MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Packer / Compiler

Sections

Data Directory

offsetsizetypecomment
0312320EXE03/26/2020 10:02:47#
15c115HTM#
3c8502885PNG(93 x 302)#
3d3985545PNG(186 x 604)#
440b815729PNG(256 x 256)#
4c400753641BINoverlay data past EOF#
Scanning the drive for archives:
1 file, 1065961 bytes (1041 KiB)


--
Type = Rar5
Offset = 312320
Physical Size = 753641
Solid = -
Blocks = 3
Encrypted = -
Multivolume = -
Volumes = 1
Comment = Silent=1
Overwrite=1
Path="C:/crtref/"
Setup=MMHfyN1KUsTJOBvBjzGlbdHS9oVV2j.vbe
Update=U

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2020-12-08 12:05:21 ....A       898712       752697  9rgZVeNcpNbOK5vGmyvU.exe
2020-12-08 12:05:02 ....A          142          142  MMHfyN1KUsTJOBvBjzGlbdHS9oVV2j.vbe
2020-12-08 12:05:02 ....A          422          375  qJinAgXQ4XD9SKHPndOH6nHwmTlPZ3.bat
------------------- ----- ------------ ------------  ------------------------
2020-12-08 12:05:21             899276       753214  3 files
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] ignoring invalid PEdump::BITMAPINFOHEADER

[?] can't find file_offset of VA 0x0