.- - -----÷M÷E÷N÷U÷------------------------------------------------------------- --- ----  -------------.
!  WALL ! STATS ! GOODIES ! YARA ! FAQ ! RSS                                                            !
`--------------  - ---  ---------- -------- -------- -------- -------- ----------------- -  ---- ---- --'

                                           ATM MALWARE NOTICE 
                    4941331c64e0389d5ec966122ef71a99d8f9830f13e9afa758e03275f896c2eb
 
Date...........: 2014-06-05
Family.........: Trojan.Skimer
File name......: netmgr.dll
File size......: 66.00 KB
Type file......: DLL/Windows
Virscan........: VT - HA
Documentation..: https://securelist.com/atm-infector/74772/

Entropy:


Binary Histogram:


=== PEDUMP REPORT === 
=== MZ Header === signature: "MZ" bytes_in_last_block: 80 0x50 blocks_in_file: 2 2 num_relocs: 0 0 header_paragraphs: 4 4 min_extra_paragraphs: 15 0xf max_extra_paragraphs: 65535 0xffff ss: 0 0 sp: 184 0xb8 checksum: 0 0 ip: 0 0 cs: 0 0 reloc_table_offset: 64 0x40 overlay_number: 26 0x1a reserved0: 0 0 oem_id: 0 0 oem_info: 0 0 reserved2: 0 0 reserved3: 0 0 reserved4: 0 0 reserved5: 0 0 reserved6: 0 0 lfanew: 256 0x100 === DOS STUB === 00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| === PE Header === signature: "PE\x00\x00" # IMAGE_FILE_HEADER: Machine: 332 0x14c x86 NumberOfSections: 6 6 TimeDateStamp: "1992-06-19 22:22:17" PointerToSymbolTable: 0 0 NumberOfSymbols: 0 0 SizeOfOptionalHeader: 224 0xe0 Characteristics: 41358 0xa18e EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO 32BIT_MACHINE, DLL, BYTES_REVERSED_HI # IMAGE_OPTIONAL_HEADER32: Magic: 267 0x10b 32-bit executable LinkerVersion: 2.25 SizeOfCode: 56320 0xdc00 SizeOfInitializedData: 10240 0x2800 SizeOfUninitializedData: 0 0 AddressOfEntryPoint: 59880 0xe9e8 BaseOfCode: 4096 0x1000 BaseOfData: 61440 0xf000 ImageBase: 33554432 0x2000000 SectionAlignment: 4096 0x1000 FileAlignment: 512 0x200 OperatingSystemVersion: 4.0 ImageVersion: 0.0 SubsystemVersion: 4.0 Reserved1: 0 0 SizeOfImage: 90112 0x16000 SizeOfHeaders: 1024 0x400 CheckSum: 121446 0x1da66 Subsystem: 2 2 WINDOWS_GUI DllCharacteristics: 1 1 0x01 SizeOfStackReserve: 0 0 SizeOfStackCommit: 0 0 SizeOfHeapReserve: 1048576 0x100000 SizeOfHeapCommit: 4096 0x1000 LoaderFlags: 0 0 NumberOfRvaAndSizes: 16 0x10 === DATA DIRECTORY === EXPORT rva:0x 0 size:0x 0 IMPORT rva:0x 13000 size:0x cac RESOURCE rva:0x 15000 size:0x 5d8 EXCEPTION rva:0x 0 size:0x 0 SECURITY rva:0x 0 size:0x 0 BASERELOC rva:0x 14000 size:0x db4 DEBUG rva:0x 0 size:0x 0 ARCHITECTURE rva:0x 0 size:0x 0 GLOBALPTR rva:0x 0 size:0x 0 TLS rva:0x 0 size:0x 0 LOAD_CONFIG rva:0x 0 size:0x 0 Bound_IAT rva:0x 0 size:0x 0 IAT rva:0x 0 size:0x 0 Delay_IAT rva:0x 0 size:0x 0 CLR_Header rva:0x 0 size:0x 0 rva:0x 0 size:0x 0 === SECTIONS === NAME RVA VSZ RAW_SZ RAW_PTR nREL REL_PTR nLINE LINE_PTR FLAGS CODE 1000 dbf4 dc00 400 0 0 0 0 60000020 R-X CODE DATA f000 4e0 600 e000 0 0 0 0 c0000040 RW- IDATA BSS 10000 2eb5 0 e600 0 0 0 0 c0000000 RW- .idata 13000 cac e00 e600 0 0 0 0 c0000040 RW- IDATA .reloc 14000 db4 e00 f400 0 0 0 0 50000040 R-- IDATA SHARED .rsrc 15000 5d8 600 10200 0 0 0 0 50000040 R-- IDATA SHARED === RESOURCES === FILE_OFFSET CP LANG SIZE TYPE NAME 0x10258 1252 0 1406 RCDATA #1 === IMPORTS === MODULE_NAME HINT ORD FUNCTION_NAME kernel32.dll 0 DeleteCriticalSection kernel32.dll 0 LeaveCriticalSection kernel32.dll 0 EnterCriticalSection kernel32.dll 0 InitializeCriticalSection kernel32.dll 0 VirtualFree kernel32.dll 0 VirtualAlloc kernel32.dll 0 LocalFree kernel32.dll 0 LocalAlloc kernel32.dll 0 GetVersion kernel32.dll 0 GetCurrentThreadId kernel32.dll 0 GetThreadLocale kernel32.dll 0 GetStartupInfoA kernel32.dll 0 GetLocaleInfoA kernel32.dll 0 GetCommandLineA kernel32.dll 0 FreeLibrary kernel32.dll 0 ExitProcess kernel32.dll 0 CreateThread kernel32.dll 0 WriteFile kernel32.dll 0 UnhandledExceptionFilter kernel32.dll 0 RtlUnwind kernel32.dll 0 RaiseException kernel32.dll 0 GetStdHandle user32.dll 0 GetKeyboardType user32.dll 0 MessageBoxA advapi32.dll 0 RegQueryValueExA advapi32.dll 0 RegOpenKeyExA advapi32.dll 0 RegCloseKey kernel32.dll 0 TlsSetValue kernel32.dll 0 TlsGetValue kernel32.dll 0 TlsFree kernel32.dll 0 TlsAlloc kernel32.dll 0 LocalFree kernel32.dll 0 LocalAlloc advapi32.dll 0 RegQueryValueExA advapi32.dll 0 RegOpenKeyExA advapi32.dll 0 RegCloseKey advapi32.dll 0 OpenProcessToken advapi32.dll 0 LookupPrivilegeValueA advapi32.dll 0 AdjustTokenPrivileges kernel32.dll 0 lstrlenA kernel32.dll 0 lstrcpynA kernel32.dll 0 lstrcpyA kernel32.dll 0 lstrcmpiW kernel32.dll 0 lstrcmpiA kernel32.dll 0 lstrcmpA kernel32.dll 0 lstrcatA kernel32.dll 0 WriteFile kernel32.dll 0 WaitForSingleObjectEx kernel32.dll 0 WaitForSingleObject kernel32.dll 0 VirtualProtect kernel32.dll 0 TerminateThread kernel32.dll 0 SleepEx kernel32.dll 0 Sleep kernel32.dll 0 SizeofResource kernel32.dll 0 SetThreadPriority kernel32.dll 0 SetFilePointer kernel32.dll 0 SetEvent kernel32.dll 0 ReadFile kernel32.dll 0 OpenProcess kernel32.dll 0 MultiByteToWideChar kernel32.dll 0 LocalUnlock kernel32.dll 0 LocalSize kernel32.dll 0 LocalReAlloc kernel32.dll 0 LocalLock kernel32.dll 0 LocalFree kernel32.dll 0 LocalAlloc kernel32.dll 0 LoadResource kernel32.dll 0 LoadLibraryA kernel32.dll 0 GetVolumeInformationA kernel32.dll 0 GetTickCount kernel32.dll 0 GetThreadPriority kernel32.dll 0 GetTempFileNameA kernel32.dll 0 GetSystemTimeAsFileTime kernel32.dll 0 GetProcAddress kernel32.dll 0 GetModuleHandleA kernel32.dll 0 GetModuleFileNameA kernel32.dll 0 GetLastError kernel32.dll 0 GetFileSize kernel32.dll 0 GetExitCodeThread kernel32.dll 0 GetCurrentThreadId kernel32.dll 0 GetCurrentThread kernel32.dll 0 GetCurrentProcess kernel32.dll 0 FormatMessageA kernel32.dll 0 FindResourceA kernel32.dll 0 FileTimeToSystemTime kernel32.dll 0 FileTimeToLocalFileTime kernel32.dll 0 ExitProcess kernel32.dll 0 DeleteFileA kernel32.dll 0 CreateThread kernel32.dll 0 CreateMutexA kernel32.dll 0 CreateFileA kernel32.dll 0 CreateEventA kernel32.dll 0 CopyFileA kernel32.dll 0 CloseHandle gdi32.dll 0 TextOutA gdi32.dll 0 SelectObject gdi32.dll 0 Rectangle gdi32.dll 0 GetTextMetricsA gdi32.dll 0 Escape gdi32.dll 0 EndDoc gdi32.dll 0 DeleteObject gdi32.dll 0 DeleteDC gdi32.dll 0 CreateSolidBrush gdi32.dll 0 CreateDCA user32.dll 0 CreateWindowExA user32.dll 0 UnregisterClassA user32.dll 0 TranslateMessage user32.dll 0 SetTimer user32.dll 0 SetForegroundWindow user32.dll 0 SetFocus user32.dll 0 SendMessageA user32.dll 0 RegisterClassA user32.dll 0 PostMessageA user32.dll 0 PeekMessageA user32.dll 0 MessageBoxA user32.dll 0 LoadIconA user32.dll 0 LoadCursorA user32.dll 0 InvalidateRect user32.dll 0 GetWindowTextA user32.dll 0 GetWindowDC user32.dll 0 GetMessageA user32.dll 0 GetForegroundWindow user32.dll 0 GetDesktopWindow user32.dll 0 GetClientRect user32.dll 0 FindWindowExA user32.dll 0 FindWindowA user32.dll 0 ExitWindowsEx user32.dll 0 DrawTextA user32.dll 0 DispatchMessageA user32.dll 0 DestroyWindow user32.dll 0 DefWindowProcA user32.dll 0 CharUpperA kernel32.dll 0 GetTickCount imagehlp.dll 0 CheckSumMappedFile winspool.drv 0 EnumPrintersA user32.dll 0 wsprintfA
=== Strings ===
File pos Mem pos ID Text ======== ======= == ==== 000000000050 000002000050 0 This program must be run under Win32 000000000270 000002000270 0 .idata 000000000298 000002000298 0 .reloc 0000000002BF 0000020002BF 0 P.rsrc 000000000884 000002001484 0 wE;\$ 000000001E9F 000002002A9F 0 ~KxI[) 000000001FC8 000002002BC8 0 SOFTWARE\Borland\Delphi\RTL 000000001FE4 000002002BE4 0 FPUMaskValue 000000002031 000002002C31 0 PPRTj 0000000021AB 000002002DAB 0 YZXtp 000000002322 000002002F22 0 t=HtN 000000002744 000002003344 0 SVWUQ 000000002B00 000002003700 0 USVW1 0000000034E3 0000020040E3 0 {V,| 00000000353F 00000200413F 0 <8LaK# 000000003660 000002004260 0 /R{m6 000000003774 000002004374 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt 0000000037A8 0000020043A8 0 C:\windows\EpsStmApi.log\ 000000003BFC 0000020047FC 0 WinSta0 000000003C04 000002004804 0 default 000000003C0C 00000200480C 0 DISPLAY 000000003E55 000002004A55 0 D$XPSj 000000003EEE 000002004AEE 0 D$xPj 000000003F3B 000002004B3B 0 |$,{u 000000003FF8 000002004BF8 0 WinSta0 000000004000 000002004C00 0 MyDesktop 000000004018 000002004C18 0 ATMDialog 000000004024 000002004C24 0 hello 00000000402C 000002004C2C 0 STATIC 000000004044 000002004C44 0 default 00000000405C 000002004C5C 0 Error 000000004110 000002004D10 0 Error 000000004140 000002004D40 0 $PShpM 0000000041A3 000002004DA3 0 $PVSh 0000000041D4 000002004DD4 0 %s %s 000000004480 000002005080 0 %s Error code= %d 0000000044BC 0000020050BC 0 %s Error code= %.2X 0000000044F5 0000020050F5 0 t"Jt" 000000004504 000002005104 0 Jt Jt 000000004618 000002005218 0 OpenProcessToken 00000000462C 00000200522C 0 LookupPrivilegeValue 000000004644 000002005244 0 AdjustTokenPrivileges 0000000047F8 0000020053F8 0 getProcessEntry: 00000000480C 00000200540C 0 SeDebugPrivilege 000000004820 000002005420 0 OpenProcess 00000000482C 00000200542C 0 LoadLibraryA 00000000483C 00000200543C 0 kernel32.dll 00000000484C 00000200544C 0 GetExitCodeThread 000000004860 000002005460 0 VirtualFreeEx 000000004B38 000002005738 0 DbdDevExecute(EPP4_ENCODE_DECODE) 000000004B5C 00000200575C 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ) 000000004B88 000002005788 0 EPP Complete LOCK 000000004B9C 00000200579C 0 EPP Complete ENCODE_DECODE 000000004C58 000002005858 0 SVWUQ 000000004CA2 0000020058A2 0 $ZXu> 000000004D16 000002005916 0 ~7hhY 000000004D5C 00000200595C 0 OASYS.dll 000000004D68 000002005968 0 OasPostMessage 000000004E38 000002005A38 0 DBDDevOpen 000000004E44 000002005A44 0 DbdDevRegisterCallback File pos Mem pos ID Text ======== ======= == ==== 000000004E5C 000002005A5C 0 DbdDevLock 000000004E68 000002005A68 0 DbdDevUnregisterCallback 000000004E84 000002005A84 0 DBDDevClose 000000004F00 000002005B00 0 DbdDevUnlock 000000004F10 000002005B10 0 bdDevUnregisterCallback 000000004F28 000002005B28 0 DBDDevClose 000000005010 000002005C10 0 DbdDevAPI.dll 000000005020 000002005C20 0 DbdDevOpen 00000000502C 000002005C2C 0 DbdDevClose 000000005038 000002005C38 0 DbdDevGetInfo 000000005048 000002005C48 0 DbdDevRegisterCallback 000000005060 000002005C60 0 DbdDevUnregisterCallback 00000000507C 000002005C7C 0 DbdDevLock 000000005088 000002005C88 0 DbdDevUnlock 000000005098 000002005C98 0 DbdDevExecute 0000000051C8 000002005DC8 0 AMI function don 0000000051D9 000002005DD9 0 t return in 1 sec 0000000053F4 000002005FF4 0 RECEIPT 0000000053FC 000002005FFC 0 WINSPOOL 000000005408 000002006008 0 CreateDC 000000005414 000002006014 0 hello 00000000541C 00000200601C 0 escape 000000005424 000002006024 0 TextOut 00000000542C 00000200602C 0 enddoc 0000000054E4 0000020060E4 0 DbdDevExecute(EPP4_COPY_KEY) 000000005504 000002006104 0 EPP4_COPY_KEY TimeOut 000000005620 000002006220 0 DbdDevExecute(EPP4_LOAD_KEY) 000000005640 000002006240 0 EPP4_LOAD_KEY TimeOut 0000000056F0 0000020062F0 0 DbdDevExecute(EPP4_DELETE_KEY) 000000005710 000002006310 0 EPP4_DELETE_KEY TimeOut 00000000583C 00000200643C 0 DbdDevExecute(EPP4_ENCODE_DECODE) 000000005860 000002006460 0 EPP_Encrypt TimeOut 000000005964 000002006564 0 SVWUQ 000000005C3C 00000200683C 0 LocalAlloc 000000005C48 000002006848 0 LocalLock 00000000643A 00000200703A 0 P CNu 0000000066C4 0000020072C4 0 SVWUQ 000000006A8B 00000200768B 0 u7IBF 000000006B1A 00000200771A 0 I+NBu 000000006EA8 000002007AA8 0 %.2d/%.2d/%.2d %.2d:%.2d 000000007024 000002007C24 0 tdHuaj 00000000709C 000002007C9C 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI) 0000000070CC 000002007CCC 0 t LOCK EPP 0000000070D8 000002007CD8 0 RECEIPT_PRINTER_START_GDI 0000000070F4 000002007CF4 0 DbdDevExecute(RECEIPT_PRINTER_EJECT) 000000007278 000002007E78 0 DbdDevExecute(AFD_DISPENCE) 000000007294 000002007E94 0 CDM Complete LOCK 0000000072A8 000002007EA8 0 DbdDevExecute(AFD_PRESENT) 0000000072C4 000002007EC4 0 DbdDevExecute(AFD_RESTORE) 0000000074A0 0000020080A0 0 SeShutdownPrivilege 0000000077FC 0000020083FC 0 kernel32 000000007808 000002008408 0 DeleteFileA 000000007814 000002008414 0 FreeLibrary 000000007820 000002008420 0 GetModuleHandleA 000000007834 000002008434 0 CreateFileA 000000007840 000002008440 0 Sleep 000000007848 000002008448 0 WriteFile 000000007854 000002008454 0 CloseHandle 000000007860 000002008460 0 LocalFree 00000000786C 00000200846C 0 LoadLibraryA File pos Mem pos ID Text ======== ======= == ==== 00000000787C 00000200847C 0 user32 000000007884 000002008484 0 ExitWindowsEx 000000007894 000002008494 0 SeShutdownPrivilege 000000007A60 000002008660 0 SVWUQ 000000007B74 000002008774 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete 000000007BA0 0000020087A0 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ) 000000007ED8 000002008AD8 0 %.2X%.2X 000000007EE4 000002008AE4 0 Request Code: %.6d 000000007EF7 000002008AF7 0 Enter Responce 000000007F08 000002008B08 0 Autorization 000000007F18 000002008B18 0 1..4 - dispense cassete 000000007F30 000002008B30 0 9 - Uninstall 000000007F3E 000002008B3E 0 0 - Exit 000000007F48 000002008B48 0 Enter Command 000000008154 000002008D54 0 Diebold:OGuiFrame 000000008168 000002008D68 0 Enter Password 00000000817C 000002008D7C 0 STATIC 00000000818C 000002008D8C 0 Supply Manager 00000000819C 000002008D9C 0 Pripnt 0000000081A4 000002008DA4 0 View All Counts 0000000083BC 000002008FBC 0 DbdDevExecute(RESET) 0000000083D4 000002008FD4 0 DBDDEV_LOCK(CRW) 0000000083E8 000002008FE8 0 DbdDevExecute(MCRW_ACCEPT_INSERTION) 000000008410 000002009010 0 MCRW_ACCEPT_INSERTION 000000008455 000002009055 0 ;C*v= 000000008E45 000002009A45 0 L0(:L0Sv<V 000000008F94 000002009B94 0 DbdDevExecute(EPP4_LOAD_KEY) 000000008FB4 000002009BB4 0 EPP4_LOAD_KEY TimeOut 000000009088 000002009C88 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN) 0000000090BC 000002009CBC 0 EPP4_COMPUTE_VERIFICATION_PATTERN 0000000093C6 000002009FC6 0 :V(t 000000009848 00000200A448 0 LoadKey %.2d @ %.2d - %.2d 000000009868 00000200A468 0 LoadKey %.2d - %.2d 000000009880 00000200A480 0 CopyKey %.2d -> %.2d - %.2d 0000000098A0 00000200A4A0 0 SVWUQ 000000009934 00000200A534 0 ComID %.2d, %X, %X - %.2d, 000000009B1C 00000200A71C 0 No Transactions 000000009B2C 00000200A72C 0 No Cards (PINs) 000000009D94 00000200A994 0 Transactions %d 000000009DA5 00000200A9A5 0 Cards %d 000000009DB9 00000200A9B9 0 Non Local %d 000000009DCD 00000200A9CD 0 MAC_ID %d 000000009DE1 00000200A9E1 0 InstrumentID %d 000000009ED8 00000200AAD8 0 Grab mode %d 000000009EE8 00000200AAE8 0 Deco mode %d 000000009EF9 00000200AAF9 0 Key mode %d 000000009F0A 00000200AB0A 0 Use locals %d 000000009F1B 00000200AB1B 0 Auto delete %d 000000009F2C 00000200AB2C 0 ReturnOnCode %d 000000009F78 00000200AB78 0 %d.%d.%d.%d : %d 00000000A09C 00000200AC9C 0 SeDebugPrivilege 00000000A1E4 00000200ADE4 0 SeDebugPrivilege 00000000A2BC 00000200AEBC 0 Bound Import error 00000000A2D0 00000200AED0 0 Bound Import GetProcAddress 00000000A2EC 00000200AEEC 0 EPP4API.DLL 00000000A2F8 00000200AEF8 0 EppInit 00000000A300 00000200AF00 0 EppAttach 00000000A30C 00000200AF0C 0 EppLock 00000000A314 00000200AF14 0 CloseComPort 00000000A324 00000200AF24 0 EppExchange File pos Mem pos ID Text ======== ======= == ==== 00000000A428 00000200B028 0 19200 00000000A598 00000200B198 0 version 00000000A5A0 00000200B1A0 0 SOFTWARE\Diebold\Agilis 91x 00000000A5BC 00000200B1BC 0 Product Version 00000000A5CC 00000200B1CC 0 SOFTWARE\Diebold\Agilis 91x Core 00000000A64C 00000200B24C 0 %s%.2X 00000000A66E 00000200B26E 0 tPj 3 00000000A798 00000200B398 0 version 00000000A7A0 00000200B3A0 0 SOFTWARE\Diebold\AMI for Opteva 00000000A7C0 00000200B3C0 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva 00000000A7F4 00000200B3F4 0 SOFTWARE\Diebold\Agilis XFS for Opteva 00000000A81C 00000200B41C 0 Agilis: %s 00000000A82D 00000200B42D 0 AMI: %s 00000000A83B 00000200B43B 0 XFS: %s 00000000A849 00000200B449 0 Firmware: 00000000A978 00000200B578 0 DbdDevExecute(MCRW_CHIP_IO) 00000000A994 00000200B594 0 TimeOut MCRW_CHIP_IO 00000000AB60 00000200B760 0 Invalid Sim Response 00000000ACA4 00000200B8A4 0 DbdDevExecute(MCRW_ACCEPT_INSERTION) 00000000AD68 00000200B968 0 DbdDevExecute(MCRW_POWERON) 00000000AD84 00000200B984 0 DbdDevExecute(MCRW_POWEROFF) 00000000AE0C 00000200BA0C 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION) 00000000AEA8 00000200BAA8 0 DbdDevExecute(MCRW_MCRW_Eject) 00000000B100 00000200BD00 0 TimeOut Reset 00000000B110 00000200BD10 0 Incorrect FIle Size 00000000B4C0 00000200C0C0 0 TimeOut Reset 00000000B9A7 00000200C5A7 0 r AOu 00000000BBA0 00000200C7A0 0 kernel32.dll 00000000BBB0 00000200C7B0 0 CreateFileA 00000000BBBC 00000200C7BC 0 GetFileTime 00000000BBC8 00000200C7C8 0 SetFileTime 00000000BBD4 00000200C7D4 0 GetFileSize 00000000BBE0 00000200C7E0 0 ReadFile 00000000BBEC 00000200C7EC 0 WriteFile 00000000BBF8 00000200C7F8 0 SetFilePointer 00000000BC08 00000200C808 0 CloseHandle 00000000BC14 00000200C814 0 LocalAlloc 00000000BC20 00000200C820 0 LocalFree 00000000BC2C 00000200C82C 0 ExitThread 00000000BC38 00000200C838 0 VirtualFree 00000000BC44 00000200C844 0 Sleep 00000000BC4C 00000200C84C 0 DeleteFileA 00000000BD10 00000200C910 0 SeDebugPrivilege 00000000BE44 00000200CA44 0 Check sum error 00000000BE54 00000200CA54 0 Update 00000000BE5C 00000200CA5C 0 Not executable file 00000000BED1 00000200CAD1 0 |$0jd 00000000C14F 00000200CD4F 0 $ZXrM 00000000C156 00000200CD56 0 ZX|G3 00000000C4EC 00000200D0EC 0 c:\Program Files\Diebold\Abc\message.trc 00000000C518 00000200D118 0 c:\Diebold\css\message.trc 00000000C534 00000200D134 0 FileSize %d 00000000C545 00000200D145 0 Transactions %d 00000000C556 00000200D156 0 ComKeys %d 00000000C714 00000200D314 0 hook.LoadLibrary: 00000000C728 00000200D328 0 GetProcAddress 00000000C738 00000200D338 0 hook.VirtualProtect 00000000C8E4 00000200D4E4 0 mode6main 00000000C8F8 00000200D4F8 0 ws2_32.dll 00000000C904 00000200D504 0 WSASend File pos Mem pos ID Text ======== ======= == ==== 00000000CCE8 00000200D8E8 0 Enter command: 00000000D3B8 00000200DFB8 0 E PWS 00000000D476 00000200E076 0 8NTFS 00000000D6E4 00000200E2E4 0 DbdDevRegisterCallback 00000000D6FC 00000200E2FC 0 DbdDevAPI.dll 00000000D70C 00000200E30C 0 EppExchange 00000000D718 00000200E318 0 EPP4API.dll 00000000D724 00000200E324 0 DbdDevExecute 00000000D752 00000200E352 0 Pj@SV 00000000D7B4 00000200E3B4 0 VProtect1 00000000D7C4 00000200E3C4 0 SVWUQ 00000000D870 00000200E470 0 Begin 00000000D878 00000200E478 0 Error 00000000D884 00000200E484 0 t decode const 00000000D900 00000200E500 0 mu.exe 00000000D989 00000200E589 0 33333 00000000D9AB 00000200E5AB 0 UUUU3 00000000DAFD 00000200E6FD 0 VWUSQ 00000000DB45 00000200E745 0 33333 00000000DB67 00000200E767 0 UUUU3 00000000DC1B 00000200E81B 0 UUUU3 00000000DC79 00000200E879 0 VWUSQ 00000000DD30 00000200E930 0 UUUU3 00000000DFE0 00000200EBE0 0 dfd6jdk 00000000DFE8 00000200EBE8 0 kdu32rbs 00000000E04C 00000200F04C 0 Error 00000000E054 00000200F054 0 Runtime error at 00000000 00000000E074 00000200F074 0 0123456789ABCDEF 00000000E0B0 00000200F0B0 0 SeTtInGs6.34.3 00000000E1C2 00000200F1C2 0 <o:o:_;OPO 00000000E1D1 00000200F1D1 0 OLONO 00000000E1DD 00000200F1DD 0 O!O%O 00000000E394 00000200F394 0 <4,$?7/' 00000000E3DA 00000200F3DA 0 !"#$%&'()*+,-./012345678 00000000E425 00000200F425 0 (3-!0 00000000E42C 00000200F42C 0 ,1'8"5 00000000E954 000002013354 0 kernel32.dll 00000000E964 000002013364 0 DeleteCriticalSection 00000000E97C 00000201337C 0 LeaveCriticalSection 00000000E994 000002013394 0 EnterCriticalSection 00000000E9AC 0000020133AC 0 InitializeCriticalSection 00000000E9C8 0000020133C8 0 VirtualFree 00000000E9D6 0000020133D6 0 VirtualAlloc 00000000E9E6 0000020133E6 0 LocalFree 00000000E9F2 0000020133F2 0 LocalAlloc 00000000EA00 000002013400 0 GetVersion 00000000EA0E 00000201340E 0 GetCurrentThreadId 00000000EA24 000002013424 0 GetThreadLocale 00000000EA36 000002013436 0 GetStartupInfoA 00000000EA48 000002013448 0 GetLocaleInfoA 00000000EA5A 00000201345A 0 GetCommandLineA 00000000EA6C 00000201346C 0 FreeLibrary 00000000EA7A 00000201347A 0 ExitProcess 00000000EA88 000002013488 0 CreateThread 00000000EA98 000002013498 0 WriteFile 00000000EAA4 0000020134A4 0 UnhandledExceptionFilter 00000000EAC0 0000020134C0 0 RtlUnwind 00000000EACC 0000020134CC 0 RaiseException 00000000EADE 0000020134DE 0 GetStdHandle 00000000EAEC 0000020134EC 0 user32.dll File pos Mem pos ID Text ======== ======= == ==== 00000000EAFA 0000020134FA 0 GetKeyboardType 00000000EB0C 00000201350C 0 MessageBoxA 00000000EB18 000002013518 0 advapi32.dll 00000000EB28 000002013528 0 RegQueryValueExA 00000000EB3C 00000201353C 0 RegOpenKeyExA 00000000EB4C 00000201354C 0 RegCloseKey 00000000EB58 000002013558 0 kernel32.dll 00000000EB68 000002013568 0 TlsSetValue 00000000EB76 000002013576 0 TlsGetValue 00000000EB84 000002013584 0 TlsFree 00000000EB8E 00000201358E 0 TlsAlloc 00000000EB9A 00000201359A 0 LocalFree 00000000EBA6 0000020135A6 0 LocalAlloc 00000000EBB2 0000020135B2 0 advapi32.dll 00000000EBC2 0000020135C2 0 RegQueryValueExA 00000000EBD6 0000020135D6 0 RegOpenKeyExA 00000000EBE6 0000020135E6 0 RegCloseKey 00000000EBF4 0000020135F4 0 OpenProcessToken 00000000EC08 000002013608 0 LookupPrivilegeValueA 00000000EC20 000002013620 0 AdjustTokenPrivileges 00000000EC36 000002013636 0 kernel32.dll 00000000EC46 000002013646 0 lstrlenA 00000000EC52 000002013652 0 lstrcpynA 00000000EC5E 00000201365E 0 lstrcpyA 00000000EC6A 00000201366A 0 lstrcmpiW 00000000EC76 000002013676 0 lstrcmpiA 00000000EC82 000002013682 0 lstrcmpA 00000000EC8E 00000201368E 0 lstrcatA 00000000EC9A 00000201369A 0 WriteFile 00000000ECA6 0000020136A6 0 WaitForSingleObjectEx 00000000ECBE 0000020136BE 0 WaitForSingleObject 00000000ECD4 0000020136D4 0 VirtualProtect 00000000ECE6 0000020136E6 0 TerminateThread 00000000ECF8 0000020136F8 0 SleepEx 00000000ED02 000002013702 0 Sleep 00000000ED0A 00000201370A 0 SizeofResource 00000000ED1C 00000201371C 0 SetThreadPriority 00000000ED30 000002013730 0 SetFilePointer 00000000ED42 000002013742 0 SetEvent 00000000ED4E 00000201374E 0 ReadFile 00000000ED5A 00000201375A 0 OpenProcess 00000000ED68 000002013768 0 MultiByteToWideChar 00000000ED7E 00000201377E 0 LocalUnlock 00000000ED8C 00000201378C 0 LocalSize 00000000ED98 000002013798 0 LocalReAlloc 00000000EDA8 0000020137A8 0 LocalLock 00000000EDB4 0000020137B4 0 LocalFree 00000000EDC0 0000020137C0 0 LocalAlloc 00000000EDCE 0000020137CE 0 LoadResource 00000000EDDE 0000020137DE 0 LoadLibraryA 00000000EDEE 0000020137EE 0 GetVolumeInformationA 00000000EE06 000002013806 0 GetTickCount 00000000EE16 000002013816 0 GetThreadPriority 00000000EE2A 00000201382A 0 GetTempFileNameA 00000000EE3E 00000201383E 0 GetSystemTimeAsFileTime 00000000EE58 000002013858 0 GetProcAddress 00000000EE6A 00000201386A 0 GetModuleHandleA 00000000EE7E 00000201387E 0 GetModuleFileNameA 00000000EE94 000002013894 0 GetLastError 00000000EEA4 0000020138A4 0 GetFileSize File pos Mem pos ID Text ======== ======= == ==== 00000000EEB2 0000020138B2 0 GetExitCodeThread 00000000EEC6 0000020138C6 0 GetCurrentThreadId 00000000EEDC 0000020138DC 0 GetCurrentThread 00000000EEF0 0000020138F0 0 GetCurrentProcess 00000000EF04 000002013904 0 FormatMessageA 00000000EF16 000002013916 0 FindResourceA 00000000EF26 000002013926 0 FileTimeToSystemTime 00000000EF3E 00000201393E 0 FileTimeToLocalFileTime 00000000EF58 000002013958 0 ExitProcess 00000000EF66 000002013966 0 DeleteFileA 00000000EF74 000002013974 0 CreateThread 00000000EF84 000002013984 0 CreateMutexA 00000000EF94 000002013994 0 CreateFileA 00000000EFA2 0000020139A2 0 CreateEventA 00000000EFB2 0000020139B2 0 CopyFileA 00000000EFBE 0000020139BE 0 CloseHandle 00000000EFCA 0000020139CA 0 gdi32.dll 00000000EFD6 0000020139D6 0 TextOutA 00000000EFE2 0000020139E2 0 SelectObject 00000000EFF2 0000020139F2 0 Rectangle 00000000EFFE 0000020139FE 0 GetTextMetricsA 00000000F010 000002013A10 0 Escape 00000000F01A 000002013A1A 0 EndDoc 00000000F024 000002013A24 0 DeleteObject 00000000F034 000002013A34 0 DeleteDC 00000000F040 000002013A40 0 CreateSolidBrush 00000000F054 000002013A54 0 CreateDCA 00000000F05E 000002013A5E 0 user32.dll 00000000F06C 000002013A6C 0 CreateWindowExA 00000000F07E 000002013A7E 0 UnregisterClassA 00000000F092 000002013A92 0 TranslateMessage 00000000F0A6 000002013AA6 0 SetTimer 00000000F0B2 000002013AB2 0 SetForegroundWindow 00000000F0C8 000002013AC8 0 SetFocus 00000000F0D4 000002013AD4 0 SendMessageA 00000000F0E4 000002013AE4 0 RegisterClassA 00000000F0F6 000002013AF6 0 PostMessageA 00000000F106 000002013B06 0 PeekMessageA 00000000F116 000002013B16 0 MessageBoxA 00000000F124 000002013B24 0 LoadIconA 00000000F130 000002013B30 0 LoadCursorA 00000000F13E 000002013B3E 0 InvalidateRect 00000000F150 000002013B50 0 GetWindowTextA 00000000F162 000002013B62 0 GetWindowDC 00000000F170 000002013B70 0 GetMessageA 00000000F17E 000002013B7E 0 GetForegroundWindow 00000000F194 000002013B94 0 GetDesktopWindow 00000000F1A8 000002013BA8 0 GetClientRect 00000000F1B8 000002013BB8 0 FindWindowExA 00000000F1C8 000002013BC8 0 FindWindowA 00000000F1D6 000002013BD6 0 ExitWindowsEx 00000000F1E6 000002013BE6 0 DrawTextA 00000000F1F2 000002013BF2 0 DispatchMessageA 00000000F206 000002013C06 0 DestroyWindow 00000000F216 000002013C16 0 DefWindowProcA 00000000F228 000002013C28 0 CharUpperA 00000000F234 000002013C34 0 kernel32.dll 00000000F244 000002013C44 0 GetTickCount 00000000F252 000002013C52 0 imagehlp.dll 00000000F262 000002013C62 0 CheckSumMappedFile File pos Mem pos ID Text ======== ======= == ==== 00000000F276 000002013C76 0 winspool.drv 00000000F286 000002013C86 0 EnumPrintersA 00000000F294 000002013C94 0 user32.dll 00000000F2A2 000002013CA2 0 wsprintfA 00000000F40F 00000201400F 0 0"0*020:0B0J0R0Z0b0j0r0z0 00000000F43D 00000201403D 0 0&111 00000000F453 000002014053 0 5 6[6j6 00000000F467 000002014067 0 9"9,969@9V9\9j9 00000000F491 000002014091 0 :":G:Q:[:e:o: 00000000F4AF 0000020140AF 0 ;";n; 00000000F4BB 0000020140BB 0 <P<p< 00000000F4C5 0000020140C5 0 =Y>e> 00000000F4ED 0000020140ED 0 0#0(0 00000000F4F9 0000020140F9 0 0@1I1c1 00000000F50F 00000201410F 0 2p2x2~2 00000000F52B 00000201412B 0 3(3@3L3T3u3 00000000F545 000002014145 0 4J4~4 00000000F551 000002014151 0 4,545:5@5M5S5 00000000F587 000002014187 0 8$8=8N8c8p8 00000000F593 000002014193 0 8J9R9 00000000F59B 00000201419B 0 :9;I;_;}; 00000000F5AD 0000020141AD 0 <"<*<@<X<f< 00000000F5C3 0000020141C3 0 <#=P=Y= 00000000F5D3 0000020141D3 0 =?>g> 00000000F5E9 0000020141E9 0 0L0T0_0 00000000F5F7 0000020141F7 0 1h1x1~1 00000000F61B 00000201421B 0 20282d2o2 00000000F637 000002014237 0 3%3*3J3O3q3 00000000F64D 00000201424D 0 4%424H4 00000000F65D 00000201425D 0 8!858S8\8h8o8 00000000F66D 00000201426D 0 9'939:9D9N9e9v9 00000000F697 000002014297 0 :':8:B:J:R:Z:b:j:r: 00000000F6B3 0000020142B3 0 ; ;(;X; 00000000F6BB 0000020142BB 0 ;n;s; 00000000F6D3 0000020142D3 0 < <2<?<K<X<j<r<z< 00000000F703 000002014303 0 ="=*=2=:=B=J=R=Z=b=j=r=z= 00000000F743 000002014343 0 >">*>2>:>B>J>R>Z>b>j>r>z> 00000000F783 000002014383 0 ?"?*?2?:?B?J?R?Z?b?j?r?z? 00000000F7C5 0000020143C5 0 5"50565B5K5S5f5l5 00000000F7E9 0000020143E9 0 6@6N6Y6f6k6r6w6~6 00000000F813 000002014413 0 757:7F7K7W7]7b7g7n7|7 00000000F841 000002014441 0 7.8>8L8R8a8s8y8 00000000F855 000002014455 0 8t9z9 00000000F861 000002014461 0 9):a:f: 00000000F885 000002014485 0 ;M<v< 00000000F8AD 0000020144AD 0 001E1d1 00000000F8C1 0000020144C1 0 2&3E3V3[3 00000000F8D1 0000020144D1 0 3>5Q5g5 00000000F8DD 0000020144DD 0 5#606B6J6T6e6w6 00000000F8F9 0000020144F9 0 7!7&7 00000000F905 000002014505 0 8.8K8b8s8 00000000F939 000002014539 0 :6;B;L;R; 00000000F943 000002014543 0 ;c;n;s;x; 00000000F977 000002014577 0 =B>z> 00000000F983 000002014583 0 ?*?I?V?g?}? 00000000F9C3 0000020145C3 0 2N3]3j3r3{3 00000000F9F9 0000020145F9 0 606H6_6o6 00000000FA15 000002014615 0 7D7T7x7~7 00000000FA39 000002014639 0 8!808 00000000FA41 000002014641 0 <6=g= File pos Mem pos ID Text ======== ======= == ==== 00000000FA6B 00000201466B 0 4X4)5 00000000FA7D 00000201467D 0 :*:8:a: 00000000FA85 000002014685 0 :;;W;k; 00000000FA99 000002014699 0 ;<<J<Z< 00000000FAAB 0000020146AB 0 = >?>H>e> 00000000FABD 0000020146BD 0 ?!?0?;?f?{? 00000000FADD 0000020146DD 0 0%0/050C0r0}0 00000000FAED 0000020146ED 0 2&2/272B2J2V2e2r2}2 00000000FB13 000002014713 0 3(383H3T3g3z3 00000000FB21 000002014721 0 3F5Q5g5 00000000FB35 000002014735 0 6.6A6F6r6 00000000FB4F 00000201474F 0 7"7L7 00000000FB57 000002014757 0 8 84898\8 00000000FB69 000002014769 0 9(9M9 00000000FB75 000002014775 0 :):g:l: 00000000FB83 000002014783 0 <$<\< 00000000FB9F 00000201479F 0 ?9?G?a?h?u? 00000000FBCD 0000020147CD 0 : ;+;@;U;a;j;z; 00000000FBDD 0000020147DD 0 <!<6<K<W< 00000000FBEB 0000020147EB 0 <3=A=H=d=l= 00000000FBFB 0000020147FB 0 =M>d>v> 00000000FC1F 00000201481F 0 1)1/1T1 00000000FC2F 00000201482F 0 122;2B2M2T2Y2 00000000FC3D 00000201483D 0 2e2l2q2x2 00000000FC4D 00000201484D 0 3"3<3 00000000FC81 000002014881 0 9?9R9 00000000FCA3 0000020148A3 0 =4=u= 00000000FCAD 0000020148AD 0 =?>c> 00000000FCB3 0000020148B3 0 >@?E?J?o? 00000000FCDB 0000020148DB 0 0n1s1 00000000FCF3 0000020148F3 0 3+3U3 00000000FCFF 0000020148FF 0 5&555B5K5S5 00000000FD13 000002014913 0 788C8Z8j8x8 00000000FD25 000002014925 0 989H9Q9 00000000FD37 000002014937 0 9::a:j:|: 00000000FD4B 00000201494B 0 ;/;G; 00000000FD5B 00000201495B 0 <1<C<O<[<o<z< 00000000FD79 000002014979 0 >%?*?O?_?y? 00000000FD9B 00000201499B 0 0$080C0K0]0 00000000FDB5 0000020149B5 0 1)111 00000000FDE5 0000020149E5 0 7&747B7r7w7}7r8 00000000FDFB 0000020149FB 0 8Z9d9i9o9 00000000FE27 000002014A27 0 <@<H<P<[< 00000000FE39 000002014A39 0 =[>c>v>~>G?O? 00000000FE47 000002014A47 0 ?f?p? 00000000FE61 000002014A61 0 0$0+000:0?0X0b0h0v0 00000000FE91 000002014A91 0 2$2<2J2 00000000FEAB 000002014AAB 0 4&4.494Y4g4v4 00000000FED1 000002014AD1 0 5/565?5D5l5s5 00000000FF05 000002014B05 0 6#6'6+6/63676;6?6C6 00000000FF1B 000002014B1B 0 7%787K7 00000000FF31 000002014B31 0 7)8R8W8h8y8 00000000FF45 000002014B45 0 939H9W9 00000000FF4D 000002014B4D 0 9i9q9~9 00000000FF67 000002014B67 0 :#:1:::U:h:z: 00000000FF87 000002014B87 0 ;6;?;S;\;c;o; 00000000FF9F 000002014B9F 0 <2<@<I<O<V<]<|< 00000000FFBD 000002014BBD 0 =-=8=Z=q= 00000000FFF8 000002014BF8 0 D0d0~0 000000010021 000002014C21 0 1)181G1q1 File pos Mem pos ID Text ======== ======= == ==== 000000010039 000002014C39 0 2)282G2[2l2q2 00000001005F 000002014C5F 0 263c3h3 00000001006B 000002014C6B 0 4)4/464@4E4Y4 000000010089 000002014C89 0 6 6/696B6M6V6_6k6y6 0000000100F7 000002014CF7 0 :$:.:3:8:O:T:Y:p:u:z: 00000001011F 000002014D1F 0 ;%;.;6;D;R;[;l;z; 000000010144 000002014D44 0 $0(0,0 00000001016D 000002014D6D 0 1 1$1(1,1014181<1@1D1H1L1T1X1 00000001018B 000002014D8B 0 1d1h1l1p1t1x1|1 0000000101A3 000002014DA3 0 1P2T2X2\2 0000000105C9 0000020153C9 0 Q 0000000105DA 0000020153DA 0 0000000105EB 0000020153EB 0 00000001061A 00000201541A 0 000000010634 000002015434 0 0000000106A9 0000020154A9 0 000000010731 000002015531 0 000000010786 000002015586 0 0000000107D6 0000020155D6 0 PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX 000000000050 000002000050 0 This program must be run under Win32 000000000270 000002000270 0 .idata 000000000298 000002000298 0 .reloc 0000000002BF 0000020002BF 0 P.rsrc 000000000884 000002001484 0 wE;\$ 000000001E9F 000002002A9F 0 ~KxI[) 000000001FC8 000002002BC8 0 SOFTWARE\Borland\Delphi\RTL 000000001FE4 000002002BE4 0 FPUMaskValue 000000002031 000002002C31 0 PPRTj 0000000021AB 000002002DAB 0 YZXtp 000000002322 000002002F22 0 t=HtN 000000002744 000002003344 0 SVWUQ 000000002B00 000002003700 0 USVW1 0000000034E3 0000020040E3 0 {V,| 00000000353F 00000200413F 0 <8LaK# 000000003660 000002004260 0 /R{m6 000000003774 000002004374 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt 0000000037A8 0000020043A8 0 C:\windows\EpsStmApi.log\ 000000003BFC 0000020047FC 0 WinSta0 000000003C04 000002004804 0 default 000000003C0C 00000200480C 0 DISPLAY 000000003E55 000002004A55 0 D$XPSj 000000003EEE 000002004AEE 0 D$xPj 000000003F3B 000002004B3B 0 |$,{u 000000003FF8 000002004BF8 0 WinSta0 000000004000 000002004C00 0 MyDesktop 000000004018 000002004C18 0 ATMDialog 000000004024 000002004C24 0 hello 00000000402C 000002004C2C 0 STATIC 000000004044 000002004C44 0 default 00000000405C 000002004C5C 0 Error 000000004110 000002004D10 0 Error 000000004140 000002004D40 0 $PShpM 0000000041A3 000002004DA3 0 $PVSh 0000000041D4 000002004DD4 0 %s %s 000000004480 000002005080 0 %s Error code= %d 0000000044BC 0000020050BC 0 %s Error code= %.2X 0000000044F5 0000020050F5 0 t"Jt" 000000004504 000002005104 0 Jt Jt 000000004618 000002005218 0 OpenProcessToken 00000000462C 00000200522C 0 LookupPrivilegeValue File pos Mem pos ID Text ======== ======= == ==== 000000004644 000002005244 0 AdjustTokenPrivileges 0000000047F8 0000020053F8 0 getProcessEntry: 00000000480C 00000200540C 0 SeDebugPrivilege 000000004820 000002005420 0 OpenProcess 00000000482C 00000200542C 0 LoadLibraryA 00000000483C 00000200543C 0 kernel32.dll 00000000484C 00000200544C 0 GetExitCodeThread 000000004860 000002005460 0 VirtualFreeEx 000000004B38 000002005738 0 DbdDevExecute(EPP4_ENCODE_DECODE) 000000004B5C 00000200575C 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ) 000000004B88 000002005788 0 EPP Complete LOCK 000000004B9C 00000200579C 0 EPP Complete ENCODE_DECODE 000000004C58 000002005858 0 SVWUQ 000000004CA2 0000020058A2 0 $ZXu> 000000004D16 000002005916 0 ~7hhY 000000004D5C 00000200595C 0 OASYS.dll 000000004D68 000002005968 0 OasPostMessage 000000004E38 000002005A38 0 DBDDevOpen 000000004E44 000002005A44 0 DbdDevRegisterCallback 000000004E5C 000002005A5C 0 DbdDevLock 000000004E68 000002005A68 0 DbdDevUnregisterCallback 000000004E84 000002005A84 0 DBDDevClose 000000004F00 000002005B00 0 DbdDevUnlock 000000004F10 000002005B10 0 bdDevUnregisterCallback 000000004F28 000002005B28 0 DBDDevClose 000000005010 000002005C10 0 DbdDevAPI.dll 000000005020 000002005C20 0 DbdDevOpen 00000000502C 000002005C2C 0 DbdDevClose 000000005038 000002005C38 0 DbdDevGetInfo 000000005048 000002005C48 0 DbdDevRegisterCallback 000000005060 000002005C60 0 DbdDevUnregisterCallback 00000000507C 000002005C7C 0 DbdDevLock 000000005088 000002005C88 0 DbdDevUnlock 000000005098 000002005C98 0 DbdDevExecute 0000000051C8 000002005DC8 0 AMI function don 0000000051D9 000002005DD9 0 t return in 1 sec 0000000053F4 000002005FF4 0 RECEIPT 0000000053FC 000002005FFC 0 WINSPOOL 000000005408 000002006008 0 CreateDC 000000005414 000002006014 0 hello 00000000541C 00000200601C 0 escape 000000005424 000002006024 0 TextOut 00000000542C 00000200602C 0 enddoc 0000000054E4 0000020060E4 0 DbdDevExecute(EPP4_COPY_KEY) 000000005504 000002006104 0 EPP4_COPY_KEY TimeOut 000000005620 000002006220 0 DbdDevExecute(EPP4_LOAD_KEY) 000000005640 000002006240 0 EPP4_LOAD_KEY TimeOut 0000000056F0 0000020062F0 0 DbdDevExecute(EPP4_DELETE_KEY) 000000005710 000002006310 0 EPP4_DELETE_KEY TimeOut 00000000583C 00000200643C 0 DbdDevExecute(EPP4_ENCODE_DECODE) 000000005860 000002006460 0 EPP_Encrypt TimeOut 000000005964 000002006564 0 SVWUQ 000000005C3C 00000200683C 0 LocalAlloc 000000005C48 000002006848 0 LocalLock 00000000643A 00000200703A 0 P CNu 0000000066C4 0000020072C4 0 SVWUQ 000000006A8B 00000200768B 0 u7IBF 000000006B1A 00000200771A 0 I+NBu 000000006EA8 000002007AA8 0 %.2d/%.2d/%.2d %.2d:%.2d 000000007024 000002007C24 0 tdHuaj File pos Mem pos ID Text ======== ======= == ==== 00000000709C 000002007C9C 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI) 0000000070CC 000002007CCC 0 t LOCK EPP 0000000070D8 000002007CD8 0 RECEIPT_PRINTER_START_GDI 0000000070F4 000002007CF4 0 DbdDevExecute(RECEIPT_PRINTER_EJECT) 000000007278 000002007E78 0 DbdDevExecute(AFD_DISPENCE) 000000007294 000002007E94 0 CDM Complete LOCK 0000000072A8 000002007EA8 0 DbdDevExecute(AFD_PRESENT) 0000000072C4 000002007EC4 0 DbdDevExecute(AFD_RESTORE) 0000000074A0 0000020080A0 0 SeShutdownPrivilege 0000000077FC 0000020083FC 0 kernel32 000000007808 000002008408 0 DeleteFileA 000000007814 000002008414 0 FreeLibrary 000000007820 000002008420 0 GetModuleHandleA 000000007834 000002008434 0 CreateFileA 000000007840 000002008440 0 Sleep 000000007848 000002008448 0 WriteFile 000000007854 000002008454 0 CloseHandle 000000007860 000002008460 0 LocalFree 00000000786C 00000200846C 0 LoadLibraryA 00000000787C 00000200847C 0 user32 000000007884 000002008484 0 ExitWindowsEx 000000007894 000002008494 0 SeShutdownPrivilege 000000007A60 000002008660 0 SVWUQ 000000007B74 000002008774 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete 000000007BA0 0000020087A0 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ) 000000007ED8 000002008AD8 0 %.2X%.2X 000000007EE4 000002008AE4 0 Request Code: %.6d 000000007EF7 000002008AF7 0 Enter Responce 000000007F08 000002008B08 0 Autorization 000000007F18 000002008B18 0 1..4 - dispense cassete 000000007F30 000002008B30 0 9 - Uninstall 000000007F3E 000002008B3E 0 0 - Exit 000000007F48 000002008B48 0 Enter Command 000000008154 000002008D54 0 Diebold:OGuiFrame 000000008168 000002008D68 0 Enter Password 00000000817C 000002008D7C 0 STATIC 00000000818C 000002008D8C 0 Supply Manager 00000000819C 000002008D9C 0 Pripnt 0000000081A4 000002008DA4 0 View All Counts 0000000083BC 000002008FBC 0 DbdDevExecute(RESET) 0000000083D4 000002008FD4 0 DBDDEV_LOCK(CRW) 0000000083E8 000002008FE8 0 DbdDevExecute(MCRW_ACCEPT_INSERTION) 000000008410 000002009010 0 MCRW_ACCEPT_INSERTION 000000008455 000002009055 0 ;C*v= 000000008E45 000002009A45 0 L0(:L0Sv<V 000000008F94 000002009B94 0 DbdDevExecute(EPP4_LOAD_KEY) 000000008FB4 000002009BB4 0 EPP4_LOAD_KEY TimeOut 000000009088 000002009C88 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN) 0000000090BC 000002009CBC 0 EPP4_COMPUTE_VERIFICATION_PATTERN 0000000093C6 000002009FC6 0 :V(t 000000009848 00000200A448 0 LoadKey %.2d @ %.2d - %.2d 000000009868 00000200A468 0 LoadKey %.2d - %.2d 000000009880 00000200A480 0 CopyKey %.2d -> %.2d - %.2d 0000000098A0 00000200A4A0 0 SVWUQ 000000009934 00000200A534 0 ComID %.2d, %X, %X - %.2d, 000000009B1C 00000200A71C 0 No Transactions 000000009B2C 00000200A72C 0 No Cards (PINs) 000000009D94 00000200A994 0 Transactions %d 000000009DA5 00000200A9A5 0 Cards %d 000000009DB9 00000200A9B9 0 Non Local %d File pos Mem pos ID Text ======== ======= == ==== 000000009DCD 00000200A9CD 0 MAC_ID %d 000000009DE1 00000200A9E1 0 InstrumentID %d 000000009ED8 00000200AAD8 0 Grab mode %d 000000009EE8 00000200AAE8 0 Deco mode %d 000000009EF9 00000200AAF9 0 Key mode %d 000000009F0A 00000200AB0A 0 Use locals %d 000000009F1B 00000200AB1B 0 Auto delete %d 000000009F2C 00000200AB2C 0 ReturnOnCode %d 000000009F78 00000200AB78 0 %d.%d.%d.%d : %d 00000000A09C 00000200AC9C 0 SeDebugPrivilege 00000000A1E4 00000200ADE4 0 SeDebugPrivilege 00000000A2BC 00000200AEBC 0 Bound Import error 00000000A2D0 00000200AED0 0 Bound Import GetProcAddress 00000000A2EC 00000200AEEC 0 EPP4API.DLL 00000000A2F8 00000200AEF8 0 EppInit 00000000A300 00000200AF00 0 EppAttach 00000000A30C 00000200AF0C 0 EppLock 00000000A314 00000200AF14 0 CloseComPort 00000000A324 00000200AF24 0 EppExchange 00000000A428 00000200B028 0 19200 00000000A598 00000200B198 0 version 00000000A5A0 00000200B1A0 0 SOFTWARE\Diebold\Agilis 91x 00000000A5BC 00000200B1BC 0 Product Version 00000000A5CC 00000200B1CC 0 SOFTWARE\Diebold\Agilis 91x Core 00000000A64C 00000200B24C 0 %s%.2X 00000000A66E 00000200B26E 0 tPj 3 00000000A798 00000200B398 0 version 00000000A7A0 00000200B3A0 0 SOFTWARE\Diebold\AMI for Opteva 00000000A7C0 00000200B3C0 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva 00000000A7F4 00000200B3F4 0 SOFTWARE\Diebold\Agilis XFS for Opteva 00000000A81C 00000200B41C 0 Agilis: %s 00000000A82D 00000200B42D 0 AMI: %s 00000000A83B 00000200B43B 0 XFS: %s 00000000A849 00000200B449 0 Firmware: 00000000A978 00000200B578 0 DbdDevExecute(MCRW_CHIP_IO) 00000000A994 00000200B594 0 TimeOut MCRW_CHIP_IO 00000000AB60 00000200B760 0 Invalid Sim Response 00000000ACA4 00000200B8A4 0 DbdDevExecute(MCRW_ACCEPT_INSERTION) 00000000AD68 00000200B968 0 DbdDevExecute(MCRW_POWERON) 00000000AD84 00000200B984 0 DbdDevExecute(MCRW_POWEROFF) 00000000AE0C 00000200BA0C 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION) 00000000AEA8 00000200BAA8 0 DbdDevExecute(MCRW_MCRW_Eject) 00000000B100 00000200BD00 0 TimeOut Reset 00000000B110 00000200BD10 0 Incorrect FIle Size 00000000B4C0 00000200C0C0 0 TimeOut Reset 00000000B9A7 00000200C5A7 0 r AOu 00000000BBA0 00000200C7A0 0 kernel32.dll 00000000BBB0 00000200C7B0 0 CreateFileA 00000000BBBC 00000200C7BC 0 GetFileTime 00000000BBC8 00000200C7C8 0 SetFileTime 00000000BBD4 00000200C7D4 0 GetFileSize 00000000BBE0 00000200C7E0 0 ReadFile 00000000BBEC 00000200C7EC 0 WriteFile 00000000BBF8 00000200C7F8 0 SetFilePointer 00000000BC08 00000200C808 0 CloseHandle 00000000BC14 00000200C814 0 LocalAlloc 00000000BC20 00000200C820 0 LocalFree 00000000BC2C 00000200C82C 0 ExitThread 00000000BC38 00000200C838 0 VirtualFree 00000000BC44 00000200C844 0 Sleep File pos Mem pos ID Text ======== ======= == ==== 00000000BC4C 00000200C84C 0 DeleteFileA 00000000BD10 00000200C910 0 SeDebugPrivilege 00000000BE44 00000200CA44 0 Check sum error 00000000BE54 00000200CA54 0 Update 00000000BE5C 00000200CA5C 0 Not executable file 00000000BED1 00000200CAD1 0 |$0jd 00000000C14F 00000200CD4F 0 $ZXrM 00000000C156 00000200CD56 0 ZX|G3 00000000C4EC 00000200D0EC 0 c:\Program Files\Diebold\Abc\message.trc 00000000C518 00000200D118 0 c:\Diebold\css\message.trc 00000000C534 00000200D134 0 FileSize %d 00000000C545 00000200D145 0 Transactions %d 00000000C556 00000200D156 0 ComKeys %d 00000000C714 00000200D314 0 hook.LoadLibrary: 00000000C728 00000200D328 0 GetProcAddress 00000000C738 00000200D338 0 hook.VirtualProtect 00000000C8E4 00000200D4E4 0 mode6main 00000000C8F8 00000200D4F8 0 ws2_32.dll 00000000C904 00000200D504 0 WSASend 00000000CCE8 00000200D8E8 0 Enter command: 00000000D3B8 00000200DFB8 0 E PWS 00000000D476 00000200E076 0 8NTFS 00000000D6E4 00000200E2E4 0 DbdDevRegisterCallback 00000000D6FC 00000200E2FC 0 DbdDevAPI.dll 00000000D70C 00000200E30C 0 EppExchange 00000000D718 00000200E318 0 EPP4API.dll 00000000D724 00000200E324 0 DbdDevExecute 00000000D752 00000200E352 0 Pj@SV 00000000D7B4 00000200E3B4 0 VProtect1 00000000D7C4 00000200E3C4 0 SVWUQ 00000000D870 00000200E470 0 Begin 00000000D878 00000200E478 0 Error 00000000D884 00000200E484 0 t decode const 00000000D900 00000200E500 0 mu.exe 00000000D989 00000200E589 0 33333 00000000D9AB 00000200E5AB 0 UUUU3 00000000DAFD 00000200E6FD 0 VWUSQ 00000000DB45 00000200E745 0 33333 00000000DB67 00000200E767 0 UUUU3 00000000DC1B 00000200E81B 0 UUUU3 00000000DC79 00000200E879 0 VWUSQ 00000000DD30 00000200E930 0 UUUU3 00000000DFE0 00000200EBE0 0 dfd6jdk 00000000DFE8 00000200EBE8 0 kdu32rbs 00000000E04C 00000200F04C 0 Error 00000000E054 00000200F054 0 Runtime error at 00000000 00000000E074 00000200F074 0 0123456789ABCDEF 00000000E0B0 00000200F0B0 0 SeTtInGs6.34.3 00000000E1C2 00000200F1C2 0 <o:o:_;OPO 00000000E1D1 00000200F1D1 0 OLONO 00000000E1DD 00000200F1DD 0 O!O%O 00000000E394 00000200F394 0 <4,$?7/' 00000000E3DA 00000200F3DA 0 !"#$%&'()*+,-./012345678 00000000E425 00000200F425 0 (3-!0 00000000E42C 00000200F42C 0 ,1'8"5 00000000E954 000002013354 0 kernel32.dll 00000000E964 000002013364 0 DeleteCriticalSection 00000000E97C 00000201337C 0 LeaveCriticalSection 00000000E994 000002013394 0 EnterCriticalSection 00000000E9AC 0000020133AC 0 InitializeCriticalSection File pos Mem pos ID Text ======== ======= == ==== 00000000E9C8 0000020133C8 0 VirtualFree 00000000E9D6 0000020133D6 0 VirtualAlloc 00000000E9E6 0000020133E6 0 LocalFree 00000000E9F2 0000020133F2 0 LocalAlloc 00000000EA00 000002013400 0 GetVersion 00000000EA0E 00000201340E 0 GetCurrentThreadId 00000000EA24 000002013424 0 GetThreadLocale 00000000EA36 000002013436 0 GetStartupInfoA 00000000EA48 000002013448 0 GetLocaleInfoA 00000000EA5A 00000201345A 0 GetCommandLineA 00000000EA6C 00000201346C 0 FreeLibrary 00000000EA7A 00000201347A 0 ExitProcess 00000000EA88 000002013488 0 CreateThread 00000000EA98 000002013498 0 WriteFile 00000000EAA4 0000020134A4 0 UnhandledExceptionFilter 00000000EAC0 0000020134C0 0 RtlUnwind 00000000EACC 0000020134CC 0 RaiseException 00000000EADE 0000020134DE 0 GetStdHandle 00000000EAEC 0000020134EC 0 user32.dll 00000000EAFA 0000020134FA 0 GetKeyboardType 00000000EB0C 00000201350C 0 MessageBoxA 00000000EB18 000002013518 0 advapi32.dll 00000000EB28 000002013528 0 RegQueryValueExA 00000000EB3C 00000201353C 0 RegOpenKeyExA 00000000EB4C 00000201354C 0 RegCloseKey 00000000EB58 000002013558 0 kernel32.dll 00000000EB68 000002013568 0 TlsSetValue 00000000EB76 000002013576 0 TlsGetValue 00000000EB84 000002013584 0 TlsFree 00000000EB8E 00000201358E 0 TlsAlloc 00000000EB9A 00000201359A 0 LocalFree 00000000EBA6 0000020135A6 0 LocalAlloc 00000000EBB2 0000020135B2 0 advapi32.dll 00000000EBC2 0000020135C2 0 RegQueryValueExA 00000000EBD6 0000020135D6 0 RegOpenKeyExA 00000000EBE6 0000020135E6 0 RegCloseKey 00000000EBF4 0000020135F4 0 OpenProcessToken 00000000EC08 000002013608 0 LookupPrivilegeValueA 00000000EC20 000002013620 0 AdjustTokenPrivileges 00000000EC36 000002013636 0 kernel32.dll 00000000EC46 000002013646 0 lstrlenA 00000000EC52 000002013652 0 lstrcpynA 00000000EC5E 00000201365E 0 lstrcpyA 00000000EC6A 00000201366A 0 lstrcmpiW 00000000EC76 000002013676 0 lstrcmpiA 00000000EC82 000002013682 0 lstrcmpA 00000000EC8E 00000201368E 0 lstrcatA 00000000EC9A 00000201369A 0 WriteFile 00000000ECA6 0000020136A6 0 WaitForSingleObjectEx 00000000ECBE 0000020136BE 0 WaitForSingleObject 00000000ECD4 0000020136D4 0 VirtualProtect 00000000ECE6 0000020136E6 0 TerminateThread 00000000ECF8 0000020136F8 0 SleepEx 00000000ED02 000002013702 0 Sleep 00000000ED0A 00000201370A 0 SizeofResource 00000000ED1C 00000201371C 0 SetThreadPriority 00000000ED30 000002013730 0 SetFilePointer 00000000ED42 000002013742 0 SetEvent 00000000ED4E 00000201374E 0 ReadFile 00000000ED5A 00000201375A 0 OpenProcess File pos Mem pos ID Text ======== ======= == ==== 00000000ED68 000002013768 0 MultiByteToWideChar 00000000ED7E 00000201377E 0 LocalUnlock 00000000ED8C 00000201378C 0 LocalSize 00000000ED98 000002013798 0 LocalReAlloc 00000000EDA8 0000020137A8 0 LocalLock 00000000EDB4 0000020137B4 0 LocalFree 00000000EDC0 0000020137C0 0 LocalAlloc 00000000EDCE 0000020137CE 0 LoadResource 00000000EDDE 0000020137DE 0 LoadLibraryA 00000000EDEE 0000020137EE 0 GetVolumeInformationA 00000000EE06 000002013806 0 GetTickCount 00000000EE16 000002013816 0 GetThreadPriority 00000000EE2A 00000201382A 0 GetTempFileNameA 00000000EE3E 00000201383E 0 GetSystemTimeAsFileTime 00000000EE58 000002013858 0 GetProcAddress 00000000EE6A 00000201386A 0 GetModuleHandleA 00000000EE7E 00000201387E 0 GetModuleFileNameA 00000000EE94 000002013894 0 GetLastError 00000000EEA4 0000020138A4 0 GetFileSize 00000000EEB2 0000020138B2 0 GetExitCodeThread 00000000EEC6 0000020138C6 0 GetCurrentThreadId 00000000EEDC 0000020138DC 0 GetCurrentThread 00000000EEF0 0000020138F0 0 GetCurrentProcess 00000000EF04 000002013904 0 FormatMessageA 00000000EF16 000002013916 0 FindResourceA 00000000EF26 000002013926 0 FileTimeToSystemTime 00000000EF3E 00000201393E 0 FileTimeToLocalFileTime 00000000EF58 000002013958 0 ExitProcess 00000000EF66 000002013966 0 DeleteFileA 00000000EF74 000002013974 0 CreateThread 00000000EF84 000002013984 0 CreateMutexA 00000000EF94 000002013994 0 CreateFileA 00000000EFA2 0000020139A2 0 CreateEventA 00000000EFB2 0000020139B2 0 CopyFileA 00000000EFBE 0000020139BE 0 CloseHandle 00000000EFCA 0000020139CA 0 gdi32.dll 00000000EFD6 0000020139D6 0 TextOutA 00000000EFE2 0000020139E2 0 SelectObject 00000000EFF2 0000020139F2 0 Rectangle 00000000EFFE 0000020139FE 0 GetTextMetricsA 00000000F010 000002013A10 0 Escape 00000000F01A 000002013A1A 0 EndDoc 00000000F024 000002013A24 0 DeleteObject 00000000F034 000002013A34 0 DeleteDC 00000000F040 000002013A40 0 CreateSolidBrush 00000000F054 000002013A54 0 CreateDCA 00000000F05E 000002013A5E 0 user32.dll 00000000F06C 000002013A6C 0 CreateWindowExA 00000000F07E 000002013A7E 0 UnregisterClassA 00000000F092 000002013A92 0 TranslateMessage 00000000F0A6 000002013AA6 0 SetTimer 00000000F0B2 000002013AB2 0 SetForegroundWindow 00000000F0C8 000002013AC8 0 SetFocus 00000000F0D4 000002013AD4 0 SendMessageA 00000000F0E4 000002013AE4 0 RegisterClassA 00000000F0F6 000002013AF6 0 PostMessageA 00000000F106 000002013B06 0 PeekMessageA 00000000F116 000002013B16 0 MessageBoxA 00000000F124 000002013B24 0 LoadIconA 00000000F130 000002013B30 0 LoadCursorA File pos Mem pos ID Text ======== ======= == ==== 00000000F13E 000002013B3E 0 InvalidateRect 00000000F150 000002013B50 0 GetWindowTextA 00000000F162 000002013B62 0 GetWindowDC 00000000F170 000002013B70 0 GetMessageA 00000000F17E 000002013B7E 0 GetForegroundWindow 00000000F194 000002013B94 0 GetDesktopWindow 00000000F1A8 000002013BA8 0 GetClientRect 00000000F1B8 000002013BB8 0 FindWindowExA 00000000F1C8 000002013BC8 0 FindWindowA 00000000F1D6 000002013BD6 0 ExitWindowsEx 00000000F1E6 000002013BE6 0 DrawTextA 00000000F1F2 000002013BF2 0 DispatchMessageA 00000000F206 000002013C06 0 DestroyWindow 00000000F216 000002013C16 0 DefWindowProcA 00000000F228 000002013C28 0 CharUpperA 00000000F234 000002013C34 0 kernel32.dll 00000000F244 000002013C44 0 GetTickCount 00000000F252 000002013C52 0 imagehlp.dll 00000000F262 000002013C62 0 CheckSumMappedFile 00000000F276 000002013C76 0 winspool.drv 00000000F286 000002013C86 0 EnumPrintersA 00000000F294 000002013C94 0 user32.dll 00000000F2A2 000002013CA2 0 wsprintfA 00000000F40F 00000201400F 0 0"0*020:0B0J0R0Z0b0j0r0z0 00000000F43D 00000201403D 0 0&111 00000000F453 000002014053 0 5 6[6j6 00000000F467 000002014067 0 9"9,969@9V9\9j9 00000000F491 000002014091 0 :":G:Q:[:e:o: 00000000F4AF 0000020140AF 0 ;";n; 00000000F4BB 0000020140BB 0 <P<p< 00000000F4C5 0000020140C5 0 =Y>e> 00000000F4ED 0000020140ED 0 0#0(0 00000000F4F9 0000020140F9 0 0@1I1c1 00000000F50F 00000201410F 0 2p2x2~2 00000000F52B 00000201412B 0 3(3@3L3T3u3 00000000F545 000002014145 0 4J4~4 00000000F551 000002014151 0 4,545:5@5M5S5 00000000F587 000002014187 0 8$8=8N8c8p8 00000000F593 000002014193 0 8J9R9 00000000F59B 00000201419B 0 :9;I;_;}; 00000000F5AD 0000020141AD 0 <"<*<@<X<f< 00000000F5C3 0000020141C3 0 <#=P=Y= 00000000F5D3 0000020141D3 0 =?>g> 00000000F5E9 0000020141E9 0 0L0T0_0 00000000F5F7 0000020141F7 0 1h1x1~1 00000000F61B 00000201421B 0 20282d2o2 00000000F637 000002014237 0 3%3*3J3O3q3 00000000F64D 00000201424D 0 4%424H4 00000000F65D 00000201425D 0 8!858S8\8h8o8 00000000F66D 00000201426D 0 9'939:9D9N9e9v9 00000000F697 000002014297 0 :':8:B:J:R:Z:b:j:r: 00000000F6B3 0000020142B3 0 ; ;(;X; 00000000F6BB 0000020142BB 0 ;n;s; 00000000F6D3 0000020142D3 0 < <2<?<K<X<j<r<z< 00000000F703 000002014303 0 ="=*=2=:=B=J=R=Z=b=j=r=z= 00000000F743 000002014343 0 >">*>2>:>B>J>R>Z>b>j>r>z> 00000000F783 000002014383 0 ?"?*?2?:?B?J?R?Z?b?j?r?z? 00000000F7C5 0000020143C5 0 5"50565B5K5S5f5l5 00000000F7E9 0000020143E9 0 6@6N6Y6f6k6r6w6~6 00000000F813 000002014413 0 757:7F7K7W7]7b7g7n7|7 File pos Mem pos ID Text ======== ======= == ==== 00000000F841 000002014441 0 7.8>8L8R8a8s8y8 00000000F855 000002014455 0 8t9z9 00000000F861 000002014461 0 9):a:f: 00000000F885 000002014485 0 ;M<v< 00000000F8AD 0000020144AD 0 001E1d1 00000000F8C1 0000020144C1 0 2&3E3V3[3 00000000F8D1 0000020144D1 0 3>5Q5g5 00000000F8DD 0000020144DD 0 5#606B6J6T6e6w6 00000000F8F9 0000020144F9 0 7!7&7 00000000F905 000002014505 0 8.8K8b8s8 00000000F939 000002014539 0 :6;B;L;R; 00000000F943 000002014543 0 ;c;n;s;x; 00000000F977 000002014577 0 =B>z> 00000000F983 000002014583 0 ?*?I?V?g?}? 00000000F9C3 0000020145C3 0 2N3]3j3r3{3 00000000F9F9 0000020145F9 0 606H6_6o6 00000000FA15 000002014615 0 7D7T7x7~7 00000000FA39 000002014639 0 8!808 00000000FA41 000002014641 0 <6=g= 00000000FA6B 00000201466B 0 4X4)5 00000000FA7D 00000201467D 0 :*:8:a: 00000000FA85 000002014685 0 :;;W;k; 00000000FA99 000002014699 0 ;<<J<Z< 00000000FAAB 0000020146AB 0 = >?>H>e> 00000000FABD 0000020146BD 0 ?!?0?;?f?{? 00000000FADD 0000020146DD 0 0%0/050C0r0}0 00000000FAED 0000020146ED 0 2&2/272B2J2V2e2r2}2 00000000FB13 000002014713 0 3(383H3T3g3z3 00000000FB21 000002014721 0 3F5Q5g5 00000000FB35 000002014735 0 6.6A6F6r6 00000000FB4F 00000201474F 0 7"7L7 00000000FB57 000002014757 0 8 84898\8 00000000FB69 000002014769 0 9(9M9 00000000FB75 000002014775 0 :):g:l: 00000000FB83 000002014783 0 <$<\< 00000000FB9F 00000201479F 0 ?9?G?a?h?u? 00000000FBCD 0000020147CD 0 : ;+;@;U;a;j;z; 00000000FBDD 0000020147DD 0 <!<6<K<W< 00000000FBEB 0000020147EB 0 <3=A=H=d=l= 00000000FBFB 0000020147FB 0 =M>d>v> 00000000FC1F 00000201481F 0 1)1/1T1 00000000FC2F 00000201482F 0 122;2B2M2T2Y2 00000000FC3D 00000201483D 0 2e2l2q2x2 00000000FC4D 00000201484D 0 3"3<3 00000000FC81 000002014881 0 9?9R9 00000000FCA3 0000020148A3 0 =4=u= 00000000FCAD 0000020148AD 0 =?>c> 00000000FCB3 0000020148B3 0 >@?E?J?o? 00000000FCDB 0000020148DB 0 0n1s1 00000000FCF3 0000020148F3 0 3+3U3 00000000FCFF 0000020148FF 0 5&555B5K5S5 00000000FD13 000002014913 0 788C8Z8j8x8 00000000FD25 000002014925 0 989H9Q9 00000000FD37 000002014937 0 9::a:j:|: 00000000FD4B 00000201494B 0 ;/;G; 00000000FD5B 00000201495B 0 <1<C<O<[<o<z< 00000000FD79 000002014979 0 >%?*?O?_?y? 00000000FD9B 00000201499B 0 0$080C0K0]0 00000000FDB5 0000020149B5 0 1)111 00000000FDE5 0000020149E5 0 7&747B7r7w7}7r8 File pos Mem pos ID Text ======== ======= == ==== 00000000FDFB 0000020149FB 0 8Z9d9i9o9 00000000FE27 000002014A27 0 <@<H<P<[< 00000000FE39 000002014A39 0 =[>c>v>~>G?O? 00000000FE47 000002014A47 0 ?f?p? 00000000FE61 000002014A61 0 0$0+000:0?0X0b0h0v0 00000000FE91 000002014A91 0 2$2<2J2 00000000FEAB 000002014AAB 0 4&4.494Y4g4v4 00000000FED1 000002014AD1 0 5/565?5D5l5s5 00000000FF05 000002014B05 0 6#6'6+6/63676;6?6C6 00000000FF1B 000002014B1B 0 7%787K7 00000000FF31 000002014B31 0 7)8R8W8h8y8 00000000FF45 000002014B45 0 939H9W9 00000000FF4D 000002014B4D 0 9i9q9~9 00000000FF67 000002014B67 0 :#:1:::U:h:z: 00000000FF87 000002014B87 0 ;6;?;S;\;c;o; 00000000FF9F 000002014B9F 0 <2<@<I<O<V<]<|< 00000000FFBD 000002014BBD 0 =-=8=Z=q= 00000000FFF8 000002014BF8 0 D0d0~0 000000010021 000002014C21 0 1)181G1q1 000000010039 000002014C39 0 2)282G2[2l2q2 00000001005F 000002014C5F 0 263c3h3 00000001006B 000002014C6B 0 4)4/464@4E4Y4 000000010089 000002014C89 0 6 6/696B6M6V6_6k6y6 0000000100F7 000002014CF7 0 :$:.:3:8:O:T:Y:p:u:z: 00000001011F 000002014D1F 0 ;%;.;6;D;R;[;l;z; 000000010144 000002014D44 0 $0(0,0 00000001016D 000002014D6D 0 1 1$1(1,1014181<1@1D1H1L1T1X1 00000001018B 000002014D8B 0 1d1h1l1p1t1x1|1 0000000101A3 000002014DA3 0 1P2T2X2\2 0000000105C9 0000020153C9 0 Q 0000000105DA 0000020153DA 0 0000000105EB 0000020153EB 0 00000001061A 00000201541A 0 000000010634 000002015434 0 0000000106A9 0000020154A9 0 000000010731 000002015531 0 000000010786 000002015586 0 0000000107D6 0000020155D6 0 PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
=== DOWNLOAD ===