[Guide]How to unpack Sro_client.exe

09/15/2009 07:38 yakir51#31
o.0 can someone explain whate is thet program? whate it can do? i didnt understand anything from it
09/15/2009 10:20 kavabunga123#32
Is it oke what is written on first page ? It says there are some wrong jumps and calls. Althought when running this way it seems fine, doesnt work with edxloader and always give different file size according to drew's unpacked ones. So i guess there is something wrong??
09/16/2009 15:19 crazymushroom#33
Thx for the guide. Maybe you can add "Unpack the sro_client again everytime sro updates(every tuesday)"
09/19/2009 16:08 Janick_#34
Mhh that Testosterone loader still doesn't work here ?
I unpacked it and now ?
09/22/2009 10:47 mibtuga#35
the stripper doesnt work with me :(

this is what happens:

09:45:37 - starting c:\program files\silkroad\sro_client.exe..
Victim ImageBase - 00400000
Victim EntryPoint - 00001000
09:45:37 - unhandled break at 026e75bb..
09:45:38 - asprotect detected..
09:45:38 - loading modules..
0x76fd0000 - module ntdll.dll loaded..
0x75900000 - module kernel32.dll loaded..
0x765f0000 - module gdi32.dll loaded..
0x769f0000 - module user32.dll loaded..
0x76640000 - module advapi32.dll loaded..
0x75680000 - module rpcrt4.dll loaded..
0x76a90000 - module imm32.dll loaded..
0x76740000 - module msctf.dll loaded..
0x764f0000 - module msvcrt.dll loaded..
0x759e0000 - module shell32.dll loaded..
0x75760000 - module shlwapi.dll loaded..
0x77130000 - module wininet.dll loaded..
0x75750000 - module normaliz.dll loaded..
0x757c0000 - module urlmon.dll loaded..
0x76810000 - module ole32.dll loaded..
0x76b30000 - module oleaut32.dll loaded..
0x76bd0000 - module iertutil.dll loaded..
0x76710000 - module ws2_32.dll loaded..
0x76bc0000 - module nsi.dll loaded..
0x74dd0000 - module version.dll loaded..
0x69a60000 - module ddraw.dll loaded..
0x6a2a0000 - module dciman32.dll loaded..
0x76e40000 - module setupapi.dll loaded..
0x72ae0000 - module dwmapi.dll loaded..
0x74f20000 - module iphlpapi.dll loaded..
0x74ee0000 - module dhcpcsvc.dll loaded..
0x75200000 - module dnsapi.dll loaded..
0x75510000 - module secur32.dll loaded..
0x74ed0000 - module winnsi.dll loaded..
0x74ea0000 - module dhcpcsvc6.dll loaded..
0x74150000 - module winmm.dll loaded..
0x74110000 - module oleacc.dll loaded..
0x72610000 - module d3d9.dll loaded..
0x72ab0000 - module d3d8thk.dll loaded..
0x715e0000 - module dsound.dll loaded..
0x74970000 - module powrprof.dll loaded..
0x77220000 - module lpk.dll loaded..
0x76dc0000 - module usp10.dll loaded..
0x743c0000 - module comctl32.dll loaded..
0x737b0000 - module wsock32.dll loaded..
0x746c0000 - module uxtheme.dll loaded..
09:45:38 - hooking modules..
module kernel32.dll - hooked
module gdi32.dll - hooked
module user32.dll - hooked
module advapi32.dll - hooked
module rpcrt4.dll - hooked
module imm32.dll - hooked
module msctf.dll - hooked
module msvcrt.dll - hooked
module shell32.dll - hooked
module shlwapi.dll - hooked
module wininet.dll - hooked
module normaliz.dll - hooked
module urlmon.dll - hooked
module ole32.dll - hooked
module oleaut32.dll - hooked
module iertutil.dll - hooked
module ws2_32.dll - hooked
module nsi.dll - hooked
module version.dll - hooked
module ddraw.dll - hooked
module dciman32.dll - hooked
module setupapi.dll - hooked
module dwmapi.dll - hooked
module iphlpapi.dll - hooked
module dhcpcsvc.dll - hooked
module dnsapi.dll - hooked
module secur32.dll - hooked
module winnsi.dll - hooked
module dhcpcsvc6.dll - hooked
module winmm.dll - hooked
module oleacc.dll - hooked
module d3d9.dll - hooked
module d3d8thk.dll - hooked
module dsound.dll - hooked
module powrprof.dll - hooked
module lpk.dll - hooked
module usp10.dll - hooked
module comctl32.dll - hooked
module wsock32.dll - hooked
module uxtheme.dll - hooked
09:45:39 - unhandled break at 026e75bb..
09:45:39 - tracing..
09:45:39 - processing relocation..
09:45:39 - processing import..
Unrecognized function at address: 03110be8
Unrecognized function at address: 034e062b
09:45:43 - processing VM..
09:45:43 - comparing sections..
ScrambledEntry at RVA: 006462cc (.text) ( old entry - 03740000, new entry - 01008000 )
Original EntryPoint :00644c42
09:45:44 - saving C:\Program Files\Silkroad\_sro_client.exe..
09:45:45 - saving C:\Program Files\Silkroad\_sro_client.exe.log ..
09:45:45 - done..

and when I use edxSilkroadLoader_Lite it says that the file is packed and that I need to unpack it -.-

plz help me
09/22/2009 15:39 GibCo2ntra#36
Quote:
Originally Posted by mibtuga View Post
the stripper doesnt work with me :(

this is what happens:

...
skipped
...

and when I use edxSilkroadLoader_Lite it says that the file is packed and that I need to unpack it -.-

plz help me
Rename your original "sro_client.exe" to "BACKUPsro_client.exe" or something like that.. and rename "_sro_client.exe" to "sro_client.exe"
09/24/2009 14:56 XchangliiX#37
got Shell32.dll runtime error -.-
may becahuse i have another ot sth. like this. need to unpack ksro v1.640
09/28/2009 17:07 Ferpa_#38
i have error here, i need unpack ksro, ver 1.640 any please, help me ?
or unpack for me! :S
09/29/2009 19:11 lakus#39
Nice tut ;) I done unpack 1.215 ^^
10/24/2009 16:57 sonsuzaxx#40
thank you
12/11/2009 13:31 B_A__Baracus#41
Stripper doesn't work with win7 64bit-.-
12/11/2009 16:09 Kazuyaš#42
Quote:
Originally Posted by B_A__Baracus View Post
Stripper doesn't work with win7 64bit-.-
mhm, so your gonna have to download OllyDBG v2 and do it 100% manually.
02/11/2010 23:19 pelley-pelle#43
im looking for a loader that work can any one help me!
03/30/2010 01:01 kekleak#44
thanks for this.
06/17/2010 09:33 alexhun#45
Stripper doesn't work for me. It show error. :'( PLS ANYONE HELP, send a download link or anything!!