MZ Header

Rich Header

DOS stub

00000000: 0e 1f ba 0e 00 b4 09 cd  21 b8 01 4c cd 21 54 68  |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72  61 6d 20 63 61 6e 6e 6f  |is program canno|
00000020: 74 20 62 65 20 72 75 6e  20 69 6e 20 44 4f 53 20  |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a  24 00 00 00 00 00 00 00  |mode....$.......|

PE Header

Packer / Compiler

Sections

Data Directory

StringTable 040904B0

VS_FIXEDFILEINFO

offsetsizetypecomment
15c115HTM#
aa3811794AVI#
1083455762PNG(256 x 256)#
1e20671162BINoverlay data past EOF#
Scanning the drive for archives:
1 file, 194560 bytes (190 KiB)


--
Type = PE
Physical Size = 194560
CPU = x64
64-bit = +
Characteristics = Executable LargeAddress
Created = 2012-07-26 02:10:04
Headers Size = 1024
Checksum = 206875
Name = WEXTRACT.EXE            .MUI
Image Size = 221184
Section Alignment = 4096
File Alignment = 512
Code Size = 31744
Initialized Data Size = 161792
Uninitialized Data Size = 0
Linker Version = 10.10
OS Version = 6.2
Image Version = 6.2
Subsystem Version = 6.1
Subsystem = Windows GUI
DLL Characteristics = Relocated NX-Compatible TerminalServerAware 0x20
Stack Reserve = 524288
Stack Commit = 8192
Heap Reserve = 1048576
Heap Commit = 4096
Image Base = 5368709120
Comment = FileVersion: 10.0.9200.16384
FileVersion: 10.00.9200.16384 (win8_rtm.120725-1247)
ProductVersion: 10.0.9200.16384
ProductVersion: 10.00.9200.16384
CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor                                           
InternalName: Wextract                
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE            .MUI
ProductName: Windows® Internet Explorer
----
Path = .rsrc/RCDATA/CABINET
Size = 41941
Packed Size = 41941
--
Path = .rsrc/RCDATA/CABINET
Type = Cab
Physical Size = 41941
Method = LZX:21
Blocks = 1
Volumes = 1
Volume Index = 0
ID = 20804

   Date      Time    Attr         Size   Compressed  Name
------------------- ----- ------------ ------------  ------------------------
2015-04-01 01:22:50 ....A        11543               eb596ff5-558b-4e9c-9b35-11b7dde35770.inf
2015-04-01 01:22:50 ....A          155               eb596ff5-558b-4e9c-9b35-11b7dde35770.cmp
2015-04-01 01:22:50 ....A         3616               eb596ff5-558b-4e9c-9b35-11b7dde35770.cms
2015-04-01 01:22:50 ....A           71               routes.txt
2015-04-01 01:22:48 ....A        35840               cmroute.dll
2015-04-01 01:22:50 ....A         1030               eb596ff5-558b-4e9c-9b35-11b7dde35770.cer
2015-04-01 01:22:50 ....A         2284               eb596ff5-558b-4e9c-9b35-11b7dde35770.pbk
2015-04-01 01:22:50 ....A         5430               azurebox16.ico
2015-04-01 01:22:50 ....A         4286               azurebox32.ico
2015-04-01 01:22:50 ....A       138934               azurevpnbanner.bmp
------------------- ----- ------------ ------------  ------------------------
2015-04-01 01:22:50             203189       194560  10 files
offset:( 0x )size:( 0x )hotkeys:-=[]<>, offset/size fields are also editable

[?] ignoring invalid PEdump::BITMAPINFOHEADER