这个啊,壳的残留信息没清除掉,你可以看DIE判断Confuser(1.X)的逻辑
[JavaScript] 纯文本查看 复制代码 // DIE's signature file
init("protector","Confuser");
function getConfuserVersion()
{
var sResult="";
var nOffset=PE.section[0].FileOffset;
var nSize=PE.section[0].FileSize;
var nVersionOffset=PE.findString(nOffset,nSize,"Confuser v");
if(nVersionOffset!=-1)
{
sResult=PE.getString(nVersionOffset+10);
}
return sResult;
}
function detect(bShowType,bShowVersion,bShowOptions)
{
if(PE.isNETStringPresent("ConfusedByAttribute"))
{
var sConfuserVersion=getConfuserVersion();
if(sConfuserVersion!="")
{
sVersion=sConfuserVersion;
}
else
{
sVersion="1.X";
}
bDetected=1;
}
return result(bShowType,bShowVersion,bShowOptions);
}
|