.- - -----÷M÷E÷N÷U÷------------------------------------------------------------- --- ---- -------------.
! WALL ! STATS ! GOODIES ! YARA ! FAQ ! RSS ! EMV !
`-------------- - --- ---------- -------- -------- -------- -------- ----------------- - ---- ---- --'
ATM MALWARE NOTICE
4941331c64e0389d5ec966122ef71a99d8f9830f13e9afa758e03275f896c2eb
Date...........: 2014-06-05
Family.........: Trojan.Skimer
File name......: netmgr.dll
File size......: 66.00 KB
Type file......: DLL/Windows
Virscan........: VT - HA
Documentation..: https://securelist.com/atm-infector/74772/
Entropy:
Binary Histogram:
=== PEDUMP REPORT ===
=== MZ Header ===
signature: "MZ"
bytes_in_last_block: 80 0x50
blocks_in_file: 2 2
num_relocs: 0 0
header_paragraphs: 4 4
min_extra_paragraphs: 15 0xf
max_extra_paragraphs: 65535 0xffff
ss: 0 0
sp: 184 0xb8
checksum: 0 0
ip: 0 0
cs: 0 0
reloc_table_offset: 64 0x40
overlay_number: 26 0x1a
reserved0: 0 0
oem_id: 0 0
oem_info: 0 0
reserved2: 0 0
reserved3: 0 0
reserved4: 0 0
reserved5: 0 0
reserved6: 0 0
lfanew: 256 0x100
=== DOS STUB ===
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..|
00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus|
00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W|
00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........|
00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
=== PE Header ===
signature: "PE\x00\x00"
# IMAGE_FILE_HEADER:
Machine: 332 0x14c x86
NumberOfSections: 6 6
TimeDateStamp: "1992-06-19 22:22:17"
PointerToSymbolTable: 0 0
NumberOfSymbols: 0 0
SizeOfOptionalHeader: 224 0xe0
Characteristics: 41358 0xa18e EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED
LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO
32BIT_MACHINE, DLL, BYTES_REVERSED_HI
# IMAGE_OPTIONAL_HEADER32:
Magic: 267 0x10b 32-bit executable
LinkerVersion: 2.25
SizeOfCode: 56320 0xdc00
SizeOfInitializedData: 10240 0x2800
SizeOfUninitializedData: 0 0
AddressOfEntryPoint: 59880 0xe9e8
BaseOfCode: 4096 0x1000
BaseOfData: 61440 0xf000
ImageBase: 33554432 0x2000000
SectionAlignment: 4096 0x1000
FileAlignment: 512 0x200
OperatingSystemVersion: 4.0
ImageVersion: 0.0
SubsystemVersion: 4.0
Reserved1: 0 0
SizeOfImage: 90112 0x16000
SizeOfHeaders: 1024 0x400
CheckSum: 121446 0x1da66
Subsystem: 2 2 WINDOWS_GUI
DllCharacteristics: 1 1 0x01
SizeOfStackReserve: 0 0
SizeOfStackCommit: 0 0
SizeOfHeapReserve: 1048576 0x100000
SizeOfHeapCommit: 4096 0x1000
LoaderFlags: 0 0
NumberOfRvaAndSizes: 16 0x10
=== DATA DIRECTORY ===
EXPORT rva:0x 0 size:0x 0
IMPORT rva:0x 13000 size:0x cac
RESOURCE rva:0x 15000 size:0x 5d8
EXCEPTION rva:0x 0 size:0x 0
SECURITY rva:0x 0 size:0x 0
BASERELOC rva:0x 14000 size:0x db4
DEBUG rva:0x 0 size:0x 0
ARCHITECTURE rva:0x 0 size:0x 0
GLOBALPTR rva:0x 0 size:0x 0
TLS rva:0x 0 size:0x 0
LOAD_CONFIG rva:0x 0 size:0x 0
Bound_IAT rva:0x 0 size:0x 0
IAT rva:0x 0 size:0x 0
Delay_IAT rva:0x 0 size:0x 0
CLR_Header rva:0x 0 size:0x 0
rva:0x 0 size:0x 0
=== SECTIONS ===
NAME RVA VSZ RAW_SZ RAW_PTR nREL REL_PTR nLINE LINE_PTR FLAGS
CODE 1000 dbf4 dc00 400 0 0 0 0 60000020 R-X CODE
DATA f000 4e0 600 e000 0 0 0 0 c0000040 RW- IDATA
BSS 10000 2eb5 0 e600 0 0 0 0 c0000000 RW-
.idata 13000 cac e00 e600 0 0 0 0 c0000040 RW- IDATA
.reloc 14000 db4 e00 f400 0 0 0 0 50000040 R-- IDATA SHARED
.rsrc 15000 5d8 600 10200 0 0 0 0 50000040 R-- IDATA SHARED
=== RESOURCES ===
FILE_OFFSET CP LANG SIZE TYPE NAME
0x10258 1252 0 1406 RCDATA #1
=== IMPORTS ===
MODULE_NAME HINT ORD FUNCTION_NAME
kernel32.dll 0 DeleteCriticalSection
kernel32.dll 0 LeaveCriticalSection
kernel32.dll 0 EnterCriticalSection
kernel32.dll 0 InitializeCriticalSection
kernel32.dll 0 VirtualFree
kernel32.dll 0 VirtualAlloc
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
kernel32.dll 0 GetVersion
kernel32.dll 0 GetCurrentThreadId
kernel32.dll 0 GetThreadLocale
kernel32.dll 0 GetStartupInfoA
kernel32.dll 0 GetLocaleInfoA
kernel32.dll 0 GetCommandLineA
kernel32.dll 0 FreeLibrary
kernel32.dll 0 ExitProcess
kernel32.dll 0 CreateThread
kernel32.dll 0 WriteFile
kernel32.dll 0 UnhandledExceptionFilter
kernel32.dll 0 RtlUnwind
kernel32.dll 0 RaiseException
kernel32.dll 0 GetStdHandle
user32.dll 0 GetKeyboardType
user32.dll 0 MessageBoxA
advapi32.dll 0 RegQueryValueExA
advapi32.dll 0 RegOpenKeyExA
advapi32.dll 0 RegCloseKey
kernel32.dll 0 TlsSetValue
kernel32.dll 0 TlsGetValue
kernel32.dll 0 TlsFree
kernel32.dll 0 TlsAlloc
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
advapi32.dll 0 RegQueryValueExA
advapi32.dll 0 RegOpenKeyExA
advapi32.dll 0 RegCloseKey
advapi32.dll 0 OpenProcessToken
advapi32.dll 0 LookupPrivilegeValueA
advapi32.dll 0 AdjustTokenPrivileges
kernel32.dll 0 lstrlenA
kernel32.dll 0 lstrcpynA
kernel32.dll 0 lstrcpyA
kernel32.dll 0 lstrcmpiW
kernel32.dll 0 lstrcmpiA
kernel32.dll 0 lstrcmpA
kernel32.dll 0 lstrcatA
kernel32.dll 0 WriteFile
kernel32.dll 0 WaitForSingleObjectEx
kernel32.dll 0 WaitForSingleObject
kernel32.dll 0 VirtualProtect
kernel32.dll 0 TerminateThread
kernel32.dll 0 SleepEx
kernel32.dll 0 Sleep
kernel32.dll 0 SizeofResource
kernel32.dll 0 SetThreadPriority
kernel32.dll 0 SetFilePointer
kernel32.dll 0 SetEvent
kernel32.dll 0 ReadFile
kernel32.dll 0 OpenProcess
kernel32.dll 0 MultiByteToWideChar
kernel32.dll 0 LocalUnlock
kernel32.dll 0 LocalSize
kernel32.dll 0 LocalReAlloc
kernel32.dll 0 LocalLock
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
kernel32.dll 0 LoadResource
kernel32.dll 0 LoadLibraryA
kernel32.dll 0 GetVolumeInformationA
kernel32.dll 0 GetTickCount
kernel32.dll 0 GetThreadPriority
kernel32.dll 0 GetTempFileNameA
kernel32.dll 0 GetSystemTimeAsFileTime
kernel32.dll 0 GetProcAddress
kernel32.dll 0 GetModuleHandleA
kernel32.dll 0 GetModuleFileNameA
kernel32.dll 0 GetLastError
kernel32.dll 0 GetFileSize
kernel32.dll 0 GetExitCodeThread
kernel32.dll 0 GetCurrentThreadId
kernel32.dll 0 GetCurrentThread
kernel32.dll 0 GetCurrentProcess
kernel32.dll 0 FormatMessageA
kernel32.dll 0 FindResourceA
kernel32.dll 0 FileTimeToSystemTime
kernel32.dll 0 FileTimeToLocalFileTime
kernel32.dll 0 ExitProcess
kernel32.dll 0 DeleteFileA
kernel32.dll 0 CreateThread
kernel32.dll 0 CreateMutexA
kernel32.dll 0 CreateFileA
kernel32.dll 0 CreateEventA
kernel32.dll 0 CopyFileA
kernel32.dll 0 CloseHandle
gdi32.dll 0 TextOutA
gdi32.dll 0 SelectObject
gdi32.dll 0 Rectangle
gdi32.dll 0 GetTextMetricsA
gdi32.dll 0 Escape
gdi32.dll 0 EndDoc
gdi32.dll 0 DeleteObject
gdi32.dll 0 DeleteDC
gdi32.dll 0 CreateSolidBrush
gdi32.dll 0 CreateDCA
user32.dll 0 CreateWindowExA
user32.dll 0 UnregisterClassA
user32.dll 0 TranslateMessage
user32.dll 0 SetTimer
user32.dll 0 SetForegroundWindow
user32.dll 0 SetFocus
user32.dll 0 SendMessageA
user32.dll 0 RegisterClassA
user32.dll 0 PostMessageA
user32.dll 0 PeekMessageA
user32.dll 0 MessageBoxA
user32.dll 0 LoadIconA
user32.dll 0 LoadCursorA
user32.dll 0 InvalidateRect
user32.dll 0 GetWindowTextA
user32.dll 0 GetWindowDC
user32.dll 0 GetMessageA
user32.dll 0 GetForegroundWindow
user32.dll 0 GetDesktopWindow
user32.dll 0 GetClientRect
user32.dll 0 FindWindowExA
user32.dll 0 FindWindowA
user32.dll 0 ExitWindowsEx
user32.dll 0 DrawTextA
user32.dll 0 DispatchMessageA
user32.dll 0 DestroyWindow
user32.dll 0 DefWindowProcA
user32.dll 0 CharUpperA
kernel32.dll 0 GetTickCount
imagehlp.dll 0 CheckSumMappedFile
winspool.drv 0 EnumPrintersA
user32.dll 0 wsprintfA
=== Strings ===
File pos Mem pos ID Text
======== ======= == ====
000000000050 000002000050 0 This program must be run under Win32
000000000270 000002000270 0 .idata
000000000298 000002000298 0 .reloc
0000000002BF 0000020002BF 0 P.rsrc
000000000884 000002001484 0 wE;\$
000000001E9F 000002002A9F 0 ~KxI[)
000000001FC8 000002002BC8 0 SOFTWARE\Borland\Delphi\RTL
000000001FE4 000002002BE4 0 FPUMaskValue
000000002031 000002002C31 0 PPRTj
0000000021AB 000002002DAB 0 YZXtp
000000002322 000002002F22 0 t=HtN
000000002744 000002003344 0 SVWUQ
000000002B00 000002003700 0 USVW1
0000000034E3 0000020040E3 0 {V,|
00000000353F 00000200413F 0 <8LaK#
000000003660 000002004260 0 /R{m6
000000003774 000002004374 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt
0000000037A8 0000020043A8 0 C:\windows\EpsStmApi.log\
000000003BFC 0000020047FC 0 WinSta0
000000003C04 000002004804 0 default
000000003C0C 00000200480C 0 DISPLAY
000000003E55 000002004A55 0 D$XPSj
000000003EEE 000002004AEE 0 D$xPj
000000003F3B 000002004B3B 0 |$,{u
000000003FF8 000002004BF8 0 WinSta0
000000004000 000002004C00 0 MyDesktop
000000004018 000002004C18 0 ATMDialog
000000004024 000002004C24 0 hello
00000000402C 000002004C2C 0 STATIC
000000004044 000002004C44 0 default
00000000405C 000002004C5C 0 Error
000000004110 000002004D10 0 Error
000000004140 000002004D40 0 $PShpM
0000000041A3 000002004DA3 0 $PVSh
0000000041D4 000002004DD4 0 %s %s
000000004480 000002005080 0 %s Error code= %d
0000000044BC 0000020050BC 0 %s Error code= %.2X
0000000044F5 0000020050F5 0 t"Jt"
000000004504 000002005104 0 Jt Jt
000000004618 000002005218 0 OpenProcessToken
00000000462C 00000200522C 0 LookupPrivilegeValue
000000004644 000002005244 0 AdjustTokenPrivileges
0000000047F8 0000020053F8 0 getProcessEntry:
00000000480C 00000200540C 0 SeDebugPrivilege
000000004820 000002005420 0 OpenProcess
00000000482C 00000200542C 0 LoadLibraryA
00000000483C 00000200543C 0 kernel32.dll
00000000484C 00000200544C 0 GetExitCodeThread
000000004860 000002005460 0 VirtualFreeEx
000000004B38 000002005738 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000004B5C 00000200575C 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ)
000000004B88 000002005788 0 EPP Complete LOCK
000000004B9C 00000200579C 0 EPP Complete ENCODE_DECODE
000000004C58 000002005858 0 SVWUQ
000000004CA2 0000020058A2 0 $ZXu>
000000004D16 000002005916 0 ~7hhY
000000004D5C 00000200595C 0 OASYS.dll
000000004D68 000002005968 0 OasPostMessage
000000004E38 000002005A38 0 DBDDevOpen
000000004E44 000002005A44 0 DbdDevRegisterCallback
File pos Mem pos ID Text
======== ======= == ====
000000004E5C 000002005A5C 0 DbdDevLock
000000004E68 000002005A68 0 DbdDevUnregisterCallback
000000004E84 000002005A84 0 DBDDevClose
000000004F00 000002005B00 0 DbdDevUnlock
000000004F10 000002005B10 0 bdDevUnregisterCallback
000000004F28 000002005B28 0 DBDDevClose
000000005010 000002005C10 0 DbdDevAPI.dll
000000005020 000002005C20 0 DbdDevOpen
00000000502C 000002005C2C 0 DbdDevClose
000000005038 000002005C38 0 DbdDevGetInfo
000000005048 000002005C48 0 DbdDevRegisterCallback
000000005060 000002005C60 0 DbdDevUnregisterCallback
00000000507C 000002005C7C 0 DbdDevLock
000000005088 000002005C88 0 DbdDevUnlock
000000005098 000002005C98 0 DbdDevExecute
0000000051C8 000002005DC8 0 AMI function don
0000000051D9 000002005DD9 0 t return in 1 sec
0000000053F4 000002005FF4 0 RECEIPT
0000000053FC 000002005FFC 0 WINSPOOL
000000005408 000002006008 0 CreateDC
000000005414 000002006014 0 hello
00000000541C 00000200601C 0 escape
000000005424 000002006024 0 TextOut
00000000542C 00000200602C 0 enddoc
0000000054E4 0000020060E4 0 DbdDevExecute(EPP4_COPY_KEY)
000000005504 000002006104 0 EPP4_COPY_KEY TimeOut
000000005620 000002006220 0 DbdDevExecute(EPP4_LOAD_KEY)
000000005640 000002006240 0 EPP4_LOAD_KEY TimeOut
0000000056F0 0000020062F0 0 DbdDevExecute(EPP4_DELETE_KEY)
000000005710 000002006310 0 EPP4_DELETE_KEY TimeOut
00000000583C 00000200643C 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000005860 000002006460 0 EPP_Encrypt TimeOut
000000005964 000002006564 0 SVWUQ
000000005C3C 00000200683C 0 LocalAlloc
000000005C48 000002006848 0 LocalLock
00000000643A 00000200703A 0 P CNu
0000000066C4 0000020072C4 0 SVWUQ
000000006A8B 00000200768B 0 u7IBF
000000006B1A 00000200771A 0 I+NBu
000000006EA8 000002007AA8 0 %.2d/%.2d/%.2d %.2d:%.2d
000000007024 000002007C24 0 tdHuaj
00000000709C 000002007C9C 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI)
0000000070CC 000002007CCC 0 t LOCK EPP
0000000070D8 000002007CD8 0 RECEIPT_PRINTER_START_GDI
0000000070F4 000002007CF4 0 DbdDevExecute(RECEIPT_PRINTER_EJECT)
000000007278 000002007E78 0 DbdDevExecute(AFD_DISPENCE)
000000007294 000002007E94 0 CDM Complete LOCK
0000000072A8 000002007EA8 0 DbdDevExecute(AFD_PRESENT)
0000000072C4 000002007EC4 0 DbdDevExecute(AFD_RESTORE)
0000000074A0 0000020080A0 0 SeShutdownPrivilege
0000000077FC 0000020083FC 0 kernel32
000000007808 000002008408 0 DeleteFileA
000000007814 000002008414 0 FreeLibrary
000000007820 000002008420 0 GetModuleHandleA
000000007834 000002008434 0 CreateFileA
000000007840 000002008440 0 Sleep
000000007848 000002008448 0 WriteFile
000000007854 000002008454 0 CloseHandle
000000007860 000002008460 0 LocalFree
00000000786C 00000200846C 0 LoadLibraryA
File pos Mem pos ID Text
======== ======= == ====
00000000787C 00000200847C 0 user32
000000007884 000002008484 0 ExitWindowsEx
000000007894 000002008494 0 SeShutdownPrivilege
000000007A60 000002008660 0 SVWUQ
000000007B74 000002008774 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete
000000007BA0 0000020087A0 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ)
000000007ED8 000002008AD8 0 %.2X%.2X
000000007EE4 000002008AE4 0 Request Code: %.6d
000000007EF7 000002008AF7 0 Enter Responce
000000007F08 000002008B08 0 Autorization
000000007F18 000002008B18 0 1..4 - dispense cassete
000000007F30 000002008B30 0 9 - Uninstall
000000007F3E 000002008B3E 0 0 - Exit
000000007F48 000002008B48 0 Enter Command
000000008154 000002008D54 0 Diebold:OGuiFrame
000000008168 000002008D68 0 Enter Password
00000000817C 000002008D7C 0 STATIC
00000000818C 000002008D8C 0 Supply Manager
00000000819C 000002008D9C 0 Pripnt
0000000081A4 000002008DA4 0 View All Counts
0000000083BC 000002008FBC 0 DbdDevExecute(RESET)
0000000083D4 000002008FD4 0 DBDDEV_LOCK(CRW)
0000000083E8 000002008FE8 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
000000008410 000002009010 0 MCRW_ACCEPT_INSERTION
000000008455 000002009055 0 ;C*v=
000000008E45 000002009A45 0 L0(:L0Sv<V
000000008F94 000002009B94 0 DbdDevExecute(EPP4_LOAD_KEY)
000000008FB4 000002009BB4 0 EPP4_LOAD_KEY TimeOut
000000009088 000002009C88 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN)
0000000090BC 000002009CBC 0 EPP4_COMPUTE_VERIFICATION_PATTERN
0000000093C6 000002009FC6 0 :V(t
000000009848 00000200A448 0 LoadKey %.2d @ %.2d - %.2d
000000009868 00000200A468 0 LoadKey %.2d - %.2d
000000009880 00000200A480 0 CopyKey %.2d -> %.2d - %.2d
0000000098A0 00000200A4A0 0 SVWUQ
000000009934 00000200A534 0 ComID %.2d, %X, %X - %.2d,
000000009B1C 00000200A71C 0 No Transactions
000000009B2C 00000200A72C 0 No Cards (PINs)
000000009D94 00000200A994 0 Transactions %d
000000009DA5 00000200A9A5 0 Cards %d
000000009DB9 00000200A9B9 0 Non Local %d
000000009DCD 00000200A9CD 0 MAC_ID %d
000000009DE1 00000200A9E1 0 InstrumentID %d
000000009ED8 00000200AAD8 0 Grab mode %d
000000009EE8 00000200AAE8 0 Deco mode %d
000000009EF9 00000200AAF9 0 Key mode %d
000000009F0A 00000200AB0A 0 Use locals %d
000000009F1B 00000200AB1B 0 Auto delete %d
000000009F2C 00000200AB2C 0 ReturnOnCode %d
000000009F78 00000200AB78 0 %d.%d.%d.%d : %d
00000000A09C 00000200AC9C 0 SeDebugPrivilege
00000000A1E4 00000200ADE4 0 SeDebugPrivilege
00000000A2BC 00000200AEBC 0 Bound Import error
00000000A2D0 00000200AED0 0 Bound Import GetProcAddress
00000000A2EC 00000200AEEC 0 EPP4API.DLL
00000000A2F8 00000200AEF8 0 EppInit
00000000A300 00000200AF00 0 EppAttach
00000000A30C 00000200AF0C 0 EppLock
00000000A314 00000200AF14 0 CloseComPort
00000000A324 00000200AF24 0 EppExchange
File pos Mem pos ID Text
======== ======= == ====
00000000A428 00000200B028 0 19200
00000000A598 00000200B198 0 version
00000000A5A0 00000200B1A0 0 SOFTWARE\Diebold\Agilis 91x
00000000A5BC 00000200B1BC 0 Product Version
00000000A5CC 00000200B1CC 0 SOFTWARE\Diebold\Agilis 91x Core
00000000A64C 00000200B24C 0 %s%.2X
00000000A66E 00000200B26E 0 tPj 3
00000000A798 00000200B398 0 version
00000000A7A0 00000200B3A0 0 SOFTWARE\Diebold\AMI for Opteva
00000000A7C0 00000200B3C0 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva
00000000A7F4 00000200B3F4 0 SOFTWARE\Diebold\Agilis XFS for Opteva
00000000A81C 00000200B41C 0 Agilis: %s
00000000A82D 00000200B42D 0 AMI: %s
00000000A83B 00000200B43B 0 XFS: %s
00000000A849 00000200B449 0 Firmware:
00000000A978 00000200B578 0 DbdDevExecute(MCRW_CHIP_IO)
00000000A994 00000200B594 0 TimeOut MCRW_CHIP_IO
00000000AB60 00000200B760 0 Invalid Sim Response
00000000ACA4 00000200B8A4 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
00000000AD68 00000200B968 0 DbdDevExecute(MCRW_POWERON)
00000000AD84 00000200B984 0 DbdDevExecute(MCRW_POWEROFF)
00000000AE0C 00000200BA0C 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION)
00000000AEA8 00000200BAA8 0 DbdDevExecute(MCRW_MCRW_Eject)
00000000B100 00000200BD00 0 TimeOut Reset
00000000B110 00000200BD10 0 Incorrect FIle Size
00000000B4C0 00000200C0C0 0 TimeOut Reset
00000000B9A7 00000200C5A7 0 r AOu
00000000BBA0 00000200C7A0 0 kernel32.dll
00000000BBB0 00000200C7B0 0 CreateFileA
00000000BBBC 00000200C7BC 0 GetFileTime
00000000BBC8 00000200C7C8 0 SetFileTime
00000000BBD4 00000200C7D4 0 GetFileSize
00000000BBE0 00000200C7E0 0 ReadFile
00000000BBEC 00000200C7EC 0 WriteFile
00000000BBF8 00000200C7F8 0 SetFilePointer
00000000BC08 00000200C808 0 CloseHandle
00000000BC14 00000200C814 0 LocalAlloc
00000000BC20 00000200C820 0 LocalFree
00000000BC2C 00000200C82C 0 ExitThread
00000000BC38 00000200C838 0 VirtualFree
00000000BC44 00000200C844 0 Sleep
00000000BC4C 00000200C84C 0 DeleteFileA
00000000BD10 00000200C910 0 SeDebugPrivilege
00000000BE44 00000200CA44 0 Check sum error
00000000BE54 00000200CA54 0 Update
00000000BE5C 00000200CA5C 0 Not executable file
00000000BED1 00000200CAD1 0 |$0jd
00000000C14F 00000200CD4F 0 $ZXrM
00000000C156 00000200CD56 0 ZX|G3
00000000C4EC 00000200D0EC 0 c:\Program Files\Diebold\Abc\message.trc
00000000C518 00000200D118 0 c:\Diebold\css\message.trc
00000000C534 00000200D134 0 FileSize %d
00000000C545 00000200D145 0 Transactions %d
00000000C556 00000200D156 0 ComKeys %d
00000000C714 00000200D314 0 hook.LoadLibrary:
00000000C728 00000200D328 0 GetProcAddress
00000000C738 00000200D338 0 hook.VirtualProtect
00000000C8E4 00000200D4E4 0 mode6main
00000000C8F8 00000200D4F8 0 ws2_32.dll
00000000C904 00000200D504 0 WSASend
File pos Mem pos ID Text
======== ======= == ====
00000000CCE8 00000200D8E8 0 Enter command:
00000000D3B8 00000200DFB8 0 E PWS
00000000D476 00000200E076 0 8NTFS
00000000D6E4 00000200E2E4 0 DbdDevRegisterCallback
00000000D6FC 00000200E2FC 0 DbdDevAPI.dll
00000000D70C 00000200E30C 0 EppExchange
00000000D718 00000200E318 0 EPP4API.dll
00000000D724 00000200E324 0 DbdDevExecute
00000000D752 00000200E352 0 Pj@SV
00000000D7B4 00000200E3B4 0 VProtect1
00000000D7C4 00000200E3C4 0 SVWUQ
00000000D870 00000200E470 0 Begin
00000000D878 00000200E478 0 Error
00000000D884 00000200E484 0 t decode const
00000000D900 00000200E500 0 mu.exe
00000000D989 00000200E589 0 33333
00000000D9AB 00000200E5AB 0 UUUU3
00000000DAFD 00000200E6FD 0 VWUSQ
00000000DB45 00000200E745 0 33333
00000000DB67 00000200E767 0 UUUU3
00000000DC1B 00000200E81B 0 UUUU3
00000000DC79 00000200E879 0 VWUSQ
00000000DD30 00000200E930 0 UUUU3
00000000DFE0 00000200EBE0 0 dfd6jdk
00000000DFE8 00000200EBE8 0 kdu32rbs
00000000E04C 00000200F04C 0 Error
00000000E054 00000200F054 0 Runtime error at 00000000
00000000E074 00000200F074 0 0123456789ABCDEF
00000000E0B0 00000200F0B0 0 SeTtInGs6.34.3
00000000E1C2 00000200F1C2 0 <o:o:_;OPO
00000000E1D1 00000200F1D1 0 OLONO
00000000E1DD 00000200F1DD 0 O!O%O
00000000E394 00000200F394 0 <4,$?7/'
00000000E3DA 00000200F3DA 0 !"#$%&'()*+,-./012345678
00000000E425 00000200F425 0 (3-!0
00000000E42C 00000200F42C 0 ,1'8"5
00000000E954 000002013354 0 kernel32.dll
00000000E964 000002013364 0 DeleteCriticalSection
00000000E97C 00000201337C 0 LeaveCriticalSection
00000000E994 000002013394 0 EnterCriticalSection
00000000E9AC 0000020133AC 0 InitializeCriticalSection
00000000E9C8 0000020133C8 0 VirtualFree
00000000E9D6 0000020133D6 0 VirtualAlloc
00000000E9E6 0000020133E6 0 LocalFree
00000000E9F2 0000020133F2 0 LocalAlloc
00000000EA00 000002013400 0 GetVersion
00000000EA0E 00000201340E 0 GetCurrentThreadId
00000000EA24 000002013424 0 GetThreadLocale
00000000EA36 000002013436 0 GetStartupInfoA
00000000EA48 000002013448 0 GetLocaleInfoA
00000000EA5A 00000201345A 0 GetCommandLineA
00000000EA6C 00000201346C 0 FreeLibrary
00000000EA7A 00000201347A 0 ExitProcess
00000000EA88 000002013488 0 CreateThread
00000000EA98 000002013498 0 WriteFile
00000000EAA4 0000020134A4 0 UnhandledExceptionFilter
00000000EAC0 0000020134C0 0 RtlUnwind
00000000EACC 0000020134CC 0 RaiseException
00000000EADE 0000020134DE 0 GetStdHandle
00000000EAEC 0000020134EC 0 user32.dll
File pos Mem pos ID Text
======== ======= == ====
00000000EAFA 0000020134FA 0 GetKeyboardType
00000000EB0C 00000201350C 0 MessageBoxA
00000000EB18 000002013518 0 advapi32.dll
00000000EB28 000002013528 0 RegQueryValueExA
00000000EB3C 00000201353C 0 RegOpenKeyExA
00000000EB4C 00000201354C 0 RegCloseKey
00000000EB58 000002013558 0 kernel32.dll
00000000EB68 000002013568 0 TlsSetValue
00000000EB76 000002013576 0 TlsGetValue
00000000EB84 000002013584 0 TlsFree
00000000EB8E 00000201358E 0 TlsAlloc
00000000EB9A 00000201359A 0 LocalFree
00000000EBA6 0000020135A6 0 LocalAlloc
00000000EBB2 0000020135B2 0 advapi32.dll
00000000EBC2 0000020135C2 0 RegQueryValueExA
00000000EBD6 0000020135D6 0 RegOpenKeyExA
00000000EBE6 0000020135E6 0 RegCloseKey
00000000EBF4 0000020135F4 0 OpenProcessToken
00000000EC08 000002013608 0 LookupPrivilegeValueA
00000000EC20 000002013620 0 AdjustTokenPrivileges
00000000EC36 000002013636 0 kernel32.dll
00000000EC46 000002013646 0 lstrlenA
00000000EC52 000002013652 0 lstrcpynA
00000000EC5E 00000201365E 0 lstrcpyA
00000000EC6A 00000201366A 0 lstrcmpiW
00000000EC76 000002013676 0 lstrcmpiA
00000000EC82 000002013682 0 lstrcmpA
00000000EC8E 00000201368E 0 lstrcatA
00000000EC9A 00000201369A 0 WriteFile
00000000ECA6 0000020136A6 0 WaitForSingleObjectEx
00000000ECBE 0000020136BE 0 WaitForSingleObject
00000000ECD4 0000020136D4 0 VirtualProtect
00000000ECE6 0000020136E6 0 TerminateThread
00000000ECF8 0000020136F8 0 SleepEx
00000000ED02 000002013702 0 Sleep
00000000ED0A 00000201370A 0 SizeofResource
00000000ED1C 00000201371C 0 SetThreadPriority
00000000ED30 000002013730 0 SetFilePointer
00000000ED42 000002013742 0 SetEvent
00000000ED4E 00000201374E 0 ReadFile
00000000ED5A 00000201375A 0 OpenProcess
00000000ED68 000002013768 0 MultiByteToWideChar
00000000ED7E 00000201377E 0 LocalUnlock
00000000ED8C 00000201378C 0 LocalSize
00000000ED98 000002013798 0 LocalReAlloc
00000000EDA8 0000020137A8 0 LocalLock
00000000EDB4 0000020137B4 0 LocalFree
00000000EDC0 0000020137C0 0 LocalAlloc
00000000EDCE 0000020137CE 0 LoadResource
00000000EDDE 0000020137DE 0 LoadLibraryA
00000000EDEE 0000020137EE 0 GetVolumeInformationA
00000000EE06 000002013806 0 GetTickCount
00000000EE16 000002013816 0 GetThreadPriority
00000000EE2A 00000201382A 0 GetTempFileNameA
00000000EE3E 00000201383E 0 GetSystemTimeAsFileTime
00000000EE58 000002013858 0 GetProcAddress
00000000EE6A 00000201386A 0 GetModuleHandleA
00000000EE7E 00000201387E 0 GetModuleFileNameA
00000000EE94 000002013894 0 GetLastError
00000000EEA4 0000020138A4 0 GetFileSize
File pos Mem pos ID Text
======== ======= == ====
00000000EEB2 0000020138B2 0 GetExitCodeThread
00000000EEC6 0000020138C6 0 GetCurrentThreadId
00000000EEDC 0000020138DC 0 GetCurrentThread
00000000EEF0 0000020138F0 0 GetCurrentProcess
00000000EF04 000002013904 0 FormatMessageA
00000000EF16 000002013916 0 FindResourceA
00000000EF26 000002013926 0 FileTimeToSystemTime
00000000EF3E 00000201393E 0 FileTimeToLocalFileTime
00000000EF58 000002013958 0 ExitProcess
00000000EF66 000002013966 0 DeleteFileA
00000000EF74 000002013974 0 CreateThread
00000000EF84 000002013984 0 CreateMutexA
00000000EF94 000002013994 0 CreateFileA
00000000EFA2 0000020139A2 0 CreateEventA
00000000EFB2 0000020139B2 0 CopyFileA
00000000EFBE 0000020139BE 0 CloseHandle
00000000EFCA 0000020139CA 0 gdi32.dll
00000000EFD6 0000020139D6 0 TextOutA
00000000EFE2 0000020139E2 0 SelectObject
00000000EFF2 0000020139F2 0 Rectangle
00000000EFFE 0000020139FE 0 GetTextMetricsA
00000000F010 000002013A10 0 Escape
00000000F01A 000002013A1A 0 EndDoc
00000000F024 000002013A24 0 DeleteObject
00000000F034 000002013A34 0 DeleteDC
00000000F040 000002013A40 0 CreateSolidBrush
00000000F054 000002013A54 0 CreateDCA
00000000F05E 000002013A5E 0 user32.dll
00000000F06C 000002013A6C 0 CreateWindowExA
00000000F07E 000002013A7E 0 UnregisterClassA
00000000F092 000002013A92 0 TranslateMessage
00000000F0A6 000002013AA6 0 SetTimer
00000000F0B2 000002013AB2 0 SetForegroundWindow
00000000F0C8 000002013AC8 0 SetFocus
00000000F0D4 000002013AD4 0 SendMessageA
00000000F0E4 000002013AE4 0 RegisterClassA
00000000F0F6 000002013AF6 0 PostMessageA
00000000F106 000002013B06 0 PeekMessageA
00000000F116 000002013B16 0 MessageBoxA
00000000F124 000002013B24 0 LoadIconA
00000000F130 000002013B30 0 LoadCursorA
00000000F13E 000002013B3E 0 InvalidateRect
00000000F150 000002013B50 0 GetWindowTextA
00000000F162 000002013B62 0 GetWindowDC
00000000F170 000002013B70 0 GetMessageA
00000000F17E 000002013B7E 0 GetForegroundWindow
00000000F194 000002013B94 0 GetDesktopWindow
00000000F1A8 000002013BA8 0 GetClientRect
00000000F1B8 000002013BB8 0 FindWindowExA
00000000F1C8 000002013BC8 0 FindWindowA
00000000F1D6 000002013BD6 0 ExitWindowsEx
00000000F1E6 000002013BE6 0 DrawTextA
00000000F1F2 000002013BF2 0 DispatchMessageA
00000000F206 000002013C06 0 DestroyWindow
00000000F216 000002013C16 0 DefWindowProcA
00000000F228 000002013C28 0 CharUpperA
00000000F234 000002013C34 0 kernel32.dll
00000000F244 000002013C44 0 GetTickCount
00000000F252 000002013C52 0 imagehlp.dll
00000000F262 000002013C62 0 CheckSumMappedFile
File pos Mem pos ID Text
======== ======= == ====
00000000F276 000002013C76 0 winspool.drv
00000000F286 000002013C86 0 EnumPrintersA
00000000F294 000002013C94 0 user32.dll
00000000F2A2 000002013CA2 0 wsprintfA
00000000F40F 00000201400F 0 0"0*020:0B0J0R0Z0b0j0r0z0
00000000F43D 00000201403D 0 0&111
00000000F453 000002014053 0 5 6[6j6
00000000F467 000002014067 0 9"9,969@9V9\9j9
00000000F491 000002014091 0 :":G:Q:[:e:o:
00000000F4AF 0000020140AF 0 ;";n;
00000000F4BB 0000020140BB 0 <P<p<
00000000F4C5 0000020140C5 0 =Y>e>
00000000F4ED 0000020140ED 0 0#0(0
00000000F4F9 0000020140F9 0 0@1I1c1
00000000F50F 00000201410F 0 2p2x2~2
00000000F52B 00000201412B 0 3(3@3L3T3u3
00000000F545 000002014145 0 4J4~4
00000000F551 000002014151 0 4,545:5@5M5S5
00000000F587 000002014187 0 8$8=8N8c8p8
00000000F593 000002014193 0 8J9R9
00000000F59B 00000201419B 0 :9;I;_;};
00000000F5AD 0000020141AD 0 <"<*<@<X<f<
00000000F5C3 0000020141C3 0 <#=P=Y=
00000000F5D3 0000020141D3 0 =?>g>
00000000F5E9 0000020141E9 0 0L0T0_0
00000000F5F7 0000020141F7 0 1h1x1~1
00000000F61B 00000201421B 0 20282d2o2
00000000F637 000002014237 0 3%3*3J3O3q3
00000000F64D 00000201424D 0 4%424H4
00000000F65D 00000201425D 0 8!858S8\8h8o8
00000000F66D 00000201426D 0 9'939:9D9N9e9v9
00000000F697 000002014297 0 :':8:B:J:R:Z:b:j:r:
00000000F6B3 0000020142B3 0 ; ;(;X;
00000000F6BB 0000020142BB 0 ;n;s;
00000000F6D3 0000020142D3 0 < <2<?<K<X<j<r<z<
00000000F703 000002014303 0 ="=*=2=:=B=J=R=Z=b=j=r=z=
00000000F743 000002014343 0 >">*>2>:>B>J>R>Z>b>j>r>z>
00000000F783 000002014383 0 ?"?*?2?:?B?J?R?Z?b?j?r?z?
00000000F7C5 0000020143C5 0 5"50565B5K5S5f5l5
00000000F7E9 0000020143E9 0 6@6N6Y6f6k6r6w6~6
00000000F813 000002014413 0 757:7F7K7W7]7b7g7n7|7
00000000F841 000002014441 0 7.8>8L8R8a8s8y8
00000000F855 000002014455 0 8t9z9
00000000F861 000002014461 0 9):a:f:
00000000F885 000002014485 0 ;M<v<
00000000F8AD 0000020144AD 0 001E1d1
00000000F8C1 0000020144C1 0 2&3E3V3[3
00000000F8D1 0000020144D1 0 3>5Q5g5
00000000F8DD 0000020144DD 0 5#606B6J6T6e6w6
00000000F8F9 0000020144F9 0 7!7&7
00000000F905 000002014505 0 8.8K8b8s8
00000000F939 000002014539 0 :6;B;L;R;
00000000F943 000002014543 0 ;c;n;s;x;
00000000F977 000002014577 0 =B>z>
00000000F983 000002014583 0 ?*?I?V?g?}?
00000000F9C3 0000020145C3 0 2N3]3j3r3{3
00000000F9F9 0000020145F9 0 606H6_6o6
00000000FA15 000002014615 0 7D7T7x7~7
00000000FA39 000002014639 0 8!808
00000000FA41 000002014641 0 <6=g=
File pos Mem pos ID Text
======== ======= == ====
00000000FA6B 00000201466B 0 4X4)5
00000000FA7D 00000201467D 0 :*:8:a:
00000000FA85 000002014685 0 :;;W;k;
00000000FA99 000002014699 0 ;<<J<Z<
00000000FAAB 0000020146AB 0 = >?>H>e>
00000000FABD 0000020146BD 0 ?!?0?;?f?{?
00000000FADD 0000020146DD 0 0%0/050C0r0}0
00000000FAED 0000020146ED 0 2&2/272B2J2V2e2r2}2
00000000FB13 000002014713 0 3(383H3T3g3z3
00000000FB21 000002014721 0 3F5Q5g5
00000000FB35 000002014735 0 6.6A6F6r6
00000000FB4F 00000201474F 0 7"7L7
00000000FB57 000002014757 0 8 84898\8
00000000FB69 000002014769 0 9(9M9
00000000FB75 000002014775 0 :):g:l:
00000000FB83 000002014783 0 <$<\<
00000000FB9F 00000201479F 0 ?9?G?a?h?u?
00000000FBCD 0000020147CD 0 : ;+;@;U;a;j;z;
00000000FBDD 0000020147DD 0 <!<6<K<W<
00000000FBEB 0000020147EB 0 <3=A=H=d=l=
00000000FBFB 0000020147FB 0 =M>d>v>
00000000FC1F 00000201481F 0 1)1/1T1
00000000FC2F 00000201482F 0 122;2B2M2T2Y2
00000000FC3D 00000201483D 0 2e2l2q2x2
00000000FC4D 00000201484D 0 3"3<3
00000000FC81 000002014881 0 9?9R9
00000000FCA3 0000020148A3 0 =4=u=
00000000FCAD 0000020148AD 0 =?>c>
00000000FCB3 0000020148B3 0 >@?E?J?o?
00000000FCDB 0000020148DB 0 0n1s1
00000000FCF3 0000020148F3 0 3+3U3
00000000FCFF 0000020148FF 0 5&555B5K5S5
00000000FD13 000002014913 0 788C8Z8j8x8
00000000FD25 000002014925 0 989H9Q9
00000000FD37 000002014937 0 9::a:j:|:
00000000FD4B 00000201494B 0 ;/;G;
00000000FD5B 00000201495B 0 <1<C<O<[<o<z<
00000000FD79 000002014979 0 >%?*?O?_?y?
00000000FD9B 00000201499B 0 0$080C0K0]0
00000000FDB5 0000020149B5 0 1)111
00000000FDE5 0000020149E5 0 7&747B7r7w7}7r8
00000000FDFB 0000020149FB 0 8Z9d9i9o9
00000000FE27 000002014A27 0 <@<H<P<[<
00000000FE39 000002014A39 0 =[>c>v>~>G?O?
00000000FE47 000002014A47 0 ?f?p?
00000000FE61 000002014A61 0 0$0+000:0?0X0b0h0v0
00000000FE91 000002014A91 0 2$2<2J2
00000000FEAB 000002014AAB 0 4&4.494Y4g4v4
00000000FED1 000002014AD1 0 5/565?5D5l5s5
00000000FF05 000002014B05 0 6#6'6+6/63676;6?6C6
00000000FF1B 000002014B1B 0 7%787K7
00000000FF31 000002014B31 0 7)8R8W8h8y8
00000000FF45 000002014B45 0 939H9W9
00000000FF4D 000002014B4D 0 9i9q9~9
00000000FF67 000002014B67 0 :#:1:::U:h:z:
00000000FF87 000002014B87 0 ;6;?;S;\;c;o;
00000000FF9F 000002014B9F 0 <2<@<I<O<V<]<|<
00000000FFBD 000002014BBD 0 =-=8=Z=q=
00000000FFF8 000002014BF8 0 D0d0~0
000000010021 000002014C21 0 1)181G1q1
File pos Mem pos ID Text
======== ======= == ====
000000010039 000002014C39 0 2)282G2[2l2q2
00000001005F 000002014C5F 0 263c3h3
00000001006B 000002014C6B 0 4)4/464@4E4Y4
000000010089 000002014C89 0 6 6/696B6M6V6_6k6y6
0000000100F7 000002014CF7 0 :$:.:3:8:O:T:Y:p:u:z:
00000001011F 000002014D1F 0 ;%;.;6;D;R;[;l;z;
000000010144 000002014D44 0 $0(0,0
00000001016D 000002014D6D 0 1 1$1(1,1014181<1@1D1H1L1T1X1
00000001018B 000002014D8B 0 1d1h1l1p1t1x1|1
0000000101A3 000002014DA3 0 1P2T2X2\2
0000000105C9 0000020153C9 0 Q
0000000105DA 0000020153DA 0
0000000105EB 0000020153EB 0
00000001061A 00000201541A 0
000000010634 000002015434 0
0000000106A9 0000020154A9 0
000000010731 000002015531 0
000000010786 000002015586 0
0000000107D6 0000020155D6 0 PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
000000000050 000002000050 0 This program must be run under Win32
000000000270 000002000270 0 .idata
000000000298 000002000298 0 .reloc
0000000002BF 0000020002BF 0 P.rsrc
000000000884 000002001484 0 wE;\$
000000001E9F 000002002A9F 0 ~KxI[)
000000001FC8 000002002BC8 0 SOFTWARE\Borland\Delphi\RTL
000000001FE4 000002002BE4 0 FPUMaskValue
000000002031 000002002C31 0 PPRTj
0000000021AB 000002002DAB 0 YZXtp
000000002322 000002002F22 0 t=HtN
000000002744 000002003344 0 SVWUQ
000000002B00 000002003700 0 USVW1
0000000034E3 0000020040E3 0 {V,|
00000000353F 00000200413F 0 <8LaK#
000000003660 000002004260 0 /R{m6
000000003774 000002004374 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt
0000000037A8 0000020043A8 0 C:\windows\EpsStmApi.log\
000000003BFC 0000020047FC 0 WinSta0
000000003C04 000002004804 0 default
000000003C0C 00000200480C 0 DISPLAY
000000003E55 000002004A55 0 D$XPSj
000000003EEE 000002004AEE 0 D$xPj
000000003F3B 000002004B3B 0 |$,{u
000000003FF8 000002004BF8 0 WinSta0
000000004000 000002004C00 0 MyDesktop
000000004018 000002004C18 0 ATMDialog
000000004024 000002004C24 0 hello
00000000402C 000002004C2C 0 STATIC
000000004044 000002004C44 0 default
00000000405C 000002004C5C 0 Error
000000004110 000002004D10 0 Error
000000004140 000002004D40 0 $PShpM
0000000041A3 000002004DA3 0 $PVSh
0000000041D4 000002004DD4 0 %s %s
000000004480 000002005080 0 %s Error code= %d
0000000044BC 0000020050BC 0 %s Error code= %.2X
0000000044F5 0000020050F5 0 t"Jt"
000000004504 000002005104 0 Jt Jt
000000004618 000002005218 0 OpenProcessToken
00000000462C 00000200522C 0 LookupPrivilegeValue
File pos Mem pos ID Text
======== ======= == ====
000000004644 000002005244 0 AdjustTokenPrivileges
0000000047F8 0000020053F8 0 getProcessEntry:
00000000480C 00000200540C 0 SeDebugPrivilege
000000004820 000002005420 0 OpenProcess
00000000482C 00000200542C 0 LoadLibraryA
00000000483C 00000200543C 0 kernel32.dll
00000000484C 00000200544C 0 GetExitCodeThread
000000004860 000002005460 0 VirtualFreeEx
000000004B38 000002005738 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000004B5C 00000200575C 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ)
000000004B88 000002005788 0 EPP Complete LOCK
000000004B9C 00000200579C 0 EPP Complete ENCODE_DECODE
000000004C58 000002005858 0 SVWUQ
000000004CA2 0000020058A2 0 $ZXu>
000000004D16 000002005916 0 ~7hhY
000000004D5C 00000200595C 0 OASYS.dll
000000004D68 000002005968 0 OasPostMessage
000000004E38 000002005A38 0 DBDDevOpen
000000004E44 000002005A44 0 DbdDevRegisterCallback
000000004E5C 000002005A5C 0 DbdDevLock
000000004E68 000002005A68 0 DbdDevUnregisterCallback
000000004E84 000002005A84 0 DBDDevClose
000000004F00 000002005B00 0 DbdDevUnlock
000000004F10 000002005B10 0 bdDevUnregisterCallback
000000004F28 000002005B28 0 DBDDevClose
000000005010 000002005C10 0 DbdDevAPI.dll
000000005020 000002005C20 0 DbdDevOpen
00000000502C 000002005C2C 0 DbdDevClose
000000005038 000002005C38 0 DbdDevGetInfo
000000005048 000002005C48 0 DbdDevRegisterCallback
000000005060 000002005C60 0 DbdDevUnregisterCallback
00000000507C 000002005C7C 0 DbdDevLock
000000005088 000002005C88 0 DbdDevUnlock
000000005098 000002005C98 0 DbdDevExecute
0000000051C8 000002005DC8 0 AMI function don
0000000051D9 000002005DD9 0 t return in 1 sec
0000000053F4 000002005FF4 0 RECEIPT
0000000053FC 000002005FFC 0 WINSPOOL
000000005408 000002006008 0 CreateDC
000000005414 000002006014 0 hello
00000000541C 00000200601C 0 escape
000000005424 000002006024 0 TextOut
00000000542C 00000200602C 0 enddoc
0000000054E4 0000020060E4 0 DbdDevExecute(EPP4_COPY_KEY)
000000005504 000002006104 0 EPP4_COPY_KEY TimeOut
000000005620 000002006220 0 DbdDevExecute(EPP4_LOAD_KEY)
000000005640 000002006240 0 EPP4_LOAD_KEY TimeOut
0000000056F0 0000020062F0 0 DbdDevExecute(EPP4_DELETE_KEY)
000000005710 000002006310 0 EPP4_DELETE_KEY TimeOut
00000000583C 00000200643C 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000005860 000002006460 0 EPP_Encrypt TimeOut
000000005964 000002006564 0 SVWUQ
000000005C3C 00000200683C 0 LocalAlloc
000000005C48 000002006848 0 LocalLock
00000000643A 00000200703A 0 P CNu
0000000066C4 0000020072C4 0 SVWUQ
000000006A8B 00000200768B 0 u7IBF
000000006B1A 00000200771A 0 I+NBu
000000006EA8 000002007AA8 0 %.2d/%.2d/%.2d %.2d:%.2d
000000007024 000002007C24 0 tdHuaj
File pos Mem pos ID Text
======== ======= == ====
00000000709C 000002007C9C 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI)
0000000070CC 000002007CCC 0 t LOCK EPP
0000000070D8 000002007CD8 0 RECEIPT_PRINTER_START_GDI
0000000070F4 000002007CF4 0 DbdDevExecute(RECEIPT_PRINTER_EJECT)
000000007278 000002007E78 0 DbdDevExecute(AFD_DISPENCE)
000000007294 000002007E94 0 CDM Complete LOCK
0000000072A8 000002007EA8 0 DbdDevExecute(AFD_PRESENT)
0000000072C4 000002007EC4 0 DbdDevExecute(AFD_RESTORE)
0000000074A0 0000020080A0 0 SeShutdownPrivilege
0000000077FC 0000020083FC 0 kernel32
000000007808 000002008408 0 DeleteFileA
000000007814 000002008414 0 FreeLibrary
000000007820 000002008420 0 GetModuleHandleA
000000007834 000002008434 0 CreateFileA
000000007840 000002008440 0 Sleep
000000007848 000002008448 0 WriteFile
000000007854 000002008454 0 CloseHandle
000000007860 000002008460 0 LocalFree
00000000786C 00000200846C 0 LoadLibraryA
00000000787C 00000200847C 0 user32
000000007884 000002008484 0 ExitWindowsEx
000000007894 000002008494 0 SeShutdownPrivilege
000000007A60 000002008660 0 SVWUQ
000000007B74 000002008774 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete
000000007BA0 0000020087A0 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ)
000000007ED8 000002008AD8 0 %.2X%.2X
000000007EE4 000002008AE4 0 Request Code: %.6d
000000007EF7 000002008AF7 0 Enter Responce
000000007F08 000002008B08 0 Autorization
000000007F18 000002008B18 0 1..4 - dispense cassete
000000007F30 000002008B30 0 9 - Uninstall
000000007F3E 000002008B3E 0 0 - Exit
000000007F48 000002008B48 0 Enter Command
000000008154 000002008D54 0 Diebold:OGuiFrame
000000008168 000002008D68 0 Enter Password
00000000817C 000002008D7C 0 STATIC
00000000818C 000002008D8C 0 Supply Manager
00000000819C 000002008D9C 0 Pripnt
0000000081A4 000002008DA4 0 View All Counts
0000000083BC 000002008FBC 0 DbdDevExecute(RESET)
0000000083D4 000002008FD4 0 DBDDEV_LOCK(CRW)
0000000083E8 000002008FE8 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
000000008410 000002009010 0 MCRW_ACCEPT_INSERTION
000000008455 000002009055 0 ;C*v=
000000008E45 000002009A45 0 L0(:L0Sv<V
000000008F94 000002009B94 0 DbdDevExecute(EPP4_LOAD_KEY)
000000008FB4 000002009BB4 0 EPP4_LOAD_KEY TimeOut
000000009088 000002009C88 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN)
0000000090BC 000002009CBC 0 EPP4_COMPUTE_VERIFICATION_PATTERN
0000000093C6 000002009FC6 0 :V(t
000000009848 00000200A448 0 LoadKey %.2d @ %.2d - %.2d
000000009868 00000200A468 0 LoadKey %.2d - %.2d
000000009880 00000200A480 0 CopyKey %.2d -> %.2d - %.2d
0000000098A0 00000200A4A0 0 SVWUQ
000000009934 00000200A534 0 ComID %.2d, %X, %X - %.2d,
000000009B1C 00000200A71C 0 No Transactions
000000009B2C 00000200A72C 0 No Cards (PINs)
000000009D94 00000200A994 0 Transactions %d
000000009DA5 00000200A9A5 0 Cards %d
000000009DB9 00000200A9B9 0 Non Local %d
File pos Mem pos ID Text
======== ======= == ====
000000009DCD 00000200A9CD 0 MAC_ID %d
000000009DE1 00000200A9E1 0 InstrumentID %d
000000009ED8 00000200AAD8 0 Grab mode %d
000000009EE8 00000200AAE8 0 Deco mode %d
000000009EF9 00000200AAF9 0 Key mode %d
000000009F0A 00000200AB0A 0 Use locals %d
000000009F1B 00000200AB1B 0 Auto delete %d
000000009F2C 00000200AB2C 0 ReturnOnCode %d
000000009F78 00000200AB78 0 %d.%d.%d.%d : %d
00000000A09C 00000200AC9C 0 SeDebugPrivilege
00000000A1E4 00000200ADE4 0 SeDebugPrivilege
00000000A2BC 00000200AEBC 0 Bound Import error
00000000A2D0 00000200AED0 0 Bound Import GetProcAddress
00000000A2EC 00000200AEEC 0 EPP4API.DLL
00000000A2F8 00000200AEF8 0 EppInit
00000000A300 00000200AF00 0 EppAttach
00000000A30C 00000200AF0C 0 EppLock
00000000A314 00000200AF14 0 CloseComPort
00000000A324 00000200AF24 0 EppExchange
00000000A428 00000200B028 0 19200
00000000A598 00000200B198 0 version
00000000A5A0 00000200B1A0 0 SOFTWARE\Diebold\Agilis 91x
00000000A5BC 00000200B1BC 0 Product Version
00000000A5CC 00000200B1CC 0 SOFTWARE\Diebold\Agilis 91x Core
00000000A64C 00000200B24C 0 %s%.2X
00000000A66E 00000200B26E 0 tPj 3
00000000A798 00000200B398 0 version
00000000A7A0 00000200B3A0 0 SOFTWARE\Diebold\AMI for Opteva
00000000A7C0 00000200B3C0 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva
00000000A7F4 00000200B3F4 0 SOFTWARE\Diebold\Agilis XFS for Opteva
00000000A81C 00000200B41C 0 Agilis: %s
00000000A82D 00000200B42D 0 AMI: %s
00000000A83B 00000200B43B 0 XFS: %s
00000000A849 00000200B449 0 Firmware:
00000000A978 00000200B578 0 DbdDevExecute(MCRW_CHIP_IO)
00000000A994 00000200B594 0 TimeOut MCRW_CHIP_IO
00000000AB60 00000200B760 0 Invalid Sim Response
00000000ACA4 00000200B8A4 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
00000000AD68 00000200B968 0 DbdDevExecute(MCRW_POWERON)
00000000AD84 00000200B984 0 DbdDevExecute(MCRW_POWEROFF)
00000000AE0C 00000200BA0C 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION)
00000000AEA8 00000200BAA8 0 DbdDevExecute(MCRW_MCRW_Eject)
00000000B100 00000200BD00 0 TimeOut Reset
00000000B110 00000200BD10 0 Incorrect FIle Size
00000000B4C0 00000200C0C0 0 TimeOut Reset
00000000B9A7 00000200C5A7 0 r AOu
00000000BBA0 00000200C7A0 0 kernel32.dll
00000000BBB0 00000200C7B0 0 CreateFileA
00000000BBBC 00000200C7BC 0 GetFileTime
00000000BBC8 00000200C7C8 0 SetFileTime
00000000BBD4 00000200C7D4 0 GetFileSize
00000000BBE0 00000200C7E0 0 ReadFile
00000000BBEC 00000200C7EC 0 WriteFile
00000000BBF8 00000200C7F8 0 SetFilePointer
00000000BC08 00000200C808 0 CloseHandle
00000000BC14 00000200C814 0 LocalAlloc
00000000BC20 00000200C820 0 LocalFree
00000000BC2C 00000200C82C 0 ExitThread
00000000BC38 00000200C838 0 VirtualFree
00000000BC44 00000200C844 0 Sleep
File pos Mem pos ID Text
======== ======= == ====
00000000BC4C 00000200C84C 0 DeleteFileA
00000000BD10 00000200C910 0 SeDebugPrivilege
00000000BE44 00000200CA44 0 Check sum error
00000000BE54 00000200CA54 0 Update
00000000BE5C 00000200CA5C 0 Not executable file
00000000BED1 00000200CAD1 0 |$0jd
00000000C14F 00000200CD4F 0 $ZXrM
00000000C156 00000200CD56 0 ZX|G3
00000000C4EC 00000200D0EC 0 c:\Program Files\Diebold\Abc\message.trc
00000000C518 00000200D118 0 c:\Diebold\css\message.trc
00000000C534 00000200D134 0 FileSize %d
00000000C545 00000200D145 0 Transactions %d
00000000C556 00000200D156 0 ComKeys %d
00000000C714 00000200D314 0 hook.LoadLibrary:
00000000C728 00000200D328 0 GetProcAddress
00000000C738 00000200D338 0 hook.VirtualProtect
00000000C8E4 00000200D4E4 0 mode6main
00000000C8F8 00000200D4F8 0 ws2_32.dll
00000000C904 00000200D504 0 WSASend
00000000CCE8 00000200D8E8 0 Enter command:
00000000D3B8 00000200DFB8 0 E PWS
00000000D476 00000200E076 0 8NTFS
00000000D6E4 00000200E2E4 0 DbdDevRegisterCallback
00000000D6FC 00000200E2FC 0 DbdDevAPI.dll
00000000D70C 00000200E30C 0 EppExchange
00000000D718 00000200E318 0 EPP4API.dll
00000000D724 00000200E324 0 DbdDevExecute
00000000D752 00000200E352 0 Pj@SV
00000000D7B4 00000200E3B4 0 VProtect1
00000000D7C4 00000200E3C4 0 SVWUQ
00000000D870 00000200E470 0 Begin
00000000D878 00000200E478 0 Error
00000000D884 00000200E484 0 t decode const
00000000D900 00000200E500 0 mu.exe
00000000D989 00000200E589 0 33333
00000000D9AB 00000200E5AB 0 UUUU3
00000000DAFD 00000200E6FD 0 VWUSQ
00000000DB45 00000200E745 0 33333
00000000DB67 00000200E767 0 UUUU3
00000000DC1B 00000200E81B 0 UUUU3
00000000DC79 00000200E879 0 VWUSQ
00000000DD30 00000200E930 0 UUUU3
00000000DFE0 00000200EBE0 0 dfd6jdk
00000000DFE8 00000200EBE8 0 kdu32rbs
00000000E04C 00000200F04C 0 Error
00000000E054 00000200F054 0 Runtime error at 00000000
00000000E074 00000200F074 0 0123456789ABCDEF
00000000E0B0 00000200F0B0 0 SeTtInGs6.34.3
00000000E1C2 00000200F1C2 0 <o:o:_;OPO
00000000E1D1 00000200F1D1 0 OLONO
00000000E1DD 00000200F1DD 0 O!O%O
00000000E394 00000200F394 0 <4,$?7/'
00000000E3DA 00000200F3DA 0 !"#$%&'()*+,-./012345678
00000000E425 00000200F425 0 (3-!0
00000000E42C 00000200F42C 0 ,1'8"5
00000000E954 000002013354 0 kernel32.dll
00000000E964 000002013364 0 DeleteCriticalSection
00000000E97C 00000201337C 0 LeaveCriticalSection
00000000E994 000002013394 0 EnterCriticalSection
00000000E9AC 0000020133AC 0 InitializeCriticalSection
File pos Mem pos ID Text
======== ======= == ====
00000000E9C8 0000020133C8 0 VirtualFree
00000000E9D6 0000020133D6 0 VirtualAlloc
00000000E9E6 0000020133E6 0 LocalFree
00000000E9F2 0000020133F2 0 LocalAlloc
00000000EA00 000002013400 0 GetVersion
00000000EA0E 00000201340E 0 GetCurrentThreadId
00000000EA24 000002013424 0 GetThreadLocale
00000000EA36 000002013436 0 GetStartupInfoA
00000000EA48 000002013448 0 GetLocaleInfoA
00000000EA5A 00000201345A 0 GetCommandLineA
00000000EA6C 00000201346C 0 FreeLibrary
00000000EA7A 00000201347A 0 ExitProcess
00000000EA88 000002013488 0 CreateThread
00000000EA98 000002013498 0 WriteFile
00000000EAA4 0000020134A4 0 UnhandledExceptionFilter
00000000EAC0 0000020134C0 0 RtlUnwind
00000000EACC 0000020134CC 0 RaiseException
00000000EADE 0000020134DE 0 GetStdHandle
00000000EAEC 0000020134EC 0 user32.dll
00000000EAFA 0000020134FA 0 GetKeyboardType
00000000EB0C 00000201350C 0 MessageBoxA
00000000EB18 000002013518 0 advapi32.dll
00000000EB28 000002013528 0 RegQueryValueExA
00000000EB3C 00000201353C 0 RegOpenKeyExA
00000000EB4C 00000201354C 0 RegCloseKey
00000000EB58 000002013558 0 kernel32.dll
00000000EB68 000002013568 0 TlsSetValue
00000000EB76 000002013576 0 TlsGetValue
00000000EB84 000002013584 0 TlsFree
00000000EB8E 00000201358E 0 TlsAlloc
00000000EB9A 00000201359A 0 LocalFree
00000000EBA6 0000020135A6 0 LocalAlloc
00000000EBB2 0000020135B2 0 advapi32.dll
00000000EBC2 0000020135C2 0 RegQueryValueExA
00000000EBD6 0000020135D6 0 RegOpenKeyExA
00000000EBE6 0000020135E6 0 RegCloseKey
00000000EBF4 0000020135F4 0 OpenProcessToken
00000000EC08 000002013608 0 LookupPrivilegeValueA
00000000EC20 000002013620 0 AdjustTokenPrivileges
00000000EC36 000002013636 0 kernel32.dll
00000000EC46 000002013646 0 lstrlenA
00000000EC52 000002013652 0 lstrcpynA
00000000EC5E 00000201365E 0 lstrcpyA
00000000EC6A 00000201366A 0 lstrcmpiW
00000000EC76 000002013676 0 lstrcmpiA
00000000EC82 000002013682 0 lstrcmpA
00000000EC8E 00000201368E 0 lstrcatA
00000000EC9A 00000201369A 0 WriteFile
00000000ECA6 0000020136A6 0 WaitForSingleObjectEx
00000000ECBE 0000020136BE 0 WaitForSingleObject
00000000ECD4 0000020136D4 0 VirtualProtect
00000000ECE6 0000020136E6 0 TerminateThread
00000000ECF8 0000020136F8 0 SleepEx
00000000ED02 000002013702 0 Sleep
00000000ED0A 00000201370A 0 SizeofResource
00000000ED1C 00000201371C 0 SetThreadPriority
00000000ED30 000002013730 0 SetFilePointer
00000000ED42 000002013742 0 SetEvent
00000000ED4E 00000201374E 0 ReadFile
00000000ED5A 00000201375A 0 OpenProcess
File pos Mem pos ID Text
======== ======= == ====
00000000ED68 000002013768 0 MultiByteToWideChar
00000000ED7E 00000201377E 0 LocalUnlock
00000000ED8C 00000201378C 0 LocalSize
00000000ED98 000002013798 0 LocalReAlloc
00000000EDA8 0000020137A8 0 LocalLock
00000000EDB4 0000020137B4 0 LocalFree
00000000EDC0 0000020137C0 0 LocalAlloc
00000000EDCE 0000020137CE 0 LoadResource
00000000EDDE 0000020137DE 0 LoadLibraryA
00000000EDEE 0000020137EE 0 GetVolumeInformationA
00000000EE06 000002013806 0 GetTickCount
00000000EE16 000002013816 0 GetThreadPriority
00000000EE2A 00000201382A 0 GetTempFileNameA
00000000EE3E 00000201383E 0 GetSystemTimeAsFileTime
00000000EE58 000002013858 0 GetProcAddress
00000000EE6A 00000201386A 0 GetModuleHandleA
00000000EE7E 00000201387E 0 GetModuleFileNameA
00000000EE94 000002013894 0 GetLastError
00000000EEA4 0000020138A4 0 GetFileSize
00000000EEB2 0000020138B2 0 GetExitCodeThread
00000000EEC6 0000020138C6 0 GetCurrentThreadId
00000000EEDC 0000020138DC 0 GetCurrentThread
00000000EEF0 0000020138F0 0 GetCurrentProcess
00000000EF04 000002013904 0 FormatMessageA
00000000EF16 000002013916 0 FindResourceA
00000000EF26 000002013926 0 FileTimeToSystemTime
00000000EF3E 00000201393E 0 FileTimeToLocalFileTime
00000000EF58 000002013958 0 ExitProcess
00000000EF66 000002013966 0 DeleteFileA
00000000EF74 000002013974 0 CreateThread
00000000EF84 000002013984 0 CreateMutexA
00000000EF94 000002013994 0 CreateFileA
00000000EFA2 0000020139A2 0 CreateEventA
00000000EFB2 0000020139B2 0 CopyFileA
00000000EFBE 0000020139BE 0 CloseHandle
00000000EFCA 0000020139CA 0 gdi32.dll
00000000EFD6 0000020139D6 0 TextOutA
00000000EFE2 0000020139E2 0 SelectObject
00000000EFF2 0000020139F2 0 Rectangle
00000000EFFE 0000020139FE 0 GetTextMetricsA
00000000F010 000002013A10 0 Escape
00000000F01A 000002013A1A 0 EndDoc
00000000F024 000002013A24 0 DeleteObject
00000000F034 000002013A34 0 DeleteDC
00000000F040 000002013A40 0 CreateSolidBrush
00000000F054 000002013A54 0 CreateDCA
00000000F05E 000002013A5E 0 user32.dll
00000000F06C 000002013A6C 0 CreateWindowExA
00000000F07E 000002013A7E 0 UnregisterClassA
00000000F092 000002013A92 0 TranslateMessage
00000000F0A6 000002013AA6 0 SetTimer
00000000F0B2 000002013AB2 0 SetForegroundWindow
00000000F0C8 000002013AC8 0 SetFocus
00000000F0D4 000002013AD4 0 SendMessageA
00000000F0E4 000002013AE4 0 RegisterClassA
00000000F0F6 000002013AF6 0 PostMessageA
00000000F106 000002013B06 0 PeekMessageA
00000000F116 000002013B16 0 MessageBoxA
00000000F124 000002013B24 0 LoadIconA
00000000F130 000002013B30 0 LoadCursorA
File pos Mem pos ID Text
======== ======= == ====
00000000F13E 000002013B3E 0 InvalidateRect
00000000F150 000002013B50 0 GetWindowTextA
00000000F162 000002013B62 0 GetWindowDC
00000000F170 000002013B70 0 GetMessageA
00000000F17E 000002013B7E 0 GetForegroundWindow
00000000F194 000002013B94 0 GetDesktopWindow
00000000F1A8 000002013BA8 0 GetClientRect
00000000F1B8 000002013BB8 0 FindWindowExA
00000000F1C8 000002013BC8 0 FindWindowA
00000000F1D6 000002013BD6 0 ExitWindowsEx
00000000F1E6 000002013BE6 0 DrawTextA
00000000F1F2 000002013BF2 0 DispatchMessageA
00000000F206 000002013C06 0 DestroyWindow
00000000F216 000002013C16 0 DefWindowProcA
00000000F228 000002013C28 0 CharUpperA
00000000F234 000002013C34 0 kernel32.dll
00000000F244 000002013C44 0 GetTickCount
00000000F252 000002013C52 0 imagehlp.dll
00000000F262 000002013C62 0 CheckSumMappedFile
00000000F276 000002013C76 0 winspool.drv
00000000F286 000002013C86 0 EnumPrintersA
00000000F294 000002013C94 0 user32.dll
00000000F2A2 000002013CA2 0 wsprintfA
00000000F40F 00000201400F 0 0"0*020:0B0J0R0Z0b0j0r0z0
00000000F43D 00000201403D 0 0&111
00000000F453 000002014053 0 5 6[6j6
00000000F467 000002014067 0 9"9,969@9V9\9j9
00000000F491 000002014091 0 :":G:Q:[:e:o:
00000000F4AF 0000020140AF 0 ;";n;
00000000F4BB 0000020140BB 0 <P<p<
00000000F4C5 0000020140C5 0 =Y>e>
00000000F4ED 0000020140ED 0 0#0(0
00000000F4F9 0000020140F9 0 0@1I1c1
00000000F50F 00000201410F 0 2p2x2~2
00000000F52B 00000201412B 0 3(3@3L3T3u3
00000000F545 000002014145 0 4J4~4
00000000F551 000002014151 0 4,545:5@5M5S5
00000000F587 000002014187 0 8$8=8N8c8p8
00000000F593 000002014193 0 8J9R9
00000000F59B 00000201419B 0 :9;I;_;};
00000000F5AD 0000020141AD 0 <"<*<@<X<f<
00000000F5C3 0000020141C3 0 <#=P=Y=
00000000F5D3 0000020141D3 0 =?>g>
00000000F5E9 0000020141E9 0 0L0T0_0
00000000F5F7 0000020141F7 0 1h1x1~1
00000000F61B 00000201421B 0 20282d2o2
00000000F637 000002014237 0 3%3*3J3O3q3
00000000F64D 00000201424D 0 4%424H4
00000000F65D 00000201425D 0 8!858S8\8h8o8
00000000F66D 00000201426D 0 9'939:9D9N9e9v9
00000000F697 000002014297 0 :':8:B:J:R:Z:b:j:r:
00000000F6B3 0000020142B3 0 ; ;(;X;
00000000F6BB 0000020142BB 0 ;n;s;
00000000F6D3 0000020142D3 0 < <2<?<K<X<j<r<z<
00000000F703 000002014303 0 ="=*=2=:=B=J=R=Z=b=j=r=z=
00000000F743 000002014343 0 >">*>2>:>B>J>R>Z>b>j>r>z>
00000000F783 000002014383 0 ?"?*?2?:?B?J?R?Z?b?j?r?z?
00000000F7C5 0000020143C5 0 5"50565B5K5S5f5l5
00000000F7E9 0000020143E9 0 6@6N6Y6f6k6r6w6~6
00000000F813 000002014413 0 757:7F7K7W7]7b7g7n7|7
File pos Mem pos ID Text
======== ======= == ====
00000000F841 000002014441 0 7.8>8L8R8a8s8y8
00000000F855 000002014455 0 8t9z9
00000000F861 000002014461 0 9):a:f:
00000000F885 000002014485 0 ;M<v<
00000000F8AD 0000020144AD 0 001E1d1
00000000F8C1 0000020144C1 0 2&3E3V3[3
00000000F8D1 0000020144D1 0 3>5Q5g5
00000000F8DD 0000020144DD 0 5#606B6J6T6e6w6
00000000F8F9 0000020144F9 0 7!7&7
00000000F905 000002014505 0 8.8K8b8s8
00000000F939 000002014539 0 :6;B;L;R;
00000000F943 000002014543 0 ;c;n;s;x;
00000000F977 000002014577 0 =B>z>
00000000F983 000002014583 0 ?*?I?V?g?}?
00000000F9C3 0000020145C3 0 2N3]3j3r3{3
00000000F9F9 0000020145F9 0 606H6_6o6
00000000FA15 000002014615 0 7D7T7x7~7
00000000FA39 000002014639 0 8!808
00000000FA41 000002014641 0 <6=g=
00000000FA6B 00000201466B 0 4X4)5
00000000FA7D 00000201467D 0 :*:8:a:
00000000FA85 000002014685 0 :;;W;k;
00000000FA99 000002014699 0 ;<<J<Z<
00000000FAAB 0000020146AB 0 = >?>H>e>
00000000FABD 0000020146BD 0 ?!?0?;?f?{?
00000000FADD 0000020146DD 0 0%0/050C0r0}0
00000000FAED 0000020146ED 0 2&2/272B2J2V2e2r2}2
00000000FB13 000002014713 0 3(383H3T3g3z3
00000000FB21 000002014721 0 3F5Q5g5
00000000FB35 000002014735 0 6.6A6F6r6
00000000FB4F 00000201474F 0 7"7L7
00000000FB57 000002014757 0 8 84898\8
00000000FB69 000002014769 0 9(9M9
00000000FB75 000002014775 0 :):g:l:
00000000FB83 000002014783 0 <$<\<
00000000FB9F 00000201479F 0 ?9?G?a?h?u?
00000000FBCD 0000020147CD 0 : ;+;@;U;a;j;z;
00000000FBDD 0000020147DD 0 <!<6<K<W<
00000000FBEB 0000020147EB 0 <3=A=H=d=l=
00000000FBFB 0000020147FB 0 =M>d>v>
00000000FC1F 00000201481F 0 1)1/1T1
00000000FC2F 00000201482F 0 122;2B2M2T2Y2
00000000FC3D 00000201483D 0 2e2l2q2x2
00000000FC4D 00000201484D 0 3"3<3
00000000FC81 000002014881 0 9?9R9
00000000FCA3 0000020148A3 0 =4=u=
00000000FCAD 0000020148AD 0 =?>c>
00000000FCB3 0000020148B3 0 >@?E?J?o?
00000000FCDB 0000020148DB 0 0n1s1
00000000FCF3 0000020148F3 0 3+3U3
00000000FCFF 0000020148FF 0 5&555B5K5S5
00000000FD13 000002014913 0 788C8Z8j8x8
00000000FD25 000002014925 0 989H9Q9
00000000FD37 000002014937 0 9::a:j:|:
00000000FD4B 00000201494B 0 ;/;G;
00000000FD5B 00000201495B 0 <1<C<O<[<o<z<
00000000FD79 000002014979 0 >%?*?O?_?y?
00000000FD9B 00000201499B 0 0$080C0K0]0
00000000FDB5 0000020149B5 0 1)111
00000000FDE5 0000020149E5 0 7&747B7r7w7}7r8
File pos Mem pos ID Text
======== ======= == ====
00000000FDFB 0000020149FB 0 8Z9d9i9o9
00000000FE27 000002014A27 0 <@<H<P<[<
00000000FE39 000002014A39 0 =[>c>v>~>G?O?
00000000FE47 000002014A47 0 ?f?p?
00000000FE61 000002014A61 0 0$0+000:0?0X0b0h0v0
00000000FE91 000002014A91 0 2$2<2J2
00000000FEAB 000002014AAB 0 4&4.494Y4g4v4
00000000FED1 000002014AD1 0 5/565?5D5l5s5
00000000FF05 000002014B05 0 6#6'6+6/63676;6?6C6
00000000FF1B 000002014B1B 0 7%787K7
00000000FF31 000002014B31 0 7)8R8W8h8y8
00000000FF45 000002014B45 0 939H9W9
00000000FF4D 000002014B4D 0 9i9q9~9
00000000FF67 000002014B67 0 :#:1:::U:h:z:
00000000FF87 000002014B87 0 ;6;?;S;\;c;o;
00000000FF9F 000002014B9F 0 <2<@<I<O<V<]<|<
00000000FFBD 000002014BBD 0 =-=8=Z=q=
00000000FFF8 000002014BF8 0 D0d0~0
000000010021 000002014C21 0 1)181G1q1
000000010039 000002014C39 0 2)282G2[2l2q2
00000001005F 000002014C5F 0 263c3h3
00000001006B 000002014C6B 0 4)4/464@4E4Y4
000000010089 000002014C89 0 6 6/696B6M6V6_6k6y6
0000000100F7 000002014CF7 0 :$:.:3:8:O:T:Y:p:u:z:
00000001011F 000002014D1F 0 ;%;.;6;D;R;[;l;z;
000000010144 000002014D44 0 $0(0,0
00000001016D 000002014D6D 0 1 1$1(1,1014181<1@1D1H1L1T1X1
00000001018B 000002014D8B 0 1d1h1l1p1t1x1|1
0000000101A3 000002014DA3 0 1P2T2X2\2
0000000105C9 0000020153C9 0 Q
0000000105DA 0000020153DA 0
0000000105EB 0000020153EB 0
00000001061A 00000201541A 0
000000010634 000002015434 0
0000000106A9 0000020154A9 0
000000010731 000002015531 0
000000010786 000002015586 0
0000000107D6 0000020155D6 0 PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
=== DOWNLOAD ===
Mirror provided by vx-underground.org, thx!