MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Packer / Compiler

Sections

Data Directory

TLS

StringTable 040904E4

VS_FIXEDFILEINFO

Signers (1)

issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Code Signing PCA 2010
serial: 3300000239B2B4E82A2234492F000000000239

Certificates (2)

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            33:00:00:02:39:b2:b4:e8:2a:22:34:49:2f:00:00:00:00:02:39
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Code Signing PCA 2010
        Validity
            Not Before: Jul 12 20:07:51 2018 GMT
            Not After : Aug  8 20:07:51 2019 GMT
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Corporation
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a5:7d:ce:0a:9c:7b:90:52:8b:77:54:b2:e4:2c:
                    65:60:68:c5:ce:2a:c8:84:c6:d4:bd:8b:78:c5:47:
                    3e:95:03:8b:25:e2:eb:b9:13:bc:2c:6c:9c:ef:a5:
                    9a:43:98:d7:a6:d2:7e:33:80:d0:39:b5:1f:19:78:
                    98:5e:13:0b:f0:cc:29:8e:a8:6e:13:49:f7:47:02:
                    27:da:4f:ba:be:55:f0:73:24:05:36:76:a4:27:23:
                    f9:d2:94:41:38:cb:ea:2d:cc:98:b1:41:5f:25:f8:
                    a4:45:6c:2f:53:55:c6:09:04:0e:94:5f:e6:88:66:
                    80:a4:c5:9e:02:c8:90:e2:ed:14:cb:7d:89:63:85:
                    9e:3c:ab:7c:13:09:39:03:49:27:b1:5c:d5:ec:1f:
                    b4:92:e3:ce:04:05:16:f7:9f:84:54:ec:57:47:3f:
                    66:d7:93:6a:36:60:4a:25:91:ef:d8:a0:20:ab:3d:
                    d2:cc:a2:d3:69:d2:2c:3e:a2:1b:79:1c:64:aa:87:
                    c8:46:9f:9a:cd:f7:65:17:a9:ff:7c:8a:02:ee:e5:
                    d3:11:4e:8f:ce:3a:23:06:bf:c5:b1:54:08:2c:f2:
                    9d:5c:fe:10:03:b8:95:86:70:f8:5d:d1:91:46:7b:
                    07:69:d6:00:ef:f9:52:5a:f0:33:0c:cf:05:56:6c:
                    d0:8b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Extended Key Usage: 
                1.3.6.1.4.1.311.61.6.1, Code Signing
            X509v3 Subject Key Identifier: 
                FE:46:3B:D5:D1:5F:0D:6B:3B:C0:1D:0B:69:B0:20:D7:E5:5C:34:C3
            X509v3 Subject Alternative Name: 
                DirName:/OU=Microsoft Ireland Operations Limited/serialNumber=230865\+440983
            X509v3 Authority Key Identifier: 
                E6:FC:5F:7B:BB:22:00:58:E4:72:4E:B5:F4:21:74:23:32:E6:EF:AC
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
            Authority Information Access: 
                CA Issuers - URI:http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt
            X509v3 Basic Constraints: critical
                CA:FALSE
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        73:a0:0a:a8:f9:3e:a1:a5:42:06:75:ae:06:91:b8:ed:2b:f9:
        72:33:88:80:cb:dc:46:82:ff:c8:d7:67:9e:2d:c8:4c:4c:49:
        e8:d9:2a:c8:3b:33:95:f0:08:4f:37:eb:1f:2b:ed:63:d8:ae:
        c6:b8:93:ce:ff:63:5f:77:6a:d0:34:d6:ca:e2:e1:29:83:ff:
        be:85:c9:45:ad:2a:e3:dc:6c:65:f6:21:a3:e9:f3:ae:c4:bf:
        50:a1:e6:ff:97:96:dc:c2:a1:68:a4:70:93:fb:8b:34:36:fb:
        32:53:6d:69:b4:f6:2b:c7:e8:1a:53:d3:08:ea:37:94:c9:a0:
        d8:c5:2c:ef:5f:c8:35:6c:aa:8f:25:40:cc:d2:9d:00:10:7e:
        27:e0:15:5a:2d:ce:17:a0:37:27:ac:c6:38:99:75:12:18:20:
        2a:e2:34:67:5b:53:3a:2b:dc:a5:03:95:5f:cd:cb:26:dc:d7:
        97:b6:27:dd:e5:49:ba:31:65:dc:a4:2f:aa:c6:bc:11:b5:a0:
        77:b0:b5:26:55:ab:ea:e5:20:25:38:93:d6:2c:c7:cd:68:90:
        41:4c:32:29:0a:cf:84:8c:fe:93:2e:04:fd:9b:23:e9:5d:6a:
        49:ca:c5:80:76:45:1a:39:0e:31:64:05:a9:ae:93:cd:dd:ec:
        32:52:44:fe

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            61:0c:52:4c:00:00:00:00:00:03
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
        Validity
            Not Before: Jul  6 20:40:17 2010 GMT
            Not After : Jul  6 20:50:17 2025 GMT
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Code Signing PCA 2010
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:e9:0e:64:50:79:67:b5:c4:e3:fd:09:00:4c:9e:
                    94:ac:f7:56:68:ea:44:d8:cf:c5:58:4f:a9:a5:76:
                    7c:6d:45:ba:d3:39:92:b4:a4:1e:f9:f9:65:82:e4:
                    17:d2:8f:fd:44:9c:08:e8:65:93:ce:2c:55:84:bf:
                    7d:08:e3:2e:2b:a8:41:2b:18:b7:a2:4b:6e:49:4c:
                    6b:15:07:de:d1:d2:c2:89:1e:71:94:cd:b5:7f:4b:
                    b4:af:08:d8:cc:88:d6:6b:17:94:3a:93:ce:26:3f:
                    ec:e6:fe:34:98:57:d5:1d:5d:49:f6:b2:2a:2e:d5:
                    85:bb:59:3f:f8:90:b4:2b:83:74:ca:2b:b3:3b:46:
                    e3:f0:46:49:c1:17:66:54:c9:1c:bd:1d:c4:55:62:
                    57:72:f8:67:b9:25:20:34:de:5d:a6:a5:95:5e:ab:
                    28:80:cd:d5:b2:9e:e5:03:b5:63:d3:b2:14:c8:c1:
                    c8:8a:26:0a:59:7f:07:ec:ff:0e:ed:80:12:35:4c:
                    12:a6:be:52:5b:f5:a6:da:e0:8b:0b:48:77:d6:85:
                    47:d5:10:b9:c6:e8:aa:ee:8b:6a:2d:05:5c:60:c6:
                    b4:2a:5b:9c:23:1c:5f:45:e3:1a:14:1e:6f:37:cb:
                    19:33:80:6a:89:4d:a3:6a:66:63:78:93:d5:30:cf:
                    95:1f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            1.3.6.1.4.1.311.21.1: 
                ...
            X509v3 Subject Key Identifier: 
                E6:FC:5F:7B:BB:22:00:58:E4:72:4E:B5:F4:21:74:23:32:E6:EF:AC
            1.3.6.1.4.1.311.20.2: 
                .
.S.u.b.C.A
            X509v3 Key Usage: 
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Authority Key Identifier: 
                D5:F6:56:CB:8F:E8:A2:5C:62:68:D1:3D:94:90:5B:D7:CE:9A:18:C4
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
            Authority Information Access: 
                CA Issuers - URI:http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
            X509v3 Certificate Policies: 
                Policy: 1.3.6.1.4.1.311.46.3
                  CPS: http://www.microsoft.com/PKI/docs/CPS/default.htm
                  User Notice:
                    Explicit Text:  
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        1a:74:ef:57:4f:29:7b:c4:16:85:78:b8:50:d3:22:fc:09:9d:
        ac:82:97:f8:34:ff:2a:2c:97:95:12:e5:e4:bf:cf:bf:93:c8:
        e3:34:a9:db:81:b8:dc:1e:00:be:d2:35:6f:af:e5:7f:79:95:
        77:e5:02:d4:f1:eb:d8:cd:4e:1e:1b:61:a2:c2:5a:23:1a:f0:
        8c:a8:62:51:45:67:08:e3:3f:3c:1e:93:f8:30:85:17:c8:39:
        40:a6:d7:0e:b3:21:29:e5:a5:a1:69:8c:22:93:cc:74:98:e7:
        a1:47:43:f2:53:ac:c0:0f:30:69:7f:fe:d2:25:20:6d:6f:61:
        d3:df:07:d5:d9:72:00:2c:69:86:76:3d:51:db:a6:39:48:c9:
        37:61:6d:07:dd:53:19:cb:a7:d6:61:c2:bf:e2:83:ab:0f:e0:
        6b:9b:95:d6:7d:28:51:b0:89:4a:51:a4:9a:6c:c8:b7:1f:4a:
        1a:0e:69:a9:d7:dc:c1:7e:d1:49:70:aa:b6:ad:bb:72:47:63:
        17:fa:a6:d6:a2:a6:86:ec:a8:10:44:9b:63:b6:b2:69:89:06:
        c7:46:86:7a:18:3f:e8:c5:1d:21:d5:7b:f9:02:23:2d:c5:41:
        cb:bf:1d:4c:c8:16:ef:b1:9c:7f:fc:22:4b:49:8a:6e:15:e3:
        a6:7f:76:5b:d1:53:79:91:85:9d:d5:d2:db:3d:73:35:f3:3c:
        ae:54:b2:52:47:6a:c0:aa:13:95:d2:8e:11:da:99:67:5e:32:
        8c:fb:37:85:d1:dc:75:85:9c:87:c6:5a:57:85:c2:bf:dd:0d:
        8f:8c:9b:2d:eb:b4:ee:cf:27:d3:b5:5e:69:fa:a4:16:04:01:
        a7:24:67:73:cf:4d:4f:b6:de:05:56:97:7a:f7:e9:52:4d:f4:
        77:05:4f:85:c6:d8:0b:f1:8e:ed:42:09:d1:0d:76:e3:23:56:
        78:22:26:36:be:ca:b1:8c:6e:aa:1d:e4:85:da:47:33:62:8f:
        a4:c9:91:33:5f:71:1e:40:af:98:65:c9:22:e8:42:21:25:8a:
        1c:2d:60:d9:37:89:41:89:2a:16:0f:d7:61:3c:94:68:60:52:
        ef:d6:47:99:a0:80:40:ee:15:81:77:3e:9c:e0:53:18:1a:50:
        1d:38:95:9b:1e:66:33:13:27:39:17:78:87:36:ce:4e:c3:5f:
        b2:f5:3d:47:53:b6:e0:e5:db:0b:61:3d:2a:d7:92:2c:ce:37:
        5a:3e:40:42:31:a4:1f:10:08:c2:56:9c:bf:24:5d:51:02:9d:
        6a:79:d2:17:d3:da:c1:94:8e:07:7b:25:71:44:ab:06:6a:e6:
        d4:c6:df:23:9a:96:75:c5

undefined method `first' for #

offsetsizetypecomment
0708096EXE05/03/2018 22:56:03#
15c115HTM#
ace00643152BINoverlay data past EOF#
Scanning the drive for archives:
1 file, 1351248 bytes (1320 KiB)


--
Type = PE
Physical Size = 1351248
CPU = x86
Characteristics = Executable 32-bit RemovableRun NetRun
Created = 2018-05-03 22:56:03
Headers Size = 1024
Checksum = 1367706
Image Size = 729088
Section Alignment = 4096
File Alignment = 512
Code Size = 303616
Initialized Data Size = 403456
Uninitialized Data Size = 0
Linker Version = 14.13
OS Version = 5.1
Image Version = 0.0
Subsystem Version = 5.1
Subsystem = Windows GUI
DLL Characteristics = Relocated NX-Compatible TerminalServerAware
Stack Reserve = 1048576
Stack Commit = 4096
Heap Reserve = 1048576
Heap Commit = 4096
Image Base = 4194304
Comment = FileVersion: 10.1.17763.132
ProductVersion: 10.1.17763.132
InternalName: setup
----
Path = [0]
Size = 634296
Packed Size = 634296
Virtual Size = 634296
Offset = 708096
--
Path = [0]
Type = Cab
Physical Size = 634289
Tail Size = 7
Method = MSZip
Blocks = 1
Volumes = 1
Volume Index = 0
ID = 0

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2018-10-23 15:23:54 ....A       208460               0
2018-05-03 15:56:22 ....A       114688               u0
2018-10-22 19:09:26 ....A       246945               u1
2018-08-09 17:42:56 ....A          797               u2
2018-08-09 17:42:56 ....A         3409               u3
2018-08-09 17:42:56 ....A         1320               u4
2018-08-09 17:42:56 ....A       155324               u5
2018-08-09 17:42:54 ....A          877               u6
2018-10-22 21:05:58 ....A       154624               u7
2018-10-22 21:07:52 ....A       203264               u8
2018-05-03 15:56:20 ....A        81920               u9
2018-08-09 17:42:56 ....A       231872               u10
2018-08-09 17:37:44 ....A       170800               u11
2018-05-03 15:56:24 ....A       180224               u12
2018-10-23 15:20:04 ....A        31500               u13
2018-10-23 15:23:54 ....A       242874               u14
------------------- ----- ------------ ------------  ------------------------
2018-10-23 15:23:54            2028898      1351248  16 files
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] can't find file_offset of VA 0x6cac0