默认
[Settings]Check DLL versions=0Show toolbar=1Status in toolbar=1Use hardware breakpoints to step=1Restore windows=236991Scroll MDI=0Horizontal scroll=0Topmost window=0Index of default font=2Index of default colours=6Index of default syntax highlighting=2Log buffer size index=0Run trace buffer size index=7Group adjacent commands in profile=1Highlighted trace register=0IDEAL disassembling mode=0Disassemble in lowercase=0Separate arguments with TAB=0Extra space between arguments=0Show default segments=1NEAR jump modifiers=1Use short form of string commands=0Use RET instead of RETN=0Size sensitive mnemonics=1SSE size decoding mode=0Top of FPU stack=1Always show memory size=1Decode registers for any IP=0Show symbolic addresses=1Show local module names=1Gray data used as filling=1Show jump direction=1Show jump path=1Show jumpfrom path=1Show path if jump is not taken=1Underline fixups=1Center FOLLOWed command=1Show stack frames=1Show local names in stack=1Extended stack trace=1Synchronize source with CPU=1Include SFX extractor in code=0SFX trace mode=0Use real SFX entry from previous run=1Ignore SFX exceptions=1First pause=1Stop on new DLL=0Stop on DLL unload=0Stop on new thread=0Stop on thread end=0Stop on debug string=0Decode SSE registers=0Enable last error=1Ignore access violations in KERNEL32=1Ignore INT3=1Ignore TRAP=1Ignore access violations=1Step in unknown commands=1Ignore division by 0=1Ignore illegal instructions=1Ignore all FPU exceptions=1Warn when frequent breaks=0Warn when break not in code=0Autoreturn=0Save original command in trace=1Show traced ESP=1Show traced flags=1Animate over system DLLs=1Trace over string commands=0Synchronize CPU and Run trace=1Ignore custom exceptions=1Smart update=1Set high priority=1Append arguments=1Use ExitProcess=1Allow injection to get WinProc=1Sort WM_XXX by name=0Type of last WinProc breakpoint=0Snow-free drawing=0Demangle symbolic names=0Keep ordinal in name=1Only ASCII printable in dump=0Allow diacritical symbols=0String decoding=3Warn if not administrator=0Warn when terminating process=0Align dialogs=1Use font of calling window=0Specified dialog font=0Number of lines that follow EIP=0Restore window positions=1Restore width of columns=0Highlight sorted column=0Compress analysis data=1Backup UDD files=1Fill rest of command with NOPs=1Reference search mode=0Global search=1Aligned search=1Allow error margin=0Keep size of hex edit selection=0Modify tag of FPU register=1Hex inspector limits=1MMX display mode=0Last selected options card=2Last selected appearance card=6Ignore case in text search=1Letter key in Disassembler=1Looseness of code analysis=1Decode pascal strings=1Guess number of arguments=1Accept far calls and returns=1Accept direct segment modifications=1Decode VxD calls=1Accept privileged commands=1Accept I/O commands=1Accept NOPs=1Accept shifts out of range=1Accept superfluous prefixes=1Accept LOCK prefixes=1Accept unaligned stack operations=1Accept non-standard command forms=1Show ARG and LOCAL in procedures=1Save analysis to file=1Analyse main module automatically=0Analyse code structure=1Decode ifs as switches=1Save trace to file=0Trace contents of registers=1Functions preserve registers=0Decode tricks=1Automatically select register type=1Show decoded arguments=1Show decoded arguments in stack=1Show arguments in call stack=1Show induced calls=0Label display mode=0Label includes module name=1Highlight symbolic labels=1Highlight RETURNs in stack=1Ignore path in user data file=1Ignore timestamp in user data file=1Ignore CRC in user data file=1Default sort mode in Names=1Save out-of-module user data=0Tabulate columns in log file=0Append data to existing log file=0Flush gathered data to log file=0Skip spaces in source comments=1Hide non-existing source files=1Tab stops=8File graph mode=2Show internal handle names=1Hide irrelevant handles=0[Colours]Scheme[0]=0,12,8,18,7,8,7,13Scheme name[0]=白底黑字Scheme[1]=14,12,7,1,3,7,3,13Scheme name[1]=蓝底黄字Scheme[2]=1,12,3,11,14,2,7,13Scheme name[2]=海军蓝Scheme[3]=15,12,7,0,8,11,7,13Scheme name[3]=普通黑Scheme[4]=0,12,8,18,7,8,7,13Scheme name[4]=方案 4Scheme[5]=14,12,7,1,3,7,3,13Scheme name[5]=方案 5Scheme[6]=1,12,3,15,14,9,9,12Scheme name[6]=Black HawkScheme[7]=1,12,3,15,11,9,9,12Scheme name[7]=数据[Fonts]Font[0]=16,8,400,0,0,0,134,2,49,0Face name[0]=TerminalFont name[0]=OEM 等宽字体Font[1]=-16,0,400,0,0,0,134,1,49,0Face name[1]=新宋体Font name[1]=Terminal 6Font[2]=16,8,400,0,0,0,134,2,49,0Face name[2]=FixedsysFont name[2]=系统等宽字体Font[3]=14,0,400,0,0,0,1,2,5,0Face name[3]=Courier NewFont name[3]=Courier (UNICODE)Font[4]=10,6,400,0,0,0,1,2,5,0Face name[4]=Lucida ConsoleFont name[4]=Lucida (UNICODE)Font[5]=9,6,700,0,0,0,255,0,48,0Face name[5]=TerminalFont name[5]=字体 5Font[6]=16,8,400,0,0,0,134,2,49,0Face name[6]=FixedsysFont name[6]=字体 6Font[7]=14,0,400,0,0,0,1,2,5,0Face name[7]=Courier NewFont name[7]=字体 7[Syntax]Commands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0Operands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0Scheme name[0]=不高亮Commands[1]=0,4,124,112,9,64,64,13,111,8,12,0,0,0Operands[1]=1,0,4,13,65,1,112,6,0,0,0,0,0,0Scheme name[1]=圣诞树Commands[2]=0,0,124,124,0,64,92,0,96,0,12,0,0,0Operands[2]=1,0,0,0,0,0,0,0,0,0,0,0,0,0Scheme name[2]=跳转及调用Commands[3]=0,0,0,0,0,0,0,0,0,0,0,0,0,0Operands[3]=0,0,0,0,0,0,0,0,0,0,0,0,0,0Scheme name[3]=高亮 3Commands[4]=0,0,0,0,0,0,0,0,0,0,0,0,0,0Operands[4]=0,0,0,0,0,0,0,0,0,0,0,0,0,0Scheme name[4]=高亮 4[History]View file=View text file=Object file=Import library=Log file=log.txtRun trace file=C:\Users\pgs\Desktop\TEMP.txtAPI help file=Text save file=Symbolic data path=.\LIBUDD path=G:\15pb\汇编\15PBOD\UDDPlugin path=G:\15pb\汇编\15PBOD\plugin查看文件=API 帮助文件=Executable[0]=H:\Music\MFCPj000.exeExecutable[1]=D:\EVPlayer\bin\EVPlayer.exeExecutable[2]=H:\Documents\Visual Studio 2017\Projects\FileCleaner2.0\123_aaa.exeExecutable[3]=H:\Documents\Visual Studio 2017\Projects\FileCleaner2.0\FileCleaner2.0 - 副本_aaa.exeExecutable[4]=H:\Documents\Visual Studio 2017\Projects\FileCleaner2.0\123.exeExecutable[5]=H:\Documents\Visual Studio 2017\Projects\FileCleaner2.0\FileCleaner2.0_aaa.exe[Plugin ODbgScript]恢复脚本窗口=0恢复脚本记录=0Restore Script window=0Restore Script Log=0MRU1=C:\Users\Andy\Desktop\脱壳脚本2.txtMRU2=MRU3=MRU4=MRU5=ScriptDir=D:\我的文档\1131578752\FileRecv\壳5\BP_FILE=D:\我的文档\1131578752\FileRecv\壳5\脱壳脚本6.txtBP_0001=NRU1=D:\我的文档\1131578752\FileRecv\壳5\脱壳脚本6.txt还原脚本窗口=1还原脚本日志=0NRU2=D:\Work\课程\软件安全课程\软件保护壳课程\脱壳练习1-10\06脱壳脚本.txtNRU3=C:\Users\Andy\Desktop\脱壳脚本.txt[System]Options position=691,270[Arguments]Executable[1]=Executable[2]=Executable[3]=Executable[4]=Executable[5]=Executable[0]=[Plugin StrongOD]CreateProcessMode=0HidePEB=1IsPatchFloat=0IsAdvGoto=1KernelMode=0KillPEBug=1SuperEnumMod=1AdvAttach=1SkipExpection=1HideWindow=1HideProcess=1ProtectProcess=1DriverKey=-82693034DriverName=Black HaOrdFirst=0BreakOnLdr=0BreakOnTls=0RemoveEpOneShot=0ShowBar=17LoadSym=1AutoUpdate=0UpdateURL=Create[Plugin IDAFicator]Custom Scheme=0,8388608,32768,8421376,128,8388736,32896,12632256,8421504,16711680,65280,16776960,255,16711935,65535,16777215,12639424,15780004,15793151,10789024DIA MAC x=0DIA MAC y=0DIA HWBP x=1115DIA HWBP y=610DIA_HWBP_POS=765,166SETTINGS_COMPILER=0DIA_ROTE_POS=0,983,160,39PATH_RADASM=C:\Tools\15PBOD\Plugin\minimalist-radasmPATH_HELP=C:\Tools\15PBOD\Plugin\minimalist-radasmDIA_CUSTOMIZE_SCHEME=0,8388608,32768,8421376,128,8388736,32896,12632256,8421504,16711680,65280,16776960,255,16711935,65535,16777215,12639424,15780004,15793151,10789024SETTINGS_MAIN=1,1,1,1,1SETTINGS_DUMP=SETTINGS_DISASM=0,0,0SETTINGS_STACK=SETTINGS_HWBP=0,0,0SETTINGS_ROTE=MNU_PATHS_DIRS_N=5MNU_PATHS_FILES_N=45SETTINGS_MSEC=500DIA_CUSTOMIZE_POS=0,0DIA_CUSTOMIZE_FUNC=1,2,3,4,5,LAYOUT_ID=0LAYOUT_SWAP_DUMP_STACK=0[Plugin 中文搜索引擎]Restore UStrRef Window=0[Placement]OllyTest=299,51,1594,1042,0CPU=32,36,1036,547,3CPU subwindows=706,1293,700,1293,528,987,462,876中文搜索引擎=55,19,786,805,1References=230,0,618,170,1Breakpoints=88,116,498,230,1Executable modules=66,87,632,230,1Threads=110,145,492,170,1Memory map=132,174,390,230,1Log data=154,203,378,290,1脚本运行窗口=261,51,304,80,1Jiack=192,32,640,480,1参考=115,32,304,61,1断点=0,0,136,39,1线程=0,0,136,39,1内存映射=0,0,304,61,1可执行模块=0,0,136,39,1记录数据=31,4,598,307,1脚本执行=0,0,587,223,1窗口=0,0,136,39,1句柄=0,0,136,39,1补丁=0,0,136,39,1Call stack=96,32,304,61,1RUN 跟踪=0,0,136,39,1源码=44,50,558,220,1监视表达式=88,100,711,290,1中间文件列表=22,25,1159,290,1Script Log Window=22,25,1135,290,1Run跟踪=154,175,567,290,1Windows=23,44,815,290,1可 执 行 模 块=44,50,726,281,1内存映射=66,75,647,337,1调用堆栈=20,30,653,240,1SEH 链=0,0,304,61,1统计=534,38,799,622,1CPU subwindows 1=374,767,336,658,450,960,388,853CPU subwindows 2=374,767,336,658,450,960,388,853CPU subwindows 3=374,767,336,658,450,960,388,853CPU subwindows 4=374,767,336,658,450,960,388,853[Columns]CPU Disassembler=72,136,320,2048CPU Dump=72,136,320,2048,CPU Stack=72,80,2048,中文搜索引擎=72,320,2048References=54,240,1536Breakpoints=54,54,150,216,1536Executable modules=54,54,54,54,96,1536Threads=54,54,66,108,60,54,72,72Memory map=54,54,54,54,72,30,48,48,1536Log data=54,1536脚本运行窗口=40,320,120,72,800参考=72,320,2048断点=72,72,200,288,2048线程=72,72,88,144,80,72,96,96内存映射=72,72,72,72,96,40,64,64,2048可执行模块=72,72,72,72,128,2048记录数据=72,2048脚本执行=30,240,240,54窗口=104,256,72,72,72,72,72,72,72,2048句柄=72,120,48,72,24,96,2048补丁=72,40,64,256,256,2048Call stack=72,72,288,224,72RUN 跟踪=72,72,72,72,256,2048源码=64,2048监视表达式=288,2048中间文件列表=240,640,256Script Log Window=72,1040Run跟踪=72,72,72,72,256,2048Windows=104,256,72,72,72,72,72,72,72,2048可 执 行 模 块=72,72,72,72,128,2048内存映射=72,72,72,72,128,2048调用堆栈=72,72,288,224,72SEH 链=72,256统计=72,72,256,2048[Appearance]CPU scheme=6CPU Disassembler=2,6,1,0,2CPU Dump=2,7,1,0,36881,2CPU Stack=2,6,0,0CPU Info=2,7,0,0CPU Registers=2,6,1,0中文搜索引擎=2,6,1,0,0References=1,0,1,0,0Breakpoints=1,0,1,0,0Executable modules=1,0,1,0,0Threads=1,0,1,0,0Memory map=1,0,1,0,0Log data=1,0,1,0,0脚本运行窗口=2,6,1,0,0参考=2,6,1,0,0断点=2,6,1,0,0线程=2,6,1,0,0内存映射=2,6,1,0,0可执行模块=2,6,1,0,0记录数据=2,6,1,0,0脚本执行=1,0,1,0,0窗口=2,6,1,0,0句柄=2,6,1,0,0补丁=2,6,1,0,0Call stack=2,6,1,0,0RUN 跟踪=2,6,1,0,0源码=2,6,0,0,0监视表达式=2,6,1,0,0中间文件列表=2,6,1,0,0Script Log Window=2,6,1,0,0Run跟踪=2,6,1,0,0Windows=2,6,1,0,0[界面选项]记录数据=2,6,1,0,0可 执 行 模 块=2,6,1,0,0内存映射=2,6,1,0,0线程=2,6,1,0,0句柄=2,6,1,0,0调用堆栈=2,6,1,0,0补丁=2,6,1,0,0源码=2,6,0,0,0Run跟踪=2,6,1,0,0参考=2,6,1,0,0断点=2,6,1,0,0中文搜索引擎=2,6,1,0,0Call stack=2,6,1,0,0可执行模块=0,6,1,0,0内存映射=2,6,1,0,0SEH 链=2,6,1,0,0RUN 跟踪=2,6,1,0,2窗口=2,6,1,0,0脚本运行窗口=2,6,1,0,0统计=2,6,1,0,0[Plugin Olly Advanced]varbps=0copytoexecutable=1usetoolhelp=0pausedex=0pluginexpand=1keepalteredcrc=0ignorechangedbp=0advancedctrlg=1numofrva=1followindisassembler=1analysisbug=1Entrypointwarning=1antiattachkill=1winupack=1antiattachkill2=1killps=1toomanypatches=0compressedcode=1dllloading=1compressedcodehandling=2dllloadmethod=1ctrlgstate=1showalljumpsfix=1TerminateProcess=0HideDebugBit=0NtGlobalFlag=0Antihwbp=0HeapFlags=0ForceFlags=0maxolly=0Writememory=0Readmemory=0Process32Next=0UnhandledExceptionFilter=0Module32Next=0CheckRemoteDebuggerPresent=0ZwSetInformationThread=0GetTickCount=0GetTickCountCounter=1ZwQuerySystemInformation=0ZwOpenProcess=0FindWindow=0Anti-RDTSCenabled=0Anti-RDTSC=0Anti-RDTSC2=0ZwQueryInformationProcess=0codebasefix=1ignoreexporttable=0ZwQueryObject=0scrambleexporttable=0maxallollywindows=0x64compat=0SuspendThread=0BlockInput=0viewfilefix=1BreakOnTls=0alwaysenableshowalljumpsandcalls=0fixc08bug=0fixtermination=1modulepointer=12lasttab=4[Plugin 书签管理 +]Restore bookmarks window=0[Plugin SkyPatch]NPATCH1=[Plugin PhantOm]PEB=1GETCOUNT=0DRX=0SETCONTEXT=1DEBSTRING=1WINVER=0GETTIMES=0REMOVEEP=1HANDLE=1WINDOWS=0DRIVER=1CAPTION=1RDTSC=1VERSION=126DELTARDTSC=34816BLOCK=0HIDENAME=extremRDTSCNAME=rdtsc[AeDebug]Debugger="C:\Windows\system32\vsjitdebugger.exe" -p %ld -e %ld[Plugin Oreans UnVirtualizer]Plugin Version=18Window Pos X=257Window Pos Y=192[Plugin OllyDisasm201]DisasmMode=0[Exceptions]Custom[0]=00000000,FFFFFFFF