Betaparticle

Diversion Tactics of an Information Systems Analyst

Extracting ThemeXP Setup Files

4/25/2007 3:59:31 AM in Computer by Matt

Tools Needed:
Wise Setup UnPacker http://kannegieser.net/~veit/programm/e_wise.arj

Downloaded e_wise and extract the files to C:\unwise\ - create this folder. e_wise_d.exe is probably the only required file being the unpacker itself.

1. Go to http://themexp.org/ and download any file you like

2. Copy & Paste the file to our "unWISE" directory and rename it to something like "red.exe".

3. Click "CTRL+R" (or Start > Run) and type "cmd /k" then when msdos windows opens up, type "cd C:\unwise".

4. At this point you should be in your "C:\unwise" directory. Now type "e_wise_d red.exe red_done". Where "e_wise_d" is our unpacker program, "red.exe" our downloaded file from themexp and "red_done" is our destination directory for extracted files. You should see series of code flying all over the dos screen, wait till it's done.

You can automate this by creating a textfile in this folder called doit.bat with this as the text:

e_wise_d red.exe red_done

and then double-clicking it in Windows Explorer, that way you can reuse it again without even the need for the command prompt.

5. Go to your "c:\unwise\red_done" directory, you should see file "00000000.BAT" click it to compile all directorys/files.

6. Now you should see "MAINDIR" directory, go to this directory. You should see spyware files in there like; atoolbar400011.exe Also you should see file "EXENAME" without extension.

7. Add .rar/zip extension to our "EXENAME" file. It should look like "EXENAME.rar" or "EXENAME.zip"

8. Now extract the file with WinRAR, go to "EXENAME" directory and you should see all the files.

To do it again, you can skip step 4 and double click the batch file you created: C:\unwise\doit.bat

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5
Bookmark and Share

Related posts

Add comment


(Will show your Gravatar icon)  

  Country flag

[b][/b] - [i][/i] - [u][/u]- [quote][/quote]



Live preview

  • 10/7/2008 1:23:30 AM