Unpacking this MAME executable

Extraction and unpacking of game archives and compression, encryption, obfuscation, decoding of unknown files
ZeeStuff
Posts: 1
Joined: Sun Feb 12, 2017 2:21 am

Unpacking this MAME executable

Post by ZeeStuff »

Hello everyone,

I have a MAME executable created by some Chinese hackers where they added PGM2 emulation, however they've obfuscated the executable and seemed to have packed it with something that doesn't allow any debugging. I ran Protection_ID against it and it says Themida/Winlicense but does not show a version. I've tried unpacking it via Themida methods of using the 1.4 script however it fails. Ollydbg also crashes when attempting to load it unless I set it to break at the system event rather than WinMain. This is beyond my capabilities so I'm asking for help as this would help to improve emulation in MAME if we are able to see what they did to add this system.

If anyone would be so kind as to help and unpack this executable, that would be awesome. Just knowing what it's packed with would be a great help as well. Thank you.

http://www.filedropper.com/mame_2

EDIT:

Apologies if this is the incorrect sub forum for this.