默认
[Settings]
Check DLL versions=0
Show toolbar=1
Status in toolbar=1
Use hardware breakpoints to step=1
Restore windows=236991
Scroll MDI=0
Horizontal scroll=0
Topmost window=0
Index of default font=2
Index of default colours=6
Index of default syntax highlighting=2
Log buffer size index=0
Run trace buffer size index=7
Group adjacent commands in profile=1
Highlighted trace register=0
IDEAL disassembling mode=0
Disassemble in lowercase=0
Separate arguments with TAB=0
Extra space between arguments=0
Show default segments=1
NEAR jump modifiers=1
Use short form of string commands=0
Use RET instead of RETN=0
Size sensitive mnemonics=1
SSE size decoding mode=0
Top of FPU stack=1
Always show memory size=1
Decode registers for any IP=0
Show symbolic addresses=1
Show local module names=1
Gray data used as filling=1
Show jump direction=1
Show jump path=1
Show jumpfrom path=1
Show path if jump is not taken=1
Underline fixups=1
Center FOLLOWed command=1
Show stack frames=1
Show local names in stack=1
Extended stack trace=1
Synchronize source with CPU=1
Include SFX extractor in code=0
SFX trace mode=0
Use real SFX entry from previous run=1
Ignore SFX exceptions=1
First pause=1
Stop on new DLL=0
Stop on DLL unload=0
Stop on new thread=0
Stop on thread end=0
Stop on debug string=0
Decode SSE registers=0
Enable last error=1
Ignore access violations in KERNEL32=1
Ignore INT3=1
Ignore TRAP=1
Ignore access violations=1
Step in unknown commands=1
Ignore division by 0=1
Ignore illegal instructions=1
Ignore all FPU exceptions=1
Warn when frequent breaks=0
Warn when break not in code=0
Autoreturn=0
Save original command in trace=1
Show traced ESP=1
Show traced flags=1
Animate over system DLLs=1
Trace over string commands=0
Synchronize CPU and Run trace=1
Ignore custom exceptions=1
Smart update=1
Set high priority=1
Append arguments=1
Use ExitProcess=1
Allow injection to get WinProc=1
Sort WM_XXX by name=0
Type of last WinProc breakpoint=0
Snow-free drawing=0
Demangle symbolic names=0
Keep ordinal in name=1
Only ASCII printable in dump=0
Allow diacritical symbols=0
String decoding=3
Warn if not administrator=0
Warn when terminating process=0
Align dialogs=1
Use font of calling window=0
Specified dialog font=0
Number of lines that follow EIP=0
Restore window positions=1
Restore width of columns=0
Highlight sorted column=0
Compress analysis data=1
Backup UDD files=1
Fill rest of command with NOPs=1
Reference search mode=0
Global search=1
Aligned search=1
Allow error margin=0
Keep size of hex edit selection=0
Modify tag of FPU register=1
Hex inspector limits=1
MMX display mode=0
Last selected options card=2
Last selected appearance card=6
Ignore case in text search=1
Letter key in Disassembler=1
Looseness of code analysis=1
Decode pascal strings=1
Guess number of arguments=1
Accept far calls and returns=1
Accept direct segment modifications=1
Decode VxD calls=1
Accept privileged commands=1
Accept I/O commands=1
Accept NOPs=1
Accept shifts out of range=1
Accept superfluous prefixes=1
Accept LOCK prefixes=1
Accept unaligned stack operations=1
Accept non-standard command forms=1
Show ARG and LOCAL in procedures=1
Save analysis to file=1
Analyse main module automatically=0
Analyse code structure=1
Decode ifs as switches=1
Save trace to file=0
Trace contents of registers=1
Functions preserve registers=0
Decode tricks=1
Automatically select register type=1
Show decoded arguments=1
Show decoded arguments in stack=1
Show arguments in call stack=1
Show induced calls=0
Label display mode=0
Label includes module name=1
Highlight symbolic labels=1
Highlight RETURNs in stack=1
Ignore path in user data file=1
Ignore timestamp in user data file=1
Ignore CRC in user data file=1
Default sort mode in Names=1
Save out-of-module user data=0
Tabulate columns in log file=0
Append data to existing log file=0
Flush gathered data to log file=0
Skip spaces in source comments=1
Hide non-existing source files=1
Tab stops=8
File graph mode=2
Show internal handle names=1
Hide irrelevant handles=0
[Colours]
Scheme[0]=0,12,8,18,7,8,7,13
Scheme name[0]=白底黑字
Scheme[1]=14,12,7,1,3,7,3,13
Scheme name[1]=蓝底黄字
Scheme[2]=1,12,3,11,14,2,7,13
Scheme name[2]=海军蓝
Scheme[3]=15,12,7,0,8,11,7,13
Scheme name[3]=普通黑
Scheme[4]=0,12,8,18,7,8,7,13
Scheme name[4]=方案 4
Scheme[5]=14,12,7,1,3,7,3,13
Scheme name[5]=方案 5
Scheme[6]=1,12,3,15,14,9,9,12
Scheme name[6]=Black Hawk
Scheme[7]=1,12,3,15,11,9,9,12
Scheme name[7]=数据
[Fonts]
Font[0]=16,8,400,0,0,0,134,2,49,0
Face name[0]=Terminal
Font name[0]=OEM 等宽字体
Font[1]=-16,0,400,0,0,0,134,1,49,0
Face name[1]=新宋体
Font name[1]=Terminal 6
Font[2]=16,8,400,0,0,0,134,2,49,0
Face name[2]=Fixedsys
Font name[2]=系统等宽字体
Font[3]=14,0,400,0,0,0,1,2,5,0
Face name[3]=Courier New
Font name[3]=Courier (UNICODE)
Font[4]=10,6,400,0,0,0,1,2,5,0
Face name[4]=Lucida Console
Font name[4]=Lucida (UNICODE)
Font[5]=9,6,700,0,0,0,255,0,48,0
Face name[5]=Terminal
Font name[5]=字体 5
Font[6]=16,8,400,0,0,0,134,2,49,0
Face name[6]=Fixedsys
Font name[6]=字体 6
Font[7]=14,0,400,0,0,0,1,2,5,0
Face name[7]=Courier New
Font name[7]=字体 7
[Syntax]
Commands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Operands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Scheme name[0]=不高亮
Commands[1]=0,4,124,112,9,64,64,13,111,8,12,0,0,0
Operands[1]=1,0,4,13,65,1,112,6,0,0,0,0,0,0
Scheme name[1]=圣诞树
Commands[2]=0,0,124,124,0,64,92,0,96,0,12,0,0,0
Operands[2]=1,0,0,0,0,0,0,0,0,0,0,0,0,0
Scheme name[2]=跳转及调用
Commands[3]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Operands[3]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Scheme name[3]=高亮 3
Commands[4]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Operands[4]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Scheme name[4]=高亮 4
[History]
View file=
View text file=
Object file=
Import library=
Log file=log.txt
Run trace file=C:\Users\pgs\Desktop\TEMP.txt
API help file=
Text save file=
Symbolic data path=.\LIB
UDD path=G:\15pb\汇编\15PBOD\UDD
Plugin path=G:\15pb\汇编\15PBOD\plugin
查看文件=
API 帮助文件=
Executable[0]=H:\Music\MFCPj000.exe
Executable[1]=D:\EVPlayer\bin\EVPlayer.exe
Executable[2]=H:\Documents\Visual Studio 2017\Projects\FileCleaner2.0\123_aaa.exe
Executable[3]=H:\Documents\Visual Studio 2017\Projects\FileCleaner2.0\FileCleaner2.0 - 副本_aaa.exe
Executable[4]=H:\Documents\Visual Studio 2017\Projects\FileCleaner2.0\123.exe
Executable[5]=H:\Documents\Visual Studio 2017\Projects\FileCleaner2.0\FileCleaner2.0_aaa.exe
[Plugin ODbgScript]
恢复脚本窗口=0
恢复脚本记录=0
Restore Script window=0
Restore Script Log=0
MRU1=C:\Users\Andy\Desktop\脱壳脚本2.txt
MRU2=
MRU3=
MRU4=
MRU5=
ScriptDir=D:\我的文档\1131578752\FileRecv\壳5\
BP_FILE=D:\我的文档\1131578752\FileRecv\壳5\脱壳脚本6.txt
BP_0001=
NRU1=D:\我的文档\1131578752\FileRecv\壳5\脱壳脚本6.txt
还原脚本窗口=1
还原脚本日志=0
NRU2=D:\Work\课程\软件安全课程\软件保护壳课程\脱壳练习1-10\06脱壳脚本.txt
NRU3=C:\Users\Andy\Desktop\脱壳脚本.txt
[System]
Options position=691,270
[Arguments]
Executable[1]=
Executable[2]=
Executable[3]=
Executable[4]=
Executable[5]=
Executable[0]=
[Plugin StrongOD]
CreateProcessMode=0
HidePEB=1
IsPatchFloat=0
IsAdvGoto=1
KernelMode=0
KillPEBug=1
SuperEnumMod=1
AdvAttach=1
SkipExpection=1
HideWindow=1
HideProcess=1
ProtectProcess=1
DriverKey=-82693034
DriverName=Black Ha
OrdFirst=0
BreakOnLdr=0
BreakOnTls=0
RemoveEpOneShot=0
ShowBar=17
LoadSym=1
AutoUpdate=0
UpdateURL=
Create
[Plugin IDAFicator]
Custom Scheme=0,8388608,32768,8421376,128,8388736,32896,12632256,8421504,16711680,65280,16776960,255,16711935,65535,16777215,12639424,15780004,15793151,10789024
DIA MAC x=0
DIA MAC y=0
DIA HWBP x=1115
DIA HWBP y=610
DIA_HWBP_POS=765,166
SETTINGS_COMPILER=0
DIA_ROTE_POS=0,983,160,39
PATH_RADASM=C:\Tools\15PBOD\Plugin\minimalist-radasm
PATH_HELP=C:\Tools\15PBOD\Plugin\minimalist-radasm
DIA_CUSTOMIZE_SCHEME=0,8388608,32768,8421376,128,8388736,32896,12632256,8421504,16711680,65280,16776960,255,16711935,65535,16777215,12639424,15780004,15793151,10789024
SETTINGS_MAIN=1,1,1,1,1
SETTINGS_DUMP=
SETTINGS_DISASM=0,0,0
SETTINGS_STACK=
SETTINGS_HWBP=0,0,0
SETTINGS_ROTE=
MNU_PATHS_DIRS_N=5
MNU_PATHS_FILES_N=45
SETTINGS_MSEC=500
DIA_CUSTOMIZE_POS=0,0
DIA_CUSTOMIZE_FUNC=1,2,3,4,5,
LAYOUT_ID=0
LAYOUT_SWAP_DUMP_STACK=0
[Plugin 中文搜索引擎]
Restore UStrRef Window=0
[Placement]
OllyTest=299,51,1594,1042,0
CPU=32,36,1036,547,3
CPU subwindows=706,1293,700,1293,528,987,462,876
中文搜索引擎=55,19,786,805,1
References=230,0,618,170,1
Breakpoints=88,116,498,230,1
Executable modules=66,87,632,230,1
Threads=110,145,492,170,1
Memory map=132,174,390,230,1
Log data=154,203,378,290,1
脚本运行窗口=261,51,304,80,1
Jiack=192,32,640,480,1
参考=115,32,304,61,1
断点=0,0,136,39,1
线程=0,0,136,39,1
内存映射=0,0,304,61,1
可执行模块=0,0,136,39,1
记录数据=31,4,598,307,1
脚本执行=0,0,587,223,1
窗口=0,0,136,39,1
句柄=0,0,136,39,1
补丁=0,0,136,39,1
Call stack=96,32,304,61,1
RUN 跟踪=0,0,136,39,1
源码=44,50,558,220,1
监视表达式=88,100,711,290,1
中间文件列表=22,25,1159,290,1
Script Log Window=22,25,1135,290,1
Run跟踪=154,175,567,290,1
Windows=23,44,815,290,1
可 执 行 模 块=44,50,726,281,1
内存映射=66,75,647,337,1
调用堆栈=20,30,653,240,1
SEH 链=0,0,304,61,1
统计=534,38,799,622,1
CPU subwindows 1=374,767,336,658,450,960,388,853
CPU subwindows 2=374,767,336,658,450,960,388,853
CPU subwindows 3=374,767,336,658,450,960,388,853
CPU subwindows 4=374,767,336,658,450,960,388,853
[Columns]
CPU Disassembler=72,136,320,2048
CPU Dump=72,136,320,2048,
CPU Stack=72,80,2048,
中文搜索引擎=72,320,2048
References=54,240,1536
Breakpoints=54,54,150,216,1536
Executable modules=54,54,54,54,96,1536
Threads=54,54,66,108,60,54,72,72
Memory map=54,54,54,54,72,30,48,48,1536
Log data=54,1536
脚本运行窗口=40,320,120,72,800
参考=72,320,2048
断点=72,72,200,288,2048
线程=72,72,88,144,80,72,96,96
内存映射=72,72,72,72,96,40,64,64,2048
可执行模块=72,72,72,72,128,2048
记录数据=72,2048
脚本执行=30,240,240,54
窗口=104,256,72,72,72,72,72,72,72,2048
句柄=72,120,48,72,24,96,2048
补丁=72,40,64,256,256,2048
Call stack=72,72,288,224,72
RUN 跟踪=72,72,72,72,256,2048
源码=64,2048
监视表达式=288,2048
中间文件列表=240,640,256
Script Log Window=72,1040
Run跟踪=72,72,72,72,256,2048
Windows=104,256,72,72,72,72,72,72,72,2048
可 执 行 模 块=72,72,72,72,128,2048
内存映射=72,72,72,72,128,2048
调用堆栈=72,72,288,224,72
SEH 链=72,256
统计=72,72,256,2048
[Appearance]
CPU scheme=6
CPU Disassembler=2,6,1,0,2
CPU Dump=2,7,1,0,36881,2
CPU Stack=2,6,0,0
CPU Info=2,7,0,0
CPU Registers=2,6,1,0
中文搜索引擎=2,6,1,0,0
References=1,0,1,0,0
Breakpoints=1,0,1,0,0
Executable modules=1,0,1,0,0
Threads=1,0,1,0,0
Memory map=1,0,1,0,0
Log data=1,0,1,0,0
脚本运行窗口=2,6,1,0,0
参考=2,6,1,0,0
断点=2,6,1,0,0
线程=2,6,1,0,0
内存映射=2,6,1,0,0
可执行模块=2,6,1,0,0
记录数据=2,6,1,0,0
脚本执行=1,0,1,0,0
窗口=2,6,1,0,0
句柄=2,6,1,0,0
补丁=2,6,1,0,0
Call stack=2,6,1,0,0
RUN 跟踪=2,6,1,0,0
源码=2,6,0,0,0
监视表达式=2,6,1,0,0
中间文件列表=2,6,1,0,0
Script Log Window=2,6,1,0,0
Run跟踪=2,6,1,0,0
Windows=2,6,1,0,0
[界面选项]
记录数据=2,6,1,0,0
可 执 行 模 块=2,6,1,0,0
内存映射=2,6,1,0,0
线程=2,6,1,0,0
句柄=2,6,1,0,0
调用堆栈=2,6,1,0,0
补丁=2,6,1,0,0
源码=2,6,0,0,0
Run跟踪=2,6,1,0,0
参考=2,6,1,0,0
断点=2,6,1,0,0
中文搜索引擎=2,6,1,0,0
Call stack=2,6,1,0,0
可执行模块=0,6,1,0,0
内存映射=2,6,1,0,0
SEH 链=2,6,1,0,0
RUN 跟踪=2,6,1,0,2
窗口=2,6,1,0,0
脚本运行窗口=2,6,1,0,0
统计=2,6,1,0,0
[Plugin Olly Advanced]
varbps=0
copytoexecutable=1
usetoolhelp=0
pausedex=0
pluginexpand=1
keepalteredcrc=0
ignorechangedbp=0
advancedctrlg=1
numofrva=1
followindisassembler=1
analysisbug=1
Entrypointwarning=1
antiattachkill=1
winupack=1
antiattachkill2=1
killps=1
toomanypatches=0
compressedcode=1
dllloading=1
compressedcodehandling=2
dllloadmethod=1
ctrlgstate=1
showalljumpsfix=1
TerminateProcess=0
HideDebugBit=0
NtGlobalFlag=0
Antihwbp=0
HeapFlags=0
ForceFlags=0
maxolly=0
Writememory=0
Readmemory=0
Process32Next=0
UnhandledExceptionFilter=0
Module32Next=0
CheckRemoteDebuggerPresent=0
ZwSetInformationThread=0
GetTickCount=0
GetTickCountCounter=1
ZwQuerySystemInformation=0
ZwOpenProcess=0
FindWindow=0
Anti-RDTSCenabled=0
Anti-RDTSC=0
Anti-RDTSC2=0
ZwQueryInformationProcess=0
codebasefix=1
ignoreexporttable=0
ZwQueryObject=0
scrambleexporttable=0
maxallollywindows=0
x64compat=0
SuspendThread=0
BlockInput=0
viewfilefix=1
BreakOnTls=0
alwaysenableshowalljumpsandcalls=0
fixc08bug=0
fixtermination=1
modulepointer=12
lasttab=4
[Plugin 书签管理 +]
Restore bookmarks window=0
[Plugin SkyPatch]
NPATCH1=
[Plugin PhantOm]
PEB=1
GETCOUNT=0
DRX=0
SETCONTEXT=1
DEBSTRING=1
WINVER=0
GETTIMES=0
REMOVEEP=1
HANDLE=1
WINDOWS=0
DRIVER=1
CAPTION=1
RDTSC=1
VERSION=126
DELTARDTSC=34816
BLOCK=0
HIDENAME=extrem
RDTSCNAME=rdtsc
[AeDebug]
Debugger="C:\Windows\system32\vsjitdebugger.exe" -p %ld -e %ld
[Plugin Oreans UnVirtualizer]
Plugin Version=18
Window Pos X=257
Window Pos Y=192
[Plugin OllyDisasm201]
DisasmMode=0
[Exceptions]
Custom[0]=00000000,FFFFFFFF