Co
(MM club member)
2021-11-18 01:08 PM
Extract kixtart script from an executable

All,

It's been ages ago since I created my last Kixtart script. I now come across compiled Kixtart scripts. As often, the administrator has left the company. How can I extract the script from this executable and find out what the script does?

Cheers,

Co


AllenAdministrator
(KiX Supporter)
2021-11-18 01:56 PM
Re: Extract kixtart script from an executable

If it was compiled with Kix2Exe, I'm pretty sure it was tokenized as well. I doubt there is anyone but Ruud who could help you.

It's been over 10 years. Glad to see you back.


Co
(MM club member)
2021-11-18 02:39 PM
Re: Extract kixtart script from an executable

Thanks Allen,

I had a nice time here on the Kixtart forum. Unfortunately I hardly come across Kixtart at companies anymore. with that, the visit to this forum has slowly become less and less and Before you know it, it's been over 10 years since my last here...


I was already afraid that the executables would not be extractable. Now I have to somehow figure out, what these executables do.


AllenAdministrator
(KiX Supporter)
2021-11-18 06:52 PM
Re: Extract kixtart script from an executable

Again, I'm guessing Kix2Exe, but if it is K2E, monitor the temp directory while the exe is running. It creates a folder to drop the kix32.exe and script in. The file will most likely be tokenized, but if not, you would have the script.

ShaneEP
(MM club member)
2021-11-18 09:51 PM
Re: Extract kixtart script from an executable

Also just an idea...I believe there was a program called RegShot that I have used in the past to find before and after changes to registry. Might be worth a shot, in the case you think the script may be making registry edits.

Co
(MM club member)
2021-11-19 02:06 PM
Re: Extract kixtart script from an executable

Thanks, The temp dir and regshot are indeed things I can look at :-)

Ruud van Velsen
(Hey THIS is FUN)
2022-04-08 02:41 PM
Re: Extract kixtart script from an executable

If anyone runs into "orphaned" tokenized scripts, send me a ping and I'll what I can do.