Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2020-Mar-11 14:50:28 |
Detected languages |
Chinese - PRC
English - United States Japanese - Japan Korean - Korea |
CompanyName | Ewmt2 |
FileDescription | Ewmt2 Launcher |
FileVersion | 1.0.28249.1 |
InternalName | Ewmt2 |
LegalCopyright | Copyright (C) 2015 @ Davian Thule && [DEV]EWC0d3r |
OriginalFilename | Ewmt2.exe |
ProductName | Ewmt2 S1 |
ProductVersion | 3.0 |
Suspicious | PEiD Signature: |
ASPack v2.12
UPX -> www.upx.sourceforge.net |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to Whirlpool Uses constants related to AES Uses constants related to Blowfish Uses constants related to RC5 or RC6 Uses constants related to Twofish Uses constants related to TEA Uses known Diffie-Helman primes Microsoft's Cryptography API |
Suspicious | The PE is possibly packed. | Unusual section name found: .data1 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x140 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2020-Mar-11 14:50:28 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 12.0 |
SizeOfCode | 0x220000 |
SizeOfInitializedData | 0x4d0600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x001D7F9B (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x221000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x6f3000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
OutputDebugStringW
HeapReAlloc SetStdHandle FreeEnvironmentStringsW GetEnvironmentStringsW GetFileAttributesExW GetPrivateProfileStringA lstrlenA GetCurrentDirectoryA MoveFileA FindClose FindNextFileA FindFirstFileA SetFileAttributesA InitializeCriticalSection LeaveCriticalSection EnterCriticalSection DeleteCriticalSection GetSystemInfo GetCurrentDirectoryW MultiByteToWideChar Module32Next Module32First GetCurrentProcessId HeapFree GetProcessHeap HeapAlloc FlushFileBuffers GetTimeZoneInformation GetOEMCP GetACP IsValidCodePage ReadConsoleW SetFilePointerEx GetConsoleMode FreeLibrary HeapSize GetModuleFileNameW GetStdHandle EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetModuleHandleW GetStartupInfoW WriteConsoleW TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount SetLastError CreateProcessA GetFileType GetCPInfo LoadLibraryExW GetCurrentThreadId RtlUnwind RaiseException GetCommandLineA AreFileApisANSI GetModuleHandleExW ExitProcess GetSystemTimeAsFileTime IsDebuggerPresent DecodePointer EncodePointer GetStringTypeW CreateFileW IsProcessorFeaturePresent HeapValidate QueryPerformanceCounter ReleaseSemaphore GetLocaleInfoA CompareStringA WideCharToMultiByte GetVersionExA GetSystemDirectoryA LoadLibraryA lstrlenW GlobalUnlock GlobalLock ReadFile WriteFile OutputDebugStringA TlsFree GetExitCodeProcess ResumeThread WaitForSingleObject LoadLibraryExA GetTickCount ReadProcessMemory CloseHandle Process32Next OpenProcess Process32First CreateToolhelp32Snapshot GetModuleHandleA GetProcAddress GetCurrentProcess TerminateProcess CreateThread SetEnvironmentVariableA SetEndOfFile QueryPerformanceFrequency DeleteFileA GetModuleFileNameA GlobalFree UnhandledExceptionFilter CreateDirectoryW WinExec GetCurrentThread SetUnhandledExceptionFilter CreateFileA CreateFileMappingA UnmapViewOfFile MapViewOfFile GetFileSize CreateDirectoryA GlobalAlloc Sleep GetLastError GetComputerNameA GetConsoleCP GetVolumeInformationA |
---|---|
USER32.dll |
MessageBoxA
GetDC FillRect ReleaseDC PeekMessageA ClientToScreen GetClientRect OffsetRect SetRect GetAsyncKeyState PostQuitMessage GetCursorPos ScreenToClient FindWindowA LoadIconA CharPrevExA CharNextExA CharNextW GetClipboardData CloseClipboard OpenClipboard GetKeyboardLayout GetKeyboardLayoutNameA DispatchMessageA TranslateMessage GetMessageA LoadCursorA AdjustWindowRectEx GetMenu RegisterClassA SetWindowLongA GetWindowLongA UpdateWindow SetFocus MoveWindow DestroyWindow GetWindowTextA WindowFromPoint SendMessageA FindWindowExA IsWindow CreateWindowExA RegisterClassExA UnregisterClassA DefWindowProcA SetWindowPos SystemParametersInfoA GetKeyState LoadImageA DestroyCursor ShowCursor SetCursor SetCursorPos SetCapture ReleaseCapture ChangeDisplaySettingsA ShowWindow GetCapture GetSystemMetrics LoadStringA InvalidateRect |
GDI32.dll |
GetStockObject
EnumFontFamiliesExA CreateFontIndirectA GetCharABCWidthsFloatW GetTextExtentPoint32W SelectObject SetBkColor SetTextColor CreateSolidBrush DeleteObject StretchBlt GetTextExtentPoint32A TextOutA CreateDIBSection SetBkMode DeleteDC CreateCompatibleDC TextOutW |
ADVAPI32.dll |
GetLengthSid
RegOpenKeyExA RegQueryValueExA RegOpenKeyA CryptGenRandom GetUserNameA CryptAcquireContextA CryptCreateHash CryptReleaseContext CryptHashData CryptDestroyHash CryptGetHashParam OpenProcessToken GetTokenInformation AllocateAndInitializeSid RegCloseKey InitializeAcl AddAccessDeniedAce AddAccessAllowedAce InitializeSecurityDescriptor FreeSid SetSecurityInfo SetSecurityDescriptorDacl |
SHELL32.dll |
ShellExecuteA
SHGetSpecialFolderPathA |
ole32.dll |
CoInitializeEx
OleUninitialize OleInitialize CoGetClassObject OleSetContainedObject CoUninitialize CoInitialize CoCreateInstance |
WINMM.dll |
timeGetTime
timeEndPeriod timeGetDevCaps timeBeginPeriod |
d3d8.dll |
Direct3DCreate8
|
python27.dll |
Py_BuildValue
PyErr_SetString PyExc_RuntimeError PyTuple_GetItem PyList_New PyString_FromString PyList_Append Py_InitModule4 PyModule_AddIntConstant PyTuple_Size PyDict_GetItemString PyLong_AsLong PyLong_FromUnsignedLongLong PyLong_FromLongLong PyDict_Size PyDict_Next PyString_InternFromString PyObject_GetAttrString PyObject_GetAttr PyCallable_Check PyLong_AsLongLong PyFloat_AsDouble PyString_AsString PyErr_Clear PyErr_BadArgument PyErr_Print PyObject_CallObject PyNumber_Check _Py_NoneStruct PyDict_SetItemString PyModule_GetDict PyInt_AsLong PyErr_Fetch Py_SetProgramName Py_Initialize Py_Finalize PyRun_StringFlags PyImport_AddModule PyImport_ImportModule |
DevIL.dll |
ilOriginFunc
ilLoad ilGetInteger ilConvertImage ilCopyPixels ilDeleteImages ilShutDown ilSave ilTexImage ilSetPixels ilInit ilBindImage ilEnable ilGenImages |
IMM32.dll |
ImmGetOpenStatus
ImmSetConversionStatus ImmGetConversionStatus ImmGetCandidateListW ImmSetCompositionStringW ImmGetCompositionStringW ImmAssociateContext ImmReleaseContext ImmGetContext ImmIsIME ImmGetIMEFileNameA ImmNotifyIME |
PSAPI.DLL |
EnumProcessModules
EnumProcesses GetModuleFileNameExA |
imagehlp.dll |
StackWalk
EnumerateLoadedModules GetTimestampForLoadedLibrary |
VERSION.dll |
VerQueryValueA
GetFileVersionInfoA GetFileVersionInfoSizeA |
granny2.dll |
_GrannyReadEntireFileFromMemory@8
_GrannyFreeFileSection@8 _GrannyFreeFile@4 GrannyPNT332VertexType _GrannyDeformVertices@24 _GrannyFreeMeshDeformer@4 _GrannyNewMeshDeformer@16 _GrannyCopyMeshIndices@12 _GrannyGetMeshVertices@4 _GrannyCopyMeshVertices@12 _GrannyGetMeshVertexType@4 _GrannyGetMeshTriangleGroups@4 _GrannyGetMeshTriangleGroupCount@4 _GrannyPlayControlledAnimation@12 _GrannySetControlRawLocalClock@8 _GrannyConvertSingleObject@20 _GrannyFindMatchingMember@16 _GrannyGetMaterialTextureByType@8 _GrannySetLogCallback@4 _GrannyGetControlRawLocalClock@4 _GrannySetControlEaseOutCurve@28 _GrannySetControlEaseOut@8 _GrannySetControlEaseInCurve@28 _GrannySetControlEaseIn@8 _GrannyGetControlLocalDuration@4 _GrannySetControlSpeed@8 _GrannyGetControlSpeed@4 _GrannySetControlLoopCount@8 _GrannyGetControlLoopCount@4 _GrannyFreeControlIfComplete@4 _GrannyControlIsComplete@4 _GrannyCompleteControlAt@8 _GrannyFreeControlOnceUnused@4 _GrannyFreeControl@4 _GrannyGetMeshIndexCount@4 _GrannyMeshIsRigid@4 _GrannyGetMeshVertexCount@4 _GrannyGetTotalTypeSize@4 _GrannyGetWorldPoseComposite4x4@8 _GrannyGetWorldPose4x4@8 _GrannyFreeWorldPose@4 _GrannyNewWorldPose@4 _GrannyFindBoneByName@12 _GrannyGetMeshBindingToBoneIndices@4 _GrannyFreeMeshBinding@4 _GrannyNewMeshBinding@12 _GrannyFreeModelInstance@4 _GrannyInstantiateModel@4 _GrannyGetWorldPoseComposite4x4Array@4 _GrannyFreeLocalPose@4 _GrannyNewLocalPose@4 _GrannyUpdateModelMatrix@20 _GrannySampleModelAnimationsAccelerated@20 _GrannyFreeCompletedModelControls@4 _GrannySetModelClock@8 _GrannyGetSourceSkeleton@4 _GrannyGetFileInfo@4 |
mss32.dll |
_AIL_decompress_ASI@24
_AIL_decompress_ADPCM@12 _AIL_open_digital_driver@16 _AIL_open_stream@12 _AIL_close_digital_driver@4 _AIL_enumerate_3D_providers@12 _AIL_open_3D_provider@4 _AIL_close_3D_provider@4 _AIL_open_3D_listener@4 _AIL_close_3D_listener@4 _AIL_set_3D_position@16 _AIL_set_3D_velocity@20 _AIL_set_3D_orientation@28 _AIL_startup@0 _AIL_shutdown@0 _AIL_set_redist_directory@4 _AIL_close_stream@4 _AIL_start_stream@4 _AIL_pause_stream@8 _AIL_set_stream_volume_levels@12 _AIL_stream_volume_levels@12 _AIL_set_stream_loop_count@8 _AIL_stream_status@4 _AIL_last_error@0 _AIL_WAV_info@8 _AIL_release_sample_handle@4 _AIL_init_sample@4 _AIL_set_sample_file@12 _AIL_start_sample@4 _AIL_stop_sample@4 _AIL_resume_sample@4 _AIL_end_sample@4 _AIL_set_sample_volume_pan@12 _AIL_set_sample_loop_count@8 _AIL_sample_status@4 _AIL_sample_volume_pan@12 _AIL_allocate_3D_sample_handle@4 _AIL_release_3D_sample_handle@4 _AIL_start_3D_sample@4 _AIL_stop_3D_sample@4 _AIL_resume_3D_sample@4 _AIL_end_3D_sample@4 _AIL_set_3D_sample_file@8 _AIL_set_3D_sample_volume@8 _AIL_set_3D_sample_loop_count@8 _AIL_3D_sample_status@4 _AIL_3D_sample_volume@4 _AIL_auto_update_3D_position@8 _AIL_set_file_callbacks@16 _AIL_file_read@8 _AIL_allocate_sample_handle@4 _AIL_file_type@8 _AIL_mem_free_lock@4 |
SpeedTreeRT.dll |
?LoadTree@CSpeedTreeRT@@QAE_NPBEI@Z
?LoadTree@CSpeedTreeRT@@QAE_NPBD@Z ?MakeInstance@CSpeedTreeRT@@QAEPAV1@XZ ?Compute@CSpeedTreeRT@@QAE_NPBMI_N@Z ??3CSpeedTreeRT@@SAXPAX@Z ??2CSpeedTreeRT@@SAPAXI@Z ??1CSpeedTreeRT@@QAE@XZ ??0CSpeedTreeRT@@QAE@XZ ??1STextures@CSpeedTreeRT@@QAE@XZ ??0STextures@CSpeedTreeRT@@QAE@XZ ?SetTreeSize@CSpeedTreeRT@@QAEXMM@Z ?GetTreePosition@CSpeedTreeRT@@QBEPBMXZ ?SetTreePosition@CSpeedTreeRT@@QAEXMMM@Z ??1SGeometry@CSpeedTreeRT@@QAE@XZ ?SetBranchLightingMethod@CSpeedTreeRT@@QAEXW4ELightingMethod@1@@Z ?SetCamera@CSpeedTreeRT@@SAXPBM0@Z ?GetTextures@CSpeedTreeRT@@QBEXAAUSTextures@1@@Z ?GetGeometry@CSpeedTreeRT@@QAEXAAUSGeometry@1@KFFF@Z ?GetNumFrondLodLevels@CSpeedTreeRT@@QBEGXZ ?GetNumLeafLodLevels@CSpeedTreeRT@@QBEGXZ ?GetNumBranchLodLevels@CSpeedTreeRT@@QBEGXZ ?SetLodLimits@CSpeedTreeRT@@QAEXMM@Z ?SetDropToBillboard@CSpeedTreeRT@@SAX_N@Z ?SetLodLevel@CSpeedTreeRT@@QAEXM@Z ?ComputeLodLevel@CSpeedTreeRT@@QAEXXZ ?SetLocalMatrices@CSpeedTreeRT@@QAEXII@Z ?SetFrondWindMethod@CSpeedTreeRT@@QAEXW4EWindMethod@1@@Z ?SetBranchWindMethod@CSpeedTreeRT@@QAEXW4EWindMethod@1@@Z ?SetLeafWindMethod@CSpeedTreeRT@@QAEXW4EWindMethod@1@@Z ?SetNumLeafRockingGroups@CSpeedTreeRT@@QAEXI@Z ?SetLeafRockingState@CSpeedTreeRT@@QAEX_N@Z ?GetFrondMaterial@CSpeedTreeRT@@QBEPBMXZ ?GetLeafMaterial@CSpeedTreeRT@@QBEPBMXZ ?SetLightState@CSpeedTreeRT@@SAXI_N@Z ?SetNumWindMatrices@CSpeedTreeRT@@SAXI@Z ?SetLeafLightingMethod@CSpeedTreeRT@@QAEXW4ELightingMethod@1@@Z ?SetTextureFlip@CSpeedTreeRT@@SAX_N@Z ?GetCurrentError@CSpeedTreeRT@@SAPBDXZ ?GetBoundingBox@CSpeedTreeRT@@QBEXPAM@Z ?GetBranchMaterial@CSpeedTreeRT@@QBEPBMXZ ?GetCollisionObjectCount@CSpeedTreeRT@@QAEIXZ ?GetCollisionObject@CSpeedTreeRT@@QAEXIAAW4ECollisionObjectType@1@PAM1@Z ??0SGeometry@CSpeedTreeRT@@QAE@XZ ?SetLightAttributes@CSpeedTreeRT@@SAXIPBM@Z ?SetWindStrength@CSpeedTreeRT@@QAEMMMM@Z ?SetTime@CSpeedTreeRT@@SAXM@Z ?SetFrondLightingMethod@CSpeedTreeRT@@QAEXW4ELightingMethod@1@@Z |
DINPUT8.dll |
DirectInput8Create
|
WS2_32.dll |
#11
#9 #4 #116 #115 #111 #23 #19 #18 #52 #3 #16 #10 #151 |
DDRAW.dll |
DirectDrawCreate
|
OLEAUT32.dll |
#2
#8 #9 #6 |
Ewmt2 |
's |
IDS_WARN_BAD_DRIVER |
IDS_WARN_NO_TNL |
Cannot read %s file |
File '%s' is not latest version. Please launch patcher. |
Please run patcher. |
's |
메틴2 |
의 |
그래픽 드라이버를 업데이트 하시기 바랍니다. |
사용하고 계신 시스템의 그래픽카드는 3D TnL 하드웨어 가속이 지원되지 않아 |
게임이 느리게 실행되거나 제대로 실행되지 않을수 있습니다. |
%s 파일을 읽을 수 없습니다. |
'%s' 파일은 최신버전이 아닙니다. 런처를 다시 실행해주세요. |
클라이언트는 패처를 사용해서 실행되어야 합니다. |
's |
希望您能更新显卡驱动。 |
您的显卡不支持3D TnL 硬件加速 |
游戏将无法正常运行。 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.28249.0 |
ProductVersion | 1.0.0.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
CompanyName | Ewmt2 |
FileDescription | Ewmt2 Launcher |
FileVersion (#2) | 1.0.28249.1 |
InternalName | Ewmt2 |
LegalCopyright | Copyright (C) 2015 @ Davian Thule && [DEV]EWC0d3r |
OriginalFilename | Ewmt2.exe |
ProductName | Ewmt2 S1 |
ProductVersion (#2) | 3.0 |
Resource LangID | Korean - Korea |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x6ae730 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0xc510b891 |
---|---|
Unmarked objects | 0 |
48 (9044) | 1 |
Linker (VC++ 6.0 SP5 imp/exp build 8447) | 60 |
199 (41118) | 5 |
ASM objects (VS2013 build 21005) | 75 |
C++ objects (VS2013 build 21005) | 86 |
C objects (VS2013 build 21005) | 263 |
C objects (9178) | 6 |
C++ objects (9178) | 76 |
18 (8444) | 1 |
Unmarked objects (#2) | 8 |
Imports (9210) | 6 |
C++ objects (VS2013 UPD5 build 40629) | 208 |
C objects (VS2013 UPD5 build 40629) | 1 |
C objects (VS2008 SP1 build 30729) | 54 |
Imports (VS2008 SP1 build 30729) | 33 |
Total imports | 524 |
229 (VS2013 UPD5 build 40629) | 150 |
Resource objects (VS2013 build 21005) | 1 |
151 | 1 |
Linker (VS2013 UPD5 build 40629) | 1 |