4731f40c3ba5a04baa46f83954a11dc8

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2019-Jan-04 12:09:33
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName GOG.com
FileDescription Baldur's Gate 3 Setup
FileVersion
LegalCopyright 2018 GOG Sp. z o.o. All rights reserved.
OriginalFileName
ProductName Baldur's Gate 3
ProductVersion Release - v4.1.1.6072089 - Patch Patch7_Hotfix3.[5

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://www.jrsoftware.org
  • http://www.jrsoftware.org/ishelp/index.php?topic
  • jrsoftware.org
  • www.jrsoftware.org
Suspicious The PE is possibly packed. Unusual section name found: .itext
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: GOG sp. z o.o
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/72 (Scanned on 2025-01-03 16:01:17) All the AVs think this file is safe.

Hashes

MD5 4731f40c3ba5a04baa46f83954a11dc8
SHA1 0ba5c297552d0086bf81b87713153a574cce0c13
SHA256 15d867bdc439e10a350c218ba26e3cc73fe58c9aba8d2af992e9a7eecab63298
SHA3 61cdf7e1bc1210eef88be5dccda07caebd528b0553e399abcbecc0e07c9adc92
SSDeep 49152:rig5lhfzLNUVZVQv4Dth9GCbUCje+ug+Hmjv4gA:RlhfWVZ35Vnug+GjvC
Imports Hash c60f9a83fcd28ab2eb686b76b194eb79

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 9
TimeDateStamp 2019-Jan-04 12:09:33
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x10a00
SizeOfInitializedData 0x1e200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0001185C (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x12000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x39000
SizeOfHeaders 0x400
Checksum 0x299343
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6cc0699e81d9eada39aa93fb49a33a43
SHA1 dacef918b3e833d3d23fc3b6c782c09d1e051daf
SHA256 fb09bb8f2827848c3807fbc9f2d7d2371b9414a46a23e2e310ddfa40490687bb
SHA3 b5581056555b5631f382989960838a5cadb04a5f60347ebadb3db1cb35c74069
VirtualSize 0xf810
VirtualAddress 0x1000
SizeOfRawData 0xfa00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.38077

.itext

MD5 0a16fa3cfb5034c3e5689fd6e68bcad9
SHA1 c2fe6aac906cb027794f534569d1f87887d746e2
SHA256 d4f3604d8d705e4a6d29e173502b774b0a1fd09289022d5ca7b93b4b5ebe5923
SHA3 a5d6612158fad8162ce30721530b18ef9f205cdc26267742d47d4866a139f549
VirtualSize 0xff4
VirtualAddress 0x11000
SizeOfRawData 0x1000
PointerToRawData 0xfe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.86823

.data

MD5 b57a55f3413eca195378a861cf080776
SHA1 43cfeefb7597bf17591571f54279b8ba3302c139
SHA256 0b9028370f648bb43c00e15025add4a05eef40bdc682c606413a75e40c70eca9
SHA3 00e3ea53260cf399d138fdd1d02e672162ca0023c0de8fcf40eee6d03129ff46
VirtualSize 0xc8c
VirtualAddress 0x12000
SizeOfRawData 0xe00
PointerToRawData 0x10e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.25991

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x56c8
VirtualAddress 0x13000
SizeOfRawData 0
PointerToRawData 0x11c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 e9b9c0328fd9628ad4d6ab8283dcb20e
SHA1 fd2927174e310130a51bdd648aefde6f89fe0007
SHA256 68a126ba6dddfa52cdc395cca81ae415921071acf02f75b7c00faf9d90353760
SHA3 8d72ac9fda0d2c851f62aab12f92db53db9fb187e522555aa7e82502850ce7a2
VirtualSize 0xe04
VirtualAddress 0x19000
SizeOfRawData 0x1000
PointerToRawData 0x11c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.59781

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8
VirtualAddress 0x1a000
SizeOfRawData 0
PointerToRawData 0x12c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 3dffc444ccc131c9dcee18db49ee6403
SHA1 45d8f890e32cc1adf7ded113fd19004c8869f419
SHA256 821b0bda5922cc6f5fb74fb3a160e39c97727c21beb1ecf4f96e3bcfad9edbe3
SHA3 426ea652dcd361ec016030230ec1c87a2bc522f69cfb4c2af6313465cb2c516f
VirtualSize 0x18
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x12c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.204488

.reloc

MD5 d45f4c562f75dff51360c37ae64c57f6
SHA1 4d2964b1ef49a47ea03bb7e0c70b45115d8a557c
SHA256 975e4a996449068b3de5cd47ed6c7dfda1135301a2b4a31e0497056e291c50f3
SHA3 98c9db5b2e60c53cce093e8b555454de26be37d7c3b6a3cc71781858ee4cecd6
VirtualSize 0x1394
VirtualAddress 0x1c000
SizeOfRawData 0x1400
PointerToRawData 0x12e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.53416

.rsrc

MD5 e586b2ed20ca576b0b5149a601a4e538
SHA1 622cfb1894516b1d1341ae246c31ddf1c64aaf7f
SHA256 765985e10f926795ace05a364a665ab98aa484ff3fd43782985b2a83a17513fb
SHA3 10e1b6c8a6060fae256a98d77e972f8e22571ce87036b789392359c0f3f519bd
VirtualSize 0x1adb0
VirtualAddress 0x1e000
SizeOfRawData 0x1ae00
PointerToRawData 0x14200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.75818

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
user32.dll (#2) GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
comctl32.dll InitCommonControls
kernel32.dll (#4) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#3) RegQueryValueExW
RegOpenKeyExW
RegCloseKey

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.12391
MD5 cf9a6e717da9905f890d56decc8678d2
SHA1 90f954506edf16a064241cf0f1f894a62cfd73b4
SHA256 42c928be39968cf703a5d53c7a26443ed5d4170dd4494bf57bda8189a5079417
SHA3 42e3029dcd97128f1b66af76d8665b91b41c4d6fb33ff8991b1585b77011561f

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.43915
MD5 9d26503f6570a4a3bc5d9fb0d2e09d0a
SHA1 bf2171df1dc48608c13b60ee84b055b701e090ed
SHA256 573594fbcef3de2b659be4913881583a78699aba19fca919afdde52382ee70b3
SHA3 11c58f33d166fa682e97a0ea8b91bb04b7c2027d909e6bb57ce617ccc1123b8d

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.88504
MD5 e6f8e51ba875a7dccd1be4da61dd062c
SHA1 d34fb7e738f3aef4c01644ff2780574967b171ef
SHA256 71b197d0a0e13323d0a4df43c922b43077ff9a45655dce3a6be5094ff265f3eb
SHA3 4ab984e0aae9da3b861cbe291cde4752fd7a6aeb18d67adde7a5637d246bded3

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xb69a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96547
Detected Filetype PNG graphic file
MD5 c9970e2fe2aa4161f760aa08404a0669
SHA1 07c2673d30b97bcc1a530af7d71c3748a348087f
SHA256 ea0f69d1cfe965ab083983fd2666f5344c6203b8a61bc1748b74e6ac72c5634e
SHA3 8d3625aff872d72b250b5f5bb0221ecd165132a361ab2e84fda82644ed45e6de

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.79234
MD5 2ed6fd4dcebc5bc61e7778d50950e07a
SHA1 c94520b5d959bcb26a81cfb161df4580781b0ee8
SHA256 861d1225004c93acccef08faa901bf6efe11a4ca12e4e2139ebae7e38c3ef1bd
SHA3 6324920c2080a39cee63270967e0c40236e0bfbca3e6253d695c6dc6565fe761

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.89025
MD5 667b48fd7ba5c34d4cb44a4f1513ac22
SHA1 d8a52066e1ed45986a6edd9d94e4842bfea1327d
SHA256 a06d0a2829ea91c17be4aaa422fcf54d085ccf9b5f3eec82ee0c4c9ccf4b117a
SHA3 f912da9c470d7efd7d6bff92ad99df192dc81a030c98c1e8dc412aa5cc75ef69

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.23976
MD5 409040c7690d2fbd0289082dbfdd338d
SHA1 16fe2c60c60e6f1a23322ab78416263955a30fb5
SHA256 a912680cf8a64f748ccbefa6309174ef3023961779842c5a3698853ad62dd11d
SHA3 df34a936a6f8b4b9d475de95e3776123e1cff1e52bd7139a274fb6029d795fc8

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56031
MD5 e518b8ae009986dd90363fcc61d7fff7
SHA1 24ed3f9f44fce167e79b53ea5f9b0505c4d567e1
SHA256 34ea1c2173226ecc593f8a2b0224c51ebbee1928715bda9339eec7717a822b89
SHA3 519dec097566117a56d9c49b0a711e82451c0f81fbb53f042549a61cd51122e6

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xd4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25287
MD5 ac85ded4e576ce909f5460536b63a4f1
SHA1 07e0380006e58eec02eaaa047a58aceeef1552d3
SHA256 e1d818d622875ce2cf81883816ef982aa05a724c46f82b3e67875e0bc24228b1
SHA3 d70f10064348a4608f8b92740e05f739736144b222db3aa5c51187c75c5cc4eb

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xa4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26919
MD5 519a33f5d2b4442ef3caf6d4501995fb
SHA1 e54df9d112555eb11a132bfee15b69ac186b422e
SHA256 80bc91470ef70d527d0c4e0824945bc3b17ff84f464bca425661c3e7e1972ce7
SHA3 88c911ed5f1b1354c3379baaaef2540d70c370fd877f536d069dc0ea55cd0b13

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33268
MD5 234c2763997eec9c8a72ef190b928d68
SHA1 089fcaabba97f63455ce8a47e2d5d07fa56ba55b
SHA256 33ef72f38fc1fe2842c44e11bb351f94385bb186fee0fadbefc9364ed52aeb93
SHA3 10cbb07d784f332702d9d3451649950c1af6fb999ac1c2dac82df168cba5f302

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x34c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34579
MD5 2596d19a6b88cbba9c9c9cb003affbc6
SHA1 37091a716fd1eed000e0c3bb195fbd589a750608
SHA256 7f63f3f944a0b62f8f3b35a60141081599f7f175605ced7e1b4dcb80fda58c8a
SHA3 0b2581dd0c1b08d882b1f4c4014652d2e7d046d95aa3df236690e9d22572b27c

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x294
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28057
MD5 1f9009e4d5b61392e05aa8ac6eceb6aa
SHA1 4af6f3144fff0951da37370a3d200e8d74fc4862
SHA256 cb21f2b28bfc6b8046348c7a96bf97149dc5f91e1cc1a4f2904a1044a008425a
SHA3 c1aebde06ed543947facd67a9541283cbec74e559e267c1b84c168a2bf839812

CHARTABLE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x82e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5072
MD5 6e9c1c8c0a0ec8d73165779560cd7ba4
SHA1 d044c45e2ffd24e1abef00079577df385e325ab4
SHA256 677245e2a6b2eb5495b4965b8c26025a4b26e8b8c21a825f658cb390b493b9a0
SHA3 3ec7819e8561ecad66b1ef2652d4f3b275030f7cf402f276daa38f28d288e4e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 a40263c75fde7440b1086b7da9c51fc2
SHA1 139a84f87110fb5cb16a386adade21f30cae98b0
SHA256 e7dbe99baa5c1045cdf7004edb037018b2e0f639a5edcf800ec4514d5c8e35b5
SHA3 d3a734fa7d36868d301f9569de92e1bfc551e4b5cf6d7c59eace8d0a554093c0

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x150
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17906
MD5 9247d9dfc002426bf15a38569e1117d6
SHA1 724fbe0b18bf415f1871fbc45570b1ba809b1acd
SHA256 05efbff33471fec1389d42d84ee0572448b1dabb86c18ee38dd6463ff7f927af
SHA3 908ebb293645b24313fed4562495cebabd348ab84dceaded2145fa135e0ee180

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.22976
MD5 30903a47b9290538401f564cbd1f7f84
SHA1 7990a37efecb9bfcee29543b4073b827e6e42e10
SHA256 4e6d00c8e4728a79c581bee0f0d7d6c22de132158b39d9e9bb6df3dbd545ac4e
SHA3 1c33fe10b3503c99826db70f0d044a4eb75e9419fba192f5cb456d86211023b3

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71858
Detected Filetype Icon file
MD5 232023b445cbe11daa44739e40da75f1
SHA1 20cd92e6f023491463dd9adf68c77ed89e364039
SHA256 2f9f6e32df7bc4b78172d2445ca9489ff8b9694c339c1072825293963ca4c437
SHA3 57202acd336ab756f32a8b7954e03e893f81c2945b658c2be188a3b3bdedbb5d

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x584
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85625
MD5 4c65bee5f68fabec74ba19fbea652f07
SHA1 4e20833c444ea83e93422b8bee5ed73001a7adca
SHA256 eea6785979daf2ba8a6b94e8acf7a4205fb8f3c8f11c91fcb8ce1dd899849edb
SHA3 e912132882f920bab9af0c6cc8c16015f1e44e834b7ee98ccd95699726bf58cb

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x62c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.13965
MD5 f78a870573f5bf2f15570e286257fae7
SHA1 eaccbf47cd42836b0e21ab2196b86d98a28733ca
SHA256 356ca8abf11d97bf9dcbff47c04bf1ddcb8685ef84d38e6850ec6c28a37655b9
SHA3 f19c38bb277b8098eb08d8b9a12df0b660a7c01098e20adda4c4fc5765d937ca

String Table contents

Friday
Saturday
Invalid file name - %s
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
Invalid variant type conversion
Invalid variant operation
Invalid argument
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
Jan
Feb
Mar
Apr
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Out of memory
I/O error %d
File not found
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName GOG.com
FileDescription Baldur's Gate 3 Setup
FileVersion (#2)
LegalCopyright 2018 GOG Sp. z o.o. All rights reserved.
OriginalFileName
ProductName Baldur's Gate 3
ProductVersion (#2) Release - v4.1.1.6072089 - Patch Patch7_Hotfix3.[5
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x41a000
EndAddressOfRawData 0x41a008
AddressOfIndex 0x4127ac
AddressOfCallbacks 0x41b010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
<-- -->