cfg
2013-04-21 22:24:56 ....A           38               defaultscope.cfg
2013-04-05 14:41:14 ....A          159               FFwhtlist.cfg
2013-04-23 14:41:32 ....A           86               IEwhtlst.cfg
2013-09-12 07:37:49 ....A         8130               REGhcr.cfg
2013-07-09 07:37:54 ....A           48               REGhkcu_and_hklm_allow.cfg
2014-02-04 06:29:17 ....A         3377               REGhkcu_and_hklm_software.cfg
2013-11-05 22:23:48 ....A         3025               REGhkcu_software_appdatalow.cfg
2014-01-08 02:07:18 ....A         1664               REGhkcu_software_microsoft.cfg
2013-11-05 22:20:01 ....A        36278               REGhklm_software_classes.cfg
2013-11-05 22:21:04 ....A           79               REGISTRYUSERSID.cfg
2013-04-21 23:19:58 ....A          211               runvalues_x64.cfg
2013-04-21 23:15:04 ....A          129               runvalues_x86.cfg
2013-11-05 22:22:15 ....A           45               serviceseventlog.cfg
2013-11-05 22:19:47 ....A         1718               APPID_clsid.dat
2013-11-05 22:19:27 ....A         1599               APPID_files.dat
2013-09-12 07:36:00 ....A           84               APPPATHS.dat
2013-08-02 22:26:50 ....A           78               APPROVEDEXTENSIONS_clsid.dat
2013-07-11 20:28:28 ....A         3158               askCLSID.dat
2013-04-29 22:13:32 ....A          488               askregkey_x64.dat
2013-04-29 22:14:04 ....A          260               askregkey_x86.dat
2013-04-29 22:16:08 ....A          424               askregvalue_x64.dat
2013-04-29 22:16:24 ....A          345               askregvalue_x86.dat
2013-07-08 20:10:58 ....A           30               askservices.dat
2014-03-23 21:19:10 ....A          174               badAPPINIT.dat
2014-03-23 21:21:58 ....A        30558               BHO_clsid.dat
2014-03-23 21:21:25 ....A         1459               BHO_name.dat
2005-02-28 00:40:46 ....A        45056               CHOICE.DAT
2014-01-01 09:17:59 ....A        13038               CLSID_clsid.dat
2012-12-08 07:27:02 ....A        17920               CUT.DAT
2013-11-05 22:20:33 ....A         3836               ELEVATIONPOLICY_clsid.dat
2013-08-02 15:39:08 ....A           16               EXT.dat
2012-12-08 07:27:02 ....A          119               FFbrowsermngr.dat
2014-03-23 21:22:13 ....A        10561               FFextensions.dat
2013-11-05 22:17:50 ....A          353               FFpluginREG.dat
2012-12-08 07:27:02 ....A           75               FFplugins.dat
2014-03-23 21:21:07 ....A         3653               FFprefs.dat
2013-04-29 22:21:20 ....A          177               FFregkey_x64.dat
2013-04-29 22:21:30 ....A          109               FFregkey_x86.dat
2014-03-23 21:19:25 ....A         1512               FFXML.dat
2014-03-23 21:20:29 ....A         1433               FFXPI.dat
2013-08-29 03:15:27 ....A         6957               FWCLSID.dat
2013-08-22 03:06:01 ....A           15               IFEO.dat
2013-11-05 22:21:34 ....A         5598               INTERFACE_clsid.dat
2013-11-05 22:24:21 ....A          277               MENUEXT.dat
2013-10-15 19:02:40 ....A          392               modules.dat
2013-01-24 13:19:44 ....A          178               moduleservices.dat
2012-12-15 11:36:10 ....A        43520               NIRCMD.DAT
2013-08-02 14:41:12 ....A           33               NOTIFY.dat
2013-09-12 07:38:33 ....A          878               PREAPPROVED_clsid.dat
2014-01-08 02:06:59 ....A          141               PRODUCTS.dat
2014-01-08 01:58:54 ....A         1732               S1518COMPONENTS.dat
2010-10-22 01:15:22 ....A        98816               SED.DAT
2014-04-06 04:32:27 ....A         4173               services.dat
2013-11-05 22:23:16 ....A         1518               SETTINGS_clsid.dat
2013-02-01 15:14:00 ....A        57344               SHORTCUT.DAT
2014-01-01 09:18:15 ....A         1638               STATS_clsid.dat
2014-01-08 02:05:48 ....A         7685               TRACING.dat
2013-11-05 22:21:17 ....A         3518               TYPELIB_clsid.dat
2014-01-08 02:06:06 ....A        14243               UNINSTALL.dat
2013-08-02 14:37:58 ....A          100               UpgradeCodes.dat
2013-08-08 08:46:04 ....A       401408               WGET.DAT
2014-02-04 06:00:17 ....A          502               WOW6432NODE.dat
2012-12-08 07:27:02 ....A       163328               erunt/ERDNT.E_E
2012-12-08 07:27:02 ....A         2815               erunt/ERDNTDOS.LOC
2012-12-08 07:27:02 ....A         3275               erunt/ERDNTWIN.LOC
2012-12-08 07:27:02 ....A         4090               erunt/ERUNT.LOC
2012-12-08 07:27:02 ....A       157696       152207  erunt/ERUNT.EXE
2014-04-06 05:17:36 ....A            0            0  temp/null.txt
2014-04-06 05:17:36 D....            0            0  temp
2014-04-06 04:25:43 D....            0            0  erunt
------------------- ----- ------------ ------------  ------------------------
2014-04-06 05:51:21            1755045       922493  109 files, 2 folders
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

everything is OK