7d5d9e08e0f048168db7fd529fcbf638

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1992-Jun-19 22:22:17
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName Decepticon
FileDescription Total War Three Kingdoms Setup
FileVersion
LegalCopyright Decepticon
ProductName Total War Three Kingdoms
ProductVersion v.1.7.1

Plugin Output

Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessA
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 4449314 bytes of data starting at offset 0x14a00.

Hashes

MD5 7d5d9e08e0f048168db7fd529fcbf638
SHA1 8822ffb93051b08b9595ad3a9514a19dd08917de
SHA256 712ff8e1b0e486b852d0cbe998179f3dfefaba857da6394354c07214e5653e24
SHA3 43cd1fe3bd7ea356d872fb65b14f00445eb84ddbd24dd7af285576945d371551
SSDeep 98304:wE1sc97xLiVPpX/GBmRlolahu1VVl5LuSYHgYY:/1BrLiPpPh4VlLXIgh
Imports Hash 4fb639b17a439bf0efa713bd4c6e715b

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 1992-Jun-19 22:22:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x9400
SizeOfInitializedData 0xb200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00009C14 (Section: CODE)
BaseOfCode 0x1000
BaseOfData 0xb000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 1.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x1c000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

CODE

MD5 0f1e58bee0e7f7b353de3dde9de0259d
SHA1 cd63f5af7ca6959334a306e7d9bdb2cf56525e70
SHA256 7890404ed39ba0d699a791a17047bae44bd2287e3e4fb71a80d5b0474f87dd00
SHA3 bdaad60feea207f5cc9268aef0bf82e12020be650bb30e0f28a19f27697197a0
VirtualSize 0x9338
VirtualAddress 0x1000
SizeOfRawData 0x9400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.55652

DATA

MD5 e7dd09e5875d98f57a11be52cd2304a5
SHA1 a46ccf47a822e3d4b226525beb4168bf5702df5b
SHA256 f7f25afb75691a6bbdd6667a4ac9e9c8572311c6f2add8d017142497ebc963a2
SHA3 eb69a46cd1b83ec238ceb21b9e96d639b91287df37ebdfa7a27e923664b46cde
VirtualSize 0x24c
VirtualAddress 0xb000
SizeOfRawData 0x400
PointerToRawData 0x9800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.7543

BSS

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xe50
VirtualAddress 0xc000
SizeOfRawData 0
PointerToRawData 0x9c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 bb5485bf968b970e5ea81292af2acdba
SHA1 40a39d9e8c8cecd5356ab96745d82d2ebfe17cfb
SHA256 d9ea6e80cc1edfdffa8d534a8c61448b19b74d683845b94ad6d9a543e5ceb8cf
SHA3 09274dc071547ce3dc33528de99c9ad5a9eb119600e5a61b3127f74cde6dcfbf
VirtualSize 0x950
VirtualAddress 0xd000
SizeOfRawData 0xa00
PointerToRawData 0x9c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.43073

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8
VirtualAddress 0xe000
SizeOfRawData 0
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 9ba824905bf9c7922b6fc87a38b74366
SHA1 f43ee83e6afa1c343ff6db68e13efde43471cbb6
SHA256 ad44157821ba24c07dd44f66940dd75adee9d6919a0577c5a75aa502637dddaa
SHA3 370eba5499bce03a18d462f5b9e6ee4598126f2a2243cc5fa1590c7c7245c5d7
VirtualSize 0x18
VirtualAddress 0xf000
SizeOfRawData 0x200
PointerToRawData 0xa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.204488

.reloc

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8b0
VirtualAddress 0x10000
SizeOfRawData 0
PointerToRawData 0xa800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED

.rsrc

MD5 1a329c92420712f03cabd42b3a487d5b
SHA1 7cfdd0489d15f6f625b6efbe8beeef5c015eea32
SHA256 f6e65c0fcc593238a9383b92603e4939b26928b94717d20fa09a76cadba31a71
SHA3 e854d389c333139686cec4e86ee8957d5e8ea6205332cb4beeb699c0f354168a
VirtualSize 0xa04c
VirtualAddress 0x11000
SizeOfRawData 0xa200
PointerToRawData 0xa800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 4.25693

Imports

kernel32.dll DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
user32.dll MessageBoxA
oleaut32.dll VariantChangeTypeEx
VariantCopyInd
VariantClear
SysStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA
kernel32.dll (#2) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
ExitProcess
CreateFileA
CloseHandle
user32.dll (#2) MessageBoxA
comctl32.dll InitCommonControls
advapi32.dll (#2) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
OpenProcessToken
LookupPrivilegeValueA

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82837
MD5 25d6ad3a4d2181cd4643f663ad8021ab
SHA1 51c5ba8110f6a41e252194678ceabddf405917ca
SHA256 d47d70d1464d85b28230ed47edcc28f28559feed794f17da7f9c4d25a1870524
SHA3 b429ef4ae241233f6fa6dd9bfbf05c459a042316c3be008a2980a478faf0addb

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67558
MD5 6763ab19171b06ac737f959d1fd65bf0
SHA1 25e98fcf3f5e33ae57e540f0b24f679bf02c90e3
SHA256 2f597281c59acb81da4db5d7f7a0ec4060517a62e28a76e40b45b5b96d9c4885
SHA3 014375e2738316b2181de8299f85893c699325db82ce516bc96469c9f60b0f28

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89827
MD5 03cb28c621511d2623c295c558e9782f
SHA1 21d5bba93898887e90bb01f065a5f25b10472a72
SHA256 584236b052ecc4ba8a02d44aeeac346cc5b807239fb5e2c7f46f961cec2359bd
SHA3 852ea0c178864b5d8ee6df23906ee211b56d4609a5f201b8a83069180a271ce7

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.51539
MD5 8c92b6bb5cfee595e19db36973435c63
SHA1 a84c1ee38311ad71a8752ace13ccaad2892ed3ab
SHA256 6101039b2a2e54b0cf59aaad5fbc967a46862bc271bc5793058c4c2b2ed98d97
SHA3 1234953b03f19173ba8a99a78850088791c942dd4482e510211c7cc35255a996

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.15892
MD5 07ab40232a754ed2c0c15f56192dde9b
SHA1 72a8b142843ed9ba3c1366a0c2dd830dc5dcf0b0
SHA256 a46669b7090cad24527074dfd013eb298836b9dff9db55f781cc3589705f9312
SHA3 27f58ef50cacda60d91b08ee15dab02815a9587a93fb666ee8706572a6043dfd

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26966
MD5 55db13156d52e71e247bf594cef9be66
SHA1 e1ed9f3fb7e19f63cd4d16074f11f7b992036a35
SHA256 5f428fc081986f24be631756b8b5e4c7113241a91d36b22240d6fc847b758a86
SHA3 aa21f2495f864196a61c8f85e531571186e981d4254b1c8f9e3320ab92f5ce30

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1a68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.60483
MD5 d1f895b65364542e3fe539ca366de5be
SHA1 102279d92ae4c85aacd085b5680359c7636cef39
SHA256 9cf88dfb9851ae399493e1e42a1162367d3eacd46dda30781bf260feca009112
SHA3 f93618994ebf3504f711c274e1c3c6c8412cfaba51d27883da64f8d47a6f4d42

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.72355
MD5 d2d493f4e91c327c9c37201326dca452
SHA1 c0412588649c619fa09f17ecebdf917c530dc068
SHA256 b97446fcd9e86758aa319cc241e1288fc2bd3d89dfb80e581d173f6fc643d298
SHA3 086298815cd53c84e551d83b4110e211a66f692df98332483d3e1eac73497667

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.75794
MD5 4c54402688c6359279c8b4724ba62786
SHA1 62e0c9ba9f11a8b84610efc99e7c2d194425713f
SHA256 640c1804ccd1f401283694b42f0e887deddb60fb8632f2839d79d50ba7fc850e
SHA3 321d0218457e5b76d2e8feef657c69c87c5a6db4c1fd9ddf06319a69a1dc4f5f

10

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x6b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.81688
MD5 dfdeffd191f83bb3c5276fd21b959021
SHA1 fb50663ab9544ffda973be17e8b7412d999f3a89
SHA256 d734a5446401d6b72abd67a5dff4aa38f205576f3e4a9a7fa360f9961d1b9efd
SHA3 5a1a37f9c5a8136a04d622af7e7a2adbab7ab73b892e0ae3fe077e5f575f7f21

11

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.84944
MD5 17b21007300b6143ae9580bc38b2a167
SHA1 7b3fdeddc9f2209d04bb787a9f74a29cf0c71475
SHA256 97b2c6129aa9f2c73bc1e163da3e7b3e5938a3eab39188cd981fab04ec5d3d2c
SHA3 9e18f0d999f1cf6a6469c07cb9596917582a3c8f8ce6889eb51d1b9a8d26ca64

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2f2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21823
MD5 bbf4b644f9dd284b35eb31573d0df2f7
SHA1 4f9885ae629e83464e313af5254ef86f01accd0b
SHA256 2c0d32398e3c95657a577c044cc32fe24fa058d0c32e13099b26fd678de8354f
SHA3 ebed2e4a929600c1460761d462143feb092840986b31c9748d3aeb8174d4205e

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x30c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31515
MD5 ac2a0551cb90f91d779ee8622682dfb1
SHA1 ff0db7d2f48d85ceb3539b21ebe9d0ca3443f1da
SHA256 840989e0a92f2746ae60b8e3efc1a39bcca17e82df3634c1643d76141fc75bb3
SHA3 58a85f5c53df73aa79e5f5a36aa151ca0d9da4d450ebc2975a3ee827b46342a5

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2ce
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25024
MD5 c99b474c52df3049dfb38b5308f2827d
SHA1 7375e693629ce6bbd1a0419621d094bcd2c67bb7
SHA256 26bda4da3649a575157a6466468a0a86944756643855954120fd715f3c9c7f78
SHA3 c6013febd14dd876e3b81111ec17dd2724dbf4147b0ad7be9d03259bcb59fef3

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86149
MD5 aec4e28ea9db1361160cde225d158108
SHA1 249013a10cde021c713ba2dc8912f9e05be35735
SHA256 d786490af7fe66042fb4a7d52023f5a1442f9b5e65d067b9093d1a128a6af34c
SHA3 a067c4d88d719ed8d568951acb776bd798b691a8b153f8d94ba0574ede1fbf4c

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20731
MD5 c76a8843204c0572bca24ada35abe8c7
SHA1 066052030d0a32310da8cb5a51d0590960a65f32
SHA256 00a0794f0a493c167f64ed8b119d49bdc59f76bb35e5c295dc047095958ee2fd
SHA3 07523cf88b3803ea41acfeb3c9c0c4b5b4b9fb6f9a3232802491d8de1b6c9166

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xae
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04592
MD5 4bd4f3f6d918ba49d8800ad83d277a86
SHA1 1f5e4c73965fea1d1f729efbe7568dcd081a2168
SHA256 34973a8a33b90ec734bd328198311f579666d5aeb04c94f469ebb822689de3c3
SHA3 2d01c56a5bf0b390addf4fb5b6ae02f9a64bd03ffd300d3763615bbb8ec911fe

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.56808
MD5 e470d49c079b0d7f0cd72f84c34c26e5
SHA1 a73c7387b9c1fae4acb995f1abd9fe2e2dea5cb1
SHA256 2f673a582960542d3e43a7060cb9ed787bf1b7a3c835bd4f317603450b145d71
SHA3 34716a15a65e6bdccb5245085e3b2152c65470a1b168e05ddc02f28d80f8358e

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.05962
MD5 4804d177e6b5147ac6e8b30e8f0a42d8
SHA1 02983acdfb2bcce6009e508874e5065707323b91
SHA256 3de0cfb642dcf11bf4923c5d97a8a438cf03f0b4726d13599f082fbc05b59dc3
SHA3 33f11b400a0f293fb122ae7d2033be46f482968a0cf019c21d6e98c06aa57ffa

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x4b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74817
MD5 a836d0bb6aa04c5f5fc53ad158c85730
SHA1 7b7c2b98803b8ebc56b2b5fac192b29ff871f9ac
SHA256 8e6019a0cd8ec1f43e4915fdc722570855031aacc6fc42da45bf3ecf3c313d30
SHA3 793d5b9036818da034d49b80a423c681dd93f6112fdfe4ad5f82f57ad887399c

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x560
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06505
MD5 a55a7d7c9ff1dedb9adde63011baa3dd
SHA1 292e1726ad2fb93963565934fd3778a46f91ecf9
SHA256 2cf04736815666b1c1b91422e56e0a431c9e03075b7f543325fd16b88cff1b9e
SHA3 9e3955461fcb3b2d303ad2a473b4f1c4012a882a3e303ba6e7b0170fbb09819e

String Table contents

'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time
'%s' is not a valid date and time
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Invalid variant type conversion
Invalid variant operation
Variant method calls not supported
Read
Write
Format result longer than 4096 characters
Format string too long
Error creating variant array
Variant is not an array
Variant array index out of bounds
External exception %x
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName Decepticon
FileDescription Total War Three Kingdoms Setup
FileVersion (#2)
LegalCopyright Decepticon
ProductName Total War Three Kingdoms
ProductVersion (#2) v.1.7.1
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x40e000
EndAddressOfRawData 0x40e008
AddressOfIndex 0x40c3d0
AddressOfCallbacks 0x40f010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: directory 5 has a size of 0! This PE may have been manually crafted! [*] Warning: Section BSS has a size of 0! [*] Warning: Section .tls has a size of 0! [*] Warning: Section .reloc has a size of 0! [*] Warning: Please edit the configuration file with your VirusTotal API key. [!] Error: Could not load yara_rules/bitcoin.yara! Could not load company_names.yara! [!] Error: Could not load yara_rules/monero.yara! [!] Error: Could not load yara_rules/findcrypt.yara! [!] Error: Could not load yara_rules/compilers.yara! [!] Error: Could not load yara_rules/suspicious_strings.yara! [!] Error: Could not load yara_rules/domains.yara! [!] Error: Could not load yara_rules/peid.yara!