MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Packer / Compiler

Sections

Data Directory

offsetsizetypecomment
0120832EXE02/17/2012 14:55:21#
15c115HTM#
1f58651207RARPassword Protected:Encrypted Headers!#
2bd8d298609BINoverlay data past EOF#
Scanning the drive for archives:
1 file, 478206 bytes (467 KiB)


--
Type = Rar
Offset = 128390
Physical Size = 349816
Solid = -
Blocks = 3
Multivolume = -
Volumes = 1

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2016-12-25 08:41:44 ....A        64512        35598  mHNXiZ.exe
2016-12-25 08:41:44 ....A       311367       311367  x
2016-12-25 08:41:44 ....A       284982          951  kson.bmp
------------------- ----- ------------ ------------  ------------------------
2016-12-25 08:41:44             660861       347916  3 files
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] can't find file_offset of VA 0x2c42c

[!] string size(59428) > stringtable size(556). truncated to 554

[!] cannot convert "!W0\xFA\x0Fk(1yFF\xEB\f\x05eF"... to UTF-16

[!] string size(72682) > stringtable size(974). truncated to 972

[!] cannot convert "\fNWh\x82\xA8Z9Fx~]\xE87\xF0\x8A"... to UTF-16

[!] string size(66164) > stringtable size(530). truncated to 528

[!] cannot convert "J\x1D;\x81\xC9\xBE(^\xD5S\xD8W\x95\x1CT&"... to UTF-16

[!] string size(15490) > stringtable size(776). truncated to 774

[!] cannot convert "\x14\x8D\x88\xEE85y\xAE\xBE\x89A\x02\xE7\xF6F6"... to UTF-16

[!] string size(61442) > stringtable size(380). truncated to 378

[!] cannot convert "\x8B\x93?\xB6\xD1\xF0\xA5t\x8A\x12\xEB\x03o8\xE0\xF9"... to UTF-16

[!] string size(45506) > stringtable size(102). truncated to 100

[!] cannot convert "\xE2\x8B\x12\x85\xC5+l\xFEi\xE3WX\xE2\xF4OB"... to UTF-16

[?] can't find file_offset of VA 0x14bb0