Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 12-31-2017, 04:30
Stingered Stingered is online now
Friend
 
Join Date: Dec 2017
Posts: 257
Rept. Given: 0
Rept. Rcvd 2 Times in 2 Posts
Thanks Given: 297
Thanks Rcvd at 179 Times in 89 Posts
Stingered Reputation: 2
Likely N00b question - Bassmod.dll

Is it fairly normal for this DLL to be used for crack/Keygen EXEs? This seems to get flagged as a virus, a lot, but once the DLL is extracted it seems pretty benign:

seg003:10012280 0000000F C GetProcAddress
seg003:100122A4 0000000C C GlobalAlloc
seg003:100122C0 0000000C C timeGetTime
seg003:1001244A 00000015 C BASSMOD_ErrorGetCode
seg003:1001245F 0000000D C BASSMOD_Free
seg003:1001246C 0000000F C BASSMOD_GetCPU
seg003:1001247B 0000001D C BASSMOD_GetDeviceDescription
seg003:10012498 00000013 C BASSMOD_GetVersion
seg003:100124AB 00000012 C BASSMOD_GetVolume
seg003:100124BD 0000000D C BASSMOD_Init
seg003:100124CA 00000014 C BASSMOD_MusicDecode
seg003:100124DE 00000012 C BASSMOD_MusicFree
seg003:100124F0 00000017 C BASSMOD_MusicGetLength
seg003:10012507 00000015 C BASSMOD_MusicGetName
seg003:1001251C 00000019 C BASSMOD_MusicGetPosition
seg003:10012535 00000017 C BASSMOD_MusicGetVolume
seg003:1001254C 00000016 C BASSMOD_MusicIsActive
seg003:10012562 00000012 C BASSMOD_MusicLoad
seg003:10012574 00000013 C BASSMOD_MusicPause
seg003:10012587 00000012 C BASSMOD_MusicPlay
seg003:10012599 00000014 C BASSMOD_MusicPlayEx
seg003:100125AD 00000018 C BASSMOD_MusicRemoveSync
seg003:100125C5 00000018 C BASSMOD_MusicSetAmplify
seg003:100125DD 00000017 C BASSMOD_MusicSetPanSep
seg003:100125F4 00000019 C BASSMOD_MusicSetPosition
seg003:1001260D 0000001F C BASSMOD_MusicSetPositionScaler
seg003:1001262C 00000015 C BASSMOD_MusicSetSync
seg003:10012641 00000017 C BASSMOD_MusicSetVolume
seg003:10012658 00000012 C BASSMOD_MusicStop
seg003:1001266A 00000012 C BASSMOD_SetVolume
seg003:1001267C 0000000C C BASSMOD.dll

THX!
Reply With Quote
  #2  
Old 12-31-2017, 05:46
zeffy zeffy is offline
Friend
 
Join Date: Jul 2017
Posts: 44
Rept. Given: 3
Rept. Rcvd 7 Times in 6 Posts
Thanks Given: 194
Thanks Rcvd at 163 Times in 47 Posts
zeffy Reputation: 7
Yes I think it's fairly normal, it's used for playing music like .xm tracker modules.

If you are worried about it e.g. being modified to contain malware, you could check its hash against the official release of BASSMOD here: https://www.un4seen.com/bassmod.html
Reply With Quote
The Following User Says Thank You to zeffy For This Useful Post:
Stingered (12-31-2017)
  #3  
Old 12-31-2017, 08:56
Stingered Stingered is online now
Friend
 
Join Date: Dec 2017
Posts: 257
Rept. Given: 0
Rept. Rcvd 2 Times in 2 Posts
Thanks Given: 297
Thanks Rcvd at 179 Times in 89 Posts
Stingered Reputation: 2
Quote:
Originally Posted by zeffy View Post
Yes I think it's fairly normal, it's used for playing music like .xm tracker modules.

If you are worried about it e.g. being modified to contain malware, you could check its hash against the official release of BASSMOD here: https://www.un4seen.com/bassmod.html
There was a hash match for the latest downloadable version. Good call.
Reply With Quote
The Following User Says Thank You to Stingered For This Useful Post:
niculaita (12-31-2017)
  #4  
Old 01-02-2018, 21:34
LaDidi LaDidi is offline
VIP
 
Join Date: Aug 2004
Posts: 211
Rept. Given: 2
Rept. Rcvd 11 Times in 10 Posts
Thanks Given: 47
Thanks Rcvd at 41 Times in 24 Posts
LaDidi Reputation: 11
@Stingered:
It's due to compression method used : upx
Reply With Quote
The Following User Says Thank You to LaDidi For This Useful Post:
Stingered (01-03-2018)
  #5  
Old 01-02-2018, 22:04
squareD's Avatar
squareD squareD is offline
VIP
 
Join Date: Aug 2005
Location: Banana Republic
Posts: 301
Rept. Given: 31
Rept. Rcvd 35 Times in 27 Posts
Thanks Given: 37
Thanks Rcvd at 110 Times in 72 Posts
squareD Reputation: 36
I use bass.dll since years and years for playing really music in keygens, instead of xm racket, so believe me it's normal...
__________________
The three worst enemies of the reversers: sun , fresh air and especially this unbearable roar of birds ...
Reply With Quote
The Following User Says Thank You to squareD For This Useful Post:
Stingered (01-03-2018)
  #6  
Old 01-03-2018, 22:24
ReBirth's Avatar
ReBirth ReBirth is offline
Family
 
Join Date: Nov 2011
Posts: 79
Rept. Given: 12
Rept. Rcvd 39 Times in 20 Posts
Thanks Given: 19
Thanks Rcvd at 125 Times in 29 Posts
ReBirth Reputation: 39
Quote:
Originally Posted by LaDidi View Post
@Stingered:
It's due to compression method used : upx
it's Petite not upx. most un4seen stuff compressed by petite
un4seen.com/petite/
Reply With Quote
The Following User Says Thank You to ReBirth For This Useful Post:
Stingered (01-04-2018)
  #7  
Old 01-16-2018, 02:23
LaDidi LaDidi is offline
VIP
 
Join Date: Aug 2004
Posts: 211
Rept. Given: 2
Rept. Rcvd 11 Times in 10 Posts
Thanks Given: 47
Thanks Rcvd at 41 Times in 24 Posts
LaDidi Reputation: 11
@ReBirth :
The ones I've needeed to unpack used UPX...
Reply With Quote
The Following User Says Thank You to LaDidi For This Useful Post:
Stingered (01-16-2018)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Static linking of Bassmod in Delphi Sn!per X Source Code 0 01-13-2016 22:12
Question|IDA PRO Stitch General Discussion 10 02-17-2015 01:48
Question on PKE TmC General Discussion 8 09-19-2007 23:59
n00b Quest II(tm) abitofboth General Discussion 5 01-19-2006 15:32
N00b : help ? abitofboth General Discussion 11 05-05-2005 15:12


All times are GMT +8. The time now is 02:24.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )