Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [Settings]
- Check DLL versions=0
- Show toolbar=1
- Status in toolbar=0
- Use hardware breakpoints to step=0
- Restore windows=9
- Scroll MDI=0
- Horizontal scroll=0
- Topmost window=0
- Index of default font=1
- Index of default colours=0
- Index of default syntax highlighting=1
- Log buffer size index=0
- Run trace buffer size index=1
- Group adjacent commands in profile=1
- Highlighted trace register=-1
- IDEAL disassembling mode=0
- Disassemble in lowercase=0
- Separate arguments with TAB=0
- Extra space between arguments=0
- Show default segments=1
- NEAR jump modifiers=0
- Use short form of string commands=0
- Use RET instead of RETN=0
- Size sensitive mnemonics=1
- SSE size decoding mode=0
- Top of FPU stack=1
- Always show memory size=1
- Decode registers for any IP=0
- Show symbolic addresses=1
- Show local module names=1
- Gray data used as filling=1
- Show jump direction=1
- Show jump path=1
- Show jumpfrom path=1
- Show path if jump is not taken=1
- Underline fixups=1
- Center FOLLOWed command=0
- Show stack frames=1
- Show local names in stack=1
- Extended stack trace=0
- Synchronize source with CPU=0
- Include SFX extractor in code=0
- SFX trace mode=0
- Use real SFX entry from previous run=1
- Ignore SFX exceptions=0
- First pause=2
- Stop on new DLL=0
- Stop on DLL unload=0
- Stop on new thread=0
- Stop on thread end=0
- Stop on debug string=0
- Decode SSE registers=0
- Enable last error=1
- Ignore access violations in KERNEL32=1
- Ignore INT3=0
- Ignore TRAP=0
- Ignore access violations=0
- Step in unknown commands=0
- Ignore division by 0=0
- Ignore illegal instructions=0
- Ignore all FPU exceptions=0
- Warn when frequent breaks=0
- Warn when break not in code=0
- Autoreturn=0
- Save original command in trace=0
- Show traced ESP=0
- Show traced flags=0
- Animate over system DLLs=0
- Trace over string commands=0
- Synchronize CPU and Run trace=0
- Ignore custom exceptions=0
- Smart update=1
- Set high priority=1
- Append arguments=1
- Use ExitProcess=1
- Allow injection to get WinProc=0
- Sort WM_XXX by name=0
- Type of last WinProc breakpoint=0
- Snow-free drawing=0
- Demangle symbolic names=0
- Keep ordinal in name=1
- Only ASCII printable in dump=0
- Allow diacritical symbols=0
- String decoding=0
- Warn if not administrator=0
- Warn when terminating process=0
- Align dialogs=1
- Use font of calling window=0
- Specified dialog font=0
- Number of lines that follow EIP=0
- Restore window positions=1
- Restore width of columns=0
- Highlight sorted column=0
- Compress analysis data=1
- Backup UDD files=1
- Fill rest of command with NOPs=1
- Reference search mode=0
- Global search=1
- Aligned search=0
- Allow error margin=0
- Keep size of hex edit selection=1
- Modify tag of FPU register=1
- Hex inspector limits=1
- MMX display mode=0
- Last selected options card=7
- Last selected appearance card=6
- Ignore case in text search=1
- Letter key in Disassembler=1
- Looseness of code analysis=1
- Decode pascal strings=1
- Guess number of arguments=1
- Accept far calls and returns=0
- Accept direct segment modifications=0
- Decode VxD calls=0
- Accept privileged commands=0
- Accept I/O commands=0
- Accept NOPs=1
- Accept shifts out of range=0
- Accept superfluous prefixes=0
- Accept LOCK prefixes=0
- Accept unaligned stack operations=1
- Accept non-standard command forms=1
- Show ARG and LOCAL in procedures=0
- Save analysis to file=1
- Analyse main module automatically=1
- Analyse code structure=1
- Decode ifs as switches=0
- Save trace to file=0
- Trace contents of registers=1
- Functions preserve registers=0
- Decode tricks=0
- Automatically select register type=0
- Show decoded arguments=1
- Show decoded arguments in stack=1
- Show arguments in call stack=1
- Show induced calls=1
- Label display mode=0
- Label includes module name=0
- Highlight symbolic labels=0
- Highlight RETURNs in stack=1
- Ignore path in user data file=0
- Ignore timestamp in user data file=1
- Ignore CRC in user data file=0
- Default sort mode in Names=1
- Save out-of-module user data=0
- Tabulate columns in log file=0
- Append data to existing log file=0
- Flush gathered data to log file=0
- Skip spaces in source comments=1
- Hide non-existing source files=0
- Tab stops=8
- File graph mode=2
- Show internal handle names=0
- Hide irrelevant handles=0
- [Plugin Command line]
- Command line window X=0
- Command line window Y=0
- Restore command line window=0
- [Plugin Bookmarks]
- Restore bookmarks window=0
- [Placement]
- OllyTest=678,51,640,480,1
- CPU=0,0,526,373,3
- CPU subwindows=465,932,459,932,423,733,385,910
- Call stack=449,135,608,285,3
- Executable modules=112,112,748,285,1
- Threads=168,168,580,210,1
- Breakpoints=440,243,587,296,1
- Memory map=255,148,461,285,1
- Run trace=84,84,510,285,1
- Log data=140,140,447,360,1
- Windows=112,112,727,285,1
- [History]
- View file=
- View text file=
- Object file=
- Import library=
- Log file=log.txt
- Run trace file=rtrace.txt
- API help file=
- Text save file=
- Symbolic data path=
- UDD path=udd
- Plugin path=plg
- Executable[1]=
- Executable[2]=
- Executable[3]=
- Executable[4]=
- Executable[5]=
- Executable[0]=
- [Colours]
- Scheme[0]=0,12,8,18,7,19,14,13
- Scheme name[0]=Black on white
- Scheme[1]=14,12,7,1,3,7,3,13
- Scheme name[1]=Yellow on blue
- Scheme[2]=1,12,3,11,14,2,7,13
- Scheme name[2]=Marine
- Scheme[3]=15,12,7,0,8,11,7,13
- Scheme name[3]=Mostly black
- Scheme[4]=0,12,8,18,7,8,7,13
- Scheme name[4]=Scheme 4
- Scheme[5]=14,12,7,1,3,7,3,13
- Scheme name[5]=Scheme 5
- Scheme[6]=1,12,3,11,14,2,7,13
- Scheme name[6]=Scheme 6
- Scheme[7]=15,12,7,0,8,11,7,13
- Scheme name[7]=Scheme 7
- [Fonts]
- Font[0]=12,8,400,0,0,0,255,2,49,0
- Face name[0]=Terminal
- Font name[0]=OEM fixed font
- Font[1]=-13,0,700,0,0,0,204,1,49,0
- Face name[1]=Consolas
- Font name[1]=Terminal 6
- Font[2]=16,8,400,0,0,0,204,2,33,0
- Face name[2]=Fixedsys
- Font name[2]=System fixed font
- Font[3]=14,0,400,0,0,0,1,2,5,0
- Face name[3]=Courier New
- Font name[3]=Courier (UNICODE)
- Font[4]=10,6,400,0,0,0,1,2,5,0
- Face name[4]=Lucida Console
- Font name[4]=Lucida (UNICODE)
- Font[5]=9,6,700,0,0,0,255,0,48,0
- Face name[5]=Terminal
- Font name[5]=Font 5
- Font[6]=16,8,400,0,0,0,204,2,33,0
- Face name[6]=Fixedsys
- Font name[6]=Font 6
- Font[7]=14,0,400,0,0,0,1,2,5,0
- Face name[7]=Courier New
- Font name[7]=Font 7
- [Syntax]
- Commands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
- Operands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
- Scheme name[0]=No highlighting
- Commands[1]=32,4,124,112,80,64,68,13,111,8,12,0,0,0
- Operands[1]=1,4,4,13,81,113,0,12,0,0,0,0,0,0
- Scheme name[1]=Christmas tree
- Commands[2]=0,0,124,112,0,64,64,0,96,0,0,0,0,0
- Operands[2]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
- Scheme name[2]=Jumps'n'calls
- Commands[3]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
- Operands[3]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
- Scheme name[3]=Hilite 3
- Commands[4]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
- Operands[4]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
- Scheme name[4]=Hilite 4
- [Arguments]
- Executable[1]=
- Executable[2]=
- Executable[3]=
- Executable[4]=
- Executable[5]=
- Executable[0]=
- [System]
- Options position=538,198
- [Appearance]
- CPU scheme=0
- CPU Disassembler=1,0,0,0,1
- CPU Dump=1,0,1,0,8705,0
- CPU Stack=1,0,0,0
- CPU Info=1,0,0,0
- CPU Registers=1,0,1,0
- Call stack=1,0,1,0,0
- Executable modules=1,0,1,0,0
- Threads=1,0,1,0,0
- Breakpoints=1,0,1,0,0
- Memory map=1,0,1,0,0
- Run trace=1,0,1,0,0
- Log data=1,0,1,0,0
- Windows=1,0,1,0,0
- [Columns]
- CPU Disassembler=63,119,280,1792
- CPU Dump=63,231
- CPU Stack=63,70,1792
- Call stack=63,63,252,196,63
- Executable modules=63,63,63,63,112,1792
- Threads=63,63,77,126,70,63,84,84
- Breakpoints=63,63,175,252,1792
- Memory map=63,63,63,63,84,35,56,56,1792
- Run trace=63,63,63,63,224,1792
- Log data=63,1792
- Windows=91,224,63,63,63,63,63,63,63,1792
- [Plugin Olly Advanced]
- lasttab=1
- varbps=0
- showalljumpsfix=0
- TerminateProcess=0
- HideDebugBit=0
- NtGlobalFlag=0
- Antihwbp=0
- HeapFlags=0
- ForceFlags=0
- maxolly=0
- Writememory=0
- Readmemory=0
- Process32Next=0
- UnhandledExceptionFilter=0
- Module32Next=0
- CheckRemoteDebuggerPresent=0
- ZwSetInformationThread=0
- GetTickCount=0
- GetTickCountCounter=1
- ZwQuerySystemInformation=0
- ZwOpenProcess=0
- FindWindow=0
- Anti-RDTSCenabled=0
- Anti-RDTSC=0
- Anti-RDTSC2=0
- ZwQueryInformationProcess=0
- codebasefix=0
- ignoreexporttable=0
- ZwQueryObject=0
- scrambleexporttable=0
- maxallollywindows=0
- x64compat=1
- SuspendThread=0
- BlockInput=0
- viewfilefix=0
- copytoexecutable=0
- usetoolhelp=0
- pausedex=0
- pluginexpand=0
- keepalteredcrc=0
- ignorechangedbp=0
- advancedctrlg=0
- numofrva=0
- followindisassembler=0
- analysisbug=0
- Entrypointwarning=0
- antiattachkill=0
- winupack=0
- BreakOnTls=0
- killps=0
- alwaysenableshowalljumpsandcalls=0
- fixc08bug=0
- fixtermination=0
- toomanypatches=0
- compressedcode=0
- dllloading=0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement