| parent | Guardius.exe | |
|---|---|---|
| filename | Guardius.unpacked.exe | |
| size | 1967408 (0x1e0530) | |
| md5 | 867dd9105c62ecdb46eaa1eb1f98ff85 | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0x110 |
Rich Header
| lib id | version | times used |
|---|---|---|
| 110 | 50727 | 1 |
| 149 | 30729 | 35 |
| 109 | 50727 | 13 |
| 132 | 21022 | 8 |
| 131 | 30729 | 231 |
| 132 | 30729 | 158 |
| 123 | 50727 | 29 |
| 1 | 0 | 423 |
| 138 | 30729 | 63 |
| 146 | 30729 | 1 |
| 148 | 21022 | 1 |
| 145 | 30729 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
StringTable 040904B0
| FileVersion | 4, 1, 0, 8 |
| ProductVersion | 4, 1, 0, 8 |
| Comments | local setups |
| CompanyName | Perion Network Ltd |
| FileDescription | Guardius Installer |
| InternalName | Perion Installer |
| LegalCopyright | Copyright © 2013 Perion Network Ltd. |
| ProductName | Guardius Installer |
| XVI_Compid | 133 |
| XVI_InternalProdVer | 4.1.0.8.44.4.1 |
VS_FIXEDFILEINFO
| FileVersion | 4.1.0.8 |
| ProductVersion | 4.1.0.8 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x17 |
| FileFlags | 0 |
| FileOS | 4 |
| FileType | 1 |
| FileSubtype | 0 |
| offset | size | type | comment | |
|---|---|---|---|---|
| 0 | 1960960 | EXE | 11/03/2013 14:02:40 | # |
| 15c1 | 15 | HTM | # | |
| 17113c | 977 | PNG | (1 x 1) | # |
| 171510 | 977 | PNG | (1 x 1) | # |
| 1718e4 | 977 | PNG | (1 x 1) | # |
| 171cb8 | 977 | PNG | (1 x 1) | # |
| 17208c | 977 | PNG | (1 x 1) | # |
| 172460 | 977 | PNG | (1 x 1) | # |
| 172834 | 977 | PNG | (1 x 1) | # |
| 172c08 | 977 | PNG | (1 x 1) | # |
| 172fdc | 977 | PNG | (1 x 1) | # |
| 1733b0 | 977 | PNG | (1 x 1) | # |
| 173784 | 1838 | PNG | (32 x 32) | # |
| 173eb4 | 8700 | PNG | (163 x 349) | # |
| 1760b0 | 35172 | PNG | (335 x 349) | # |
| 17ea14 | 8700 | PNG | (163 x 349) | # |
| 180c10 | 7420 | PNG | (499 x 58) | # |
| 18290c | 7420 | PNG | (499 x 58) | # |
| 184608 | 8700 | PNG | (163 x 349) | # |
| 186804 | 5125 | PNG | (335 x 349) | # |
| 187c0c | 8700 | PNG | (163 x 349) | # |
| 18cc38 | 4159 | PNG | (48 x 48) | # |
| 18dc78 | 4325 | PNG | (499 x 100) | # |
| 18ed60 | 4235 | PNG | (420 x 105) | # |
| 18fdec | 4312 | PNG | (499 x 100) | # |
| 190ec4 | 4240 | PNG | (420 x 105) | # |
| 191f54 | 4254 | PNG | (499 x 100) | # |
| 192ff4 | 4161 | PNG | (420 x 105) | # |
| 194038 | 977 | PNG | (1 x 1) | # |
| 19440c | 977 | PNG | (1 x 1) | # |
| 1947e0 | 14006 | PNG | (499 x 101) | # |
| 197e98 | 977 | PNG | (1 x 1) | # |
| 19826c | 977 | PNG | (1 x 1) | # |
| 1a5a40 | 977 | PNG | (1 x 1) | # |
| 1b3e14 | 977 | PNG | (1 x 1) | # |
| 1b41e8 | 977 | PNG | (1 x 1) | # |
| 1b45bc | 977 | PNG | (1 x 1) | # |
| 1b4990 | 977 | PNG | (1 x 1) | # |
| 1b4d64 | 977 | PNG | (1 x 1) | # |
| 1b5138 | 977 | PNG | (1 x 1) | # |
| 1b550c | 977 | PNG | (1 x 1) | # |
| 1b58e0 | 977 | PNG | (1 x 1) | # |
| 1b5cb4 | 977 | PNG | (1 x 1) | # |
| 1b6088 | 6577 | PNG | (420 x 105) | # |
| 1b7a3c | 6569 | PNG | (420 x 105) | # |
| 1b93e8 | 6508 | PNG | (420 x 105) | # |
| 1bad54 | 977 | PNG | (1 x 1) | # |
| 1dec00 | 6448 | BIN | overlay data past EOF | # |
Scanning the drive for archives: 1 file, 1967408 bytes (1922 KiB) Errors: 1
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
everything is OK
offset:( 0x )