以下是我用FileInfo检测的结果
Watcom C/C++ (*LE) CauseWay                                           40000
 run.exe                 DEC            HEX             Interesting values
════════════════════════════════════════════════════════════════════════════════
 Signature    "LE"           4C45h               46688    0000B660h
────────────────────────────────────────────────────────────────────────────────
 Address  CS : IP        00000001h :000CA498h          Entry point :   123E98h
          SS : SP        00000003h :0005A510h          Auto DS num : 00000003h
1→──────────────────────────────────────────────────────────────────────────────
 Table ofs. to Object    00196          00C4h  (0000B724h)   Count :        3h
         Object pages    00268          010Ch  (0000B76Ch)   Count :      152h
            Resources    01620          0654h  (0000BCB4h)   Count :        0h
        Resident name    01620          0654h  (0000BCB4h)     CPU : 80386
              Entries    20067          4E63h  (000104C3h)   Flags : 00000200h
────────────────────────────────────────────────────────────────────────────────
 Offset to data pages                  59A00h   OS: OS/2      Size :     1000h
       first iterated    00000          0000h                sLast :      5EBh
 Instance pg. preload    00000          0000h        preload Count :        0h
         pages demand    00000          0000h                  CRC : 00000000h
────────────────────────────────────────────────────────────────────────────────
 Size initial heap       00000          0000h    EB 76 57 41 54  43 4F 4D 20 43
             stack       00000          0000h    2F 43 2B 2B 33  32 20 52 75 6E
这是以前的dos版软件,现在的脱壳软件大部份都是脱PE壳的,不知道有哪一款软件可以脱?
好像ghost75也用了causeway dos extender,在论坛里好像有人说脱了,不知道是怎么做到的?
原文件在这里:
http://218.16.122.71/run.rar
请会的人帮帮忙,谢谢了
 Last edited by dosgame on 2006-7-19 at 00:58 ]