1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452
| [History] UDD path=C:\Users\lenovo\Desktop\吾爱破解专用版Ollydbg\吾爱破解专用版Ollydbg\UDD Plugin path=C:\Users\lenovo\Desktop\吾爱破解专用版Ollydbg\吾爱破解专用版Ollydbg\plugin View file= View text file= Object file= Import library= Log file= Run trace file=rtrace.txt API help file= Text save file= Symbolic data path= Executable[1]=C:\Users\lenovo\Desktop\吾爱破解专用版Ollydbg\吾爱破解专用版Ollydbg\OllyDBG.EXE Executable[2]=C:\Users\lenovo\Desktop\吾爱破解专用版Ollydbg\吾爱破解专用版Ollydbg\吾爱破解[LCG].exe Executable[3]=C:\Users\lenovo\Desktop\1.exe Executable[4]=C:\Users\lenovo\Desktop\reverse2_final.exe Executable[5]=C:\Users\lenovo\Desktop\packed.exe Executable[0]=C:\Users\lenovo\Desktop\ollydbg\ollydbg\OllyDBG.EXE [Settings] Check DLL versions=0 Show toolbar=1 Status in toolbar=1 Use hardware breakpoints to step=1 Restore windows=2193 Scroll MDI=0 Horizontal scroll=0 Topmost window=0 Index of default font=1 Index of default colours=0 Index of default syntax highlighting=0 Log buffer size index=0 Run trace buffer size index=1 Group adjacent commands in profile=1 Highlighted trace register=-1 IDEAL disassembling mode=0 Disassemble in lowercase=1 Separate arguments with TAB=0 Extra space between arguments=0 Show default segments=1 NEAR jump modifiers=0 Use short form of string commands=0 Use RET instead of RETN=0 Size sensitive mnemonics=1 SSE size decoding mode=0 Top of FPU stack=1 Always show memory size=1 Decode registers for any IP=1 Show symbolic addresses=1 Show local module names=1 Gray data used as filling=1 Show jump direction=1 Show jump path=1 Show jumpfrom path=1 Show path if jump is not taken=1 Underline fixups=1 Center FOLLOWed command=1 Show stack frames=1 Show local names in stack=1 Extended stack trace=1 Synchronize source with CPU=1 Include SFX extractor in code=0 SFX trace mode=0 Use real SFX entry from previous run=1 Ignore SFX exceptions=1 First pause=1 Stop on new DLL=0 Stop on DLL unload=0 Stop on new thread=0 Stop on thread end=0 Stop on debug string=0 Decode SSE registers=0 Enable last error=1 Ignore access violations in KERNEL32=1 Ignore INT3=1 Ignore TRAP=1 Ignore access violations=1 Step in unknown commands=1 Ignore division by 0=1 Ignore illegal instructions=1 Ignore all FPU exceptions=1 Warn when frequent breaks=0 Warn when break not in code=0 Autoreturn=0 Save original command in trace=1 Show traced ESP=1 Show traced flags=1 Animate over system DLLs=1 Trace over string commands=0 Synchronize CPU and Run trace=1 Ignore custom exceptions=1 Smart update=1 Set high priority=1 Append arguments=1 Use ExitProcess=1 Allow injection to get WinProc=0 Sort WM_XXX by name=0 Type of last WinProc breakpoint=0 Snow-free drawing=0 Demangle symbolic names=1 Keep ordinal in name=1 Only ASCII printable in dump=0 Allow diacritical symbols=0 String decoding=3 Warn if not administrator=0 Warn when terminating process=0 Align dialogs=1 Use font of calling window=0 Specified dialog font=0 Number of lines that follow EIP=0 Restore window positions=1 Restore width of columns=0 Highlight sorted column=0 Compress analysis data=1 Backup UDD files=1 Fill rest of command with NOPs=1 Reference search mode=0 Global search=1 Aligned search=1 Allow error margin=0 Keep size of hex edit selection=1 Modify tag of FPU register=1 Hex inspector limits=1 MMX display mode=0 Last selected options card=5 Last selected appearance card=3 Ignore case in text search=1 Letter key in Disassembler=1 Looseness of code analysis=1 Decode pascal strings=1 Guess number of arguments=1 Accept far calls and returns=1 Accept direct segment modifications=1 Decode VxD calls=1 Accept privileged commands=1 Accept I/O commands=1 Accept NOPs=1 Accept shifts out of range=1 Accept superfluous prefixes=1 Accept LOCK prefixes=1 Accept unaligned stack operations=1 Accept non-standard command forms=1 Show ARG and LOCAL in procedures=1 Save analysis to file=1 Analyse main module automatically=1 Analyse code structure=1 Decode ifs as switches=1 Save trace to file=0 Trace contents of registers=1 Functions preserve registers=0 Decode tricks=1 Automatically select register type=1 Show decoded arguments=1 Show decoded arguments in stack=1 Show arguments in call stack=1 Show induced calls=1 Label display mode=0 Label includes module name=1 Highlight symbolic labels=1 Highlight RETURNs in stack=1 Ignore path in user data file=1 Ignore timestamp in user data file=1 Ignore CRC in user data file=1 Default sort mode in Names=1 Save out-of-module user data=0 Tabulate columns in log file=0 Append data to existing log file=0 Flush gathered data to log file=0 Skip spaces in source comments=1 Hide non-existing source files=1 Tab stops=8 File graph mode=2 Show internal handle names=0 Hide irrelevant handles=0 [Plugin ODbgScript] Restore Script window=0 Restore Script Log=0 BP_0001= 恢复脚本窗口 =0 还原脚本日志 =0 恢复脚本窗口 =0 还原脚本日志 =0 恢复脚本窗口 =0 还原脚本日志 =0 恢复脚本窗口 =0 还原脚本日志 =0 恢复脚本窗口 =0 还原脚本日志 =0 还原脚本窗口=0 还原脚本日志=0 MRU1=C:\Users\lenovo\Desktop\od.txt MRU2= MRU3= MRU4= MRU5= ScriptDir=C:\Users\lenovo\Desktop\od.txt BP_FILE=C:\Users\lenovo\Desktop\od.txt [System] Options position=134,126 Call DLL position=20,89 [Plugin IDAFicator] Custom Scheme=0,8388608,32768,8421376,128,8388736,32896,12632256,8421504,16711680,65280,16776960,255,16711935,65535,16777215,12639424,15780004,15793151,10789024 disableClickJmp=1 DIA MAC x=0 DIA MAC y=0 DIA HWBP x=0 DIA HWBP y=0 Custom BP list=NonaWrite disasmCode=0 PATH_RADASM=C:\吾爱破解专用版Ollydbg\plugin\minimalist-radasm PATH_HELP=C:\吾爱破解专用版Ollydbg\plugin\IDAFICATOR.hlp SETTINGS_MSEC=500 DIA_CUSTOMIZE_SCHEME=0,8388608,32768,8421376,128,8388736,32896,12632256,8421504,16711680,65280,16776960,255,16711935,65535,16777215,12639424,15780004,15793151,10789024 SETTINGS_MAIN=1,1,1,1,1 SETTINGS_DUMP= SETTINGS_DISASM=1,0,0 SETTINGS_STACK= SETTINGS_HWBP=0,0,0 SETTINGS_ROTE= LAYOUT_ID=0 LAYOUT_SWAP_DUMP_STACK=0 SETTINGS_COMPILER=0 DIA_ROTE_POS=-4,-4,1032,746 MNU_PATHS_DIRS_N=0 MNU_PATHS_FILES_N=0 [Plugin 超级字串参考] Restore UStrRef Window=1 [Placement] OllyTest=434,64,1219,623,1 CPU=35,302,1027,472,3 CPU subwindows=601,1459,595,1459,583,1155,518,1179 超级字串参考=22,29,618,230,1 Executable modules=0,0,162,45,1 Memory map=0,0,162,45,1 Log data=282,17,312,45,1 Threads=0,0,162,45,1 Windows=0,0,162,45,1 Handles=132,16,547,437,1 Patches=278,0,312,45,1 Call stack=137,16,312,45,1 Source=44,58,372,274,1 References=0,0,162,45,1 Breakpoints=0,0,162,45,1 中文搜索引擎=278,38,312,57,1 Call tree=0,0,312,45,1 脚本运行窗口=193,89,201,45,1 Watch expressions=99,37,540,230,1 Source files=66,87,474,230,1 Run trace=22,29,432,230,1 SEH chain=88,116,270,230,1 CPU subwindows 1=374,767,336,658,450,960,388,853 CPU subwindows 2=374,767,336,658,450,960,388,853 CPU subwindows 3=374,767,336,658,450,960,388,853 CPU subwindows 4=374,767,336,658,450,960,388,853 [Colours] Scheme[0]=10,12,18,0,5,15,13,13 Scheme name[0]=Dave's black Scheme[1]=1,5,0,18,7,18,4,12 Scheme name[1]=Fancy Nico Scheme[2]=7,12,7,10,11,7,3,13 Scheme name[2]=Kostya's blue Scheme[3]=7,12,7,0,5,15,18,13 Scheme name[3]=Dami's black Scheme[4]=0,12,8,18,7,8,7,13 Scheme name[4]=Scheme 4 Scheme[5]=14,12,7,1,3,7,3,13 Scheme name[5]=Scheme 5 Scheme[6]=1,12,3,11,14,2,7,13 Scheme name[6]=Scheme 6 Scheme[7]=15,12,7,0,8,11,7,13 Scheme name[7]=Scheme 7 [Fonts] Font[0]=16,8,400,0,0,0,134,2,49,0 Face name[0]=Terminal Font name[0]=OEM 等宽字体 Font[1]=-12,0,400,0,0,0,134,1,49,0 Face name[1]=新宋体 Font name[1]=Terminal 6 Font[2]=16,8,400,0,0,0,134,2,49,0 Face name[2]=Fixedsys Font name[2]=系统等宽字体 Font[3]=14,0,400,0,0,0,1,2,5,0 Face name[3]=Courier New Font name[3]=Courier (UNICODE) Font[4]=10,6,400,0,0,0,1,2,5,0 Face name[4]=Lucida Console Font name[4]=Lucida (UNICODE) Font[5]=9,6,700,0,0,0,255,0,48,0 Face name[5]=Terminal Font name[5]=字体 5 Font[6]=16,8,400,0,0,0,134,2,49,0 Face name[6]=Fixedsys Font name[6]=字体 6 Font[7]=14,0,400,0,0,0,1,2,5,0 Face name[7]=Courier New Font name[7]=字体 7 [Syntax] Commands[1]=10,7,12,12,14,12,12,13,96,7,14,0,0,0 Operands[1]=1,7,7,7,13,14,10,11,0,0,0,0,0,0 Scheme name[1]=Dave Commands[2]=1,1,1,1,1,1,1,4,109,12,12,0,0,0 Operands[2]=1,1,2,4,12,2,2,5,0,0,0,0,0,0 Scheme name[2]=Fancy Nico Commands[3]=14,4,124,124,9,110,64,13,111,8,12,0,0,0 Operands[3]=1,10,4,13,11,13,15,6,0,0,0,0,0,0 Scheme name[3]=Kostya's xmas tree Commands[4]=7,7,2,12,6,12,10,13,96,7,14,0,0,0 Operands[4]=1,7,7,7,13,7,10,11,0,0,0,0,0,0 Scheme name[4]=Dami Commands[5]=0,0,0,0,0,0,0,0,0,0,0,0,0,0 Operands[5]=0,0,0,0,0,0,0,0,0,0,0,0,0,0 Scheme name[5]=No highlighting Commands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0 Operands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0 Scheme name[0]=No highlighting [Arguments] Executable[1]= Executable[2]= Executable[3]= Executable[4]= Executable[5]= Executable[0]= [Appearance] CPU scheme=3 CPU Disassembler=2,3,0,0,3 CPU Dump=2,3,1,0,4353,0 CPU Stack=2,3,0,0 CPU Info=2,3,0,0 CPU Registers=2,3,1,0 超级字串参考=1,0,1,0,0 Executable modules=1,0,1,0,0 Memory map=1,0,1,0,0 Log data=1,0,1,0,0 Threads=1,0,1,0,0 Windows=1,0,1,0,0 Handles=1,0,1,0,0 Patches=1,0,1,0,0 Call stack=1,0,1,0,0 Source=1,0,0,0,0 References=1,0,1,0,0 Breakpoints=1,0,1,0,0 中文搜索引擎=1,0,1,0,0 Call tree=1,0,1,0,0 脚本运行窗口=1,0,1,0,0 Watch expressions=1,0,1,0,0 Source files=1,0,1,0,0 Run trace=1,0,1,0,0 SEH chain=1,0,1,0,0 [Columns] CPU Disassembler=72,136,320,2048 CPU Dump=72,384,136, CPU Stack=72,80,2048, 超级字串参考=54,240,1536 Executable modules=54,54,54,54,223,1536 Memory map=54,54,54,54,72,30,48,48,1536 Log data=54,1536 Threads=54,54,66,108,60,54,72,72 Windows=78,192,54,54,54,54,54,54,54,1536 Handles=54,90,36,54,18,72,1536 Patches=54,30,48,192,192,1536 Call stack=54,54,216,168,54 Source=48,1536 References=54,240,1536 Breakpoints=54,54,150,216,1536 中文搜索引擎=54,240,1536 Call tree=192,192,192,192 脚本运行窗口=30,240,90,54,600 Watch expressions=216,1536 Source files=54,96,1536 Run trace=54,54,54,54,192,1536 SEH chain=54,192 [Plugin StrongOD] CreateProcessMode=0 HidePEB=1 IsPatchFloat=1 IsAdvGoto=0 KernelMode=1 KillPEBug=1 SuperEnumMod=1 AdvAttach=1 SkipExpection=1 OrdFirst=0 BreakOnLdr=0 BreakOnTls=1 RemoveEpOneShot=1 ShowBar=17 LoadSym=0 AutoUpdate=0 HideWindow=1 HideProcess=1 ProtectProcess=1 DriverKey=-514523012 DriverName=Rockey5U UpdateURL= [Plugin 中文搜索引擎] Restore UStrRef Window=1 [Import libraries] Implib[0]=C:\吾爱破解专用版Ollydbg\LIB\MFC42.Lib Implib[1]=C:\吾爱破解专用版Ollydbg\LIB\mfc42d.lib Implib[2]=C:\吾爱破解专用版Ollydbg\LIB\mfc42u.lib Implib[3]=C:\吾爱破解专用版Ollydbg\LIB\mfc42ud.lib Implib[4]=C:\吾爱破解专用版Ollydbg\LIB\mfc71.Lib Implib[5]=C:\吾爱破解专用版Ollydbg\LIB\mfc71d.lib Implib[6]=C:\吾爱破解专用版Ollydbg\LIB\mfc71u.lib Implib[7]=C:\吾爱破解专用版Ollydbg\LIB\mfc71ud.lib Implib[8]=C:\吾爱破解专用版Ollydbg\LIB\mfc80.lib Implib[9]=C:\吾爱破解专用版Ollydbg\LIB\mfc80d.lib Implib[10]=C:\吾爱破解专用版Ollydbg\LIB\mfc80u.lib Implib[11]=C:\吾爱破解专用版Ollydbg\LIB\mfc80ud.lib Implib[12]=C:\吾爱破解专用版Ollydbg\LIB\mfcd42d.lib Implib[13]=C:\吾爱破解专用版Ollydbg\LIB\mfcd42ud.lib Implib[14]=C:\吾爱破解专用版Ollydbg\LIB\mfcn42d.lib Implib[15]=C:\吾爱破解专用版Ollydbg\LIB\mfcn42ud.lib Implib[16]=C:\吾爱破解专用版Ollydbg\LIB\mfco42d.lib Implib[17]=C:\吾爱破解专用版Ollydbg\LIB\mfco42ud.lib Implib[18]=C:\吾爱破解专用版Ollydbg\LIB\MSVBVM50.lib Implib[19]=C:\吾爱破解专用版Ollydbg\LIB\msvbvm60.lib Implib[20]=C:\吾爱破解专用版Ollydbg\LIB\msvcp60.lib Implib[21]=C:\吾爱破解专用版Ollydbg\LIB\msvcp71.lib Implib[22]=C:\吾爱破解专用版Ollydbg\LIB\msvcp80.lib Implib[23]=C:\吾爱破解专用版Ollydbg\LIB\MSVCR70.lib Implib[24]=C:\吾爱破解专用版Ollydbg\LIB\msvcr71.lib Implib[25]=C:\吾爱破解专用版Ollydbg\LIB\msvcr80.lib Implib[26]=C:\吾爱破解专用版Ollydbg\LIB\msvcrt.lib Implib[27]=C:\吾爱破解专用版Ollydbg\LIB\comctl32.lib Implib[28]=C:\吾爱破解专用版Ollydbg\LIB\dbgeng.lib Implib[29]=C:\吾爱破解专用版Ollydbg\LIB\dbghelp.lib Implib[30]=C:\吾爱破解专用版Ollydbg\LIB\kernel32.lib Implib[31]=C:\吾爱破解专用版Ollydbg\LIB\ntdll.lib Implib[32]=C:\吾爱破解专用版Ollydbg\LIB\oleaut32.lib Implib[33]=C:\吾爱破解专用版Ollydbg\LIB\oledlg.lib Implib[34]=C:\吾爱破解专用版Ollydbg\LIB\ollydbg.lib Implib[35]=C:\吾爱破解专用版Ollydbg\LIB\ws2_32.lib Implib[36]=C:\吾爱破解专用版Ollydbg\LIB\wsock32.lib [Plugin ILLY] AutoRun=0 [参数] 参数[0]=123123 参数[1]=""AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAo\CAAAAAAAAAAAAAAAA谏浸鐜_賢$鬪)杀11n冾?n?{zH刓?顾lj蓒]鵁w?Zy;パ_r6I?磹瘐匷髀囦蘙Zg砚??翗蒳?HC/糠蹠i?9T'證悘6桁礎/廰谴7??夷僲既《魺D}踒??鋫n3鰉螒|?ㄞ哨>e枯@f锏q韅翇$?l??d蒖<睮W糀Q?瘴?梆`憭绯y{??"" Argument[1]=1 Argument[0]=123123 [Exceptions] Custom[0]=00000000,FFFFFFFF
|