PE structurePE file structure

Import table
RegOpenKeyExA, RegSetValueExA, RegDeleteValueA, RegEnumValueA, RegQueryInfoKeyA, RegCreateKeyExA, RegQueryValueExA, RegQueryValueA, RegCloseKey
ImageList_Add, ImageList_GetIcon, ImageList_Draw, ImageList_Remove, ImageList_GetImageCount, ImageList_GetImageInfo, ImageList_BeginDrag, ImageList_ReplaceIcon, ImageList_EndDrag, ImageList_DragEnter, ImageList_DragLeave, ImageList_DragMove
SetTextJustification, TextOutA, GetTextFaceA, CreateFontA, CreateDIBSection, SetDIBitsToDevice, ExtTextOutA, CreateCompatibleDC, Polyline, CreatePen, OffsetRgn, GetDIBits, PtInRegion, DeleteObject, GetCurrentObject, SetStretchBltMode, GetStockObject, StretchBlt, BitBlt, SelectObject, CreateCompatibleBitmap, GetTextExtentPoint32A, FrameRgn, FillRgn, CombineRgn, CreatePolygonRgn, CreateEllipticRgn, CreateRectRgn, CreateFontIndirectA, CreateSolidBrush, GetObjectA
GdipCreateBitmapFromScan0, GdipBitmapLockBits, GdipBitmapUnlockBits, GdipBitmapGetPixel, GdipBitmapSetPixel, GdiplusStartup, GdipDeleteGraphics, GdipCloneImage, GdipCreateBitmapFromStreamICM, GdipCreateBitmapFromStream, GdipGetImageWidth, GdipDisposeImage, GdipAlloc, GdipFree, GdipDrawImageRectI, GdipCreateFromHDC, GdipGetImageHeight, GdiplusShutdown
SetEvent, WaitForSingleObject, WaitForMultipleObjects, CreateThread, CreateEventA, GetTickCount, lstrcpynA, GetDriveTypeA, GetPrivateProfileIntA, GlobalFree, GlobalUnlock, GlobalLock, GlobalAlloc, lstrlenA, CreateProcessA, GetWindowsDirectoryA, FreeLibrary, GetProcAddress, LoadLibraryA, lstrcatA, GetSystemDirectoryA, lstrcpyA, GetLastError, CreateDirectoryA, Sleep, GetFullPathNameA, CreateMutexA, DeviceIoControl, CreateFileA, GetCurrentThreadId, GetSystemDefaultLangID, GetModuleHandleA, GetModuleFileNameA, InterlockedIncrement, InterlockedDecrement, RaiseException, InitializeCriticalSection, DeleteCriticalSection, GetVersion, lstrcmpiA, lstrcmpiW, CompareStringA, CompareStringW, GetEnvironmentVariableA, GetEnvironmentVariableW, GetStringTypeExA, GetStringTypeExW, GetVolumeInformationA, GetCurrentProcess, GetFileSize, GetTimeFormatA, GetDateFormatA, GetNumberFormatA, LocalFree, FormatMessageA, WinExec, SizeofResource, LockResource, LoadResource, FindResourceA, ResumeThread, GetUserDefaultLangID, EnterCriticalSection, LeaveCriticalSection, ReadFile, SetFilePointer, TerminateThread, GetStartupInfoA, ExitProcess, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, CloseHandle, lstrlenW, WideCharToMultiByte, MultiByteToWideChar, GetPrivateProfileStringA, GetVersionExA, GetThreadLocale, WritePrivateProfileStringA, DeleteFileA, InterlockedExchange, GetExitCodeProcess, GetLocaleInfoA, GetACP
StgCreateDocfile, CoCreateInstance, CoInitialize, CoUninitialize, StgOpenStorage, CoTaskMemFree, StringFromCLSID, OleInitialize, OleUninitialize, CoTaskMemAlloc, OleLoadFromStream, OleSaveToStream, CreateStreamOnHGlobal, CoFreeUnusedLibraries
ShellExecuteA, DragQueryFileA, DragFinish, DragAcceptFiles, SHBrowseForFolderA, SHGetFileInfoA, SHGetDesktopFolder, SHGetMalloc, SHGetPathFromIDListA, SHGetSpecialFolderLocation
GetClassNameA, LoadStringA, CallWindowProcA, wsprintfW, ClipCursor, EqualRect, UnregisterClassA, CharUpperW, CharUpperA, CharLowerW, CharLowerA, SetWindowLongA, GetMonitorInfoA, AdjustWindowRect, GetWindowLongA, DefWindowProcA, RegisterClassA, GetCapture, RedrawWindow, ReleaseCapture, SetCapture, SetCursor, ClientToScreen, FindWindowA, ShowWindow, SendMessageTimeoutA, GetFocus, MessageBoxA, GetKeyState, PtInRect, GetDesktopWindow, SetRect, TranslateAcceleratorA, TranslateMessage, DispatchMessageA, PostQuitMessage, OpenClipboard, GetWindowTextA, SetClipboardData, CloseClipboard, DestroyAcceleratorTable, GetCursorPos, LoadAcceleratorsA, LoadImageA, DestroyCursor, SystemParametersInfoA, GetWindowPlacement, MapDialogRect, WinHelpA, IsChild, UpdateWindow, ModifyMenuA, DestroyWindow, IsMenu, GetMenu, GetWindow, DrawFocusRect, MonitorFromWindow, GetDlgCtrlID, LoadCursorA, GetParent, KillTimer, GetWindowRect, BringWindowToTop, IsZoomed, GetSystemMenu, PostMessageA, CheckMenuRadioItem, RemoveMenu, InsertMenuA, CheckMenuItem, AppendMenuA, DeleteMenu, GetWindowRgn, IsWindowVisible, IsIconic, InvalidateRect, IntersectRect, SetRectEmpty, IsRectEmpty, SetWindowTextA, DestroyIcon, PeekMessageA, GetMessageA, IsWindow, PostThreadMessageA, MessageBeep, CopyIcon, InflateRect, EnumChildWindows, EmptyClipboard, LoadIconA, SetTimer, GetWindowDC, GetSysColorBrush, GetSysColor, GetMenuItemInfoA, SetMenuItemInfoA, ReleaseDC, GetDC, LoadMenuA, GetSubMenu, GetMenuItemID, GetMenuItemCount, CreatePopupMenu, DrawFrameControl, FillRect, LoadBitmapA, OffsetRect, CopyRect, ScreenToClient, SetWindowPos, GetSystemMetrics, EnableWindow, GetClientRect, SetWindowRgn, SendMessageA, SetForegroundWindow
VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA
HttpOpenRequestA, HttpAddRequestHeadersA, HttpSendRequestA, InternetConnectA, InternetCrackUrlA, InternetCloseHandle, InternetReadFile, InternetOpenA, HttpQueryInfoA
mixerGetNumDevs, mixerOpen, mixerGetLineControlsA, mixerGetControlDetailsA, mixerSetControlDetails, mixerGetDevCapsA, mciSendCommandA, mixerGetLineInfoA, mixerClose


Nero ShowTime by Nero AG (Signed)

Version:   3, 2, 3, 2
MD5:   85da70afdd8233226fd07e8153c6a3f3
SHA1:   308e8aa7daed6bb4f0fae280ac08a187cc0d2d3c
SHA256:   edd43fefb4dbad1e44f53604a455bb4f33b0493596bedb25c548b35ee9925c7f


showtime.exe executes as a process with the local user's privileges. It configures an autoplay handler withing explorer.exe named NeroAutoPlay7PlayAudioCD that will launch the program automatically. It is installed with a couple of know programs including Nero 7 Essentials published by Nero AG, Nero 7 Essentials from Nero AG and Nero 7 Essentials by Nero AG. The file is digitally signed by Nero AG which was issued by the VeriSign certificate authority (CA).


File name:showtime.exe
Publisher:Nero AG
Product name:Nero ShowTime
Typical file path:C:\Program Files\nero\nero 7\nero showtime\showtime.exe
File version:3, 2, 3, 2
Size:4.6 MB (4,825,088 bytes)
Issued to:Nero AG
Authority (CA):VeriSign
Expiration date:Thursday, June 21, 2012
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 7.1
Autoplay handlers
Runs under the registry key 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers'
  • Handler name 'NeroAutoPlay8PlayDVD'
  • Handler name 'NeroAutoPlay8PlayAudioCD'
  • Handler name 'NeroAutoPlay9PlayDVD'
  • Handler name 'NeroAutoPlay9PlayAudioCD'
  • Handler name 'NeroAutoPlay7PlayDVD'
  • Handler name 'NeroAutoPlay7PlayAudioCD'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 41.51%
Microsoft Windows XP 33.96%
Windows 7 Ultimate 11.32%
Windows 8 Single Language 7.55%
Windows 7 Home Basic 1.89%
Windows 7 Professional 1.89%
Windows 8 Pro with Media Center 1.89%

Distribution by countryDistribution by country

United States installs about 32.08% of Nero ShowTime.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 42.86%
Toshiba 25.00%
American Megatrends 12.50%
Intel 7.14%
Hewlett-Packard 5.36%
Sony 3.57%
Acer 3.57%
