What an EXE actually contains
A Windows executable is a Portable Executable file: a structured container holding machine code, resources and metadata in labelled sections. The metadata is the part worth reading. It records which processor the program targets, which system libraries it calls, who signed it, what version it claims to be, and which icons and manifests it carries.
This tool parses that structure the way a hex editor would โ as bytes at known offsets. No instruction in the file is ever executed, which is why reading an untrusted executable here carries no risk.
How to extract an EXE file online
- Open the executable. Drop the .exe onto the box above, or click to browse. Parsing starts immediately and runs entirely in your browser.
- Read the overview. Check the architecture, subsystem, publisher, version, build date, installer type, and whether the file is code-signed or packed.
- Open the tabs. Pull out icons, list an embedded ZIP payload, read the strings and URLs compiled into the binary, or inspect the section table and imported libraries.
- Download what you need. Save icons as .ico or .png, extract embedded files individually, or download the whole report as a text file.
What the extractor pulls out
- Icons โ every icon group in the file, rebuilt into multi-size
.icofiles, plus each individual size as PNG or ICO. - Version and publisher details โ product name, company, description, file and product version, copyright and original filename.
- Embedded files โ when the executable carries a ZIP payload, its contents are listed and each file is extractable.
- Strings, URLs and email addresses โ the readable ASCII and UTF-16 text compiled into the binary, which often reveals which servers a program contacts.
- Structure โ PE sections, imported DLLs, entry point, build timestamp, overlay size, and whether the manifest demands administrator rights.
- Signature details โ the organisation names embedded in the Authenticode certificate, so you can see who signed the file.
- SHA-256 hash โ computed on demand, with a lookup link for reputation services.
Supported file types
Any Portable Executable file works: .exe, .dll, .sys,
.ocx, .cpl, .scr and Node native modules. Both 32-bit (PE32) and
64-bit (PE32+) binaries parse, on x86, x64, ARM and ARM64.
Headers and resources are read from targeted slices of the file rather than loading it whole, so a
400 MB installer opens as quickly as a 2 MB utility. Strings are scanned across the whole file up to
12 MB, and across the first 2 MB above that, which keeps the page responsive on very large installers.
Windows Installer packages (.msi) are detected and identified, but use a different container
that is not unpacked here.
Why inspecting here beats running it
Double-clicking an unknown installer grants it the full authority of your user account. Reading it grants nothing. This page treats the executable purely as bytes, so nothing inside it can act.
Because parsing is local, the file is also never transmitted โ which matters when the binary is proprietary, internal or under NDA. The hash feature is deliberately built the same way: SHA-256 is computed in your browser and only those 64 characters travel to a reputation service, so you can check whether a file is already known to be malicious without handing the file itself to anyone.
What this tool does not do
Four boundaries are worth stating plainly:
- It is not an antivirus. It reports what a file contains. It does not judge whether the file is malicious.
- It does not unpack every installer. Full file extraction requires a ZIP-based payload. NSIS, Inno Setup, InstallShield, MSI and solid 7-Zip or RAR payloads are identified but not extracted.
- It does not verify the signature chain. The names inside the certificate are read and displayed; confirming the signature is cryptographically valid requires Windows itself.
- It does not decompile. Machine code is not translated back into source.
Why people extract EXE files
- Getting an application icon โ designers and IT teams pulling a clean .ico or PNG for shortcuts, documentation or a software catalogue.
- Vetting a download โ checking the publisher, signature and embedded URLs before trusting an installer from an unfamiliar source.
- Software inventory โ recording exact product and file versions for licensing or asset records.
- Recovering bundled assets โ retrieving files packed into an old self-extracting archive whose source is long gone.
- Troubleshooting โ confirming whether a binary is 32-bit or 64-bit, .NET or native, packed or plain, before debugging a compatibility fault.
Which installers can be fully unpacked
Windows installers are not one format, so expectations should differ by type:
- ZIP self-extracting archives โ listed and extracted here in full.
- NSIS, Inno Setup, InstallShield, 7-Zip and RAR SFX โ identified here, then unpacked with 7-Zip on the desktop: right-click the file, choose 7-Zip, then Open archive.
- MSI packages โ identified here, then extracted on Windows with
msiexec /a package.msi /qb TARGETDIR=C:\out.
If icons are all you need, the icon extractor is the more direct tool. For a plain archive rather than an executable, use the ZIP extractor.
For complete technical workflows and cross-platform instructions, read our guides on how to extract EXE files without installing software, how to open and extract EXE files on Mac and Chromebook, how Windows icons are stored in EXE files, or learn about installer packages in what is inside an MSI file.
PE format standards and extraction edge cases
Windows executables use the Portable Executable (PE) format documented in the PE/COFF specification (Microsoft, last updated 2023). A PE file begins with a DOS stub (signature MZ, 0x4D5A), followed at offset 0x3C by a pointer to the PE signature (0x50450000). The PE header contains a COFF file header and an Optional Header; the section table follows immediately.
Three extraction edge cases: (a) 64-bit executables (PE32+) use a slightly larger
Optional Header with 64-bit ImageBase and SizeOfStackReserve โ the Magic field (0x10B for
PE32, 0x20B for PE32+) distinguishes them, and both are parsed correctly; (b) the resource
section (.rsrc) uses a tree of resource types, names and language IDs โ a
complex application can carry many icon sizes and string tables, all of which are reported;
(c) .NET assemblies are PE files with a CLR header in the Optional Header DataDirectory โ
their managed metadata is not parsed here, but all PE headers and native resources are read
normally.
Frequently asked questions
Can I extract an EXE file online for free?
Yes. Drop the file above and it is parsed in your browser. There is no signup, no daily cap and no size limit beyond your device's memory.
How do I extract the icon from an EXE?
Open the file and go to the Icons tab. Each icon group is rebuilt into a multi-size .ico for one-click download, and every individual size can be saved as PNG or ICO. The icon extractor does the same job with fewer steps.
Is my file uploaded to your server?
No. Header parsing, icon rebuilding, decompression and hashing all happen inside your browser. The executable is never transmitted, stored or logged.
Is it dangerous to open a suspicious EXE here?
No. The file is read as data and never executed, so its code cannot run. This is substantially safer than double-clicking it. The tool is not an antivirus, though โ it reports contents, it does not judge intent.
Why can't the tool extract the files inside my installer?
Full extraction needs a ZIP-based payload. NSIS, Inno Setup and MSI packages store files in custom containers that a browser cannot unpack, so they are identified instead. Use 7-Zip on the desktop for those.
Can I extract text from an EXE?
Yes. The Strings tab lists the readable ASCII and UTF-16 text compiled into the binary, and filters it down to URLs and email addresses on request.
Does the build date always show when the program was made?
Not always. The timestamp comes from the PE header, and reproducible builds sometimes store a hash there instead of a date. Implausible values are flagged rather than presented as dates.
Does this work on Mac, Linux or a phone?
Yes. Any modern browser works, so you can inspect Windows executables without a Windows machine.