Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [Settings]
- Check DLL versions=0
- GUI language=0
- Topmost window=0
- Show main menu items that don't apply=0
- Show popup items that don't apply=0
- Show toolbar=1
- Use system colours in toolbar=0
- Status in toolbar=0
- Flash duration=1
- Autoupdate interval=4
- Mode of main window=0
- Restore windows=13
- Bring OllyDbg to top on pause=1
- Restore window positions=1
- Restore width of columns=1
- Restore sorting criterium=1
- Highlight sorted column=1
- Right click selects=1
- Index of default font=3
- Index of default UNICODE font=3
- Index of default colours=2
- Code highlighting=0
- Horizontal scroll=0
- Snow-free drawing=0
- Append arguments=1
- Allow diacritical symbols=1
- Decode pascal strings=1
- Use IsTextUnicode=0
- String decoding=2
- File graph mode=2
- Put ASCII text to clipboard=0
- Monitor internal memory allocation=0
- Dialog font mode=0
- Font in dialogs=0
- Align dialogs=1
- Global search=1
- Aligned search=0
- Search accuracy=0
- Ignore case=1
- Search direction=0
- Floating search with margin=0
- Allow extra commands in sequence=1
- Allow jumps into the sequence=0
- Keep size of hex edit selection=0
- List sorting mode=0
- Modify FPU tag=0
- MMX display mode=0
- Show tooltips in dialog windows=1
- X options coordinate=324
- Y options coordinate=182
- Last selected options pane=14
- Last edited font in options=6
- Last edited scheme in options=0
- Last edited colour index in options=0
- Last edited highlighting in options=1
- Last edited highlighting index in options=0
- Warnmode when not administrator=1
- Warnmode for packed code in Analyzer=0
- Warnmode when INT3 breakpoint is corrupt=0
- Warnmode when breakpoint set on non-command=0
- Warnmode when EIP set on non-command=0
- Warnmode when clipboard size too large=0
- Warnmode when all threads are suspended=0
- Warnmode when thread is changed=0
- Warnmode when process is still running=0
- Warnmode when active when closing OllyDbg=0
- Warnmode when unable to close process=0
- Warnmode when executable differs from udd=0
- Warnmode when INT3 in udd has different cmd=0
- Warnmode when fixups are modified=0
- Warnmode when IAT is copied back to exe=0
- Warnmode when IAT is autocopied back to exe=0
- Warnmode when copy of executable file changed=0
- Warnmode when memory breakpoint on stack=0
- Warnmode when modified debug registers=0
- Warnmode when launching loaddll=0
- Warnmode when EIP inside the patch=0
- Only ASCII printable in dump=0
- Code page for ASCII dumps=1252
- Code page for multibyte dumps=65001
- Underline fixups=1
- Show jump direction=1
- Show jump path=1
- Show grayed path if jump is not taken=1
- Fill rest of command with NOPs=0
- Action on letter key in Disassembler=1
- Wide characters in UNICODE dumps=1
- Disable GDI scripting support=0
- Automatically backup user code=0
- Visible lines when scrolling disasm=1
- IDEAL disassembling mode=0
- Disassemble in lowercase=0
- Separate arguments with TAB=0
- Extra space between arguments=0
- Show default segments=1
- Always show memory size=1
- NEAR jump modifiers=0
- Alternative forms of conditional commands=1
- Use short form of string commands=0
- Use RET instead of RETN=0
- SSE size decoding mode=0
- Jump hint decoding mode=0
- Size sensitive mnemonics=1
- Top of FPU stack=1
- Show symbolic addresses=1
- Show local module names=1
- Demangle symbolic names=1
- Show call arguments=0
- Type of break command=0
- Use hardware breakpoints for stepping=1
- Hide unimportant handles=1
- Show original handle names=0
- Permanent breakpoints on system code=0
- First pause=1
- Pause on attach=2
- Pause on Loaddll=1
- Assume flat selectors=0
- Ignore access violations in KERNEL32=1
- Ignore INT3 in MSCORWKS=1
- Ignore INT3=1
- Ignore TRAP=1
- Ignore access violations=1
- Ignore division by 0=1
- Ignore illegal instructions=1
- Ignore all FPU exceptions=1
- Ignore all service exceptions=1
- Ignore custom exception ranges=1
- Call UnhandledExceptionFilter=0
- Report ignored exceptions to log=1
- Autoreturn=0
- Use DebugBreakProcess=0
- Use ExitProcess=1
- Warn when frequent breaks=0
- Allow command emulation=1
- Debug child processes=0
- Animation delay index=0
- Stop on new DLL=0
- Stop on DLL unload=0
- Stop only on selected modules=0
- Stop on debug string=0
- Stop on new thread=0
- Stop on thread end=0
- Enable use of debugging data=1
- Use dbghelp to walk stack=0
- Use Microsoft Symbol Server=0
- Hide missing source files=1
- Hide internal compiler names=1
- Skip leading spaces from source=1
- Hide Call DLL window on call=0
- Pause after call to DLL is finished=1
- Allow .NET debugging=0
- Scan registry for GUIDs on starup=0
- Run trace protocolling options=0
- Run trace buffer size index=1
- Trace over system DLLs=1
- Trace over string commands=0
- Save traced commands=0
- Save accessed memory to trace=0
- Save FPU registers to trace=0
- Synchronize CPU and Run trace=0
- Set breakpoints on callbacks in hit trace=0
- Hit trace mode for indirect jumps=0
- Stop hit trace if not command=0
- Hit trace outside the code section=2
- Keep hit trace between sessions=1
- Show symbolic names in protocol range list=0
- Allow automatic SFX extraction=1
- SFX extraction mode=0
- Use real SFX entry from previous run=0
- Ignore SFX exceptions=0
- Use predictions in search=1
- References include indirect jumps=1
- Add origin to search results=0
- Default resource language=9
- Gray inactive windows=1
- Gray register names=0
- Center FOLLOWed command=1
- Decode registers for any IP=1
- Hide current registers warning=0
- Remove code hilite on register hilite=1
- Automatically select register type=1
- Enable SSE registers=1
- Label display mode=0
- Highlight symbolic labels=1
- Log buffer size index=0
- Tabulate columns in log file=1
- Append data to existing log file=0
- Auto analysis=3
- No predicted registers in system DLLs=0
- Fuzzy analysis=1
- Report problems during analysis=0
- Decode tricks=1
- Mark tricks=0
- Search for library functions=1
- Decode ifs as switches=0
- Mark only important operands=0
- Functions preserve registers=0
- Ignore braces in udd path=1
- Guess number of arguments=1
- Guess arguments from mangled names=0
- Guess meaning of guessed arguments=1
- Show uncertain arguments=1
- Rename value dependent arguments=0
- Show predicted values=1
- Show ARG and LOCAL in disassembly=1
- Use symbolic names for ARG and LOCAL=0
- Show ARG and LOCAL in comments=1
- Show loops=1
- Accept far calls and returns=0
- Accept direct segment modifications=0
- Accept privileged commands=0
- Accept I/O commands=0
- Accept NOPs=1
- Accept shifts out of range=0
- Accept superfluous prefixes=0
- Accept default prefixes=1
- Accept valid LOCK prefixes=1
- Accept unaligned stack operations=1
- Accept suspicious ESP operations=0
- Accept non-standard command forms=1
- Accept access to nonexisting memory=0
- Accept interrupt commands=0
- Block external WM_CLOSE=1
- Activate speech=0
- Translate commands and registers=1
- Skip leading zeros in hex numbers=1
- [History]
- Executable[0]=C:\Program Files\GravityWell\GravityWell.exe
- Arguments[0]=
- Current dir[0]=
- Executable[1]=C:\Documents and Settings\Jay\Desktop\GWELL35X\GWELL32.EXE
- Arguments[1]=
- Current dir[1]=
- Executable[2]=C:\Program Files\PixtopianBook\PixtopianBook.exe
- Arguments[2]=
- Current dir[2]=
- Executable[3]=C:\Documents and Settings\Jay\My Documents\Downloads\snd-reversingwithlena-tutorials\snd-reversingwithlena-tutorial04.tutorial\files\pixtopianbook107.exe
- Arguments[3]=
- Current dir[3]=
- Executable[4]=C:\Documents and Settings\Jay\My Documents\Downloads\snd-reversingwithlena-tutorials\snd-reversingwithlena-tutorial03.tutorial\files\RegisterMe.Oops.exe
- Arguments[4]=
- Current dir[4]=
- Executable[5]=C:\Documents and Settings\Jay\My Documents\Downloads\snd-reversingwithlena-tutorials\snd-reversingwithlena-tutorial03.tutorial\files\RegisterMe.exe
- Arguments[5]=
- Current dir[5]=
- Log file=C:\Documents and Settings\Wij\Bureaublad\nag2.txt
- Trace save file=trace.txt
- Data directory=C:\Documents and Settings\Jay\Desktop\ollydbg
- Standard library directory=C:\Documents and Settings\Jay\Desktop\ollydbg
- Plugin directory=C:\Documents and Settings\Jay\Desktop\ollydbg\plugins
- API help file=C:\Documents and Settings\Jay\My Documents\Downloads\Win32api and x86 Opcodes\WIN32.HLP
- Alternative initialization file=C:\Documents and Settings\Jay\My Documents\Downloads\snd-reversingwithlena-tutorials\snd-reversingwithlena-tutorial01.tutorial\files\ollydbg.ini
- Last viewed file=
- Last keyboard shortcuts file=shortcuts.ini
- Last object or library file=
- Last image library file=
- Debug data directory[0]=
- Debug data directory[1]=
- Debug data directory[2]=
- Previous JIT=drwtsn32 -p %ld -e %ld -g
- [OllyDbg]
- Placement=0,2,1024,736,1
- [CPU]
- Placement=19,77,1177,436,3
- Offset[0]=-4
- Offset[1]=50
- Offset[2]=61
- Offset[3]=0
- [CPU Disasm]
- Appearance=6,0,0,0,2
- Columns=72,136,355,2048
- [CPU Info]
- Appearance=1,0,0,0,0
- [CPU registers]
- Appearance=6,0,1,0,0
- Local=0,66304
- [CPU Dump]
- Appearance=6,0,1,0,0
- Columns=72,388,136
- Local=00011001
- [CPU Stack]
- Appearance=6,0,0,0,0
- Columns=72,80,40,2048
- Local=000A0104
- [Dialog placement]
- Edit data=463,238
- Assemble=560,55
- Known jumps and calls=1139,335
- Edit register=1195,106
- Enter string=599,197
- Command search=746,125
- Set breakpoint=599,353
- Enter search string=1138,294
- Search for data=599,211
- Select structure=994,386
- Select range of exception codes=335,146
- Condition to pause run or hit trace=0,46
- Commands protocolled by run trace=0,46
- [Command help]
- Placement=22,29,375,214,1
- Appearance=3,2,0,0,0
- [Run trace data]
- Placement=44,58,1068,230,1
- Appearance=3,2,1,0,0
- Columns=63,56,63,63,280,168,1792
- Sort=0
- [Windows]
- Placement=110,145,921,230,1
- Appearance=3,2,1,0,0
- Columns=91,224,63,63,63,56,63,63,63,63,84
- Sort=0
- [INT3 breakpoints]
- Placement=132,174,865,230,1
- Appearance=3,2,1,0,0
- Columns=63,63,84,280,1792
- Sort=0
- [Patches]
- Placement=0,0,1024,436,2
- Appearance=3,2,1,0,0
- Columns=63,63,35,56,224,224,1792
- Sort=0
- [Filedump]
- Placement=81,115,837,230,1
- Appearance=6,2,1,0,0
- [Dialog placement]
- Edit data=692,68
- Assemble=692,198
- Known jumps and calls=1139,335
- [Command help]
- Placement=22,29,375,214,1
- Appearance=3,2,0,0,0
- [Run trace data]
- Placement=44,58,1068,230,1
- Appearance=3,2,1,0,0
- Columns=63,56,63,63,280,168,1792
- Sort=0
- [Windows]
- Placement=110,145,921,230,1
- Appearance=3,2,1,0,0
- Columns=91,224,63,63,63,56,63,63,63,63,84
- Sort=0
- [INT3 breakpoints]
- Placement=132,174,865,230,1
- Appearance=3,2,1,0,0
- Columns=63,63,84,280,1792
- Sort=0
- [Patches]
- Placement=154,203,1040,230,1
- Appearance=3,2,1,0,0
- Columns=63,63,35,56,224,224,1792
- Sort=0
- [Search tab]
- Appearance[3]=6,2,1,0,0
- Columns[3]=72,320,2048
- Sort[3]=0
- Appearance[1]=3,2,1,0,0
- Columns[1]=63,280,1792
- Sort[1]=0
- [Search]
- Placement=44,58,456,322,1
- [Attach]
- Appearance=3,2,1,0,0
- Columns=63,84,196,1792
- Sort=0
- [Memory]
- Placement=44,58,998,230,1
- Appearance=6,2,1,0,0
- Columns=72,72,128,80,192,128,114,156,2048
- Sort=0
- [Goto]
- Appearance=6,2,0,0,0
- [Modules]
- Placement=66,87,1152,230,1
- Appearance=6,2,1,0,0
- Columns=72,72,72,128,96,128,320,2048
- Sort=0
- [Structure]
- Placement=44,58,697,434,1
- Appearance=3,2,1,0,0
- [Dump]
- Placement=66,87,543,230,1
- Appearance=6,2,1,0,0
- [Memory breakpoints]
- Placement=44,58,683,230,1
- Appearance=3,2,1,0,0
- Columns=63,63,63,35,84,1792
- Sort=0
- [Threads]
- Placement=154,203,823,230,1
- Appearance=3,2,1,0,0
- Columns=42,63,126,208,63,63,63,222,84,84
- Sort=0
- [Ignored exceptions]
- Range[0]=0 ffffffff
- [Colour schemes]
- Scheme name[0]=Black on white
- Foreground_1[0]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[0]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[0]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[0]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[0]=0
- Modified commands[0]=0
- Scheme name[1]=Yellow on blue
- Foreground_1[1]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[1]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[1]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[1]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[1]=0
- Modified commands[1]=0
- Scheme name[2]=Marine
- Foreground_1[2]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[2]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[2]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[2]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[2]=0
- Modified commands[2]=0
- Scheme name[3]=Mostly black
- Foreground_1[3]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[3]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[3]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[3]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[3]=0
- Modified commands[3]=0
- Scheme name[4]=Scheme 4
- Foreground_1[4]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[4]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[4]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[4]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[4]=0
- Modified commands[4]=0
- Scheme name[5]=Scheme 5
- Foreground_1[5]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[5]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[5]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[5]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[5]=0
- Modified commands[5]=0
- Scheme name[6]=Scheme 6
- Foreground_1[6]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[6]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[6]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[6]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[6]=0
- Modified commands[6]=0
- Scheme name[7]=Scheme 7
- Foreground_1[7]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[7]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[7]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[7]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[7]=0
- Modified commands[7]=0
- [Highlighting schemes]
- Scheme name[1]=Christmas tree
- Foreground_1[1]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[1]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[1]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[1]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[1]=1
- Modified commands[1]=1
- Scheme name[2]=Jumps and calls
- Foreground_1[2]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[2]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[2]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[2]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[2]=0
- Modified commands[2]=0
- Scheme name[3]=Memory access
- Foreground_1[3]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[3]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[3]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[3]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[3]=1
- Modified commands[3]=1
- Scheme name[4]=Hilite 4
- Foreground_1[4]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[4]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[4]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[4]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[4]=0
- Modified commands[4]=0
- Scheme name[5]=Hilite 5
- Foreground_1[5]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[5]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[5]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[5]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[5]=0
- Modified commands[5]=0
- Scheme name[6]=Hilite 6
- Foreground_1[6]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[6]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[6]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[6]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[6]=0
- Modified commands[6]=0
- Scheme name[7]=Hilite 7
- Foreground_1[7]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Foreground_2[7]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_1[7]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Background_2[7]=*,*,*,*,*,*,*,*,*,*,*,*,*,*,*,*
- Operands[7]=0
- Modified commands[7]=0
- [Fonts]
- Font name[0]=OEM fixed font
- Font data[0]=-16,0,400,0,0,0,255,1,49,0,0,0
- Face name[0]=Terminal
- Font name[1]=Terminal 6
- Font data[1]=9,6,700,0,0,0,255,0,1,1,0,0
- Face name[1]=Terminal
- Font name[2]=System fixed font
- Font data[2]=0,0,0,0,0,0,0,0,0,0,0,16
- Face name[2]=
- Font name[3]=Courier (UNICODE)
- Font data[3]=14,0,400,0,0,0,1,2,5,-2,0,0
- Face name[3]=Courier New
- Font name[4]=Lucida (UNICODE)
- Font data[4]=10,6,400,0,0,0,1,2,5,0,0,0
- Face name[4]=Lucida Console
- Font name[5]=Font 5
- Font data[5]=9,6,700,0,0,0,255,0,1,1,0,0
- Face name[5]=Terminal
- Font name[6]=Font 6
- Font data[6]=0,0,0,0,0,0,0,0,0,0,0,16
- Face name[6]=
- Font name[7]=Font 7
- Font data[7]=14,0,400,0,0,0,1,2,5,-2,0,0
- Face name[7]=Courier New
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement