- 积分
- 1207
- 最后登录
- 2024-5-6
- 精华
- 0
- 阅读权限
- 40
- 主题
- 1102
- UID
- 2755893
- 帖子
- 2118
- PB币
- 3689
- 威望
- 60
- 贡献
- 0
- 技术
- 775
- 活跃
- 3638
- UID
- 2755893
- 帖子
- 2118
- PB币
- 3689
- 贡献
- 0
- 技术
- 775
- 活跃
- 3638
|
29107 发表于 2024-4-8 11:21
挂起也是可以的,也可以直接从更新提取出ntoskrnl或其他组件
感谢解答,确实可以看到,用7z打开了ntoskrnl,可以找到一个version.txt文件
FILEVERSION 6,1,7601,27017
PRODUCTVERSION 6,1,7601,27017
FILEFLAGSMASK 0x3F
FILEFLAGS 0x0
FILEOS VOS_NT_WINDOWS32
FILETYPE VFT_APP
FILESUBTYPE 0x0
{
BLOCK "StringFileInfo"
{
BLOCK "040904B0"
{
VALUE "CompanyName", "Microsoft Corporation"
VALUE "FileDescription", "NT Kernel & System"
VALUE "FileVersion", "6.1.7601.27017 (win7sp1_ldr_escrow.240226-1830)"
VALUE "InternalName", "ntkrnlmp.exe"
VALUE "LegalCopyright", "© Microsoft Corporation. All rights reserved."
VALUE "OriginalFilename", "ntkrnlmp.exe"
VALUE "ProductName", "Microsoft® Windows® Operating System"
VALUE "ProductVersion", "6.1.7601.27017"
}
}
BLOCK "VarFileInfo"
{
VALUE "Translation", 0x409, 1200
}
} |
|