Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 11-07-2005, 19:10
macpiter
 
Posts: n/a
ripping some data from upx packed file

Hi,

I`ve got upx packed file that contains some graphic and music module. It`s a keygenerator from vengenace group. I used procdump32 to dump keygen process from memory and now file is 10 times bigger than original and still works fine so I suppose that file is now unpacked and descrambled (maybe I`m wrong, I don`t know). Then I used DOS multi ripper 3.0 and I found these bitmaps inside. It also found mxm file (probably it`s a gus music module format) but file is to big and has many unwanted informations about dll calls inside so I`m sure that file is incorrect. So my question is...would it be possible to ripp manualy music played by keygen ?? I know that some people did such thing so can you give my some clues ? I`d be gratefull for every suggestion

Best regards
Peter
Reply With Quote
  #2  
Old 11-08-2005, 11:53
nskSem
 
Posts: n/a
1. Open EXE in hex-editor (hiew, winhex etc) and try to find header signature (you may open existing BMP, or MXM and saw it) and dum it.
2. Disassemble EXE and find GDI, WindowsMedia or DirectX API entry and debug it in programm work.
Head and hand will help you.
Reply With Quote
  #3  
Old 11-09-2005, 03:31
Unforgiv3N's Avatar
Unforgiv3N Unforgiv3N is offline
Friend
 
Join Date: Aug 2005
Posts: 172
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 3 Times in 3 Posts
Unforgiv3N Reputation: 0
Try Heaven$oftware Resource Tunner, it have a good UPX Unpacker that also works with Modified UPX files!

and music file should be play with Winamp!
Reply With Quote
  #4  
Old 11-09-2005, 07:41
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
and mxm file (and other files)may be attached as overlay or may be in resource of exe file. You must find it's type to dump.

Last edited by Newbie_Cracker; 11-09-2005 at 07:44.
Reply With Quote
  #5  
Old 11-09-2005, 20:41
Human
 
Posts: n/a
mxm is reduced size xm for mxm player, there is xm2mxm converter and viceversa, so fire up google and look for mxm2xm thats all
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to SMC a packed ocx file? killl General Discussion 1 08-22-2005 23:55


All times are GMT +8. The time now is 17:29.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )