.- - -----÷M÷E÷N÷U÷------------------------------------------------------------- --- ----  -------------.
!  WALL ! STATS ! GOODIES ! YARA ! FAQ ! RSS ! EMV                                                      !
`--------------  - ---  ---------- -------- -------- -------- -------- ----------------- -  ---- ---- --'

                                           ATM MALWARE NOTICE 
                    5ab6358e1886655257c437ebad71b98a6575313b2f9327359661aac5d450c45a
 
Date...........: 2014-06-05
Family.........: Trojan.Skimer
File name......: netmgr.dll
File size......: 65.00 KB
Type file......: DLL/Windows
Virscan........: VT - HA
Documentation..: https://securelist.com/atm-infector/74772/

Entropy:


Binary Histogram:


=== PEDUMP REPORT === 
=== MZ Header === signature: "MZ" bytes_in_last_block: 80 0x50 blocks_in_file: 2 2 num_relocs: 0 0 header_paragraphs: 4 4 min_extra_paragraphs: 15 0xf max_extra_paragraphs: 65535 0xffff ss: 0 0 sp: 184 0xb8 checksum: 0 0 ip: 0 0 cs: 0 0 reloc_table_offset: 64 0x40 overlay_number: 26 0x1a reserved0: 0 0 oem_id: 0 0 oem_info: 0 0 reserved2: 0 0 reserved3: 0 0 reserved4: 0 0 reserved5: 0 0 reserved6: 0 0 lfanew: 256 0x100 === DOS STUB === 00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| === PE Header === signature: "PE\x00\x00" # IMAGE_FILE_HEADER: Machine: 332 0x14c x86 NumberOfSections: 6 6 TimeDateStamp: "1992-06-19 22:22:17" PointerToSymbolTable: 0 0 NumberOfSymbols: 0 0 SizeOfOptionalHeader: 224 0xe0 Characteristics: 41358 0xa18e EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO 32BIT_MACHINE, DLL, BYTES_REVERSED_HI # IMAGE_OPTIONAL_HEADER32: Magic: 267 0x10b 32-bit executable LinkerVersion: 2.25 SizeOfCode: 56320 0xdc00 SizeOfInitializedData: 9216 0x2400 SizeOfUninitializedData: 0 0 AddressOfEntryPoint: 59756 0xe96c BaseOfCode: 4096 0x1000 BaseOfData: 61440 0xf000 ImageBase: 33554432 0x2000000 SectionAlignment: 4096 0x1000 FileAlignment: 512 0x200 OperatingSystemVersion: 4.0 ImageVersion: 0.0 SubsystemVersion: 4.0 Reserved1: 0 0 SizeOfImage: 90112 0x16000 SizeOfHeaders: 1024 0x400 CheckSum: 125134 0x1e8ce Subsystem: 2 2 WINDOWS_GUI DllCharacteristics: 1 1 0x01 SizeOfStackReserve: 0 0 SizeOfStackCommit: 0 0 SizeOfHeapReserve: 1048576 0x100000 SizeOfHeapCommit: 4096 0x1000 LoaderFlags: 0 0 NumberOfRvaAndSizes: 16 0x10 === DATA DIRECTORY === EXPORT rva:0x 0 size:0x 0 IMPORT rva:0x 13000 size:0x cac RESOURCE rva:0x 15000 size:0x 114 EXCEPTION rva:0x 0 size:0x 0 SECURITY rva:0x 0 size:0x 0 BASERELOC rva:0x 14000 size:0x db0 DEBUG rva:0x 0 size:0x 0 ARCHITECTURE rva:0x 0 size:0x 0 GLOBALPTR rva:0x 0 size:0x 0 TLS rva:0x 0 size:0x 0 LOAD_CONFIG rva:0x 0 size:0x 0 Bound_IAT rva:0x 0 size:0x 0 IAT rva:0x 0 size:0x 0 Delay_IAT rva:0x 0 size:0x 0 CLR_Header rva:0x 0 size:0x 0 rva:0x 0 size:0x 0 === SECTIONS === NAME RVA VSZ RAW_SZ RAW_PTR nREL REL_PTR nLINE LINE_PTR FLAGS CODE 1000 db78 dc00 400 0 0 0 0 60000020 R-X CODE DATA f000 4dc 600 e000 0 0 0 0 c0000040 RW- IDATA BSS 10000 2eb5 0 e600 0 0 0 0 c0000000 RW- .idata 13000 cac e00 e600 0 0 0 0 c0000040 RW- IDATA .reloc 14000 db0 e00 f400 0 0 0 0 50000040 R-- IDATA SHARED .rsrc 15000 114 200 10200 0 0 0 0 50000040 R-- IDATA SHARED === RESOURCES === FILE_OFFSET CP LANG SIZE TYPE NAME 0x10258 1252 0 185 RCDATA #1 === IMPORTS === MODULE_NAME HINT ORD FUNCTION_NAME kernel32.dll 0 DeleteCriticalSection kernel32.dll 0 LeaveCriticalSection kernel32.dll 0 EnterCriticalSection kernel32.dll 0 InitializeCriticalSection kernel32.dll 0 VirtualFree kernel32.dll 0 VirtualAlloc kernel32.dll 0 LocalFree kernel32.dll 0 LocalAlloc kernel32.dll 0 GetVersion kernel32.dll 0 GetCurrentThreadId kernel32.dll 0 GetThreadLocale kernel32.dll 0 GetStartupInfoA kernel32.dll 0 GetLocaleInfoA kernel32.dll 0 GetCommandLineA kernel32.dll 0 FreeLibrary kernel32.dll 0 ExitProcess kernel32.dll 0 CreateThread kernel32.dll 0 WriteFile kernel32.dll 0 UnhandledExceptionFilter kernel32.dll 0 RtlUnwind kernel32.dll 0 RaiseException kernel32.dll 0 GetStdHandle user32.dll 0 GetKeyboardType user32.dll 0 MessageBoxA advapi32.dll 0 RegQueryValueExA advapi32.dll 0 RegOpenKeyExA advapi32.dll 0 RegCloseKey kernel32.dll 0 TlsSetValue kernel32.dll 0 TlsGetValue kernel32.dll 0 TlsFree kernel32.dll 0 TlsAlloc kernel32.dll 0 LocalFree kernel32.dll 0 LocalAlloc advapi32.dll 0 RegQueryValueExA advapi32.dll 0 RegOpenKeyExA advapi32.dll 0 RegCloseKey advapi32.dll 0 OpenProcessToken advapi32.dll 0 LookupPrivilegeValueA advapi32.dll 0 AdjustTokenPrivileges kernel32.dll 0 lstrlenA kernel32.dll 0 lstrcpynA kernel32.dll 0 lstrcpyA kernel32.dll 0 lstrcmpiW kernel32.dll 0 lstrcmpiA kernel32.dll 0 lstrcmpA kernel32.dll 0 lstrcatA kernel32.dll 0 WriteFile kernel32.dll 0 WaitForSingleObjectEx kernel32.dll 0 WaitForSingleObject kernel32.dll 0 VirtualProtect kernel32.dll 0 TerminateThread kernel32.dll 0 SleepEx kernel32.dll 0 Sleep kernel32.dll 0 SizeofResource kernel32.dll 0 SetThreadPriority kernel32.dll 0 SetFilePointer kernel32.dll 0 SetEvent kernel32.dll 0 ReadFile kernel32.dll 0 OpenProcess kernel32.dll 0 MultiByteToWideChar kernel32.dll 0 LocalUnlock kernel32.dll 0 LocalSize kernel32.dll 0 LocalReAlloc kernel32.dll 0 LocalLock kernel32.dll 0 LocalFree kernel32.dll 0 LocalAlloc kernel32.dll 0 LoadResource kernel32.dll 0 LoadLibraryA kernel32.dll 0 GetVolumeInformationA kernel32.dll 0 GetTickCount kernel32.dll 0 GetThreadPriority kernel32.dll 0 GetTempFileNameA kernel32.dll 0 GetSystemTimeAsFileTime kernel32.dll 0 GetProcAddress kernel32.dll 0 GetModuleHandleA kernel32.dll 0 GetModuleFileNameA kernel32.dll 0 GetLastError kernel32.dll 0 GetFileSize kernel32.dll 0 GetExitCodeThread kernel32.dll 0 GetCurrentThreadId kernel32.dll 0 GetCurrentThread kernel32.dll 0 GetCurrentProcess kernel32.dll 0 FormatMessageA kernel32.dll 0 FindResourceA kernel32.dll 0 FileTimeToSystemTime kernel32.dll 0 FileTimeToLocalFileTime kernel32.dll 0 ExitProcess kernel32.dll 0 DeleteFileA kernel32.dll 0 CreateThread kernel32.dll 0 CreateMutexA kernel32.dll 0 CreateFileA kernel32.dll 0 CreateEventA kernel32.dll 0 CopyFileA kernel32.dll 0 CloseHandle gdi32.dll 0 TextOutA gdi32.dll 0 SelectObject gdi32.dll 0 Rectangle gdi32.dll 0 GetTextMetricsA gdi32.dll 0 Escape gdi32.dll 0 EndDoc gdi32.dll 0 DeleteObject gdi32.dll 0 DeleteDC gdi32.dll 0 CreateSolidBrush gdi32.dll 0 CreateDCA user32.dll 0 CreateWindowExA user32.dll 0 UnregisterClassA user32.dll 0 TranslateMessage user32.dll 0 SetTimer user32.dll 0 SetForegroundWindow user32.dll 0 SetFocus user32.dll 0 SendMessageA user32.dll 0 RegisterClassA user32.dll 0 PostMessageA user32.dll 0 PeekMessageA user32.dll 0 MessageBoxA user32.dll 0 LoadIconA user32.dll 0 LoadCursorA user32.dll 0 InvalidateRect user32.dll 0 GetWindowTextA user32.dll 0 GetWindowDC user32.dll 0 GetMessageA user32.dll 0 GetForegroundWindow user32.dll 0 GetDesktopWindow user32.dll 0 GetClientRect user32.dll 0 FindWindowExA user32.dll 0 FindWindowA user32.dll 0 ExitWindowsEx user32.dll 0 DrawTextA user32.dll 0 DispatchMessageA user32.dll 0 DestroyWindow user32.dll 0 DefWindowProcA user32.dll 0 CharUpperA kernel32.dll 0 GetTickCount imagehlp.dll 0 CheckSumMappedFile winspool.drv 0 EnumPrintersA user32.dll 0 wsprintfA
=== Strings ===
File pos Mem pos ID Text ======== ======= == ==== 000000000050 000002000050 0 This program must be run under Win32 000000000270 000002000270 0 .idata 000000000298 000002000298 0 .reloc 0000000002BF 0000020002BF 0 P.rsrc 000000000884 000002001484 0 wE;\$ 000000001E9F 000002002A9F 0 ~KxI[) 000000001FC8 000002002BC8 0 SOFTWARE\Borland\Delphi\RTL 000000001FE4 000002002BE4 0 FPUMaskValue 000000002031 000002002C31 0 PPRTj 0000000021AB 000002002DAB 0 YZXtp 000000002322 000002002F22 0 t=HtN 000000002744 000002003344 0 SVWUQ 000000002B00 000002003700 0 USVW1 0000000034E3 0000020040E3 0 {V,| 00000000353F 00000200413F 0 <8LaK# 000000003660 000002004260 0 /R{m6 000000003774 000002004374 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt 0000000037A8 0000020043A8 0 C:\windows\EpsStmApi.log\ 000000003BFC 0000020047FC 0 WinSta0 000000003C04 000002004804 0 default 000000003C0C 00000200480C 0 DISPLAY 000000003E55 000002004A55 0 D$XPSj 000000003EEE 000002004AEE 0 D$xPj 000000003F3B 000002004B3B 0 |$,{u 000000003FF8 000002004BF8 0 WinSta0 000000004000 000002004C00 0 MyDesktop 000000004018 000002004C18 0 ATMDialog 000000004024 000002004C24 0 hello 00000000402C 000002004C2C 0 STATIC 000000004044 000002004C44 0 default 00000000405C 000002004C5C 0 Error 000000004110 000002004D10 0 Error 000000004140 000002004D40 0 $PShpM 0000000041A3 000002004DA3 0 $PVSh 0000000041D4 000002004DD4 0 %s %s 000000004480 000002005080 0 %s Error code= %d 0000000044BC 0000020050BC 0 %s Error code= %.2X 0000000044F5 0000020050F5 0 t"Jt" 000000004504 000002005104 0 Jt Jt 000000004618 000002005218 0 OpenProcessToken 00000000462C 00000200522C 0 LookupPrivilegeValue 000000004644 000002005244 0 AdjustTokenPrivileges 0000000047F8 0000020053F8 0 getProcessEntry: 00000000480C 00000200540C 0 SeDebugPrivilege 000000004820 000002005420 0 OpenProcess 00000000482C 00000200542C 0 LoadLibraryA 00000000483C 00000200543C 0 kernel32.dll 00000000484C 00000200544C 0 GetExitCodeThread 000000004860 000002005460 0 VirtualFreeEx 000000004B38 000002005738 0 DbdDevExecute(EPP4_ENCODE_DECODE) 000000004B5C 00000200575C 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ) 000000004B88 000002005788 0 EPP Complete LOCK 000000004B9C 00000200579C 0 EPP Complete ENCODE_DECODE 000000004C58 000002005858 0 SVWUQ 000000004CA2 0000020058A2 0 $ZXu> 000000004D16 000002005916 0 ~7hhY 000000004D5C 00000200595C 0 OASYS.dll 000000004D68 000002005968 0 OasPostMessage 000000004E38 000002005A38 0 DBDDevOpen 000000004E44 000002005A44 0 DbdDevRegisterCallback File pos Mem pos ID Text ======== ======= == ==== 000000004E5C 000002005A5C 0 DbdDevLock 000000004E68 000002005A68 0 DbdDevUnregisterCallback 000000004E84 000002005A84 0 DBDDevClose 000000004F00 000002005B00 0 DbdDevUnlock 000000004F10 000002005B10 0 bdDevUnregisterCallback 000000004F28 000002005B28 0 DBDDevClose 000000005010 000002005C10 0 DbdDevAPI.dll 000000005020 000002005C20 0 DbdDevOpen 00000000502C 000002005C2C 0 DbdDevClose 000000005038 000002005C38 0 DbdDevGetInfo 000000005048 000002005C48 0 DbdDevRegisterCallback 000000005060 000002005C60 0 DbdDevUnregisterCallback 00000000507C 000002005C7C 0 DbdDevLock 000000005088 000002005C88 0 DbdDevUnlock 000000005098 000002005C98 0 DbdDevExecute 0000000051C8 000002005DC8 0 AMI function don 0000000051D9 000002005DD9 0 t return in 1 sec 0000000053F4 000002005FF4 0 RECEIPT 0000000053FC 000002005FFC 0 WINSPOOL 000000005408 000002006008 0 CreateDC 000000005414 000002006014 0 hello 00000000541C 00000200601C 0 escape 000000005424 000002006024 0 TextOut 00000000542C 00000200602C 0 enddoc 0000000054E4 0000020060E4 0 DbdDevExecute(EPP4_COPY_KEY) 000000005504 000002006104 0 EPP4_COPY_KEY TimeOut 000000005620 000002006220 0 DbdDevExecute(EPP4_LOAD_KEY) 000000005640 000002006240 0 EPP4_LOAD_KEY TimeOut 0000000056F0 0000020062F0 0 DbdDevExecute(EPP4_DELETE_KEY) 000000005710 000002006310 0 EPP4_DELETE_KEY TimeOut 00000000583C 00000200643C 0 DbdDevExecute(EPP4_ENCODE_DECODE) 000000005860 000002006460 0 EPP_Encrypt TimeOut 000000005964 000002006564 0 SVWUQ 000000005C3C 00000200683C 0 LocalAlloc 000000005C48 000002006848 0 LocalLock 000000006442 000002007042 0 P CNu 0000000066D0 0000020072D0 0 SVWUQ 000000006A97 000002007697 0 u7IBF 000000006B26 000002007726 0 I+NBu 000000006EBC 000002007ABC 0 %.2d/%.2d/%.2d %.2d:%.2d 000000007038 000002007C38 0 tdHuaj 0000000070B0 000002007CB0 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI) 0000000070E0 000002007CE0 0 t LOCK EPP 0000000070EC 000002007CEC 0 RECEIPT_PRINTER_START_GDI 000000007108 000002007D08 0 DbdDevExecute(RECEIPT_PRINTER_EJECT) 00000000728C 000002007E8C 0 DbdDevExecute(AFD_DISPENCE) 0000000072A8 000002007EA8 0 CDM Complete LOCK 0000000072BC 000002007EBC 0 DbdDevExecute(AFD_PRESENT) 0000000072D8 000002007ED8 0 DbdDevExecute(AFD_RESTORE) 0000000074B4 0000020080B4 0 SeShutdownPrivilege 000000007810 000002008410 0 kernel32 00000000781C 00000200841C 0 DeleteFileA 000000007828 000002008428 0 FreeLibrary 000000007834 000002008434 0 GetModuleHandleA 000000007848 000002008448 0 CreateFileA 000000007854 000002008454 0 Sleep 00000000785C 00000200845C 0 WriteFile 000000007868 000002008468 0 CloseHandle 000000007874 000002008474 0 LocalFree 000000007880 000002008480 0 LoadLibraryA File pos Mem pos ID Text ======== ======= == ==== 000000007890 000002008490 0 user32 000000007898 000002008498 0 ExitWindowsEx 0000000078A8 0000020084A8 0 SeShutdownPrivilege 000000007A74 000002008674 0 SVWUQ 000000007B88 000002008788 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete 000000007BB4 0000020087B4 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ) 000000007EEC 000002008AEC 0 %.2X%.2X 000000007EF8 000002008AF8 0 Request Code: %.6d 000000007F0B 000002008B0B 0 Enter Responce 000000007F1C 000002008B1C 0 Autorization 000000007F2C 000002008B2C 0 1..4 - dispense cassete 000000007F44 000002008B44 0 9 - Uninstall 000000007F52 000002008B52 0 0 - Exit 000000007F5C 000002008B5C 0 Enter Command 000000008168 000002008D68 0 Diebold:OGuiFrame 00000000817C 000002008D7C 0 Enter Password 000000008190 000002008D90 0 STATIC 0000000081A0 000002008DA0 0 Supply Manager 0000000081B0 000002008DB0 0 Pripnt 0000000081B8 000002008DB8 0 View All Counts 0000000083D0 000002008FD0 0 DbdDevExecute(RESET) 0000000083E8 000002008FE8 0 DBDDEV_LOCK(CRW) 0000000083FC 000002008FFC 0 DbdDevExecute(MCRW_ACCEPT_INSERTION) 000000008424 000002009024 0 MCRW_ACCEPT_INSERTION 000000008469 000002009069 0 ;C&v= 000000008E45 000002009A45 0 L0(:L0Sv<V 000000008F94 000002009B94 0 DbdDevExecute(EPP4_LOAD_KEY) 000000008FB4 000002009BB4 0 EPP4_LOAD_KEY TimeOut 000000009088 000002009C88 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN) 0000000090BC 000002009CBC 0 EPP4_COMPUTE_VERIFICATION_PATTERN 00000000924B 000002009E4B 0 TQ,Rj 0000000093E2 000002009FE2 0 :V(t 000000009834 00000200A434 0 LoadKey %.2d @ %.2d - %.2d 000000009854 00000200A454 0 LoadKey %.2d - %.2d 00000000986C 00000200A46C 0 CopyKey %.2d -> %.2d - %.2d 00000000988C 00000200A48C 0 SVWUQ 000000009920 00000200A520 0 ComID %.2d, %X, %X - %.2d, 000000009AE0 00000200A6E0 0 No Transactions 000000009AF0 00000200A6F0 0 No Cards (PINs) 000000009D6C 00000200A96C 0 Transactions %d 000000009D7D 00000200A97D 0 Cards %d 000000009D91 00000200A991 0 Non Local %d 000000009DA5 00000200A9A5 0 MAC_ID %d 000000009DB9 00000200A9B9 0 InstrumentID %d 000000009EB0 00000200AAB0 0 Grab mode %d 000000009EC0 00000200AAC0 0 Deco mode %d 000000009ED1 00000200AAD1 0 Key mode %d 000000009EE2 00000200AAE2 0 Use locals %d 000000009EF3 00000200AAF3 0 Auto delete %d 000000009F04 00000200AB04 0 ReturnOnCode %d 000000009F50 00000200AB50 0 %d.%d.%d.%d : %d 00000000A074 00000200AC74 0 SeDebugPrivilege 00000000A1BC 00000200ADBC 0 SeDebugPrivilege 00000000A294 00000200AE94 0 Bound Import error 00000000A2A8 00000200AEA8 0 Bound Import GetProcAddress 00000000A2C4 00000200AEC4 0 EPP4API.DLL 00000000A2D0 00000200AED0 0 EppInit 00000000A2D8 00000200AED8 0 EppAttach 00000000A2E4 00000200AEE4 0 EppLock 00000000A2EC 00000200AEEC 0 CloseComPort File pos Mem pos ID Text ======== ======= == ==== 00000000A2FC 00000200AEFC 0 EppExchange 00000000A400 00000200B000 0 19200 00000000A570 00000200B170 0 version 00000000A578 00000200B178 0 SOFTWARE\Diebold\Agilis 91x 00000000A594 00000200B194 0 Product Version 00000000A5A4 00000200B1A4 0 SOFTWARE\Diebold\Agilis 91x Core 00000000A624 00000200B224 0 %s%.2X 00000000A646 00000200B246 0 tPj 3 00000000A770 00000200B370 0 version 00000000A778 00000200B378 0 SOFTWARE\Diebold\AMI for Opteva 00000000A798 00000200B398 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva 00000000A7CC 00000200B3CC 0 SOFTWARE\Diebold\Agilis XFS for Opteva 00000000A7F4 00000200B3F4 0 Agilis: %s 00000000A805 00000200B405 0 AMI: %s 00000000A813 00000200B413 0 XFS: %s 00000000A821 00000200B421 0 Firmware: 00000000A950 00000200B550 0 DbdDevExecute(MCRW_CHIP_IO) 00000000A96C 00000200B56C 0 TimeOut MCRW_CHIP_IO 00000000AB38 00000200B738 0 Invalid Sim Response 00000000AC7C 00000200B87C 0 DbdDevExecute(MCRW_ACCEPT_INSERTION) 00000000AD40 00000200B940 0 DbdDevExecute(MCRW_POWERON) 00000000AD5C 00000200B95C 0 DbdDevExecute(MCRW_POWEROFF) 00000000ADE4 00000200B9E4 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION) 00000000AE80 00000200BA80 0 DbdDevExecute(MCRW_MCRW_Eject) 00000000B0D8 00000200BCD8 0 TimeOut Reset 00000000B0E8 00000200BCE8 0 Incorrect FIle Size 00000000B498 00000200C098 0 TimeOut Reset 00000000B95F 00000200C55F 0 r AOu 00000000BB58 00000200C758 0 kernel32.dll 00000000BB68 00000200C768 0 CreateFileA 00000000BB74 00000200C774 0 GetFileTime 00000000BB80 00000200C780 0 SetFileTime 00000000BB8C 00000200C78C 0 GetFileSize 00000000BB98 00000200C798 0 ReadFile 00000000BBA4 00000200C7A4 0 WriteFile 00000000BBB0 00000200C7B0 0 SetFilePointer 00000000BBC0 00000200C7C0 0 CloseHandle 00000000BBCC 00000200C7CC 0 LocalAlloc 00000000BBD8 00000200C7D8 0 LocalFree 00000000BBE4 00000200C7E4 0 ExitThread 00000000BBF0 00000200C7F0 0 VirtualFree 00000000BBFC 00000200C7FC 0 Sleep 00000000BC04 00000200C804 0 DeleteFileA 00000000BCC8 00000200C8C8 0 SeDebugPrivilege 00000000BDFC 00000200C9FC 0 Check sum error 00000000BE0C 00000200CA0C 0 Update 00000000BE14 00000200CA14 0 Not executable file 00000000BE89 00000200CA89 0 |$0jd 00000000C107 00000200CD07 0 $ZXrM 00000000C10E 00000200CD0E 0 ZX|G3 00000000C4A4 00000200D0A4 0 c:\Program Files\Diebold\Abc\message.trc 00000000C4D0 00000200D0D0 0 c:\Diebold\css\message.trc 00000000C4EC 00000200D0EC 0 FileSize %d 00000000C4FD 00000200D0FD 0 Transactions %d 00000000C50E 00000200D10E 0 ComKeys %d 00000000C6CC 00000200D2CC 0 hook.LoadLibrary: 00000000C6E0 00000200D2E0 0 GetProcAddress 00000000C6F0 00000200D2F0 0 hook.VirtualProtect 00000000C89C 00000200D49C 0 mode6main 00000000C8B0 00000200D4B0 0 ws2_32.dll File pos Mem pos ID Text ======== ======= == ==== 00000000C8BC 00000200D4BC 0 WSASend 00000000CC6C 00000200D86C 0 Enter command: 00000000D33C 00000200DF3C 0 E PWS 00000000D3FA 00000200DFFA 0 8NTFS 00000000D668 00000200E268 0 DbdDevRegisterCallback 00000000D680 00000200E280 0 DbdDevAPI.dll 00000000D690 00000200E290 0 EppExchange 00000000D69C 00000200E29C 0 EPP4API.dll 00000000D6A8 00000200E2A8 0 DbdDevExecute 00000000D6D6 00000200E2D6 0 Pj@SV 00000000D738 00000200E338 0 VProtect1 00000000D748 00000200E348 0 SVWUQ 00000000D7F4 00000200E3F4 0 Begin 00000000D7FC 00000200E3FC 0 Error 00000000D808 00000200E408 0 t decode const 00000000D884 00000200E484 0 mu.exe 00000000D90D 00000200E50D 0 33333 00000000D92F 00000200E52F 0 UUUU3 00000000DA81 00000200E681 0 VWUSQ 00000000DAC9 00000200E6C9 0 33333 00000000DAEB 00000200E6EB 0 UUUU3 00000000DB9F 00000200E79F 0 UUUU3 00000000DBFD 00000200E7FD 0 VWUSQ 00000000DCB4 00000200E8B4 0 UUUU3 00000000DF64 00000200EB64 0 dfd6jdk 00000000DF6C 00000200EB6C 0 kdu32rbs 00000000E04C 00000200F04C 0 Error 00000000E054 00000200F054 0 Runtime error at 00000000 00000000E074 00000200F074 0 0123456789ABCDEF 00000000E0B0 00000200F0B0 0 SeTtInGs6.34.2 00000000E0C0 00000200F0C0 0 macau 00000000E1C2 00000200F1C2 0 <o:o:_;OPO 00000000E1D1 00000200F1D1 0 OLONO 00000000E1DD 00000200F1DD 0 O!O%O 00000000E390 00000200F390 0 <4,$?7/' 00000000E3D6 00000200F3D6 0 !"#$%&'()*+,-./012345678 00000000E421 00000200F421 0 (3-!0 00000000E428 00000200F428 0 ,1'8"5 00000000E954 000002013354 0 kernel32.dll 00000000E964 000002013364 0 DeleteCriticalSection 00000000E97C 00000201337C 0 LeaveCriticalSection 00000000E994 000002013394 0 EnterCriticalSection 00000000E9AC 0000020133AC 0 InitializeCriticalSection 00000000E9C8 0000020133C8 0 VirtualFree 00000000E9D6 0000020133D6 0 VirtualAlloc 00000000E9E6 0000020133E6 0 LocalFree 00000000E9F2 0000020133F2 0 LocalAlloc 00000000EA00 000002013400 0 GetVersion 00000000EA0E 00000201340E 0 GetCurrentThreadId 00000000EA24 000002013424 0 GetThreadLocale 00000000EA36 000002013436 0 GetStartupInfoA 00000000EA48 000002013448 0 GetLocaleInfoA 00000000EA5A 00000201345A 0 GetCommandLineA 00000000EA6C 00000201346C 0 FreeLibrary 00000000EA7A 00000201347A 0 ExitProcess 00000000EA88 000002013488 0 CreateThread 00000000EA98 000002013498 0 WriteFile 00000000EAA4 0000020134A4 0 UnhandledExceptionFilter 00000000EAC0 0000020134C0 0 RtlUnwind 00000000EACC 0000020134CC 0 RaiseException File pos Mem pos ID Text ======== ======= == ==== 00000000EADE 0000020134DE 0 GetStdHandle 00000000EAEC 0000020134EC 0 user32.dll 00000000EAFA 0000020134FA 0 GetKeyboardType 00000000EB0C 00000201350C 0 MessageBoxA 00000000EB18 000002013518 0 advapi32.dll 00000000EB28 000002013528 0 RegQueryValueExA 00000000EB3C 00000201353C 0 RegOpenKeyExA 00000000EB4C 00000201354C 0 RegCloseKey 00000000EB58 000002013558 0 kernel32.dll 00000000EB68 000002013568 0 TlsSetValue 00000000EB76 000002013576 0 TlsGetValue 00000000EB84 000002013584 0 TlsFree 00000000EB8E 00000201358E 0 TlsAlloc 00000000EB9A 00000201359A 0 LocalFree 00000000EBA6 0000020135A6 0 LocalAlloc 00000000EBB2 0000020135B2 0 advapi32.dll 00000000EBC2 0000020135C2 0 RegQueryValueExA 00000000EBD6 0000020135D6 0 RegOpenKeyExA 00000000EBE6 0000020135E6 0 RegCloseKey 00000000EBF4 0000020135F4 0 OpenProcessToken 00000000EC08 000002013608 0 LookupPrivilegeValueA 00000000EC20 000002013620 0 AdjustTokenPrivileges 00000000EC36 000002013636 0 kernel32.dll 00000000EC46 000002013646 0 lstrlenA 00000000EC52 000002013652 0 lstrcpynA 00000000EC5E 00000201365E 0 lstrcpyA 00000000EC6A 00000201366A 0 lstrcmpiW 00000000EC76 000002013676 0 lstrcmpiA 00000000EC82 000002013682 0 lstrcmpA 00000000EC8E 00000201368E 0 lstrcatA 00000000EC9A 00000201369A 0 WriteFile 00000000ECA6 0000020136A6 0 WaitForSingleObjectEx 00000000ECBE 0000020136BE 0 WaitForSingleObject 00000000ECD4 0000020136D4 0 VirtualProtect 00000000ECE6 0000020136E6 0 TerminateThread 00000000ECF8 0000020136F8 0 SleepEx 00000000ED02 000002013702 0 Sleep 00000000ED0A 00000201370A 0 SizeofResource 00000000ED1C 00000201371C 0 SetThreadPriority 00000000ED30 000002013730 0 SetFilePointer 00000000ED42 000002013742 0 SetEvent 00000000ED4E 00000201374E 0 ReadFile 00000000ED5A 00000201375A 0 OpenProcess 00000000ED68 000002013768 0 MultiByteToWideChar 00000000ED7E 00000201377E 0 LocalUnlock 00000000ED8C 00000201378C 0 LocalSize 00000000ED98 000002013798 0 LocalReAlloc 00000000EDA8 0000020137A8 0 LocalLock 00000000EDB4 0000020137B4 0 LocalFree 00000000EDC0 0000020137C0 0 LocalAlloc 00000000EDCE 0000020137CE 0 LoadResource 00000000EDDE 0000020137DE 0 LoadLibraryA 00000000EDEE 0000020137EE 0 GetVolumeInformationA 00000000EE06 000002013806 0 GetTickCount 00000000EE16 000002013816 0 GetThreadPriority 00000000EE2A 00000201382A 0 GetTempFileNameA 00000000EE3E 00000201383E 0 GetSystemTimeAsFileTime 00000000EE58 000002013858 0 GetProcAddress 00000000EE6A 00000201386A 0 GetModuleHandleA 00000000EE7E 00000201387E 0 GetModuleFileNameA File pos Mem pos ID Text ======== ======= == ==== 00000000EE94 000002013894 0 GetLastError 00000000EEA4 0000020138A4 0 GetFileSize 00000000EEB2 0000020138B2 0 GetExitCodeThread 00000000EEC6 0000020138C6 0 GetCurrentThreadId 00000000EEDC 0000020138DC 0 GetCurrentThread 00000000EEF0 0000020138F0 0 GetCurrentProcess 00000000EF04 000002013904 0 FormatMessageA 00000000EF16 000002013916 0 FindResourceA 00000000EF26 000002013926 0 FileTimeToSystemTime 00000000EF3E 00000201393E 0 FileTimeToLocalFileTime 00000000EF58 000002013958 0 ExitProcess 00000000EF66 000002013966 0 DeleteFileA 00000000EF74 000002013974 0 CreateThread 00000000EF84 000002013984 0 CreateMutexA 00000000EF94 000002013994 0 CreateFileA 00000000EFA2 0000020139A2 0 CreateEventA 00000000EFB2 0000020139B2 0 CopyFileA 00000000EFBE 0000020139BE 0 CloseHandle 00000000EFCA 0000020139CA 0 gdi32.dll 00000000EFD6 0000020139D6 0 TextOutA 00000000EFE2 0000020139E2 0 SelectObject 00000000EFF2 0000020139F2 0 Rectangle 00000000EFFE 0000020139FE 0 GetTextMetricsA 00000000F010 000002013A10 0 Escape 00000000F01A 000002013A1A 0 EndDoc 00000000F024 000002013A24 0 DeleteObject 00000000F034 000002013A34 0 DeleteDC 00000000F040 000002013A40 0 CreateSolidBrush 00000000F054 000002013A54 0 CreateDCA 00000000F05E 000002013A5E 0 user32.dll 00000000F06C 000002013A6C 0 CreateWindowExA 00000000F07E 000002013A7E 0 UnregisterClassA 00000000F092 000002013A92 0 TranslateMessage 00000000F0A6 000002013AA6 0 SetTimer 00000000F0B2 000002013AB2 0 SetForegroundWindow 00000000F0C8 000002013AC8 0 SetFocus 00000000F0D4 000002013AD4 0 SendMessageA 00000000F0E4 000002013AE4 0 RegisterClassA 00000000F0F6 000002013AF6 0 PostMessageA 00000000F106 000002013B06 0 PeekMessageA 00000000F116 000002013B16 0 MessageBoxA 00000000F124 000002013B24 0 LoadIconA 00000000F130 000002013B30 0 LoadCursorA 00000000F13E 000002013B3E 0 InvalidateRect 00000000F150 000002013B50 0 GetWindowTextA 00000000F162 000002013B62 0 GetWindowDC 00000000F170 000002013B70 0 GetMessageA 00000000F17E 000002013B7E 0 GetForegroundWindow 00000000F194 000002013B94 0 GetDesktopWindow 00000000F1A8 000002013BA8 0 GetClientRect 00000000F1B8 000002013BB8 0 FindWindowExA 00000000F1C8 000002013BC8 0 FindWindowA 00000000F1D6 000002013BD6 0 ExitWindowsEx 00000000F1E6 000002013BE6 0 DrawTextA 00000000F1F2 000002013BF2 0 DispatchMessageA 00000000F206 000002013C06 0 DestroyWindow 00000000F216 000002013C16 0 DefWindowProcA 00000000F228 000002013C28 0 CharUpperA 00000000F234 000002013C34 0 kernel32.dll 00000000F244 000002013C44 0 GetTickCount File pos Mem pos ID Text ======== ======= == ==== 00000000F252 000002013C52 0 imagehlp.dll 00000000F262 000002013C62 0 CheckSumMappedFile 00000000F276 000002013C76 0 winspool.drv 00000000F286 000002013C86 0 EnumPrintersA 00000000F294 000002013C94 0 user32.dll 00000000F2A2 000002013CA2 0 wsprintfA 00000000F40F 00000201400F 0 0"0*020:0B0J0R0Z0b0j0r0z0 00000000F43D 00000201403D 0 0&111 00000000F453 000002014053 0 5 6[6j6 00000000F467 000002014067 0 9"9,969@9V9\9j9 00000000F491 000002014091 0 :":G:Q:[:e:o: 00000000F4AF 0000020140AF 0 ;";n; 00000000F4BB 0000020140BB 0 <P<p< 00000000F4C5 0000020140C5 0 =Y>e> 00000000F4ED 0000020140ED 0 0#0(0 00000000F4F9 0000020140F9 0 0@1I1c1 00000000F50F 00000201410F 0 2p2x2~2 00000000F52B 00000201412B 0 3(3@3L3T3u3 00000000F545 000002014145 0 4J4~4 00000000F551 000002014151 0 4,545:5@5M5S5 00000000F587 000002014187 0 8$8=8N8c8p8 00000000F593 000002014193 0 8J9R9 00000000F59B 00000201419B 0 :9;I;_;}; 00000000F5AD 0000020141AD 0 <"<*<@<X<f< 00000000F5C3 0000020141C3 0 <#=P=Y= 00000000F5D3 0000020141D3 0 =?>g> 00000000F5E9 0000020141E9 0 0L0T0_0 00000000F5F7 0000020141F7 0 1h1x1~1 00000000F61B 00000201421B 0 20282d2o2 00000000F637 000002014237 0 3%3*3J3O3q3 00000000F64D 00000201424D 0 4%424H4 00000000F65D 00000201425D 0 8!858S8\8h8o8 00000000F66D 00000201426D 0 9'939:9D9N9e9v9 00000000F697 000002014297 0 :':8:B:J:R:Z:b:j:r: 00000000F6B3 0000020142B3 0 ; ;(;X; 00000000F6BB 0000020142BB 0 ;n;s; 00000000F6D3 0000020142D3 0 < <2<?<K<X<j<r<z< 00000000F703 000002014303 0 ="=*=2=:=B=J=R=Z=b=j=r=z= 00000000F743 000002014343 0 >">*>2>:>B>J>R>Z>b>j>r>z> 00000000F783 000002014383 0 ?"?*?2?:?B?J?R?Z?b?j?r?z? 00000000F7C5 0000020143C5 0 5"50565B5K5S5f5l5 00000000F7E9 0000020143E9 0 6@6N6Y6f6k6r6w6~6 00000000F813 000002014413 0 757:7F7K7W7]7b7g7n7|7 00000000F841 000002014441 0 7.8>8L8R8a8s8y8 00000000F855 000002014455 0 8t9z9 00000000F861 000002014461 0 9):a:f: 00000000F885 000002014485 0 ;M<v< 00000000F8AD 0000020144AD 0 001E1d1 00000000F8C1 0000020144C1 0 2&3E3V3[3 00000000F8D1 0000020144D1 0 3>5Q5g5 00000000F8DD 0000020144DD 0 5#606B6J6T6e6w6 00000000F8F9 0000020144F9 0 7!7&7 00000000F905 000002014505 0 8.8K8b8s8 00000000F939 000002014539 0 :6;B;L;R; 00000000F943 000002014543 0 ;c;n;s;x; 00000000F977 000002014577 0 =B>z> 00000000F983 000002014583 0 ?*?I?V?g?}? 00000000F9C3 0000020145C3 0 2N3]3j3r3{3 00000000F9F9 0000020145F9 0 606H6_6o6 00000000FA15 000002014615 0 7D7T7x7~7 File pos Mem pos ID Text ======== ======= == ==== 00000000FA39 000002014639 0 8!808 00000000FA41 000002014641 0 <6=g= 00000000FA4D 00000201464D 0 >"?r? 00000000FA6F 00000201466F 0 4d455 00000000FA81 000002014681 0 :?:M:v: 00000000FA89 000002014689 0 :O;k; 00000000FAA1 0000020146A1 0 <n<t< 00000000FAB1 0000020146B1 0 >S>\>y> 00000000FABF 0000020146BF 0 ?0?5?D?O?z? 00000000FAE0 0000020146E0 0 )090C0I0W0 00000000FAED 0000020146ED 0 0*212:2C2K2V2 00000000FAFB 0000020146FB 0 2j2y2 00000000FB15 000002014715 0 3,3<3L3\3h3{3 00000000FB25 000002014725 0 3Z5e5{5 00000000FB39 000002014739 0 6B6U6Z6 00000000FB51 000002014751 0 7,767 00000000FB5D 00000201475D 0 8H8M8p8 00000000FB6B 00000201476B 0 9)9<9a9 00000000FB77 000002014777 0 9#:=:{: 00000000FB87 000002014787 0 <8<p< 00000000FB9F 00000201479F 0 >$?1?M?[?u?|? 00000000FBD1 0000020147D1 0 : ;+;@;U;a;j;z; 00000000FBE1 0000020147E1 0 <!<6<K<W< 00000000FBEF 0000020147EF 0 <3=A=H=d=l= 00000000FBFF 0000020147FF 0 =W>q> 00000000FC21 000002014821 0 0#1L1U1[1 00000000FC33 000002014833 0 2'2.292@2E2L2Q2X2]2d2n2 00000000FC51 000002014851 0 3(3x3 00000000FC63 000002014863 0 4W5w5 00000000FC83 000002014883 0 9*989K9 00000000FC8D 00000201488D 0 91:[: 00000000FC93 000002014893 0 :B;{; 00000000FCA5 0000020148A5 0 =M=e= 00000000FCAF 0000020148AF 0 >;>g> 00000000FCB7 0000020148B7 0 ?"?G?Y?o? 00000000FCDB 0000020148DB 0 0F1K1]1b1 00000000FD05 000002014905 0 5#5+585 00000000FD17 000002014917 0 828B8P8 00000000FD27 000002014927 0 9 9)9 00000000FD39 000002014939 0 :9:B:T:d:m: 00000000FD4F 00000201494F 0 ;6;J;k; 00000000FD5F 00000201495F 0 <'<3<G<R<Z<h< 00000000FD7D 00000201497D 0 ?'?7?Q?h?|? 00000000FD9F 00000201499F 0 0#050]0i0s0 00000000FDB7 0000020149B7 0 1]1b1p1 00000000FDCB 0000020149CB 0 496E6R6 00000000FDD3 0000020149D3 0 6n6|6 00000000FDE9 0000020149E9 0 6*7/757*8Z8i8 00000000FDFD 0000020149FD 0 9!9'9H9U9v9 00000000FE0F 000002014A0F 0 9A:F: 00000000FE2D 000002014A2D 0 <s=}= 00000000FE3B 000002014A3B 0 >.>6> 00000000FE47 000002014A47 0 ?(?7?G? 00000000FE6F 000002014A6F 0 0 0.090@0G0W0c0r0x0 00000000FE83 000002014A83 0 0+1=1O1d1 00000000FE97 000002014A97 0 2B2d2 00000000FE9D 000002014A9D 0 2a3v3~3 00000000FEB5 000002014AB5 0 4.4;4L4T4Z4_4d4i4s4x4}4 00000000FED9 000002014AD9 0 4$5+5 00000000FF23 000002014B23 0 7'7?7 File pos Mem pos ID Text ======== ======= == ==== 00000000FF37 000002014B37 0 8)8Y8 00000000FF53 000002014B53 0 9.999E9V9b9j9 00000000FF73 000002014B73 0 :7:Q:Z:c:i: 00000000FF8F 000002014B8F 0 ;3;z; 00000000FFAD 000002014BAD 0 <$<,<6<J< 00000000FFC1 000002014BC1 0 =+=3=;=F= 00000000FFCD 000002014BCD 0 >->5>b>n>z> 00000000FFDF 000002014BDF 0 ?2?S?_?g?~? 00000000FFFF 000002014BFF 0 0"0,020<0B0H0P0Y0b0k0v0 000000010027 000002014C27 0 1@1R1 000000010049 000002014C49 0 2#2+20252:2F2K2P2U2 000000010075 000002014C75 0 344B4Z4>5V5s5 000000010097 000002014C97 0 5+696>6 0000000100A7 000002014CA7 0 7,797A7X7 0000000100B1 000002014CB1 0 7h7p7x7 0000000100BB 000002014CBB 0 8%8-8G8R8]8c8x8~8 0000000100D5 000002014CD5 0 9.9@9D9H9L9P9T9X9\9 0000000100E9 000002014CE9 0 9h9|9 00000001010B 000002014D0B 0 :/:;:K:a:k: 00000001012F 000002014D2F 0 ;$;3;D; 000000010140 000002014D40 0 $0(0,0 000000010169 000002014D69 0 1 1$1(1,1014181<1@1D1H1L1T1X1 000000010187 000002014D87 0 1d1h1l1p1t1x1|1 00000001019F 000002014D9F 0 1L2P2T2X2\2 000000010311 000002015111 0 PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD 000000000050 000002000050 0 This program must be run under Win32 000000000270 000002000270 0 .idata 000000000298 000002000298 0 .reloc 0000000002BF 0000020002BF 0 P.rsrc 000000000884 000002001484 0 wE;\$ 000000001E9F 000002002A9F 0 ~KxI[) 000000001FC8 000002002BC8 0 SOFTWARE\Borland\Delphi\RTL 000000001FE4 000002002BE4 0 FPUMaskValue 000000002031 000002002C31 0 PPRTj 0000000021AB 000002002DAB 0 YZXtp 000000002322 000002002F22 0 t=HtN 000000002744 000002003344 0 SVWUQ 000000002B00 000002003700 0 USVW1 0000000034E3 0000020040E3 0 {V,| 00000000353F 00000200413F 0 <8LaK# 000000003660 000002004260 0 /R{m6 000000003774 000002004374 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt 0000000037A8 0000020043A8 0 C:\windows\EpsStmApi.log\ 000000003BFC 0000020047FC 0 WinSta0 000000003C04 000002004804 0 default 000000003C0C 00000200480C 0 DISPLAY 000000003E55 000002004A55 0 D$XPSj 000000003EEE 000002004AEE 0 D$xPj 000000003F3B 000002004B3B 0 |$,{u 000000003FF8 000002004BF8 0 WinSta0 000000004000 000002004C00 0 MyDesktop 000000004018 000002004C18 0 ATMDialog 000000004024 000002004C24 0 hello 00000000402C 000002004C2C 0 STATIC 000000004044 000002004C44 0 default 00000000405C 000002004C5C 0 Error 000000004110 000002004D10 0 Error 000000004140 000002004D40 0 $PShpM 0000000041A3 000002004DA3 0 $PVSh 0000000041D4 000002004DD4 0 %s %s File pos Mem pos ID Text ======== ======= == ==== 000000004480 000002005080 0 %s Error code= %d 0000000044BC 0000020050BC 0 %s Error code= %.2X 0000000044F5 0000020050F5 0 t"Jt" 000000004504 000002005104 0 Jt Jt 000000004618 000002005218 0 OpenProcessToken 00000000462C 00000200522C 0 LookupPrivilegeValue 000000004644 000002005244 0 AdjustTokenPrivileges 0000000047F8 0000020053F8 0 getProcessEntry: 00000000480C 00000200540C 0 SeDebugPrivilege 000000004820 000002005420 0 OpenProcess 00000000482C 00000200542C 0 LoadLibraryA 00000000483C 00000200543C 0 kernel32.dll 00000000484C 00000200544C 0 GetExitCodeThread 000000004860 000002005460 0 VirtualFreeEx 000000004B38 000002005738 0 DbdDevExecute(EPP4_ENCODE_DECODE) 000000004B5C 00000200575C 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ) 000000004B88 000002005788 0 EPP Complete LOCK 000000004B9C 00000200579C 0 EPP Complete ENCODE_DECODE 000000004C58 000002005858 0 SVWUQ 000000004CA2 0000020058A2 0 $ZXu> 000000004D16 000002005916 0 ~7hhY 000000004D5C 00000200595C 0 OASYS.dll 000000004D68 000002005968 0 OasPostMessage 000000004E38 000002005A38 0 DBDDevOpen 000000004E44 000002005A44 0 DbdDevRegisterCallback 000000004E5C 000002005A5C 0 DbdDevLock 000000004E68 000002005A68 0 DbdDevUnregisterCallback 000000004E84 000002005A84 0 DBDDevClose 000000004F00 000002005B00 0 DbdDevUnlock 000000004F10 000002005B10 0 bdDevUnregisterCallback 000000004F28 000002005B28 0 DBDDevClose 000000005010 000002005C10 0 DbdDevAPI.dll 000000005020 000002005C20 0 DbdDevOpen 00000000502C 000002005C2C 0 DbdDevClose 000000005038 000002005C38 0 DbdDevGetInfo 000000005048 000002005C48 0 DbdDevRegisterCallback 000000005060 000002005C60 0 DbdDevUnregisterCallback 00000000507C 000002005C7C 0 DbdDevLock 000000005088 000002005C88 0 DbdDevUnlock 000000005098 000002005C98 0 DbdDevExecute 0000000051C8 000002005DC8 0 AMI function don 0000000051D9 000002005DD9 0 t return in 1 sec 0000000053F4 000002005FF4 0 RECEIPT 0000000053FC 000002005FFC 0 WINSPOOL 000000005408 000002006008 0 CreateDC 000000005414 000002006014 0 hello 00000000541C 00000200601C 0 escape 000000005424 000002006024 0 TextOut 00000000542C 00000200602C 0 enddoc 0000000054E4 0000020060E4 0 DbdDevExecute(EPP4_COPY_KEY) 000000005504 000002006104 0 EPP4_COPY_KEY TimeOut 000000005620 000002006220 0 DbdDevExecute(EPP4_LOAD_KEY) 000000005640 000002006240 0 EPP4_LOAD_KEY TimeOut 0000000056F0 0000020062F0 0 DbdDevExecute(EPP4_DELETE_KEY) 000000005710 000002006310 0 EPP4_DELETE_KEY TimeOut 00000000583C 00000200643C 0 DbdDevExecute(EPP4_ENCODE_DECODE) 000000005860 000002006460 0 EPP_Encrypt TimeOut 000000005964 000002006564 0 SVWUQ 000000005C3C 00000200683C 0 LocalAlloc 000000005C48 000002006848 0 LocalLock File pos Mem pos ID Text ======== ======= == ==== 000000006442 000002007042 0 P CNu 0000000066D0 0000020072D0 0 SVWUQ 000000006A97 000002007697 0 u7IBF 000000006B26 000002007726 0 I+NBu 000000006EBC 000002007ABC 0 %.2d/%.2d/%.2d %.2d:%.2d 000000007038 000002007C38 0 tdHuaj 0000000070B0 000002007CB0 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI) 0000000070E0 000002007CE0 0 t LOCK EPP 0000000070EC 000002007CEC 0 RECEIPT_PRINTER_START_GDI 000000007108 000002007D08 0 DbdDevExecute(RECEIPT_PRINTER_EJECT) 00000000728C 000002007E8C 0 DbdDevExecute(AFD_DISPENCE) 0000000072A8 000002007EA8 0 CDM Complete LOCK 0000000072BC 000002007EBC 0 DbdDevExecute(AFD_PRESENT) 0000000072D8 000002007ED8 0 DbdDevExecute(AFD_RESTORE) 0000000074B4 0000020080B4 0 SeShutdownPrivilege 000000007810 000002008410 0 kernel32 00000000781C 00000200841C 0 DeleteFileA 000000007828 000002008428 0 FreeLibrary 000000007834 000002008434 0 GetModuleHandleA 000000007848 000002008448 0 CreateFileA 000000007854 000002008454 0 Sleep 00000000785C 00000200845C 0 WriteFile 000000007868 000002008468 0 CloseHandle 000000007874 000002008474 0 LocalFree 000000007880 000002008480 0 LoadLibraryA 000000007890 000002008490 0 user32 000000007898 000002008498 0 ExitWindowsEx 0000000078A8 0000020084A8 0 SeShutdownPrivilege 000000007A74 000002008674 0 SVWUQ 000000007B88 000002008788 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete 000000007BB4 0000020087B4 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ) 000000007EEC 000002008AEC 0 %.2X%.2X 000000007EF8 000002008AF8 0 Request Code: %.6d 000000007F0B 000002008B0B 0 Enter Responce 000000007F1C 000002008B1C 0 Autorization 000000007F2C 000002008B2C 0 1..4 - dispense cassete 000000007F44 000002008B44 0 9 - Uninstall 000000007F52 000002008B52 0 0 - Exit 000000007F5C 000002008B5C 0 Enter Command 000000008168 000002008D68 0 Diebold:OGuiFrame 00000000817C 000002008D7C 0 Enter Password 000000008190 000002008D90 0 STATIC 0000000081A0 000002008DA0 0 Supply Manager 0000000081B0 000002008DB0 0 Pripnt 0000000081B8 000002008DB8 0 View All Counts 0000000083D0 000002008FD0 0 DbdDevExecute(RESET) 0000000083E8 000002008FE8 0 DBDDEV_LOCK(CRW) 0000000083FC 000002008FFC 0 DbdDevExecute(MCRW_ACCEPT_INSERTION) 000000008424 000002009024 0 MCRW_ACCEPT_INSERTION 000000008469 000002009069 0 ;C&v= 000000008E45 000002009A45 0 L0(:L0Sv<V 000000008F94 000002009B94 0 DbdDevExecute(EPP4_LOAD_KEY) 000000008FB4 000002009BB4 0 EPP4_LOAD_KEY TimeOut 000000009088 000002009C88 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN) 0000000090BC 000002009CBC 0 EPP4_COMPUTE_VERIFICATION_PATTERN 00000000924B 000002009E4B 0 TQ,Rj 0000000093E2 000002009FE2 0 :V(t 000000009834 00000200A434 0 LoadKey %.2d @ %.2d - %.2d 000000009854 00000200A454 0 LoadKey %.2d - %.2d 00000000986C 00000200A46C 0 CopyKey %.2d -> %.2d - %.2d File pos Mem pos ID Text ======== ======= == ==== 00000000988C 00000200A48C 0 SVWUQ 000000009920 00000200A520 0 ComID %.2d, %X, %X - %.2d, 000000009AE0 00000200A6E0 0 No Transactions 000000009AF0 00000200A6F0 0 No Cards (PINs) 000000009D6C 00000200A96C 0 Transactions %d 000000009D7D 00000200A97D 0 Cards %d 000000009D91 00000200A991 0 Non Local %d 000000009DA5 00000200A9A5 0 MAC_ID %d 000000009DB9 00000200A9B9 0 InstrumentID %d 000000009EB0 00000200AAB0 0 Grab mode %d 000000009EC0 00000200AAC0 0 Deco mode %d 000000009ED1 00000200AAD1 0 Key mode %d 000000009EE2 00000200AAE2 0 Use locals %d 000000009EF3 00000200AAF3 0 Auto delete %d 000000009F04 00000200AB04 0 ReturnOnCode %d 000000009F50 00000200AB50 0 %d.%d.%d.%d : %d 00000000A074 00000200AC74 0 SeDebugPrivilege 00000000A1BC 00000200ADBC 0 SeDebugPrivilege 00000000A294 00000200AE94 0 Bound Import error 00000000A2A8 00000200AEA8 0 Bound Import GetProcAddress 00000000A2C4 00000200AEC4 0 EPP4API.DLL 00000000A2D0 00000200AED0 0 EppInit 00000000A2D8 00000200AED8 0 EppAttach 00000000A2E4 00000200AEE4 0 EppLock 00000000A2EC 00000200AEEC 0 CloseComPort 00000000A2FC 00000200AEFC 0 EppExchange 00000000A400 00000200B000 0 19200 00000000A570 00000200B170 0 version 00000000A578 00000200B178 0 SOFTWARE\Diebold\Agilis 91x 00000000A594 00000200B194 0 Product Version 00000000A5A4 00000200B1A4 0 SOFTWARE\Diebold\Agilis 91x Core 00000000A624 00000200B224 0 %s%.2X 00000000A646 00000200B246 0 tPj 3 00000000A770 00000200B370 0 version 00000000A778 00000200B378 0 SOFTWARE\Diebold\AMI for Opteva 00000000A798 00000200B398 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva 00000000A7CC 00000200B3CC 0 SOFTWARE\Diebold\Agilis XFS for Opteva 00000000A7F4 00000200B3F4 0 Agilis: %s 00000000A805 00000200B405 0 AMI: %s 00000000A813 00000200B413 0 XFS: %s 00000000A821 00000200B421 0 Firmware: 00000000A950 00000200B550 0 DbdDevExecute(MCRW_CHIP_IO) 00000000A96C 00000200B56C 0 TimeOut MCRW_CHIP_IO 00000000AB38 00000200B738 0 Invalid Sim Response 00000000AC7C 00000200B87C 0 DbdDevExecute(MCRW_ACCEPT_INSERTION) 00000000AD40 00000200B940 0 DbdDevExecute(MCRW_POWERON) 00000000AD5C 00000200B95C 0 DbdDevExecute(MCRW_POWEROFF) 00000000ADE4 00000200B9E4 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION) 00000000AE80 00000200BA80 0 DbdDevExecute(MCRW_MCRW_Eject) 00000000B0D8 00000200BCD8 0 TimeOut Reset 00000000B0E8 00000200BCE8 0 Incorrect FIle Size 00000000B498 00000200C098 0 TimeOut Reset 00000000B95F 00000200C55F 0 r AOu 00000000BB58 00000200C758 0 kernel32.dll 00000000BB68 00000200C768 0 CreateFileA 00000000BB74 00000200C774 0 GetFileTime 00000000BB80 00000200C780 0 SetFileTime 00000000BB8C 00000200C78C 0 GetFileSize 00000000BB98 00000200C798 0 ReadFile 00000000BBA4 00000200C7A4 0 WriteFile File pos Mem pos ID Text ======== ======= == ==== 00000000BBB0 00000200C7B0 0 SetFilePointer 00000000BBC0 00000200C7C0 0 CloseHandle 00000000BBCC 00000200C7CC 0 LocalAlloc 00000000BBD8 00000200C7D8 0 LocalFree 00000000BBE4 00000200C7E4 0 ExitThread 00000000BBF0 00000200C7F0 0 VirtualFree 00000000BBFC 00000200C7FC 0 Sleep 00000000BC04 00000200C804 0 DeleteFileA 00000000BCC8 00000200C8C8 0 SeDebugPrivilege 00000000BDFC 00000200C9FC 0 Check sum error 00000000BE0C 00000200CA0C 0 Update 00000000BE14 00000200CA14 0 Not executable file 00000000BE89 00000200CA89 0 |$0jd 00000000C107 00000200CD07 0 $ZXrM 00000000C10E 00000200CD0E 0 ZX|G3 00000000C4A4 00000200D0A4 0 c:\Program Files\Diebold\Abc\message.trc 00000000C4D0 00000200D0D0 0 c:\Diebold\css\message.trc 00000000C4EC 00000200D0EC 0 FileSize %d 00000000C4FD 00000200D0FD 0 Transactions %d 00000000C50E 00000200D10E 0 ComKeys %d 00000000C6CC 00000200D2CC 0 hook.LoadLibrary: 00000000C6E0 00000200D2E0 0 GetProcAddress 00000000C6F0 00000200D2F0 0 hook.VirtualProtect 00000000C89C 00000200D49C 0 mode6main 00000000C8B0 00000200D4B0 0 ws2_32.dll 00000000C8BC 00000200D4BC 0 WSASend 00000000CC6C 00000200D86C 0 Enter command: 00000000D33C 00000200DF3C 0 E PWS 00000000D3FA 00000200DFFA 0 8NTFS 00000000D668 00000200E268 0 DbdDevRegisterCallback 00000000D680 00000200E280 0 DbdDevAPI.dll 00000000D690 00000200E290 0 EppExchange 00000000D69C 00000200E29C 0 EPP4API.dll 00000000D6A8 00000200E2A8 0 DbdDevExecute 00000000D6D6 00000200E2D6 0 Pj@SV 00000000D738 00000200E338 0 VProtect1 00000000D748 00000200E348 0 SVWUQ 00000000D7F4 00000200E3F4 0 Begin 00000000D7FC 00000200E3FC 0 Error 00000000D808 00000200E408 0 t decode const 00000000D884 00000200E484 0 mu.exe 00000000D90D 00000200E50D 0 33333 00000000D92F 00000200E52F 0 UUUU3 00000000DA81 00000200E681 0 VWUSQ 00000000DAC9 00000200E6C9 0 33333 00000000DAEB 00000200E6EB 0 UUUU3 00000000DB9F 00000200E79F 0 UUUU3 00000000DBFD 00000200E7FD 0 VWUSQ 00000000DCB4 00000200E8B4 0 UUUU3 00000000DF64 00000200EB64 0 dfd6jdk 00000000DF6C 00000200EB6C 0 kdu32rbs 00000000E04C 00000200F04C 0 Error 00000000E054 00000200F054 0 Runtime error at 00000000 00000000E074 00000200F074 0 0123456789ABCDEF 00000000E0B0 00000200F0B0 0 SeTtInGs6.34.2 00000000E0C0 00000200F0C0 0 macau 00000000E1C2 00000200F1C2 0 <o:o:_;OPO 00000000E1D1 00000200F1D1 0 OLONO 00000000E1DD 00000200F1DD 0 O!O%O 00000000E390 00000200F390 0 <4,$?7/' File pos Mem pos ID Text ======== ======= == ==== 00000000E3D6 00000200F3D6 0 !"#$%&'()*+,-./012345678 00000000E421 00000200F421 0 (3-!0 00000000E428 00000200F428 0 ,1'8"5 00000000E954 000002013354 0 kernel32.dll 00000000E964 000002013364 0 DeleteCriticalSection 00000000E97C 00000201337C 0 LeaveCriticalSection 00000000E994 000002013394 0 EnterCriticalSection 00000000E9AC 0000020133AC 0 InitializeCriticalSection 00000000E9C8 0000020133C8 0 VirtualFree 00000000E9D6 0000020133D6 0 VirtualAlloc 00000000E9E6 0000020133E6 0 LocalFree 00000000E9F2 0000020133F2 0 LocalAlloc 00000000EA00 000002013400 0 GetVersion 00000000EA0E 00000201340E 0 GetCurrentThreadId 00000000EA24 000002013424 0 GetThreadLocale 00000000EA36 000002013436 0 GetStartupInfoA 00000000EA48 000002013448 0 GetLocaleInfoA 00000000EA5A 00000201345A 0 GetCommandLineA 00000000EA6C 00000201346C 0 FreeLibrary 00000000EA7A 00000201347A 0 ExitProcess 00000000EA88 000002013488 0 CreateThread 00000000EA98 000002013498 0 WriteFile 00000000EAA4 0000020134A4 0 UnhandledExceptionFilter 00000000EAC0 0000020134C0 0 RtlUnwind 00000000EACC 0000020134CC 0 RaiseException 00000000EADE 0000020134DE 0 GetStdHandle 00000000EAEC 0000020134EC 0 user32.dll 00000000EAFA 0000020134FA 0 GetKeyboardType 00000000EB0C 00000201350C 0 MessageBoxA 00000000EB18 000002013518 0 advapi32.dll 00000000EB28 000002013528 0 RegQueryValueExA 00000000EB3C 00000201353C 0 RegOpenKeyExA 00000000EB4C 00000201354C 0 RegCloseKey 00000000EB58 000002013558 0 kernel32.dll 00000000EB68 000002013568 0 TlsSetValue 00000000EB76 000002013576 0 TlsGetValue 00000000EB84 000002013584 0 TlsFree 00000000EB8E 00000201358E 0 TlsAlloc 00000000EB9A 00000201359A 0 LocalFree 00000000EBA6 0000020135A6 0 LocalAlloc 00000000EBB2 0000020135B2 0 advapi32.dll 00000000EBC2 0000020135C2 0 RegQueryValueExA 00000000EBD6 0000020135D6 0 RegOpenKeyExA 00000000EBE6 0000020135E6 0 RegCloseKey 00000000EBF4 0000020135F4 0 OpenProcessToken 00000000EC08 000002013608 0 LookupPrivilegeValueA 00000000EC20 000002013620 0 AdjustTokenPrivileges 00000000EC36 000002013636 0 kernel32.dll 00000000EC46 000002013646 0 lstrlenA 00000000EC52 000002013652 0 lstrcpynA 00000000EC5E 00000201365E 0 lstrcpyA 00000000EC6A 00000201366A 0 lstrcmpiW 00000000EC76 000002013676 0 lstrcmpiA 00000000EC82 000002013682 0 lstrcmpA 00000000EC8E 00000201368E 0 lstrcatA 00000000EC9A 00000201369A 0 WriteFile 00000000ECA6 0000020136A6 0 WaitForSingleObjectEx 00000000ECBE 0000020136BE 0 WaitForSingleObject 00000000ECD4 0000020136D4 0 VirtualProtect 00000000ECE6 0000020136E6 0 TerminateThread File pos Mem pos ID Text ======== ======= == ==== 00000000ECF8 0000020136F8 0 SleepEx 00000000ED02 000002013702 0 Sleep 00000000ED0A 00000201370A 0 SizeofResource 00000000ED1C 00000201371C 0 SetThreadPriority 00000000ED30 000002013730 0 SetFilePointer 00000000ED42 000002013742 0 SetEvent 00000000ED4E 00000201374E 0 ReadFile 00000000ED5A 00000201375A 0 OpenProcess 00000000ED68 000002013768 0 MultiByteToWideChar 00000000ED7E 00000201377E 0 LocalUnlock 00000000ED8C 00000201378C 0 LocalSize 00000000ED98 000002013798 0 LocalReAlloc 00000000EDA8 0000020137A8 0 LocalLock 00000000EDB4 0000020137B4 0 LocalFree 00000000EDC0 0000020137C0 0 LocalAlloc 00000000EDCE 0000020137CE 0 LoadResource 00000000EDDE 0000020137DE 0 LoadLibraryA 00000000EDEE 0000020137EE 0 GetVolumeInformationA 00000000EE06 000002013806 0 GetTickCount 00000000EE16 000002013816 0 GetThreadPriority 00000000EE2A 00000201382A 0 GetTempFileNameA 00000000EE3E 00000201383E 0 GetSystemTimeAsFileTime 00000000EE58 000002013858 0 GetProcAddress 00000000EE6A 00000201386A 0 GetModuleHandleA 00000000EE7E 00000201387E 0 GetModuleFileNameA 00000000EE94 000002013894 0 GetLastError 00000000EEA4 0000020138A4 0 GetFileSize 00000000EEB2 0000020138B2 0 GetExitCodeThread 00000000EEC6 0000020138C6 0 GetCurrentThreadId 00000000EEDC 0000020138DC 0 GetCurrentThread 00000000EEF0 0000020138F0 0 GetCurrentProcess 00000000EF04 000002013904 0 FormatMessageA 00000000EF16 000002013916 0 FindResourceA 00000000EF26 000002013926 0 FileTimeToSystemTime 00000000EF3E 00000201393E 0 FileTimeToLocalFileTime 00000000EF58 000002013958 0 ExitProcess 00000000EF66 000002013966 0 DeleteFileA 00000000EF74 000002013974 0 CreateThread 00000000EF84 000002013984 0 CreateMutexA 00000000EF94 000002013994 0 CreateFileA 00000000EFA2 0000020139A2 0 CreateEventA 00000000EFB2 0000020139B2 0 CopyFileA 00000000EFBE 0000020139BE 0 CloseHandle 00000000EFCA 0000020139CA 0 gdi32.dll 00000000EFD6 0000020139D6 0 TextOutA 00000000EFE2 0000020139E2 0 SelectObject 00000000EFF2 0000020139F2 0 Rectangle 00000000EFFE 0000020139FE 0 GetTextMetricsA 00000000F010 000002013A10 0 Escape 00000000F01A 000002013A1A 0 EndDoc 00000000F024 000002013A24 0 DeleteObject 00000000F034 000002013A34 0 DeleteDC 00000000F040 000002013A40 0 CreateSolidBrush 00000000F054 000002013A54 0 CreateDCA 00000000F05E 000002013A5E 0 user32.dll 00000000F06C 000002013A6C 0 CreateWindowExA 00000000F07E 000002013A7E 0 UnregisterClassA 00000000F092 000002013A92 0 TranslateMessage 00000000F0A6 000002013AA6 0 SetTimer 00000000F0B2 000002013AB2 0 SetForegroundWindow File pos Mem pos ID Text ======== ======= == ==== 00000000F0C8 000002013AC8 0 SetFocus 00000000F0D4 000002013AD4 0 SendMessageA 00000000F0E4 000002013AE4 0 RegisterClassA 00000000F0F6 000002013AF6 0 PostMessageA 00000000F106 000002013B06 0 PeekMessageA 00000000F116 000002013B16 0 MessageBoxA 00000000F124 000002013B24 0 LoadIconA 00000000F130 000002013B30 0 LoadCursorA 00000000F13E 000002013B3E 0 InvalidateRect 00000000F150 000002013B50 0 GetWindowTextA 00000000F162 000002013B62 0 GetWindowDC 00000000F170 000002013B70 0 GetMessageA 00000000F17E 000002013B7E 0 GetForegroundWindow 00000000F194 000002013B94 0 GetDesktopWindow 00000000F1A8 000002013BA8 0 GetClientRect 00000000F1B8 000002013BB8 0 FindWindowExA 00000000F1C8 000002013BC8 0 FindWindowA 00000000F1D6 000002013BD6 0 ExitWindowsEx 00000000F1E6 000002013BE6 0 DrawTextA 00000000F1F2 000002013BF2 0 DispatchMessageA 00000000F206 000002013C06 0 DestroyWindow 00000000F216 000002013C16 0 DefWindowProcA 00000000F228 000002013C28 0 CharUpperA 00000000F234 000002013C34 0 kernel32.dll 00000000F244 000002013C44 0 GetTickCount 00000000F252 000002013C52 0 imagehlp.dll 00000000F262 000002013C62 0 CheckSumMappedFile 00000000F276 000002013C76 0 winspool.drv 00000000F286 000002013C86 0 EnumPrintersA 00000000F294 000002013C94 0 user32.dll 00000000F2A2 000002013CA2 0 wsprintfA 00000000F40F 00000201400F 0 0"0*020:0B0J0R0Z0b0j0r0z0 00000000F43D 00000201403D 0 0&111 00000000F453 000002014053 0 5 6[6j6 00000000F467 000002014067 0 9"9,969@9V9\9j9 00000000F491 000002014091 0 :":G:Q:[:e:o: 00000000F4AF 0000020140AF 0 ;";n; 00000000F4BB 0000020140BB 0 <P<p< 00000000F4C5 0000020140C5 0 =Y>e> 00000000F4ED 0000020140ED 0 0#0(0 00000000F4F9 0000020140F9 0 0@1I1c1 00000000F50F 00000201410F 0 2p2x2~2 00000000F52B 00000201412B 0 3(3@3L3T3u3 00000000F545 000002014145 0 4J4~4 00000000F551 000002014151 0 4,545:5@5M5S5 00000000F587 000002014187 0 8$8=8N8c8p8 00000000F593 000002014193 0 8J9R9 00000000F59B 00000201419B 0 :9;I;_;}; 00000000F5AD 0000020141AD 0 <"<*<@<X<f< 00000000F5C3 0000020141C3 0 <#=P=Y= 00000000F5D3 0000020141D3 0 =?>g> 00000000F5E9 0000020141E9 0 0L0T0_0 00000000F5F7 0000020141F7 0 1h1x1~1 00000000F61B 00000201421B 0 20282d2o2 00000000F637 000002014237 0 3%3*3J3O3q3 00000000F64D 00000201424D 0 4%424H4 00000000F65D 00000201425D 0 8!858S8\8h8o8 00000000F66D 00000201426D 0 9'939:9D9N9e9v9 00000000F697 000002014297 0 :':8:B:J:R:Z:b:j:r: 00000000F6B3 0000020142B3 0 ; ;(;X; File pos Mem pos ID Text ======== ======= == ==== 00000000F6BB 0000020142BB 0 ;n;s; 00000000F6D3 0000020142D3 0 < <2<?<K<X<j<r<z< 00000000F703 000002014303 0 ="=*=2=:=B=J=R=Z=b=j=r=z= 00000000F743 000002014343 0 >">*>2>:>B>J>R>Z>b>j>r>z> 00000000F783 000002014383 0 ?"?*?2?:?B?J?R?Z?b?j?r?z? 00000000F7C5 0000020143C5 0 5"50565B5K5S5f5l5 00000000F7E9 0000020143E9 0 6@6N6Y6f6k6r6w6~6 00000000F813 000002014413 0 757:7F7K7W7]7b7g7n7|7 00000000F841 000002014441 0 7.8>8L8R8a8s8y8 00000000F855 000002014455 0 8t9z9 00000000F861 000002014461 0 9):a:f: 00000000F885 000002014485 0 ;M<v< 00000000F8AD 0000020144AD 0 001E1d1 00000000F8C1 0000020144C1 0 2&3E3V3[3 00000000F8D1 0000020144D1 0 3>5Q5g5 00000000F8DD 0000020144DD 0 5#606B6J6T6e6w6 00000000F8F9 0000020144F9 0 7!7&7 00000000F905 000002014505 0 8.8K8b8s8 00000000F939 000002014539 0 :6;B;L;R; 00000000F943 000002014543 0 ;c;n;s;x; 00000000F977 000002014577 0 =B>z> 00000000F983 000002014583 0 ?*?I?V?g?}? 00000000F9C3 0000020145C3 0 2N3]3j3r3{3 00000000F9F9 0000020145F9 0 606H6_6o6 00000000FA15 000002014615 0 7D7T7x7~7 00000000FA39 000002014639 0 8!808 00000000FA41 000002014641 0 <6=g= 00000000FA4D 00000201464D 0 >"?r? 00000000FA6F 00000201466F 0 4d455 00000000FA81 000002014681 0 :?:M:v: 00000000FA89 000002014689 0 :O;k; 00000000FAA1 0000020146A1 0 <n<t< 00000000FAB1 0000020146B1 0 >S>\>y> 00000000FABF 0000020146BF 0 ?0?5?D?O?z? 00000000FAE0 0000020146E0 0 )090C0I0W0 00000000FAED 0000020146ED 0 0*212:2C2K2V2 00000000FAFB 0000020146FB 0 2j2y2 00000000FB15 000002014715 0 3,3<3L3\3h3{3 00000000FB25 000002014725 0 3Z5e5{5 00000000FB39 000002014739 0 6B6U6Z6 00000000FB51 000002014751 0 7,767 00000000FB5D 00000201475D 0 8H8M8p8 00000000FB6B 00000201476B 0 9)9<9a9 00000000FB77 000002014777 0 9#:=:{: 00000000FB87 000002014787 0 <8<p< 00000000FB9F 00000201479F 0 >$?1?M?[?u?|? 00000000FBD1 0000020147D1 0 : ;+;@;U;a;j;z; 00000000FBE1 0000020147E1 0 <!<6<K<W< 00000000FBEF 0000020147EF 0 <3=A=H=d=l= 00000000FBFF 0000020147FF 0 =W>q> 00000000FC21 000002014821 0 0#1L1U1[1 00000000FC33 000002014833 0 2'2.292@2E2L2Q2X2]2d2n2 00000000FC51 000002014851 0 3(3x3 00000000FC63 000002014863 0 4W5w5 00000000FC83 000002014883 0 9*989K9 00000000FC8D 00000201488D 0 91:[: 00000000FC93 000002014893 0 :B;{; 00000000FCA5 0000020148A5 0 =M=e= 00000000FCAF 0000020148AF 0 >;>g> 00000000FCB7 0000020148B7 0 ?"?G?Y?o? File pos Mem pos ID Text ======== ======= == ==== 00000000FCDB 0000020148DB 0 0F1K1]1b1 00000000FD05 000002014905 0 5#5+585 00000000FD17 000002014917 0 828B8P8 00000000FD27 000002014927 0 9 9)9 00000000FD39 000002014939 0 :9:B:T:d:m: 00000000FD4F 00000201494F 0 ;6;J;k; 00000000FD5F 00000201495F 0 <'<3<G<R<Z<h< 00000000FD7D 00000201497D 0 ?'?7?Q?h?|? 00000000FD9F 00000201499F 0 0#050]0i0s0 00000000FDB7 0000020149B7 0 1]1b1p1 00000000FDCB 0000020149CB 0 496E6R6 00000000FDD3 0000020149D3 0 6n6|6 00000000FDE9 0000020149E9 0 6*7/757*8Z8i8 00000000FDFD 0000020149FD 0 9!9'9H9U9v9 00000000FE0F 000002014A0F 0 9A:F: 00000000FE2D 000002014A2D 0 <s=}= 00000000FE3B 000002014A3B 0 >.>6> 00000000FE47 000002014A47 0 ?(?7?G? 00000000FE6F 000002014A6F 0 0 0.090@0G0W0c0r0x0 00000000FE83 000002014A83 0 0+1=1O1d1 00000000FE97 000002014A97 0 2B2d2 00000000FE9D 000002014A9D 0 2a3v3~3 00000000FEB5 000002014AB5 0 4.4;4L4T4Z4_4d4i4s4x4}4 00000000FED9 000002014AD9 0 4$5+5 00000000FF23 000002014B23 0 7'7?7 00000000FF37 000002014B37 0 8)8Y8 00000000FF53 000002014B53 0 9.999E9V9b9j9 00000000FF73 000002014B73 0 :7:Q:Z:c:i: 00000000FF8F 000002014B8F 0 ;3;z; 00000000FFAD 000002014BAD 0 <$<,<6<J< 00000000FFC1 000002014BC1 0 =+=3=;=F= 00000000FFCD 000002014BCD 0 >->5>b>n>z> 00000000FFDF 000002014BDF 0 ?2?S?_?g?~? 00000000FFFF 000002014BFF 0 0"0,020<0B0H0P0Y0b0k0v0 000000010027 000002014C27 0 1@1R1 000000010049 000002014C49 0 2#2+20252:2F2K2P2U2 000000010075 000002014C75 0 344B4Z4>5V5s5 000000010097 000002014C97 0 5+696>6 0000000100A7 000002014CA7 0 7,797A7X7 0000000100B1 000002014CB1 0 7h7p7x7 0000000100BB 000002014CBB 0 8%8-8G8R8]8c8x8~8 0000000100D5 000002014CD5 0 9.9@9D9H9L9P9T9X9\9 0000000100E9 000002014CE9 0 9h9|9 00000001010B 000002014D0B 0 :/:;:K:a:k: 00000001012F 000002014D2F 0 ;$;3;D; 000000010140 000002014D40 0 $0(0,0 000000010169 000002014D69 0 1 1$1(1,1014181<1@1D1H1L1T1X1 000000010187 000002014D87 0 1d1h1l1p1t1x1|1 00000001019F 000002014D9F 0 1L2P2T2X2\2 000000010311 000002015111 0 PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
=== DOWNLOAD === Mirror provided by vx-underground.org, thx!