MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Packer / Compiler

Sections

Data Directory

StringTable 080403a8

VS_FIXEDFILEINFO

Signers (1)

issuer: /C=US/O=Symantec Corporation/OU=Symantec Trust Network/CN=Symantec Class 3 SHA256 Code Signing CA
serial: 704EE79F856A67016F012541A75F6446

Certificates (4)

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            16:88:f0:39:25:5e:63:8e:69:14:39:07:e6:33:0b
        Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
        Validity
            Not Before: Dec 31 00:00:00 2015 GMT
            Not After : Jul  9 18:40:36 2019 GMT
        Subject: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO SHA-1 Time Stamping Signer
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:e9:e9:3d:df:d7:37:08:c9:1e:38:b2:52:53:42:
                    6d:22:f1:b1:c4:06:04:6b:9e:fd:82:74:50:43:7d:
                    c6:a0:bb:1f:4e:f9:02:71:26:b1:ef:43:d8:83:8c:
                    48:fc:e7:0f:97:7a:9a:eb:9c:de:a6:a3:0e:3b:1c:
                    44:18:75:8e:78:a5:17:69:fe:49:18:a4:e2:bb:5c:
                    4e:fe:8e:2a:54:7a:50:f0:d5:f6:cc:91:e7:99:79:
                    d7:de:79:94:d7:96:33:fe:0e:83:be:22:bf:63:16:
                    2c:a3:dd:28:1b:af:3d:ab:ea:97:d2:f1:bf:04:10:
                    e7:3d:48:45:fd:1f:68:65:c1:7f:59:99:69:c0:22:
                    31:0c:62:6e:a7:5c:65:01:21:b0:63:c4:22:18:27:
                    ee:e6:fc:d2:00:3d:47:2e:a8:b8:86:56:5d:04:dc:
                    13:17:25:6e:1c:df:44:0f:15:cd:b7:db:a5:57:76:
                    42:6f:00:68:82:99:d2:e3:c1:de:f0:8b:94:57:4c:
                    ec:08:90:22:21:ce:22:2b:98:0c:42:e6:42:93:94:
                    98:93:ef:fd:06:d9:3f:bc:5b:9b:54:3c:20:b1:ee:
                    6a:d6:47:7a:c5:ab:80:e9:30:9a:de:f1:a4:3f:55:
                    4d:0a:09:34:8a:75:29:d2:69:ad:97:0f:50:bf:f8:
                    ca:09
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:DA:ED:64:74:14:9C:14:3C:AB:DD:99:A9:BD:5B:28:4D:8B:3C:C9:D8

            X509v3 Subject Key Identifier: 
                8E:6B:2D:33:6B:F4:33:A7:93:B3:13:9A:A5:E0:0A:F7:12:35:6A:88
            X509v3 Key Usage: critical
                Digital Signature, Non Repudiation
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Extended Key Usage: critical
                Time Stamping
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.usertrust.com/UTN-USERFirst-Object.crl

            Authority Information Access: 
                OCSP - URI:http://ocsp.usertrust.com

    Signature Algorithm: sha1WithRSAEncryption
         ba:33:24:40:40:8c:7c:db:58:9f:b3:60:98:b2:f5:c0:31:fe:
         eb:1f:6e:50:f6:0a:e0:e4:e6:81:ad:26:87:a2:df:fd:b3:da:
         f4:73:f3:00:fb:29:1b:89:1b:15:3e:db:6b:52:93:2b:c4:ac:
         39:81:d7:3c:67:57:9a:39:36:e0:28:08:9a:e3:39:4f:9b:89:
         09:7f:7b:c5:61:7f:59:89:32:25:0a:6a:ae:1a:3e:f0:a2:27:
         a8:b6:c3:b8:87:f7:16:04:48:41:3d:5c:d8:ec:9f:4d:20:31:
         04:d9:65:a1:ed:cd:69:07:53:16:3d:dd:36:02:0a:88:eb:40:
         e5:06:30:0b:b8:16:4b:dc:ef:bc:55:09:ff:c6:3e:12:2e:76:
         b3:dc:ce:42:ef:f9:76:57:e1:b7:0a:05:40:98:58:9a:5d:71:
         16:93:71:8c:65:81:ea:6f:f3:89:f7:fb:73:ad:b4:e7:bf:d9:
         8e:6f:aa:0b:4f:25:f3:b8:e1:d5:dd:75:98:68:81:f8:aa:c0:
         d1:80:c2:c4:c4:39:89:c1:f6:c9:9e:6c:d7:74:f9:d9:97:f8:
         4f:c2:9a:0a:cd:5e:8f:f8:19:e9:e0:a5:9f:c4:f0:92:21:e6:
         2d:79:25:c9:22:f9:c3:f0:3a:84:57:ad:3a:16:f4:63:94:10:
         1d:5d:d0:c6

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            25:0c:e8:e0:30:61:2e:9f:2b:89:f7:05:4d:7c:f8:fd
        Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
        Validity
            Not Before: Nov  8 00:00:00 2006 GMT
            Not After : Nov  7 23:59:59 2021 GMT
        Subject: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:af:24:08:08:29:7a:35:9e:60:0c:aa:e7:4b:3b:
                    4e:dc:7c:bc:3c:45:1c:bb:2b:e0:fe:29:02:f9:57:
                    08:a3:64:85:15:27:f5:f1:ad:c8:31:89:5d:22:e8:
                    2a:aa:a6:42:b3:8f:f8:b9:55:b7:b1:b7:4b:b3:fe:
                    8f:7e:07:57:ec:ef:43:db:66:62:15:61:cf:60:0d:
                    a4:d8:de:f8:e0:c3:62:08:3d:54:13:eb:49:ca:59:
                    54:85:26:e5:2b:8f:1b:9f:eb:f5:a1:91:c2:33:49:
                    d8:43:63:6a:52:4b:d2:8f:e8:70:51:4d:d1:89:69:
                    7b:c7:70:f6:b3:dc:12:74:db:7b:5d:4b:56:d3:96:
                    bf:15:77:a1:b0:f4:a2:25:f2:af:1c:92:67:18:e5:
                    f4:06:04:ef:90:b9:e4:00:e4:dd:3a:b5:19:ff:02:
                    ba:f4:3c:ee:e0:8b:eb:37:8b:ec:f4:d7:ac:f2:f6:
                    f0:3d:af:dd:75:91:33:19:1d:1c:40:cb:74:24:19:
                    21:93:d9:14:fe:ac:2a:52:c7:8f:d5:04:49:e4:8d:
                    63:47:88:3c:69:83:cb:fe:47:bd:2b:7e:4f:c5:95:
                    ae:0e:9d:d4:d1:43:c0:67:73:e3:14:08:7e:e5:3f:
                    9f:73:b8:33:0a:cf:5d:3f:34:87:96:8a:ee:53:e8:
                    25:15
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl.verisign.com/pca3.crl

            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                  CPS: https://www.verisign.com/cps

            X509v3 Subject Key Identifier: 
                7F:D3:65:A7:C2:DD:EC:BB:F0:30:09:F3:43:39:FA:02:AF:33:31:33
            1.3.6.1.5.5.7.1.12: 
                0_.].[0Y0W0U..image/gif0!0.0...+..............k...j.H.,{..0%.#http://logo.verisign.com/vslogo.gif
            Authority Information Access: 
                OCSP - URI:http://ocsp.verisign.com

            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication, Code Signing, Netscape Server Gated Crypto, 2.16.840.1.113733.1.8.1
    Signature Algorithm: sha1WithRSAEncryption
         13:02:dd:f8:e8:86:00:f2:5a:f8:f8:20:0c:59:88:62:07:ce:
         ce:f7:4e:f9:bb:59:a1:98:e5:e1:38:dd:4e:bc:66:18:d3:ad:
         eb:18:f2:0d:c9:6d:3e:4a:94:20:c3:3c:ba:bd:65:54:c6:af:
         44:b3:10:ad:2c:6b:3e:ab:d7:07:b6:b8:81:63:c5:f9:5e:2e:
         e5:2a:67:ce:cd:33:0c:2a:d7:89:56:03:23:1f:b3:be:e8:3a:
         08:59:b4:ec:45:35:f7:8a:5b:ff:66:cf:50:af:c6:6d:57:8d:
         19:78:b7:b9:a2:d1:57:ea:1f:9a:4b:af:ba:c9:8e:12:7e:c6:
         bd:ff

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            70:4e:e7:9f:85:6a:67:01:6f:01:25:41:a7:5f:64:46
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=Symantec Corporation, OU=Symantec Trust Network, CN=Symantec Class 3 SHA256 Code Signing CA
        Validity
            Not Before: May 14 00:00:00 2015 GMT
            Not After : Aug 12 23:59:59 2018 GMT
        Subject: C=CN, ST=Beijing, L=Beijing, O=Beijing Sogou Information Service Co., Ltd., OU=Search business Division, CN=Beijing Sogou Information Service Co., Ltd.
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:b1:11:13:e2:f4:f4:85:41:6b:ae:74:f3:0a:c2:
                    af:15:ce:18:ad:7c:d6:0c:ce:ef:c0:d8:87:80:63:
                    4e:1f:2e:bf:86:4d:6b:33:b4:e0:d0:d5:a3:6b:41:
                    10:58:73:94:f3:3b:e4:a6:58:47:00:49:cb:4f:aa:
                    99:b2:a1:36:f2:4f:3f:9f:82:49:e6:6d:5e:fc:af:
                    85:6b:2c:17:ff:9f:6d:31:bf:e7:d8:71:69:7b:d4:
                    3b:a1:15:93:1a:dd:fc:9b:4d:c8:ab:11:7f:f1:c0:
                    80:ef:dc:84:dd:16:d8:ec:4f:c6:07:80:f9:86:b8:
                    bc:03:d2:5e:76:fd:95:5b:63:32:a8:b9:1f:d7:9f:
                    b6:87:90:e8:00:13:8a:75:e1:d8:62:fd:2b:95:6b:
                    49:04:29:95:0a:fe:88:36:8b:30:e7:cf:3a:e7:36:
                    c8:27:b2:3e:64:39:99:3e:e5:d5:b3:9f:0e:a2:02:
                    52:d0:78:80:a7:d7:c7:6b:25:ee:f9:0c:d1:ba:a7:
                    e1:e1:a4:b6:65:a6:5f:76:b9:0d:d3:02:87:7a:c1:
                    b8:f4:58:0f:1e:55:ed:20:53:87:ca:a0:9f:de:72:
                    ea:bd:84:0e:86:7f:57:40:68:10:28:23:7e:bb:64:
                    f7:fc:b7:91:c0:d3:18:e2:5c:f2:08:98:a1:ef:66:
                    f1:05
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: 
                CA:FALSE
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://sv.symcb.com/sv.crl

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.113733.1.7.23.3
                  CPS: https://d.symcb.com/cps
                  User Notice:
                    Explicit Text: https://d.symcb.com/rpa

            X509v3 Extended Key Usage: 
                Code Signing
            Authority Information Access: 
                OCSP - URI:http://sv.symcd.com
                CA Issuers - URI:http://sv.symcb.com/sv.crt

            X509v3 Authority Key Identifier: 
                keyid:96:3B:53:F0:79:33:97:AF:7D:83:EF:2E:2B:CC:CA:B7:86:1E:72:66

            X509v3 Subject Key Identifier: 
                D1:76:1A:E3:A7:F0:08:9C:C8:BD:36:BE:84:D6:41:15:B8:37:37:91
    Signature Algorithm: sha256WithRSAEncryption
         65:65:5a:7c:97:5c:59:ba:4c:1f:3b:c5:c4:e1:e9:94:86:98:
         1f:e2:9b:3c:8d:9c:b6:11:dc:2d:ee:f4:33:e8:67:27:aa:10:
         5e:0c:08:2e:55:4a:d7:44:b5:9d:0c:20:f5:76:05:a8:3d:ac:
         6d:0d:8d:b1:ac:3e:bb:1f:4f:ae:68:9d:e9:1b:5e:4c:0d:fb:
         63:ad:04:e4:eb:55:d2:56:e3:62:0e:8c:f7:b4:68:bc:a5:13:
         93:f8:ab:74:8b:6f:c4:75:d7:fa:9e:ea:5d:da:8d:b5:99:ce:
         3c:43:d3:15:30:09:bf:3b:b6:95:bd:72:36:45:1d:47:fd:5a:
         7d:aa:7e:54:5e:cb:e8:8c:ee:aa:52:20:74:01:f7:8f:a1:dc:
         3a:a7:db:af:a2:aa:7e:24:56:93:0c:33:65:b6:72:60:67:7e:
         bc:48:04:3b:6d:83:e5:6e:9f:b3:a1:3b:b6:65:9f:de:44:f0:
         33:86:de:23:14:08:91:a9:38:71:ca:06:f5:17:6d:75:b7:c1:
         32:c4:30:f8:1f:e6:6d:28:af:df:03:e1:b5:26:05:1f:bc:c1:
         48:57:18:4e:b5:9e:e9:68:f8:ac:91:3a:68:b2:93:af:f6:aa:
         d4:fe:4d:19:1f:d1:3d:04:a1:b0:0b:c6:a0:87:a3:64:a5:85:
         20:57:20:20

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            3d:78:d7:f9:76:49:60:b2:61:7d:f4:f0:1e:ca:86:2a
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
        Validity
            Not Before: Dec 10 00:00:00 2013 GMT
            Not After : Dec  9 23:59:59 2023 GMT
        Subject: C=US, O=Symantec Corporation, OU=Symantec Trust Network, CN=Symantec Class 3 SHA256 Code Signing CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:97:83:1e:00:16:af:2c:b1:d2:08:c4:d7:68:93:
                    51:60:1e:71:f6:e2:47:b4:db:58:4d:23:62:6a:b4:
                    bf:5a:1b:51:f7:a3:0d:18:77:68:bb:d8:36:ab:2f:
                    21:50:da:9e:f3:e7:5f:27:4e:0b:c2:97:c8:09:70:
                    93:a9:da:5c:0d:4e:a4:0d:91:a0:b4:ec:14:ce:91:
                    72:54:2e:ce:a3:db:44:e9:52:1b:3f:41:3c:ca:4a:
                    e4:aa:c0:e8:39:ab:53:cc:21:d0:cc:cf:7f:9b:e6:
                    c2:cc:58:6a:82:15:ee:3d:36:cf:1c:c5:97:07:24:
                    8e:f1:7b:be:31:2d:3d:6e:dc:b5:99:42:9f:4b:61:
                    95:5f:1c:70:ee:17:7d:db:8b:e5:61:89:78:c7:68:
                    1b:af:11:78:1a:98:ae:c4:55:47:53:d9:b3:32:d6:
                    a1:0e:46:40:c5:97:92:8a:d1:53:a7:99:5b:85:35:
                    57:d3:ea:93:62:61:20:0a:c7:30:77:24:11:4d:62:
                    83:b6:ba:7b:68:82:31:ee:65:ca:df:f9:d5:8d:b2:
                    35:dc:8c:2b:6f:6a:72:5c:60:84:9c:f2:0c:94:5e:
                    c0:56:52:00:48:cc:d3:f8:a5:7d:de:2f:d7:13:e4:
                    38:a8:84:d5:46:b8:13:86:c2:1b:9d:ea:5a:38:dd:
                    9b:db
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            Authority Information Access: 
                OCSP - URI:http://s2.symcb.com

            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.113733.1.7.23.3
                  CPS: http://www.symauth.com/cps
                  User Notice:
                    Explicit Text: http://www.symauth.com/rpa

            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://s1.symcb.com/pca3-g5.crl

            X509v3 Extended Key Usage: 
                TLS Web Client Authentication, Code Signing
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Subject Alternative Name: 
                DirName:/CN=SymantecPKI-1-567
            X509v3 Subject Key Identifier: 
                96:3B:53:F0:79:33:97:AF:7D:83:EF:2E:2B:CC:CA:B7:86:1E:72:66
            X509v3 Authority Key Identifier: 
                keyid:7F:D3:65:A7:C2:DD:EC:BB:F0:30:09:F3:43:39:FA:02:AF:33:31:33

    Signature Algorithm: sha256WithRSAEncryption
         13:85:1a:1e:69:a9:37:f7:a0:bd:a4:af:7e:1d:61:53:fe:9d:
         8c:5e:0c:a6:75:1e:78:17:23:dd:fd:ec:1a:03:55:39:fb:71:
         95:c7:65:5a:a7:8e:30:d2:44:5a:61:db:70:6f:da:21:05:c2:
         2e:73:ba:49:f1:d1:93:fe:5d:c9:cd:5e:03:e0:89:9e:3f:74:
         1e:d7:f7:38:8b:a9:d6:cf:bb:35:2f:33:58:a8:92:56:d1:c8:
         4d:3b:82:e6:79:84:16:fc:28:b0:b1:47:f3:1d:a2:3e:ee:87:
         d9:a6:7f:a4:56:a5:3f:ad:84:2e:29:de:7c:bc:a8:aa:a3:3d:
         04:01:ea:ba:93:a2:0e:50:22:29:17:4c:87:e4:3a:11:5f:d6:
         a4:25:89:9b:05:6b:2f:b4:c9:01:4c:27:7b:0b:ac:19:05:22:
         a0:60:15:3f:da:c9:fb:4d:4c:8f:fb:72:67:77:fd:27:94:c7:
         ba:35:0e:88:49:fe:8d:fd:28:af:4a:12:bd:0d:b3:97:05:de:
         44:0c:15:fa:36:2b:03:dc:c1:50:01:f1:a1:11:5d:14:e5:e2:
         bd:27:4b:54:be:2b:84:5e:0f:a6:c3:74:05:0a:ef:97:c3:89:
         22:b1:1f:77:f3:bd:cd:43:d4:f1:4c:a9:3f:b5:8b:84:af:64:
         f2:d0:14:21
pkcs7-signedData
  • 1
    • SHA1: nil
    • 1.3.6.1.4.1.311.2.1.4
      • #0
        • 1.3.6.1.4.1.311.2.1.15
          • :
            00 3c 00 3c 00 3c 00 4f  00 62 00 73 00 6f 00 6c  |.<.<.<.O.b.s.o.l|
            00 65 00 74 00 65 00 3e  00 3e 00 3e              |.e.t.e.>.>.>    |
        • SHA1
          • fd 5d b4 21 27 48 d5 34  25 8e 11 91 43 d6 cc 12  |.].!'H.4%...C...|
            0f 52 c2 bd                                       |.R..            |
    • Certificates
      • Certificate #0
        • 2
          • 16:88:F0:39:25:5E:63:8E:69:14:39:07:E6:33:0B
          • RSA-SHA1: nil
          • Issuer
            • C: US
            • ST: UT
            • L: Salt Lake City
            • O: The USERTRUST Network
            • OU: http://www.usertrust.com
            • CN: UTN-USERFirst-Object
          • 2015-12-31 00:00:00 UTC: 2019-07-09 18:40:36 UTC
          • Subject
            • C: GB
            • ST: Greater Manchester
            • L: Salford
            • O: COMODO CA Limited
            • CN: COMODO SHA-1 Time Stamping Signer
          • #5
            • rsaEncryption: nil
            • E9:E9:3D:DF:D7:37:08:C9:1E:38:B2:52:53:42:6D:22:
              F1:B1:C4:06:04:6B:9E:FD:82:74:50:43:7D:C6:A0:BB:
              1F:4E:F9:02:71:26:B1:EF:43:D8:83:8C:48:FC:E7:0F:
              97:7A:9A:EB:9C:DE:A6:A3:0E:3B:1C:44:18:75:8E:78:
              A5:17:69:FE:49:18:A4:E2:BB:5C:4E:FE:8E:2A:54:7A:
              50:F0:D5:F6:CC:91:E7:99:79:D7:DE:79:94:D7:96:33:
              FE:0E:83:BE:22:BF:63:16:2C:A3:DD:28:1B:AF:3D:AB:
              EA:97:D2:F1:BF:04:10:E7:3D:48:45:FD:1F:68:65:C1:
              7F:59:99:69:C0:22:31:0C:62:6E:A7:5C:65:01:21:B0:
              63:C4:22:18:27:EE:E6:FC:D2:00:3D:47:2E:A8:B8:86:
              56:5D:04:DC:13:17:25:6E:1C:DF:44:0F:15:CD:B7:DB:
              A5:57:76:42:6F:00:68:82:99:D2:E3:C1:DE:F0:8B:94:
              57:4C:EC:08:90:22:21:CE:22:2B:98:0C:42:E6:42:93:
              94:98:93:EF:FD:06:D9:3F:BC:5B:9B:54:3C:20:B1:EE:
              6A:D6:47:7A:C5:AB:80:E9:30:9A:DE:F1:A4:3F:55:4D:
              0A:09:34:8A:75:29:D2:69:AD:97:0F:50:BF:F8:CA:09
              : 0x010001
          • #6
            • authorityKeyIdentifier:
              da ed 64 74 14 9c 14 3c  ab dd 99 a9 bd 5b 28 4d  |..dt...<.....[(M|
              8b 3c c9 d8                                       |.<..            |
            • subjectKeyIdentifier:
              8e 6b 2d 33 6b f4 33 a7  93 b3 13 9a a5 e0 0a f7  |.k-3k.3.........|
              12 35 6a 88                                       |.5j.            |
            • keyUsage: true, 0xc0
            • basicConstraints
              • true
              • nil
            • extendedKeyUsage: true, timeStamping
            • crlDistributionPoints: http://crl.usertrust.com/UTN-USERFirst-Object.crl
            • authorityInfoAccess
              • OCSP: http://ocsp.usertrust.com
        • RSA-SHA1:
          ba 33 24 40 40 8c 7c db  58 9f b3 60 98 b2 f5 c0  |.3$@@.|.X..`....|
          31 fe eb 1f 6e 50 f6 0a  e0 e4 e6 81 ad 26 87 a2  |1...nP.......&..|
          df fd b3 da f4 73 f3 00  fb 29 1b 89 1b 15 3e db  |.....s...)....>.|
          6b 52 93 2b c4 ac 39 81  d7 3c 67 57 9a 39 36 e0  |kR.+..9....'......|
          16 04 48 41 3d 5c d8 ec  9f 4d 20 31 04 d9 65 a1  |..HA=\...M 1..e.|
          ed cd 69 07 53 16 3d dd  36 02 0a 88 eb 40 e5 06  |..i.S.=.6....@..|
          30 0b b8 16 4b dc ef bc  55 09 ff c6 3e 12 2e 76  |0...K...U...>..v|
          b3 dc ce 42 ef f9 76 57  e1 b7 0a 05 40 98 58 9a  |...B..vW....@.X.|
          5d 71 16 93 71 8c 65 81  ea 6f f3 89 f7 fb 73 ad  |]q..q.e..o....s.|
          b4 e7 bf d9 8e 6f aa 0b  4f 25 f3 b8 e1 d5 dd 75  |.....o..O%.....u|
          98 68 81 f8 aa c0 d1 80  c2 c4 c4 39 89 c1 f6 c9  |.h.........9....|
          9e 6c d7 74 f9 d9 97 f8  4f c2 9a 0a cd 5e 8f f8  |.l.t....O....^..|
          19 e9 e0 a5 9f c4 f0 92  21 e6 2d 79 25 c9 22 f9  |........!.-y%.".|
          c3 f0 3a 84 57 ad 3a 16  f4 63 94 10 1d 5d d0 c6  |..:.W.:..c...]..|
      • Certificate #1
        • 2
          • 25:0C:E8:E0:30:61:2E:9F:2B:89:F7:05:4D:7C:F8:FD
          • RSA-SHA1: nil
          • Issuer
            • C: US
            • O: VeriSign, Inc.
            • OU: Class 3 Public Primary Certification Authority
          • 2006-11-08 00:00:00 UTC: 2021-11-07 23:59:59 UTC
          • Subject
            • C: US
            • O: VeriSign, Inc.
            • OU: VeriSign Trust Network
            • OU: (c) 2006 VeriSign, Inc. - For authorized use only
            • CN: VeriSign Class 3 Public Primary Certification Authority - G5
          • #5
            • rsaEncryption: nil
            • AF:24:08:08:29:7A:35:9E:60:0C:AA:E7:4B:3B:4E:DC:
              7C:BC:3C:45:1C:BB:2B:E0:FE:29:02:F9:57:08:A3:64:
              85:15:27:F5:F1:AD:C8:31:89:5D:22:E8:2A:AA:A6:42:
              B3:8F:F8:B9:55:B7:B1:B7:4B:B3:FE:8F:7E:07:57:EC:
              EF:43:DB:66:62:15:61:CF:60:0D:A4:D8:DE:F8:E0:C3:
              62:08:3D:54:13:EB:49:CA:59:54:85:26:E5:2B:8F:1B:
              9F:EB:F5:A1:91:C2:33:49:D8:43:63:6A:52:4B:D2:8F:
              E8:70:51:4D:D1:89:69:7B:C7:70:F6:B3:DC:12:74:DB:
              7B:5D:4B:56:D3:96:BF:15:77:A1:B0:F4:A2:25:F2:AF:
              1C:92:67:18:E5:F4:06:04:EF:90:B9:E4:00:E4:DD:3A:
              B5:19:FF:02:BA:F4:3C:EE:E0:8B:EB:37:8B:EC:F4:D7:
              AC:F2:F6:F0:3D:AF:DD:75:91:33:19:1D:1C:40:CB:74:
              24:19:21:93:D9:14:FE:AC:2A:52:C7:8F:D5:04:49:E4:
              8D:63:47:88:3C:69:83:CB:FE:47:BD:2B:7E:4F:C5:95:
              AE:0E:9D:D4:D1:43:C0:67:73:E3:14:08:7E:E5:3F:9F:
              73:B8:33:0A:CF:5D:3F:34:87:96:8A:EE:53:E8:25:15
              : 0x010001
          • X509v3 extensions
            • basicConstraints: true, true
            • crlDistributionPoints: http://crl.verisign.com/pca3.crl
            • keyUsage: true, 6
            • certificatePolicies
              • anyPolicy
                • id-qt-cps: https://www.verisign.com/cps
            • subjectKeyIdentifier:
              7f d3 65 a7 c2 dd ec bb  f0 30 09 f3 43 39 fa 02  |..e......0..C9..|
              af 33 31 33                                       |.313            |
            • 1.3.6.1.5.5.7.1.12
              • image/gif
                • SHA1:
                  8f e5 d3 1a 86 ac 8d 8e  6b c3 cf 80 6a d4 48 18  |........k...j.H.|
                  2c 7b 19 2e                                       |,{..            |
                • http://logo.verisign.com/vslogo.gif
            • authorityInfoAccess
              • OCSP: http://ocsp.verisign.com
            • extendedKeyUsage
              • serverAuth: clientAuth, codeSigning, nsSGC, 2.16.840.1.113733.1.8.1
        • RSA-SHA1:
          13 02 dd f8 e8 86 00 f2  5a f8 f8 20 0c 59 88 62  |........Z.. .Y.b|
          07 ce ce f7 4e f9 bb 59  a1 98 e5 e1 38 dd 4e bc  |....N..Y....8.N.|
          66 18 d3 ad eb 18 f2 0d  c9 6d 3e 4a 94 20 c3 3c  |f........m>J. .<|
          ba bd 65 54 c6 af 44 b3  10 ad 2c 6b 3e ab d7 07  |..eT..D...,k>...|
          b6 b8 81 63 c5 f9 5e 2e  e5 2a 67 ce cd 33 0c 2a  |...c..^..*g..3.*|
          d7 89 56 03 23 1f b3 be  e8 3a 08 59 b4 ec 45 35  |..V.#....:.Y..E5|
          f7 8a 5b ff 66 cf 50 af  c6 6d 57 8d 19 78 b7 b9  |..[.f.P..mW..x..|
          a2 d1 57 ea 1f 9a 4b af  ba c9 8e 12 7e c6 bd ff  |..W...K.....~...|
      • Certificate #2
        • 2
          • 70:4E:E7:9F:85:6A:67:01:6F:01:25:41:A7:5F:64:46
          • RSA-SHA256: nil
          • Issuer
            • C: US
            • O: Symantec Corporation
            • OU: Symantec Trust Network
            • CN: Symantec Class 3 SHA256 Code Signing CA
          • 2015-05-14 00:00:00 UTC: 2018-08-12 23:59:59 UTC
          • Subject
            • C: CN
            • ST: Beijing
            • L: Beijing
            • O: Beijing Sogou Information Service Co., Ltd.
            • OU: Search business Division
            • CN: Beijing Sogou Information Service Co., Ltd.
          • #5
            • rsaEncryption: nil
            • B1:11:13:E2:F4:F4:85:41:6B:AE:74:F3:0A:C2:AF:15:
              CE:18:AD:7C:D6:0C:CE:EF:C0:D8:87:80:63:4E:1F:2E:
              BF:86:4D:6B:33:B4:E0:D0:D5:A3:6B:41:10:58:73:94:
              F3:3B:E4:A6:58:47:00:49:CB:4F:AA:99:B2:A1:36:F2:
              4F:3F:9F:82:49:E6:6D:5E:FC:AF:85:6B:2C:17:FF:9F:
              6D:31:BF:E7:D8:71:69:7B:D4:3B:A1:15:93:1A:DD:FC:
              9B:4D:C8:AB:11:7F:F1:C0:80:EF:DC:84:DD:16:D8:EC:
              4F:C6:07:80:F9:86:B8:BC:03:D2:5E:76:FD:95:5B:63:
              32:A8:B9:1F:D7:9F:B6:87:90:E8:00:13:8A:75:E1:D8:
              62:FD:2B:95:6B:49:04:29:95:0A:FE:88:36:8B:30:E7:
              CF:3A:E7:36:C8:27:B2:3E:64:39:99:3E:E5:D5:B3:9F:
              0E:A2:02:52:D0:78:80:A7:D7:C7:6B:25:EE:F9:0C:D1:
              BA:A7:E1:E1:A4:B6:65:A6:5F:76:B9:0D:D3:02:87:7A:
              C1:B8:F4:58:0F:1E:55:ED:20:53:87:CA:A0:9F:DE:72:
              EA:BD:84:0E:86:7F:57:40:68:10:28:23:7E:BB:64:F7:
              FC:B7:91:C0:D3:18:E2:5C:F2:08:98:A1:EF:66:F1:05
              : 0x010001
          • X509v3 extensions
            • basicConstraints
              • nil
            • keyUsage: true, 0x80
            • crlDistributionPoints: http://sv.symcb.com/sv.crl
            • certificatePolicies
              • 2.16.840.1.113733.1.7.23.3
                • #0
                  • id-qt-cps: https://d.symcb.com/cps
                  • id-qt-unotice: https://d.symcb.com/rpa
            • extendedKeyUsage: codeSigning
            • authorityInfoAccess
              • #0
                • OCSP: http://sv.symcd.com
                • caIssuers: http://sv.symcb.com/sv.crt
            • authorityKeyIdentifier:
              96 3b 53 f0 79 33 97 af  7d 83 ef 2e 2b cc ca b7  |.;S.y3..}...+...|
              86 1e 72 66                                       |..rf            |
            • subjectKeyIdentifier:
              d1 76 1a e3 a7 f0 08 9c  c8 bd 36 be 84 d6 41 15  |.v........6...A.|
              b8 37 37 91                                       |.77.            |
        • RSA-SHA256:
          65 65 5a 7c 97 5c 59 ba  4c 1f 3b c5 c4 e1 e9 94  |eeZ|.\Y.L.;.....|
          86 98 1f e2 9b 3c 8d 9c  b6 11 dc 2d ee f4 33 e8  |.....<.....-..3.|
          67 27 aa 10 5e 0c 08 2e  55 4a d7 44 b5 9d 0c 20  |g'..^...UJ.D... |
          f5 76 05 a8 3d ac 6d 0d  8d b1 ac 3e bb 1f 4f ae  |.v..=.m....>..O.|
          68 9d e9 1b 5e 4c 0d fb  63 ad 04 e4 eb 55 d2 56  |h...^L..c....U.V|
          e3 62 0e 8c f7 b4 68 bc  a5 13 93 f8 ab 74 8b 6f  |.b....h......t.o|
          c4 75 d7 fa 9e ea 5d da  8d b5 99 ce 3c 43 d3 15  |.u....].....
      • Certificate #3
        • 2
          • 3D:78:D7:F9:76:49:60:B2:61:7D:F4:F0:1E:CA:86:2A
          • RSA-SHA256: nil
          • Issuer
            • C: US
            • O: VeriSign, Inc.
            • OU: VeriSign Trust Network
            • OU: (c) 2006 VeriSign, Inc. - For authorized use only
            • CN: VeriSign Class 3 Public Primary Certification Authority - G5
          • 2013-12-10 00:00:00 UTC: 2023-12-09 23:59:59 UTC
          • Subject
            • C: US
            • O: Symantec Corporation
            • OU: Symantec Trust Network
            • CN: Symantec Class 3 SHA256 Code Signing CA
          • #5
            • rsaEncryption: nil
            • 97:83:1E:00:16:AF:2C:B1:D2:08:C4:D7:68:93:51:60:
              1E:71:F6:E2:47:B4:DB:58:4D:23:62:6A:B4:BF:5A:1B:
              51:F7:A3:0D:18:77:68:BB:D8:36:AB:2F:21:50:DA:9E:
              F3:E7:5F:27:4E:0B:C2:97:C8:09:70:93:A9:DA:5C:0D:
              4E:A4:0D:91:A0:B4:EC:14:CE:91:72:54:2E:CE:A3:DB:
              44:E9:52:1B:3F:41:3C:CA:4A:E4:AA:C0:E8:39:AB:53:
              CC:21:D0:CC:CF:7F:9B:E6:C2:CC:58:6A:82:15:EE:3D:
              36:CF:1C:C5:97:07:24:8E:F1:7B:BE:31:2D:3D:6E:DC:
              B5:99:42:9F:4B:61:95:5F:1C:70:EE:17:7D:DB:8B:E5:
              61:89:78:C7:68:1B:AF:11:78:1A:98:AE:C4:55:47:53:
              D9:B3:32:D6:A1:0E:46:40:C5:97:92:8A:D1:53:A7:99:
              5B:85:35:57:D3:EA:93:62:61:20:0A:C7:30:77:24:11:
              4D:62:83:B6:BA:7B:68:82:31:EE:65:CA:DF:F9:D5:8D:
              B2:35:DC:8C:2B:6F:6A:72:5C:60:84:9C:F2:0C:94:5E:
              C0:56:52:00:48:CC:D3:F8:A5:7D:DE:2F:D7:13:E4:38:
              A8:84:D5:46:B8:13:86:C2:1B:9D:EA:5A:38:DD:9B:DB
              : 0x010001
          • X509v3 extensions
            • authorityInfoAccess
              • OCSP: http://s2.symcb.com
            • basicConstraints
              • true
              • true: 0
            • certificatePolicies
              • 2.16.840.1.113733.1.7.23.3
                • #0
                  • id-qt-cps: http://www.symauth.com/cps
                  • id-qt-unotice: http://www.symauth.com/rpa
            • crlDistributionPoints: http://s1.symcb.com/pca3-g5.crl
            • extendedKeyUsage
              • clientAuth: codeSigning
            • keyUsage: true, 6
            • subjectAltName
              • CN: SymantecPKI-1-567
            • subjectKeyIdentifier:
              96 3b 53 f0 79 33 97 af  7d 83 ef 2e 2b cc ca b7  |.;S.y3..}...+...|
              86 1e 72 66                                       |..rf            |
            • authorityKeyIdentifier:
              7f d3 65 a7 c2 dd ec bb  f0 30 09 f3 43 39 fa 02  |..e......0..C9..|
              af 33 31 33                                       |.313            |
        • RSA-SHA256:
          13 85 1a 1e 69 a9 37 f7  a0 bd a4 af 7e 1d 61 53  |....i.7.....~.aS|
          fe 9d 8c 5e 0c a6 75 1e  78 17 23 dd fd ec 1a 03  |...^..u.x.#.....|
          55 39 fb 71 95 c7 65 5a  a7 8e 30 d2 44 5a 61 db  |U9.q..eZ..0.DZa.|
          70 6f da 21 05 c2 2e 73  ba 49 f1 d1 93 fe 5d c9  |po.!...s.I....].|
          cd 5e 03 e0 89 9e 3f 74  1e d7 f7 38 8b a9 d6 cf  |.^....?t...8....|
          bb 35 2f 33 58 a8 92 56  d1 c8 4d 3b 82 e6 79 84  |.5/3X..V..M;..y.|
          16 fc 28 b0 b1 47 f3 1d  a2 3e ee 87 d9 a6 7f a4  |..(..G...>......|
          56 a5 3f ad 84 2e 29 de  7c bc a8 aa a3 3d 04 01  |V.?...).|....=..|
          ea ba 93 a2 0e 50 22 29  17 4c 87 e4 3a 11 5f d6  |.....P").L..:._.|
          a4 25 89 9b 05 6b 2f b4  c9 01 4c 27 7b 0b ac 19  |.%...k/...L'{...|
          05 22 a0 60 15 3f da c9  fb 4d 4c 8f fb 72 67 77  |.".`.?...ML..rgw|
          fd 27 94 c7 ba 35 0e 88  49 fe 8d fd 28 af 4a 12  |.'...5..I...(.J.|
          bd 0d b3 97 05 de 44 0c  15 fa 36 2b 03 dc c1 50  |......D...6+...P|
          01 f1 a1 11 5d 14 e5 e2  bd 27 4b 54 be 2b 84 5e  |....]....'KT.+.^|
          0f a6 c3 74 05 0a ef 97  c3 89 22 b1 1f 77 f3 bd  |...t......"..w..|
          cd 43 d4 f1 4c a9 3f b5  8b 84 af 64 f2 d0 14 21  |.C..L.?....d...!|
    • Signer
      • 1
      • unnamed
        • #0
          • C: US
          • O: Symantec Corporation
          • OU: Symantec Trust Network
          • CN: Symantec Class 3 SHA256 Code Signing CA
        • 70:4E:E7:9F:85:6A:67:01:6F:01:25:41:A7:5F:64:46
      • SHA1: nil
      • #3
        • contentType: 1.3.6.1.4.1.311.2.1.4
        • 1.3.6.1.4.1.311.2.1.11: msCodeInd
        • messageDigest:
          09 c0 d1 90 3f c0 f5 fa  3b 44 de 0c a0 47 d0 11  |....?...;D...G..|
          14 c8 9d 02                                       |....            |
        • 1.3.6.1.4.1.311.2.1.12
          • 64 1c 72 d7 8d 2d 72 69  52 a9 62 4b              |d.r..-riR.bK    |
            : http://t.sogou.com
      • rsaEncryption:
        0c d0 73 3f 0f 3d 12 30  df 4e a5 32 a8 ba ce 3f  |..s?.=.0.N.2...?|
        06 bf 04 06 9b 15 e3 04  01 c0 a3 69 67 4e 1a 34  |...........igN.4|
        aa df 95 f5 e5 19 9d d7  9c 84 6e 36 57 29 2c 85  |..........n6W),.|
        ac 0c 23 d8 18 17 e7 4c  dc cf 15 f7 2d af 82 49  |..#....L....-..I|
        81 34 32 6c 09 bb 06 ba  6f 91 c3 c4 20 43 65 04  |.42l....o... Ce.|
        01 8c 61 45 6a 45 0d f8  12 d4 71 ae 8b 18 b1 ed  |..aEjE....q.....|
        0f ad 0f ab 05 7c 21 ae  53 be b4 fe ba 5d 7f 35  |.....|!.S....].5|
        b0 8a 11 bd 7c 36 c8 e7  00 22 df 74 e9 07 41 97  |....|6...".t..A.|
        b5 a6 27 a2 ae 4f 56 d9  41 74 11 84 59 68 08 39  |..'..OV.At..Yh.9|
        af 48 3c 96 44 a0 3e 3e  ee 7e 8c 67 60 b6 60 85  |.H<.D.>>.~.g`.`.|
        6e bd a0 d6 56 40 8e 7a  94 6d 9a 77 c4 6c c7 3d  |n...V@.z.m.w.l.=|
        d5 36 e0 bf 6b bb 27 1a  62 7c 78 3f 9c 20 da ca  |.6..k.'.b|x?. ..|
        20 99 9e 25 81 a1 91 bf  97 99 e7 08 fa 38 b4 2d  | ..%.........8.-|
        02 9a 54 b6 0c 92 a4 f7  50 99 62 0d 8a 66 0d f5  |..T.....P.b..f..|
        d2 9e 53 e2 af 28 4e 5d  66 34 e8 33 ff d3 08 03  |..S..(N]f4.3....|
        d4 0e 42 b6 fd 11 df 81  14 b6 23 4e 02 34 3c bb  |..B.......#N.4<.|
      • countersignature
        • 0
          • unnamed
            • #0
              • C: US
              • ST: UT
              • L: Salt Lake City
              • O: The USERTRUST Network
              • OU: http://www.usertrust.com
              • CN: UTN-USERFirst-Object
            • 16:88:F0:39:25:5E:63:8E:69:14:39:07:E6:33:0B
          • SHA1: nil
          • #2
            • contentType: pkcs7-data
            • signingTime: 2016-01-12 03:15:32 UTC
            • messageDigest:
              01 fa ec e2 14 d5 ec 33  cc 86 54 c3 1a 62 a6 fa  |.......3..T..b..|
              fb fb e7 22                                       |..."            |
          • rsaEncryption:
            6f 30 57 f3 66 d0 f8 95  45 98 4e 41 84 35 ac 8f  |o0W.f...E.NA.5..|
            d0 1a bf 0f 58 2e f2 32  66 52 bf 7d c3 37 c2 2d  |....X..2fR.}.7.-|
            bd 84 5d 04 59 68 4f f5  d2 50 9e 55 c4 b2 22 10  |..].YhO..P.U..".|
            88 b9 15 e7 1a 16 29 e9  3c a6 88 7b 40 cb 44 2b  |......).<..{@.D+|
            d6 e6 5f 14 87 7c 30 cd  17 32 5a f7 f5 b4 e0 72  |.._..|0..2Z....r|
            6b 90 4b 32 4d 6a 72 57  b7 cc d9 05 d5 8c cc 9f  |k.K2MjrW........|
            ec cf cd e5 9b 38 90 b3  37 f5 98 dc 38 88 cf a6  |.....8..7...8...|
            41 16 43 04 c1 fb 37 27  2d 1f 7b 8e 32 e2 0e a3  |A.C...7'-.{.2...|
            99 0a a2 6a ae 8e a0 36  64 6b 37 61 38 64 e9 01  |...j...6dk7a8d..|
            2d e8 f3 3f 77 3e 2f 25  bb f6 91 ae 52 1f 49 a0  |-..?w>/%....R.I.|
            1a 3f 03 e8 a4 91 a0 5c  01 5b 81 dc e3 db 36 b8  |.?.....\.[....6.|
            c9 b8 d6 80 cf 17 f6 e4  a8 ec b3 c7 a2 1b d9 8f  |................|
            f8 5a d8 31 69 99 0d a9  46 b8 39 2b cb 70 46 53  |.Z.1i...F.9+.pFS|
            6e 97 fd 86 6e 13 67 ff  1e f9 0c 38 bf 31 a6 b2  |n...n.g....8.1..|
            da 8d 63 43 44 98 5f a9  2d 84 0b 1f 44 df cc 91  |..cCD._.-...D...|
            09 f5 1e ee ed 95 2b c6  d2 e7 c0 71 bd d2 7a d1  |......+....q..z.|
offsetsizetypecomment
051200EXE02/24/2012 19:20:04#
15c115HTM#
c8001372424BINoverlay data past EOF#
Scanning the drive for archives:
1 file, 1423624 bytes (1391 KiB)


--
Type = PE
Physical Size = 1423624
CPU = x86
Characteristics = Executable 32-bit
Created = 2012-02-24 19:20:04
Headers Size = 1024
Checksum = 1465080
Image Size = 1732608
Section Alignment = 4096
File Alignment = 512
Code Size = 29696
Initialized Data Size = 489984
Uninitialized Data Size = 16896
Linker Version = 10.0
OS Version = 5.0
Image Version = 6.0
Subsystem Version = 5.0
Subsystem = Windows GUI
DLL Characteristics = Relocated NX-Compatible NoSEH TerminalServerAware
Stack Reserve = 1048576
Stack Commit = 4096
Heap Reserve = 1048576
Heap Commit = 4096
Image Base = 4194304
----
Path = [0]
Size = 1365960
Packed Size = 1365960
Virtual Size = 1365960
Offset = 51200
--
Path = [0]
Type = Nsis
Offset = 16384
Physical Size = 1349573
Tail Size = 3
Method = Deflate
Solid = -
Headers Size = 168398
Embedded Stub Size = 0
SubType = NSIS-Park-3 Unicode log

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2014-03-21 10:24:46 .....                     37673  $PLUGINSDIR/modern-wizard.bmp
                    .....                      4630  $PLUGINSDIR/nsDialogs.dll
                    .....                      6396  $PLUGINSDIR/System.dll
                    .....                     15711  $PLUGINSDIR/FindProcDLL.dll
                    .....                     14507  $PLUGINSDIR/KillProcDLL.dll
2016-01-12 03:12:40 .....                    140557  $TEMP/iefm/findermate.dll
2016-01-12 03:12:42 .....                     71689  $TEMP/iefm/SiteList.dll
2016-01-12 03:12:36 .....                     77849  $TEMP/iefm/CloudSetIcon.dll
2016-01-12 03:12:34 .....                     86069  $TEMP/iefm/uninst.exe
2016-01-12 03:12:28 .....                     41423  $TEMP/iefm/ExceptionReport.exe
2016-01-12 03:12:30 .....                    321251  $TEMP/iefm/findermateupdate.exe
2014-11-24 10:39:54 .....                     15244  $TEMP/iefm/gouwu1.ico
2014-03-21 10:23:40 .....                     18038  $TEMP/iefm/modern-wizard.bmp
2015-08-05 07:02:16 .....                    156212  $TEMP/iefm/msvcp90.dll
2015-08-05 07:02:16 .....                    318529  $TEMP/iefm/msvcr90.dll
2015-08-05 07:02:16 .....                       596  $TEMP/iefm/Microsoft.VC90.CRT.manifest
                    .....                     13899  $PLUGINSDIR/inetc.dll
------------------- ----- ------------ ------------  ------------------------
2016-01-12 03:12:42                         1340273  17 files
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] can't find file_offset of VA 0x86000