Skip to content

Instantly share code, notes, and snippets.

@JC-SoCal
Created January 19, 2015 00:28
Show Gist options
  • Star 3 You must be signed in to star a gist
  • Fork 1 You must be signed in to fork a gist
  • Save JC-SoCal/3ce4e2368830ba4495ed to your computer and use it in GitHub Desktop.
Save JC-SoCal/3ce4e2368830ba4495ed to your computer and use it in GitHub Desktop.
[Settings]
Check DLL versions=0
Show toolbar=1
Status in toolbar=0
Use hardware breakpoints to step=0
Restore windows=1
Scroll MDI=0
Horizontal scroll=0
Topmost window=0
Index of default font=1
Index of default colours=0
Index of default syntax highlighting=0
Log buffer size index=0
Run trace buffer size index=1
Group adjacent commands in profile=1
Highlighted trace register=-1
IDEAL disassembling mode=0
Disassemble in lowercase=0
Separate arguments with TAB=0
Extra space between arguments=0
Show default segments=1
NEAR jump modifiers=0
Use short form of string commands=0
Use RET instead of RETN=0
Size sensitive mnemonics=1
SSE size decoding mode=0
Top of FPU stack=1
Always show memory size=1
Decode registers for any IP=0
Show symbolic addresses=1
Show local module names=1
Gray data used as filling=1
Show jump direction=1
Show jump path=1
Show jumpfrom path=1
Show path if jump is not taken=1
Underline fixups=1
Center FOLLOWed command=0
Show stack frames=1
Show local names in stack=1
Extended stack trace=0
Synchronize source with CPU=0
Include SFX extractor in code=0
SFX trace mode=0
Use real SFX entry from previous run=1
Ignore SFX exceptions=0
First pause=2
Stop on new DLL=0
Stop on DLL unload=0
Stop on new thread=0
Stop on thread end=0
Stop on debug string=0
Decode SSE registers=0
Enable last error=1
Ignore access violations in KERNEL32=1
Ignore INT3=0
Ignore TRAP=0
Ignore access violations=0
Step in unknown commands=0
Ignore division by 0=0
Ignore illegal instructions=0
Ignore all FPU exceptions=0
Warn when frequent breaks=0
Warn when break not in code=1
Autoreturn=0
Save original command in trace=0
Show traced ESP=0
Show traced flags=0
Animate over system DLLs=0
Trace over string commands=0
Synchronize CPU and Run trace=0
Ignore custom exceptions=0
Smart update=1
Set high priority=1
Append arguments=1
Use ExitProcess=1
Allow injection to get WinProc=0
Sort WM_XXX by name=0
Type of last WinProc breakpoint=0
Snow-free drawing=0
Demangle symbolic names=0
Keep ordinal in name=1
Only ASCII printable in dump=0
Allow diacritical symbols=0
String decoding=0
Warn if not administrator=1
Warn when terminating process=1
Align dialogs=1
Use font of calling window=0
Specified dialog font=0
Number of lines that follow EIP=0
Restore window positions=1
Restore width of columns=0
Highlight sorted column=0
Compress analysis data=1
Backup UDD files=1
Fill rest of command with NOPs=1
Reference search mode=0
Global search=1
Aligned search=0
Allow error margin=0
Keep size of hex edit selection=1
Modify tag of FPU register=1
Hex inspector limits=1
MMX display mode=0
Last selected options card=10
Last selected appearance card=3
Ignore case in text search=1
Letter key in Disassembler=1
Looseness of code analysis=1
Decode pascal strings=1
Guess number of arguments=1
Accept far calls and returns=0
Accept direct segment modifications=0
Decode VxD calls=0
Accept privileged commands=0
Accept I/O commands=0
Accept NOPs=1
Accept shifts out of range=0
Accept superfluous prefixes=0
Accept LOCK prefixes=0
Accept unaligned stack operations=1
Accept non-standard command forms=1
Show ARG and LOCAL in procedures=0
Save analysis to file=1
Analyse main module automatically=1
Analyse code structure=1
Decode ifs as switches=0
Save trace to file=0
Trace contents of registers=1
Functions preserve registers=0
Decode tricks=0
Automatically select register type=0
Show decoded arguments=1
Show decoded arguments in stack=1
Show arguments in call stack=1
Show induced calls=1
Label display mode=0
Label includes module name=0
Highlight symbolic labels=0
Highlight RETURNs in stack=1
Ignore path in user data file=0
Ignore timestamp in user data file=1
Ignore CRC in user data file=0
Default sort mode in Names=1
Save out-of-module user data=0
Tabulate columns in log file=0
Append data to existing log file=0
Flush gathered data to log file=0
Skip spaces in source comments=1
Hide non-existing source files=0
Tab stops=8
File graph mode=2
Show internal handle names=0
Hide irrelevant handles=0
[Plugin Bookmarks]
Restore bookmarks window=0
[Plugin Command line]
Restore command line window=0
[Placement]
OllyTest=640,32,640,480,1
CPU=0,0,522,370,3
CPU subwindows=626,1205,620,1205,622,1264,512,1196
[History]
View file=
View text file=
Object file=
Import library=
Log file=log.txt
Run trace file=rtrace.txt
API help file=
Text save file=
Symbolic data path=C:\Program Files (x86)\odbg110
UDD path=C:\Program Files (x86)\odbg110\udd
Plugin path=C:\Program Files (x86)\odbg110
Executable[1]=C:\Users\JC\Desktop\qCcWLCuUxFlJAWY.exe
Executable[2]=C:\Users\JC\Desktop\lafarge-crackme2\crackme.exe
Executable[3]=
Executable[4]=
Executable[5]=
Executable[0]=C:\Users\JC\AppData\Roaming\cmdfc\cmmoinst.exe
[Colours]
Scheme[0]=0,12,8,18,7,8,7,13
Scheme name[0]=Black on white
Scheme[1]=14,12,7,1,3,7,3,13
Scheme name[1]=Yellow on blue
Scheme[2]=1,12,3,11,14,2,7,13
Scheme name[2]=Marine
Scheme[3]=15,12,7,0,8,11,7,13
Scheme name[3]=Mostly black
Scheme[4]=0,12,8,18,7,8,7,13
Scheme name[4]=Scheme 4
Scheme[5]=14,12,7,1,3,7,3,13
Scheme name[5]=Scheme 5
Scheme[6]=1,12,3,11,14,2,7,13
Scheme name[6]=Scheme 6
Scheme[7]=15,12,7,0,1,9,7,13
Scheme name[7]=JC
[Fonts]
Font[0]=12,8,400,0,0,0,255,2,49,0
Face name[0]=Terminal
Font name[0]=OEM fixed font
Font[1]=-19,0,400,0,0,0,255,1,49,1
Face name[1]=Terminal
Font name[1]=Terminal 6
Font[2]=15,8,400,0,0,0,0,2,49,0
Face name[2]=Fixedsys
Font name[2]=System fixed font
Font[3]=14,0,400,0,0,0,1,2,5,0
Face name[3]=Courier New
Font name[3]=Courier (UNICODE)
Font[4]=10,6,400,0,0,0,1,2,5,0
Face name[4]=Lucida Console
Font name[4]=Lucida (UNICODE)
Font[5]=9,6,700,0,0,0,255,0,48,0
Face name[5]=Terminal
Font name[5]=Font 5
Font[6]=15,8,400,0,0,0,0,2,49,0
Face name[6]=Fixedsys
Font name[6]=Font 6
Font[7]=-24,0,400,0,0,0,0,1,49,0
Face name[7]=Courier New
Font name[7]=JC
[Syntax]
Commands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Operands[0]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Scheme name[0]=No highlighting
Commands[1]=0,4,124,112,9,64,64,13,111,8,12,0,0,0
Operands[1]=1,0,4,13,65,1,112,6,0,0,0,0,0,0
Scheme name[1]=Christmas tree
Commands[2]=0,0,124,112,0,64,64,0,96,0,0,0,0,0
Operands[2]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Scheme name[2]=Jumps'n'calls
Commands[3]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Operands[3]=0,0,0,0,0,0,0,0,0,0,0,0,0,0
Scheme name[3]=Hilite 3
Commands[4]=31,13,112,80,11,64,64,14,96,2,12,10,10,10
Operands[4]=1,15,13,14,7,7,10,14,0,0,0,0,0,0
Scheme name[4]=JC JnC
[System]
Options position=152,174
[Arguments]
Executable[1]=
Executable[2]=
Executable[3]=
Executable[4]=
Executable[5]=
Executable[0]=
[Appearance]
CPU scheme=7
CPU Disassembler=7,7,0,0,4
CPU Dump=7,7,1,0,4225,0
CPU Stack=7,7,0,0
CPU Info=7,7,0,0
CPU Registers=7,7,1,0
[Columns]
CPU Disassembler=126,238,560,3584
CPU Dump=126,336,126
CPU Stack=126,140,3584
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment