以下是我用FileInfo检测的结果
Watcom C/C++ (*LE) CauseWay 40000
run.exe DEC HEX Interesting values
════════════════════════════════════════════════════════════════════════════════
Signature "LE" 4C45h 46688 0000B660h
────────────────────────────────────────────────────────────────────────────────
Address CS : IP 00000001h :000CA498h Entry point : 123E98h
SS : SP 00000003h :0005A510h Auto DS num : 00000003h
1→──────────────────────────────────────────────────────────────────────────────
Table ofs. to Object 00196 00C4h (0000B724h) Count : 3h
Object pages 00268 010Ch (0000B76Ch) Count : 152h
Resources 01620 0654h (0000BCB4h) Count : 0h
Resident name 01620 0654h (0000BCB4h) CPU : 80386
Entries 20067 4E63h (000104C3h) Flags : 00000200h
────────────────────────────────────────────────────────────────────────────────
Offset to data pages 59A00h OS: OS/2 Size : 1000h
first iterated 00000 0000h sLast : 5EBh
Instance pg. preload 00000 0000h preload Count : 0h
pages demand 00000 0000h CRC : 00000000h
────────────────────────────────────────────────────────────────────────────────
Size initial heap 00000 0000h EB 76 57 41 54 43 4F 4D 20 43
stack 00000 0000h 2F 43 2B 2B 33 32 20 52 75 6E
这是以前的dos版软件,现在的脱壳软件大部份都是脱PE壳的,不知道有哪一款软件可以脱?
好像ghost75也用了causeway dos extender,在论坛里好像有人说脱了,不知道是怎么做到的?
原文件在这里:
http://218.16.122.71/run.rar
请会的人帮帮忙,谢谢了
Last edited by dosgame on 2006-7-19 at 00:58 ]