Junkdb.cfg
上传用户:haohao_zhu
上传日期:2014-08-15
资源大小:2446k
文件大小:8k
- ;Originary Write by ljtt
- [OPTION]
- PrePatName=CODE
- ;set editor(max 256 char),default notepad.exe
- Editor=notepad.exe
- ; default value
- DefaultRang=01000
- DefaultType=Common
- ;set JunkType combol list
- JunkType=Common,TELock,UltraProtect,Custom
- PatList_Common=_T1,_T2,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22
- PatList_TELock=_jnz01,_jmp01,_jmp02,_telock_call02_1,_telock_call02_2,_slc_jb01,_slc_jb02,_clc_jnb01,_clc_jnb02
- PatList_UltraProtect=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,_jmp01,_jmp11,_jmp12,_jmp13,_jmp15,_call01,_call011,_call012
- PatList_Custom=_T1,_T2,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22
- ; junk template start
- [CODE_T1]
- ; pushf
- ; push 0Ah
- ;loc_1: jnb loc_3
- ; jmp loc_2
- ; _TWO_BYTE_JUNKCODE_
- ;loc_2: call loc_4
- ; _TWO_BYTE_JUNKCODE_
- ;loc_3: jnb loc_2
- ; _TWO_BYTE_JUNKCODE_
- ;loc_4: add esp,4
- ; jmp loc_5
- ; _TWO_BYTE_JUNKCODE_
- ;loc_5: dec dword ptr [esp]
- ; jno loc_6
- ; _ONE_BYTE_JUNKCODE_
- ;loc_6: jns loc_1
- ; jp loc_7
- ; _ONE_BYTE_JUNKCODE_
- ;loc_7: add esp,4
- ; popf
- ; jmp loc_8
- ; _ONE_BYTE_JUNKCODE_
- ;loc_8: ......
- S = 9C6A??730BEB02????E806000000????73F7????83C404EB02????FF0C247101??79E07A01??83C4049DEB01??
- R = 909090909090909090909090909090909090909090909090909090909090909090909090909090909090909090
- [CODE_T2]
- ; pushf
- ; jb loc_3
- ;loc_1: jmp loc_2
- ; _ONE_BYTE_JUNKCODE_
- ;loc_2: call loc_4
- ; _TWO_BYTE_JUNKCODE_
- ;loc_3: jb loc_1
- ; _ONE_BYTE_JUNKCODE_
- ;loc_4: add esp,4
- ; popf
- ; jmp loc_5
- ; _ONE_BYTE_JUNKCODE_
- ;loc_5: ....
- S = 9C720AEB01??E805000000????72F4??83C4049DEB01??
- R = 9090909090909090909090909090909090909090909090
- [CODE1]
- ; jo label
- ; jno label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 70037101??
- R = 9090909090
- [CODE2]
- ; jb label
- ; jnb label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 72037301??
- R = 9090909090
- [CODE3]
- ; je label
- ; jne label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 74037501??
- R = 9090909090
- [CODE4]
- ; jbe label
- ; ja label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 76037701??
- R = 9090909090
- [CODE5]
- ; js label
- ; jns label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 78037901??
- R = 9090909090
- [CODE6]
- ; jpe label
- ; jpo label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 7A037B01??
- R = 9090909090
- [CODE7]
- ; jl label
- ; jge label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 7C037D01??
- R = 9090909090
- [CODE8]
- ; jle label
- ; jg label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 7E037F01??
- R = 9090909090
- [CODE9]
- ; jno label
- ; jo label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 71037001??
- R = 9090909090
- [CODE10]
- ; jnb label
- ; jb label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 73037201??
- R = 9090909090
- [CODE11]
- ; jne label
- ; je label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 75037401??
- R = 9090909090
- [CODE12]
- ; ja label
- ; jbe label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 77037601??
- R = 9090909090
- [CODE13]
- ; jns label
- ; js label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 79037801??
- R = 9090909090
- [CODE14]
- ; jpo label
- ; jpe label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 7B037A01??
- R = 9090909090
- [CODE15]
- ; jge label
- ; jl label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 7D037C01??
- R = 9090909090
- [CODE16]
- ; jle label
- ; jg label
- ; db _junkcode
- ;label: ....
- ; ....
- S = 7F037E01??
- R = 9090909090
- /////////////////////////////////////////
- /////////////////////////////////////////
- [CODE17]
- ; call label_1
- ; db _junkcode,_junkcode
- ; jmp label_4
- ;label_1: pop eax
- ; jmp label_2
- ; db _junkcode,_junkcode
- ;label_2: add eax,2
- ; jmp label_3
- ; db _junkcode
- ;label_3: push eax
- ; ret
- ; db _junkcode
- ;label_4: ....
- ; ....
- S = E804000000????EB0E58EB02????83C002EB01??50C3??
- R = 9090909090909090909090909090909090909090909090
- [CODE18]
- ; push ecx
- ; xor ecx,ecx
- ; jcxz label
- ; db _junkcode
- ;label: pop ecx
- ; ....
- ; ....
- S = 5131C9E301??59
- R = 90909090909090
- [CODE19]
- ; jl label_1
- ;label_2: jmp label_3
- ; db _junkcode
- ;label_1: jz label_2
- ;label_3: ....
- ; ....
- S = 7C03EB03??74FB
- R = 90909090909090
- [CODE20]
- ; call label_1
- ; db _junkcode,_junkcode,_junkcode
- ;label_1: add esp,4
- ; jmp label_2
- ; db _junkcode,_junkcode,_junkcode
- ;label_2: jmp label_3
- ; db _junkcode,_junkcode
- ;label_3: ....
- ; ....
- S = E803??????83C404EB03??????EB02????
- R = 9090909090909090909090909090909090
- [CODE21]
- ; call label_1
- ; db _junkcode
- ; jmp label_4
- ; db _junkcode
- ;label_1: pop edi
- ; jmp label_2
- ; db _junkcode
- ;label_2: inc edi
- ; jmp label_3
- ; db _junkcode
- ;label_3: jmp edi
- ; db _junkcode
- ;label_4: ....
- S = E804000000??EB0C??5FEB01??47EB01??FFE7??
- R = 9090909090909090909090909090909090909090
- [CODE22]
- ; call label_1
- ; db _junkcode,_junkcode
- ; jmp label_4
- ;label_1: pop ecx
- ; jmp label_2
- ; db _junkcode,_junkcode
- ;label_2: add ecx,2
- ; jmp label_3
- ; db _junkcode
- ;label_3: push ecx
- ; ret
- ; db _junkcode
- ;label_4: ....
- ; ....
- S = E804000000????EB0E59EB02????83C102EB01??51C3??
- R = 9090909090909090909090909090909090909090909090
- [CODE_jnz01]
- S = 7501??
- R = 909090
- [CODE_jmp01]
- S = EB01??
- R = 909090
- [CODE_jmp02]
- S = EB02????
- R = 90909090
- [CODE_jmp03]
- S = EB03??????
- R = 9090909090
- [CODE_jmp04]
- S = EB04????????
- R = 909090909090
- [CODE_jmp05]
- S = EB05??????????
- R = 90909090909090
- [CODE_jmp06]
- S = EB06????????????
- R = 9090909090909090
- [CODE_jmp07]
- S = EB07??????????????
- R = 909090909090909090
- [CODE_jmp08]
- S = EB08????????????????
- R = 90909090909090909090
- [CODE_jmp09]
- S = EB09??????????????????
- R = 9090909090909090909090
- [CODE_jmp11]
- S = E901000000??
- R = 909090909090
- [CODE_jmp12]
- S = E902000000????
- R = 90909090909090
- [CODE_jmp13]
- S = E903000000??????
- R = 9090909090909090
- [CODE_jmp14]
- S = E904000000????????
- R = 909090909090909090
- [CODE_jmp15]
- S = E905000000??????????
- R = 90909090909090909090
- [CODE_call01]
- ; call label_1
- ; db _junkcode
- ;label_1: add esp,4
- S = E801000000??83C404
- R = 909090909090909090
- [CODE_telock_call02_1]
- S = E802000000????3006465A
- R = 9090909090909030064690
- [CODE_telock_call02_2]
- S = E802000000E800E8000000005E2BC9587402????
- R = 90909090909090E8000000005E2BC99090909090
- [CODE_call011]
- ; push eax
- ; call label_1
- ; db _junkcode
- ;label_1: pop eax
- ; pop eax
- S = 50E801000000??5858
- R = 909090909090909090
- [CODE_call012]
- ; call label_1
- ; db _junkcode
- ;label_1: add dword ptr ss:[esp],6
- ; ret
- S = E801000000??83042406C3
- R = 9090909090909090909090
- [CODE_call02]
- ; call label_1
- ; db _junkcode,_junkcode
- ; db _junkcode,_junkcode
- ;label_1: add esp,4
- S = E802000000????83C404
- R = 90909090909090909090
- [CODE_call03]
- ; call label_1
- ; db _junkcode,_junkcode
- ; db _junkcode,_junkcode
- ; db _junkcode,_junkcode
- ;label_1: add esp,4
- S = E803000000??????83C404
- R = 9090909090909090909090
- [CODE_clc_jnb01]
- ; CLC
- ; JNB label_1
- ; db _junkcode
- ;label_1:
- S = F87301??
- R = 90909090
- [CODE_clc_jnb02]
- ; CLC
- ; JNB label_1
- ; db _junkcode
- ; db _junkcode
- ;label_1:
- S = F87302????
- R = 9090909090
- [CODE_slc_jb01]
- ; CLC
- ; JNB label_1
- ; db _junkcode
- ; db _junkcode
- ;label_1:
- S = F97201??
- R = 90909090
- [CODE_slc_jb02]
- ; CLC
- ; JNB label_1
- ; db _junkcode
- ; db _junkcode
- ;label_1:
- S = F97202????
- R = 9090909090