.- - -----÷M÷E÷N÷U÷------------------------------------------------------------- --- ---- -------------.
! WALL ! STATS ! GOODIES ! YARA ! FAQ ! RSS ! EMV !
`-------------- - --- ---------- -------- -------- -------- -------- ----------------- - ---- ---- --'
ATM MALWARE NOTICE
b51973c530802ae19df8ac4d9643fc3317952242d9d42f951e094c72d730dd66
Date...........: 2012-05-17
Family.........: Trojan.Skimer.17
File name......: V629IT.DLL
File size......: 62.00 KB
Type file......: DLL/Windows
Virscan........: VT - HA
Entropy:
Binary Histogram:
=== SCREENSHOT ===
=== PEDUMP REPORT ===
=== MZ Header ===
signature: "MZ"
bytes_in_last_block: 80 0x50
blocks_in_file: 2 2
num_relocs: 0 0
header_paragraphs: 4 4
min_extra_paragraphs: 15 0xf
max_extra_paragraphs: 65535 0xffff
ss: 0 0
sp: 184 0xb8
checksum: 0 0
ip: 0 0
cs: 0 0
reloc_table_offset: 64 0x40
overlay_number: 26 0x1a
reserved0: 0 0
oem_id: 0 0
oem_info: 0 0
reserved2: 0 0
reserved3: 0 0
reserved4: 0 0
reserved5: 0 0
reserved6: 0 0
lfanew: 256 0x100
=== DOS STUB ===
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..|
00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus|
00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W|
00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........|
00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
=== PE Header ===
signature: "PE\x00\x00"
# IMAGE_FILE_HEADER:
Machine: 332 0x14c x86
NumberOfSections: 6 6
TimeDateStamp: "1992-06-19 22:22:17"
PointerToSymbolTable: 0 0
NumberOfSymbols: 0 0
SizeOfOptionalHeader: 224 0xe0
Characteristics: 41358 0xa18e EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED
LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO
32BIT_MACHINE, DLL, BYTES_REVERSED_HI
# IMAGE_OPTIONAL_HEADER32:
Magic: 267 0x10b 32-bit executable
LinkerVersion: 2.25
SizeOfCode: 53248 0xd000
SizeOfInitializedData: 9216 0x2400
SizeOfUninitializedData: 0 0
AddressOfEntryPoint: 56744 0xdda8
BaseOfCode: 4096 0x1000
BaseOfData: 57344 0xe000
ImageBase: 33554432 0x2000000
SectionAlignment: 4096 0x1000
FileAlignment: 512 0x200
OperatingSystemVersion: 4.0
ImageVersion: 0.0
SubsystemVersion: 4.0
Reserved1: 0 0
SizeOfImage: 86016 0x15000
SizeOfHeaders: 1024 0x400
CheckSum: 0 0
Subsystem: 2 2 WINDOWS_GUI
DllCharacteristics: 1 1 0x01
SizeOfStackReserve: 0 0
SizeOfStackCommit: 0 0
SizeOfHeapReserve: 1048576 0x100000
SizeOfHeapCommit: 4096 0x1000
LoaderFlags: 0 0
NumberOfRvaAndSizes: 16 0x10
=== DATA DIRECTORY ===
EXPORT rva:0x 0 size:0x 0
IMPORT rva:0x 12000 size:0x c94
RESOURCE rva:0x 14000 size:0x 200
EXCEPTION rva:0x 0 size:0x 0
SECURITY rva:0x 0 size:0x 0
BASERELOC rva:0x 13000 size:0x d08
DEBUG rva:0x 0 size:0x 0
ARCHITECTURE rva:0x 0 size:0x 0
GLOBALPTR rva:0x 0 size:0x 0
TLS rva:0x 0 size:0x 0
LOAD_CONFIG rva:0x 0 size:0x 0
Bound_IAT rva:0x 0 size:0x 0
IAT rva:0x 0 size:0x 0
Delay_IAT rva:0x 0 size:0x 0
CLR_Header rva:0x 0 size:0x 0
rva:0x 0 size:0x 0
=== SECTIONS ===
NAME RVA VSZ RAW_SZ RAW_PTR nREL REL_PTR nLINE LINE_PTR FLAGS
CODE 1000 cfa8 d000 400 0 0 0 0 60000020 R-X CODE
DATA e000 4d0 600 d400 0 0 0 0 c0000040 RW- IDATA
BSS f000 2df1 0 da00 0 0 0 0 c0000000 RW-
.idata 12000 c94 e00 da00 0 0 0 0 c0000040 RW- IDATA
.reloc 13000 d08 e00 e800 0 0 0 0 50000040 R-- IDATA SHARED
.rsrc 14000 200 200 f600 0 0 0 0 50000040 R-- IDATA SHARED
=== RESOURCES ===
FILE_OFFSET CP LANG SIZE TYPE NAME
0xf6b0 0 0 16 RCDATA DVCLAL
0xf6c0 0 0 60 RCDATA PACKAGEINFO
=== IMPORTS ===
MODULE_NAME HINT ORD FUNCTION_NAME
kernel32.dll 0 DeleteCriticalSection
kernel32.dll 0 LeaveCriticalSection
kernel32.dll 0 EnterCriticalSection
kernel32.dll 0 InitializeCriticalSection
kernel32.dll 0 VirtualFree
kernel32.dll 0 VirtualAlloc
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
kernel32.dll 0 GetVersion
kernel32.dll 0 GetCurrentThreadId
kernel32.dll 0 GetThreadLocale
kernel32.dll 0 GetStartupInfoA
kernel32.dll 0 GetLocaleInfoA
kernel32.dll 0 GetCommandLineA
kernel32.dll 0 FreeLibrary
kernel32.dll 0 ExitProcess
kernel32.dll 0 CreateThread
kernel32.dll 0 WriteFile
kernel32.dll 0 UnhandledExceptionFilter
kernel32.dll 0 RtlUnwind
kernel32.dll 0 RaiseException
kernel32.dll 0 GetStdHandle
user32.dll 0 GetKeyboardType
user32.dll 0 MessageBoxA
advapi32.dll 0 RegQueryValueExA
advapi32.dll 0 RegOpenKeyExA
advapi32.dll 0 RegCloseKey
kernel32.dll 0 TlsSetValue
kernel32.dll 0 TlsGetValue
kernel32.dll 0 TlsFree
kernel32.dll 0 TlsAlloc
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
advapi32.dll 0 RegQueryValueExA
advapi32.dll 0 RegOpenKeyExA
advapi32.dll 0 RegCloseKey
advapi32.dll 0 OpenProcessToken
advapi32.dll 0 LookupPrivilegeValueA
advapi32.dll 0 AdjustTokenPrivileges
kernel32.dll 0 lstrlenA
kernel32.dll 0 lstrcpynA
kernel32.dll 0 lstrcpyA
kernel32.dll 0 lstrcmpiW
kernel32.dll 0 lstrcmpiA
kernel32.dll 0 lstrcmpA
kernel32.dll 0 lstrcatA
kernel32.dll 0 WriteFile
kernel32.dll 0 WaitForSingleObjectEx
kernel32.dll 0 WaitForSingleObject
kernel32.dll 0 VirtualProtect
kernel32.dll 0 TerminateThread
kernel32.dll 0 SleepEx
kernel32.dll 0 Sleep
kernel32.dll 0 SizeofResource
kernel32.dll 0 SetThreadPriority
kernel32.dll 0 SetFilePointer
kernel32.dll 0 SetEvent
kernel32.dll 0 ReadFile
kernel32.dll 0 OpenProcess
kernel32.dll 0 OpenEventA
kernel32.dll 0 MultiByteToWideChar
kernel32.dll 0 LocalUnlock
kernel32.dll 0 LocalSize
kernel32.dll 0 LocalReAlloc
kernel32.dll 0 LocalLock
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
kernel32.dll 0 LoadResource
kernel32.dll 0 LoadLibraryA
kernel32.dll 0 GetVolumeInformationA
kernel32.dll 0 GetTickCount
kernel32.dll 0 GetThreadPriority
kernel32.dll 0 GetTempFileNameA
kernel32.dll 0 GetSystemTimeAsFileTime
kernel32.dll 0 GetProcAddress
kernel32.dll 0 GetModuleHandleA
kernel32.dll 0 GetModuleFileNameA
kernel32.dll 0 GetLastError
kernel32.dll 0 GetFileSize
kernel32.dll 0 GetExitCodeThread
kernel32.dll 0 GetCurrentThreadId
kernel32.dll 0 GetCurrentThread
kernel32.dll 0 GetCurrentProcess
kernel32.dll 0 FormatMessageA
kernel32.dll 0 FindResourceA
kernel32.dll 0 FileTimeToSystemTime
kernel32.dll 0 FileTimeToLocalFileTime
kernel32.dll 0 ExitProcess
kernel32.dll 0 DeleteFileA
kernel32.dll 0 CreateThread
kernel32.dll 0 CreateMutexA
kernel32.dll 0 CreateFileA
kernel32.dll 0 CreateEventA
kernel32.dll 0 CopyFileA
kernel32.dll 0 CloseHandle
gdi32.dll 0 TextOutA
gdi32.dll 0 SelectObject
gdi32.dll 0 Rectangle
gdi32.dll 0 GetTextMetricsA
gdi32.dll 0 Escape
gdi32.dll 0 EndDoc
gdi32.dll 0 DeleteObject
gdi32.dll 0 DeleteDC
gdi32.dll 0 CreateSolidBrush
gdi32.dll 0 CreateDCA
user32.dll 0 CreateWindowExA
user32.dll 0 UnregisterClassA
user32.dll 0 TranslateMessage
user32.dll 0 SetTimer
user32.dll 0 SetForegroundWindow
user32.dll 0 SetFocus
user32.dll 0 SendMessageA
user32.dll 0 RegisterClassA
user32.dll 0 PostMessageA
user32.dll 0 PeekMessageA
user32.dll 0 MessageBoxA
user32.dll 0 LoadIconA
user32.dll 0 LoadCursorA
user32.dll 0 InvalidateRect
user32.dll 0 GetWindowTextA
user32.dll 0 GetWindowDC
user32.dll 0 GetMessageA
user32.dll 0 GetForegroundWindow
user32.dll 0 GetDesktopWindow
user32.dll 0 GetClientRect
user32.dll 0 FindWindowExA
user32.dll 0 FindWindowA
user32.dll 0 ExitWindowsEx
user32.dll 0 DrawTextA
user32.dll 0 DispatchMessageA
user32.dll 0 DestroyWindow
user32.dll 0 DefWindowProcA
user32.dll 0 CharUpperA
kernel32.dll 0 GetTickCount
kernel32.dll 0 VirtualProtect
winspool.drv 0 EnumPrintersA
user32.dll 0 wsprintfA
=== Packer / Compiler ===
D1S1G v1.1 beta (D1N)
=== Strings ===
File pos Mem pos ID Text
======== ======= == ====
000000000050 000002000050 0 This program must be run under Win32
000000000270 000002000270 0 .idata
000000000298 000002000298 0 .reloc
0000000002BF 0000020002BF 0 P.rsrc
000000000594 000002001194 0 SVWUQ
0000000007B5 0000020013B5 0 w;;t$
0000000008C0 0000020014C0 0 SVWUQ
000000001B23 000002002723 0 ~KxI[)
000000001C4C 00000200284C 0 SOFTWARE\Borland\Delphi\RTL
000000001C68 000002002868 0 FPUMaskValue
000000001CB5 0000020028B5 0 PPRTj
000000001E2F 000002002A2F 0 YZXtp
000000001FA6 000002002BA6 0 t=HtN
00000000275C 00000200335C 0 USVW1
0000000030CC 000002003CCC 0 TagConstBegin
0000000030DC 000002003CDC 0 kernel32.dll
0000000030EC 000002003CEC 0 VirtualAllocEx
0000000030FC 000002003CFC 0 VirtualFreeEx
00000000310C 000002003D0C 0 WriteProcessMemory
000000003120 000002003D20 0 CreateRemoteThread
000000003134 000002003D34 0 GetWindowsDirectoryA
00000000314C 000002003D4C 0 TerminateProcess
000000003160 000002003D60 0 CreateToolhelp32Snapshot
00000000317C 000002003D7C 0 Process32First
00000000318C 000002003D8C 0 Process32Next
00000000319C 000002003D9C 0 Module32First
0000000031AC 000002003DAC 0 user32.dll
0000000031B8 000002003DB8 0 CloseDesktop
0000000031C8 000002003DC8 0 CloseWindowStation
0000000031DC 000002003DDC 0 CreateDesktopA
0000000031EC 000002003DEC 0 EnumDisplayMonitors
000000003200 000002003E00 0 GetMonitorInfoA
000000003210 000002003E10 0 GetProcessWindowStation
000000003228 000002003E28 0 GetSystemMetrics
00000000323C 000002003E3C 0 GetThreadDesktop
000000003250 000002003E50 0 OpenDesktopA
000000003260 000002003E60 0 OpenWindowStationA
000000003274 000002003E74 0 SetProcessWindowStation
00000000328C 000002003E8C 0 SetThreadDesktop
0000000032A0 000002003EA0 0 SwitchDesktop
0000000032B0 000002003EB0 0 iphlpapi.dll
0000000032C0 000002003EC0 0 GetExtendedTcpTable
0000000032D4 000002003ED4 0 SpiService.exe
0000000032E4 000002003EE4 0 C:\Program files\Diebold\AgilisXFS\bin\spiservice.exe
00000000331C 000002003F1C 0 DbdDevService.exe
000000003330 000002003F30 0 \Temp\attrib1
000000003340 000002003F40 0 \Temp\attrib4
000000003350 000002003F50 0 \Temp\mk32
00000000335C 000002003F5C 0 \Temp:attrib1
00000000336C 000002003F6C 0 \Temp:attrib4
00000000337C 000002003F7C 0 \Temp:mk32
000000003388 000002003F88 0 \Temp:opt
000000003394 000002003F94 0 TagConstEnd
0000000033A0 000002003FA0 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt
0000000033D4 000002003FD4 0 C:\windows\EpsStmApi.log\
000000003824 000002004424 0 WinSta0
00000000382C 00000200442C 0 default
000000003834 000002004434 0 DISPLAY
000000003A7D 00000200467D 0 D$XPSj
000000003B16 000002004716 0 D$xPj
File pos Mem pos ID Text
======== ======= == ====
000000003B63 000002004763 0 |$,{u
000000003C20 000002004820 0 WinSta0
000000003C28 000002004828 0 MyDesktop
000000003C40 000002004840 0 ATMDialog
000000003C4C 00000200484C 0 hello
000000003C54 000002004854 0 STATIC
000000003C6C 00000200486C 0 default
000000003C84 000002004884 0 Error
000000003D38 000002004938 0 Error
000000003DCB 0000020049CB 0 $PVSh
000000003DFC 0000020049FC 0 %s %s
000000004012 000002004C12 0 RPh4L
000000004034 000002004C34 0 %s Error code= %d
00000000404E 000002004C4E 0 RPhpL
000000004070 000002004C70 0 %s Error code= %.2X
0000000040A9 000002004CA9 0 t"Jt"
0000000040B8 000002004CB8 0 Jt Jt
0000000041CC 000002004DCC 0 OpenProcessToken
0000000041E0 000002004DE0 0 LookupPrivilegeValue
0000000041F8 000002004DF8 0 AdjustTokenPrivileges
0000000043AC 000002004FAC 0 getProcessEntry:
0000000043C0 000002004FC0 0 SeDebugPrivilege
0000000043D4 000002004FD4 0 OpenProcess
0000000043E0 000002004FE0 0 LoadLibraryA
0000000043F0 000002004FF0 0 kernel32.dll
000000004400 000002005000 0 GetExitCodeThread
000000004414 000002005014 0 VirtualFreeEx
0000000046EC 0000020052EC 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000004710 000002005310 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ)
00000000473C 00000200533C 0 EPP Complete LOCK
000000004750 000002005350 0 EPP Complete ENCODE_DECODE
00000000480C 00000200540C 0 SVWUQ
000000004856 000002005456 0 $ZXu>
000000004910 000002005510 0 OASYS.dll
00000000491C 00000200551C 0 OasPostMessage
0000000049EC 0000020055EC 0 DBDDevOpen
0000000049F8 0000020055F8 0 DbdDevRegisterCallback
000000004A10 000002005610 0 DbdDevLock
000000004A1C 00000200561C 0 DbdDevUnregisterCallback
000000004A38 000002005638 0 DBDDevClose
000000004AB4 0000020056B4 0 DbdDevUnlock
000000004AC4 0000020056C4 0 bdDevUnregisterCallback
000000004ADC 0000020056DC 0 DBDDevClose
000000004BC4 0000020057C4 0 DbdDevAPI.dll
000000004BD4 0000020057D4 0 DbdDevOpen
000000004BE0 0000020057E0 0 DbdDevClose
000000004BEC 0000020057EC 0 DbdDevGetInfo
000000004BFC 0000020057FC 0 DbdDevRegisterCallback
000000004C14 000002005814 0 DbdDevUnregisterCallback
000000004C30 000002005830 0 DbdDevLock
000000004C3C 00000200583C 0 DbdDevUnlock
000000004C4C 00000200584C 0 DbdDevExecute
000000004D74 000002005974 0 AMI function don
000000004D85 000002005985 0 t return in 1 sec
000000004FA0 000002005BA0 0 RECEIPT
000000004FA8 000002005BA8 0 WINSPOOL
000000004FB4 000002005BB4 0 CreateDC
000000004FC0 000002005BC0 0 hello
000000004FC8 000002005BC8 0 escape
000000004FD0 000002005BD0 0 TextOut
File pos Mem pos ID Text
======== ======= == ====
000000004FD8 000002005BD8 0 enddoc
000000005090 000002005C90 0 DbdDevExecute(EPP4_COPY_KEY)
0000000050B0 000002005CB0 0 EPP4_COPY_KEY TimeOut
0000000051CC 000002005DCC 0 DbdDevExecute(EPP4_LOAD_KEY)
0000000051EC 000002005DEC 0 EPP4_LOAD_KEY TimeOut
00000000529C 000002005E9C 0 DbdDevExecute(EPP4_DELETE_KEY)
0000000052BC 000002005EBC 0 EPP4_DELETE_KEY TimeOut
0000000053E8 000002005FE8 0 DbdDevExecute(EPP4_ENCODE_DECODE)
00000000540C 00000200600C 0 EPP_Encrypt TimeOut
000000005510 000002006110 0 SVWUQ
0000000057E8 0000020063E8 0 LocalAlloc
0000000057F4 0000020063F4 0 LocalLock
000000005A1A 00000200661A 0 E;,$|
000000005D90 000002006990 0 SVWUQ
000000006157 000002006D57 0 u7IBF
0000000061E6 000002006DE6 0 I+NBu
00000000657C 00000200717C 0 %.2d/%.2d/%.2d %.2d:%.2d
0000000066F8 0000020072F8 0 tdHuaj
000000006770 000002007370 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI)
0000000067A0 0000020073A0 0 t LOCK EPP
0000000067AC 0000020073AC 0 RECEIPT_PRINTER_START_GDI
0000000067C8 0000020073C8 0 DbdDevExecute(RECEIPT_PRINTER_EJECT)
00000000694C 00000200754C 0 DbdDevExecute(AFD_DISPENCE)
000000006968 000002007568 0 CDM Complete LOCK
00000000697C 00000200757C 0 DbdDevExecute(AFD_PRESENT)
000000006998 000002007598 0 DbdDevExecute(AFD_RESTORE)
000000006B58 000002007758 0 SeShutdownPrivilege
000000006E88 000002007A88 0 kernel32
000000006E94 000002007A94 0 DeleteFileA
000000006EA0 000002007AA0 0 FreeLibrary
000000006EAC 000002007AAC 0 GetModuleHandleA
000000006EC0 000002007AC0 0 CreateFileA
000000006ECC 000002007ACC 0 Sleep
000000006ED4 000002007AD4 0 WriteFile
000000006EE0 000002007AE0 0 CloseHandle
000000006EEC 000002007AEC 0 LocalFree
000000006EF8 000002007AF8 0 LoadLibraryA
000000006F08 000002007B08 0 user32
000000006F10 000002007B10 0 ExitWindowsEx
000000006F20 000002007B20 0 SeShutdownPrivilege
000000007070 000002007C70 0 DB11Stored
000000007124 000002007D24 0 SVWUQ
000000007238 000002007E38 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete
000000007264 000002007E64 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ)
00000000759C 00000200819C 0 %.2X%.2X
0000000075A8 0000020081A8 0 Request Code: %.6d
0000000075BB 0000020081BB 0 Enter Responce
0000000075CC 0000020081CC 0 Autorization
0000000075DC 0000020081DC 0 1..4 - dispense cassete
0000000075F4 0000020081F4 0 9 - Uninstall
000000007602 000002008202 0 0 - Exit
00000000760C 00000200820C 0 Enter Command
000000007818 000002008418 0 Diebold:OGuiFrame
00000000782C 00000200842C 0 Enter Password
000000007840 000002008440 0 STATIC
000000007850 000002008450 0 Supply Manager
000000007860 000002008460 0 Pripnt
000000007868 000002008468 0 View All Counts
000000007A80 000002008680 0 DbdDevExecute(RESET)
000000007A98 000002008698 0 DBDDEV_LOCK(CRW)
File pos Mem pos ID Text
======== ======= == ====
000000007AAC 0000020086AC 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
000000007AD4 0000020086D4 0 MCRW_ACCEPT_INSERTION
000000007B19 000002008719 0 ;C&v=
0000000084F5 0000020090F5 0 L0(:L0Sv<V
000000008644 000002009244 0 DbdDevExecute(EPP4_LOAD_KEY)
000000008664 000002009264 0 EPP4_LOAD_KEY TimeOut
000000008738 000002009338 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN)
00000000876C 00000200936C 0 EPP4_COMPUTE_VERIFICATION_PATTERN
00000000897D 00000200957D 0 TQ,Rj
000000008ED4 000002009AD4 0 No Transactions
000000008EE4 000002009AE4 0 No Cards (PINs)
000000009250 000002009E50 0 %s LoadKey %.2d @ %.2d - %.2d
000000009270 000002009E70 0 %s CopyKey %.2d -> %.2d - %.2d
000000009358 000002009F58 0 %s ComID %.2d - %.2d
00000000945C 00000200A05C 0 Transactions %d
00000000946D 00000200A06D 0 Cards %d
000000009481 00000200A081 0 Non Local %d
000000009495 00000200A095 0 Master KEYs %d
0000000094A9 00000200A0A9 0 MAC_ID %d
0000000095A0 00000200A1A0 0 Grab mode %d
0000000095B0 00000200A1B0 0 Deco mode %d
0000000095C1 00000200A1C1 0 Key mode %d
0000000095D2 00000200A1D2 0 Use locals %d
0000000095E3 00000200A1E3 0 Auto delete %d
0000000095F4 00000200A1F4 0 ReturnOnCode %d
000000009640 00000200A240 0 %d.%d.%d.%d : %d
000000009764 00000200A364 0 SeDebugPrivilege
0000000098AC 00000200A4AC 0 SeDebugPrivilege
000000009984 00000200A584 0 Bound Import error
000000009998 00000200A598 0 Bound Import GetProcAddress
0000000099B4 00000200A5B4 0 EPP4API.DLL
0000000099C0 00000200A5C0 0 EppInit
0000000099C8 00000200A5C8 0 EppAttach
0000000099D4 00000200A5D4 0 EppLock
0000000099DC 00000200A5DC 0 CloseComPort
0000000099EC 00000200A5EC 0 EppExchange
000000009AF0 00000200A6F0 0 19200
000000009C50 00000200A850 0 version
000000009C58 00000200A858 0 SOFTWARE\Diebold\Agilis 91x
000000009C74 00000200A874 0 Product Version
000000009C84 00000200A884 0 SOFTWARE\Diebold\Agilis 91x Core
000000009D0C 00000200A90C 0 %s%.2X
000000009D32 00000200A932 0 t]j 3
000000009E68 00000200AA68 0 version
000000009E70 00000200AA70 0 SOFTWARE\Diebold\AMI for Opteva
000000009E90 00000200AA90 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva
000000009EC4 00000200AAC4 0 SOFTWARE\Diebold\Agilis XFS for Opteva
000000009EEC 00000200AAEC 0 Agilis: %s
000000009EFD 00000200AAFD 0 AMI: %s
000000009F0B 00000200AB0B 0 XFS: %s
000000009F19 00000200AB19 0 Firmware:
00000000A048 00000200AC48 0 DbdDevExecute(MCRW_CHIP_IO)
00000000A064 00000200AC64 0 TimeOut MCRW_CHIP_IO
00000000A230 00000200AE30 0 Invalid Sim Response
00000000A374 00000200AF74 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
00000000A428 00000200B028 0 DbdDevExecute(MCRW_POWERON)
00000000A444 00000200B044 0 DbdDevExecute(MCRW_POWEROFF)
00000000A4CC 00000200B0CC 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION)
00000000A568 00000200B168 0 DbdDevExecute(MCRW_MCRW_Eject)
00000000A7C0 00000200B3C0 0 TimeOut Reset
File pos Mem pos ID Text
======== ======= == ====
00000000A7D0 00000200B3D0 0 Incorrect FIle Size
00000000ABB0 00000200B7B0 0 TimeOut Reset
00000000AC94 00000200B894 0 No Decoded Info.
00000000B154 00000200BD54 0 kernel32.dll
00000000B164 00000200BD64 0 CreateFileA
00000000B170 00000200BD70 0 GetFileTime
00000000B17C 00000200BD7C 0 SetFileTime
00000000B188 00000200BD88 0 GetFileSize
00000000B194 00000200BD94 0 ReadFile
00000000B1A0 00000200BDA0 0 WriteFile
00000000B1AC 00000200BDAC 0 SetFilePointer
00000000B1BC 00000200BDBC 0 CloseHandle
00000000B1C8 00000200BDC8 0 LocalAlloc
00000000B1D4 00000200BDD4 0 LocalFree
00000000B1E0 00000200BDE0 0 ExitThread
00000000B1EC 00000200BDEC 0 VirtualFree
00000000B1F8 00000200BDF8 0 Sleep
00000000B200 00000200BE00 0 DeleteFileA
00000000B2C4 00000200BEC4 0 SeDebugPrivilege
00000000B3BC 00000200BFBC 0 Not executable file !
00000000B435 00000200C035 0 |$0jd
00000000B6B3 00000200C2B3 0 $ZXrM
00000000B6BA 00000200C2BA 0 ZX|G3
00000000BA24 00000200C624 0 c:\Program Files\Diebold\Abc\message.trc
00000000BA50 00000200C650 0 c:\Diebold\css\message.trc
00000000BA6C 00000200C66C 0 FileSize %d
00000000BA7D 00000200C67D 0 Transactions %d
00000000BA8E 00000200C68E 0 ComKeys %d
00000000BC4C 00000200C84C 0 hook.LoadLibrary:
00000000BC60 00000200C860 0 GetProcAddress
00000000BC70 00000200C870 0 hook.VirtualProtect
00000000BE1C 00000200CA1C 0 mode6main
00000000BE30 00000200CA30 0 ws2_32.dll
00000000BE3C 00000200CA3C 0 WSASend
00000000C164 00000200CD64 0 Enter command:
00000000C834 00000200D434 0 E PWS
00000000C8F5 00000200D4F5 0 8NTFS
00000000CB38 00000200D738 0 DbdDevRegisterCallback
00000000CB50 00000200D750 0 DbdDevAPI.dll
00000000CB60 00000200D760 0 EppExchange
00000000CB6C 00000200D76C 0 EPP4API.dll
00000000CB78 00000200D778 0 DbdDevExecute
00000000CBAA 00000200D7AA 0 Pj@SW
00000000CCC0 00000200D8C0 0 mu.exe
00000000CD49 00000200D949 0 33333
00000000CD6B 00000200D96B 0 UUUU3
00000000CEBD 00000200DABD 0 VWUSQ
00000000CF05 00000200DB05 0 33333
00000000CF27 00000200DB27 0 UUUU3
00000000CFDB 00000200DBDB 0 UUUU3
00000000D039 00000200DC39 0 VWUSQ
00000000D0F0 00000200DCF0 0 UUUU3
00000000D394 00000200DF94 0 dfd6jdk
00000000D39C 00000200DF9C 0 kdu32rbs
00000000D44C 00000200E04C 0 Error
00000000D454 00000200E054 0 Runtime error at 00000000
00000000D474 00000200E074 0 0123456789ABCDEF
00000000D4B0 00000200E0B0 0 SeTtInGs6.29
00000000D5BA 00000200E1BA 0 <o:o:_;OPO
00000000D5C9 00000200E1C9 0 OLONO
File pos Mem pos ID Text
======== ======= == ====
00000000D5D5 00000200E1D5 0 O!O%O
00000000D784 00000200E384 0 <4,$?7/'
00000000D7CA 00000200E3CA 0 !"#$%&'()*+,-./012345678
00000000D815 00000200E415 0 (3-!0
00000000D81C 00000200E41C 0 ,1'8"5
00000000DD40 000002012340 0 kernel32.dll
00000000DD50 000002012350 0 DeleteCriticalSection
00000000DD68 000002012368 0 LeaveCriticalSection
00000000DD80 000002012380 0 EnterCriticalSection
00000000DD98 000002012398 0 InitializeCriticalSection
00000000DDB4 0000020123B4 0 VirtualFree
00000000DDC2 0000020123C2 0 VirtualAlloc
00000000DDD2 0000020123D2 0 LocalFree
00000000DDDE 0000020123DE 0 LocalAlloc
00000000DDEC 0000020123EC 0 GetVersion
00000000DDFA 0000020123FA 0 GetCurrentThreadId
00000000DE10 000002012410 0 GetThreadLocale
00000000DE22 000002012422 0 GetStartupInfoA
00000000DE34 000002012434 0 GetLocaleInfoA
00000000DE46 000002012446 0 GetCommandLineA
00000000DE58 000002012458 0 FreeLibrary
00000000DE66 000002012466 0 ExitProcess
00000000DE74 000002012474 0 CreateThread
00000000DE84 000002012484 0 WriteFile
00000000DE90 000002012490 0 UnhandledExceptionFilter
00000000DEAC 0000020124AC 0 RtlUnwind
00000000DEB8 0000020124B8 0 RaiseException
00000000DECA 0000020124CA 0 GetStdHandle
00000000DED8 0000020124D8 0 user32.dll
00000000DEE6 0000020124E6 0 GetKeyboardType
00000000DEF8 0000020124F8 0 MessageBoxA
00000000DF04 000002012504 0 advapi32.dll
00000000DF14 000002012514 0 RegQueryValueExA
00000000DF28 000002012528 0 RegOpenKeyExA
00000000DF38 000002012538 0 RegCloseKey
00000000DF44 000002012544 0 kernel32.dll
00000000DF54 000002012554 0 TlsSetValue
00000000DF62 000002012562 0 TlsGetValue
00000000DF70 000002012570 0 TlsFree
00000000DF7A 00000201257A 0 TlsAlloc
00000000DF86 000002012586 0 LocalFree
00000000DF92 000002012592 0 LocalAlloc
00000000DF9E 00000201259E 0 advapi32.dll
00000000DFAE 0000020125AE 0 RegQueryValueExA
00000000DFC2 0000020125C2 0 RegOpenKeyExA
00000000DFD2 0000020125D2 0 RegCloseKey
00000000DFE0 0000020125E0 0 OpenProcessToken
00000000DFF4 0000020125F4 0 LookupPrivilegeValueA
00000000E00C 00000201260C 0 AdjustTokenPrivileges
00000000E022 000002012622 0 kernel32.dll
00000000E032 000002012632 0 lstrlenA
00000000E03E 00000201263E 0 lstrcpynA
00000000E04A 00000201264A 0 lstrcpyA
00000000E056 000002012656 0 lstrcmpiW
00000000E062 000002012662 0 lstrcmpiA
00000000E06E 00000201266E 0 lstrcmpA
00000000E07A 00000201267A 0 lstrcatA
00000000E086 000002012686 0 WriteFile
00000000E092 000002012692 0 WaitForSingleObjectEx
00000000E0AA 0000020126AA 0 WaitForSingleObject
File pos Mem pos ID Text
======== ======= == ====
00000000E0C0 0000020126C0 0 VirtualProtect
00000000E0D2 0000020126D2 0 TerminateThread
00000000E0E4 0000020126E4 0 SleepEx
00000000E0EE 0000020126EE 0 Sleep
00000000E0F6 0000020126F6 0 SizeofResource
00000000E108 000002012708 0 SetThreadPriority
00000000E11C 00000201271C 0 SetFilePointer
00000000E12E 00000201272E 0 SetEvent
00000000E13A 00000201273A 0 ReadFile
00000000E146 000002012746 0 OpenProcess
00000000E154 000002012754 0 OpenEventA
00000000E162 000002012762 0 MultiByteToWideChar
00000000E178 000002012778 0 LocalUnlock
00000000E186 000002012786 0 LocalSize
00000000E192 000002012792 0 LocalReAlloc
00000000E1A2 0000020127A2 0 LocalLock
00000000E1AE 0000020127AE 0 LocalFree
00000000E1BA 0000020127BA 0 LocalAlloc
00000000E1C8 0000020127C8 0 LoadResource
00000000E1D8 0000020127D8 0 LoadLibraryA
00000000E1E8 0000020127E8 0 GetVolumeInformationA
00000000E200 000002012800 0 GetTickCount
00000000E210 000002012810 0 GetThreadPriority
00000000E224 000002012824 0 GetTempFileNameA
00000000E238 000002012838 0 GetSystemTimeAsFileTime
00000000E252 000002012852 0 GetProcAddress
00000000E264 000002012864 0 GetModuleHandleA
00000000E278 000002012878 0 GetModuleFileNameA
00000000E28E 00000201288E 0 GetLastError
00000000E29E 00000201289E 0 GetFileSize
00000000E2AC 0000020128AC 0 GetExitCodeThread
00000000E2C0 0000020128C0 0 GetCurrentThreadId
00000000E2D6 0000020128D6 0 GetCurrentThread
00000000E2EA 0000020128EA 0 GetCurrentProcess
00000000E2FE 0000020128FE 0 FormatMessageA
00000000E310 000002012910 0 FindResourceA
00000000E320 000002012920 0 FileTimeToSystemTime
00000000E338 000002012938 0 FileTimeToLocalFileTime
00000000E352 000002012952 0 ExitProcess
00000000E360 000002012960 0 DeleteFileA
00000000E36E 00000201296E 0 CreateThread
00000000E37E 00000201297E 0 CreateMutexA
00000000E38E 00000201298E 0 CreateFileA
00000000E39C 00000201299C 0 CreateEventA
00000000E3AC 0000020129AC 0 CopyFileA
00000000E3B8 0000020129B8 0 CloseHandle
00000000E3C4 0000020129C4 0 gdi32.dll
00000000E3D0 0000020129D0 0 TextOutA
00000000E3DC 0000020129DC 0 SelectObject
00000000E3EC 0000020129EC 0 Rectangle
00000000E3F8 0000020129F8 0 GetTextMetricsA
00000000E40A 000002012A0A 0 Escape
00000000E414 000002012A14 0 EndDoc
00000000E41E 000002012A1E 0 DeleteObject
00000000E42E 000002012A2E 0 DeleteDC
00000000E43A 000002012A3A 0 CreateSolidBrush
00000000E44E 000002012A4E 0 CreateDCA
00000000E458 000002012A58 0 user32.dll
00000000E466 000002012A66 0 CreateWindowExA
00000000E478 000002012A78 0 UnregisterClassA
File pos Mem pos ID Text
======== ======= == ====
00000000E48C 000002012A8C 0 TranslateMessage
00000000E4A0 000002012AA0 0 SetTimer
00000000E4AC 000002012AAC 0 SetForegroundWindow
00000000E4C2 000002012AC2 0 SetFocus
00000000E4CE 000002012ACE 0 SendMessageA
00000000E4DE 000002012ADE 0 RegisterClassA
00000000E4F0 000002012AF0 0 PostMessageA
00000000E500 000002012B00 0 PeekMessageA
00000000E510 000002012B10 0 MessageBoxA
00000000E51E 000002012B1E 0 LoadIconA
00000000E52A 000002012B2A 0 LoadCursorA
00000000E538 000002012B38 0 InvalidateRect
00000000E54A 000002012B4A 0 GetWindowTextA
00000000E55C 000002012B5C 0 GetWindowDC
00000000E56A 000002012B6A 0 GetMessageA
00000000E578 000002012B78 0 GetForegroundWindow
00000000E58E 000002012B8E 0 GetDesktopWindow
00000000E5A2 000002012BA2 0 GetClientRect
00000000E5B2 000002012BB2 0 FindWindowExA
00000000E5C2 000002012BC2 0 FindWindowA
00000000E5D0 000002012BD0 0 ExitWindowsEx
00000000E5E0 000002012BE0 0 DrawTextA
00000000E5EC 000002012BEC 0 DispatchMessageA
00000000E600 000002012C00 0 DestroyWindow
00000000E610 000002012C10 0 DefWindowProcA
00000000E622 000002012C22 0 CharUpperA
00000000E62E 000002012C2E 0 kernel32.dll
00000000E63E 000002012C3E 0 GetTickCount
00000000E64E 000002012C4E 0 VirtualProtect
00000000E65E 000002012C5E 0 winspool.drv
00000000E66E 000002012C6E 0 EnumPrintersA
00000000E67C 000002012C7C 0 user32.dll
00000000E68A 000002012C8A 0 wsprintfA
00000000E80F 00000201300F 0 0"0*020:0B0J0R0Z0b0j0r0z0
00000000E855 000002013055 0 4%515L5
00000000E85D 00000201305D 0 5.7j7
00000000E87D 00000201307D 0 8$8,8>8J8Y8e8m8x8~8
00000000E8A9 0000020130A9 0 9'929S9k9
00000000E8BB 0000020130BB 0 :O:o:
00000000E8CD 0000020130CD 0 <(<3<<<C<R<Y<{<
00000000E8EF 0000020130EF 0 >Z>c>y>
00000000E8FF 0000020130FF 0 ?*?T?]?m?u?{?
00000000E92B 00000201312B 0 0 080D0L0c0r0
00000000E945 000002013145 0 0$1H1f1v1|1
00000000E95D 00000201315D 0 2m2t2
00000000E97F 00000201317F 0 4#4G4g4
00000000E997 000002013197 0 5%6~7
00000000E9A5 0000020131A5 0 8.8C8}8
00000000E9B9 0000020131B9 0 9:9F9Z9d9w9
00000000E9CD 0000020131CD 0 :M:T:v:
00000000E9D7 0000020131D7 0 :3<[<b<z<
00000000E9E9 0000020131E9 0 =$=o=
00000000EA07 000002013207 0 >!>&>4>>>i>r>y>
00000000EA23 000002013223 0 ?)?3?;?A?O?j?
00000000EA55 000002013255 0 0%464v4}4
00000000EA69 000002013269 0 5M5o5{5
00000000EA8F 00000201328F 0 6)636Z6o6
00000000EAAB 0000020132AB 0 7'717<7O7W7|7
00000000EACD 0000020132CD 0 8+878D8V8c8o8|8
00000000EAF9 0000020132F9 0 9&9.969>9F9N9V9
File pos Mem pos ID Text
======== ======= == ====
00000000EB09 000002013309 0 9f9n9v9~9
00000000EB39 000002013339 0 :&:.:6:>:F:N:V:
00000000EB49 000002013349 0 :f:n:v:~:
00000000EB79 000002013379 0 ;&;.;6;>;F;N;V;
00000000EB89 000002013389 0 ;f;n;v;~;
00000000EBBB 0000020133BB 0 1*121:1B1J1R1
00000000EBC9 0000020133C9 0 1e1k1w1
00000000EBDD 0000020133DD 0 2*272G2h2v2
00000000EC03 000002013403 0 3#3+353;3D3]3b3n3s3
00000000EC3B 00000201343B 0 4V4f4t4z4
00000000EC8F 00000201348F 0 :,;V;
00000000ECA5 0000020134A5 0 =L=k=
00000000ECE3 0000020134E3 0 2+2@2R2m2
00000000ED05 000002013505 0 4'4C4]4p4w4
00000000ED17 000002013517 0 4O5Z5n5y5
00000000ED3F 00000201353F 0 7"7'7,777<7A7L7Q7V7a7f7k7v7{7
00000000ED85 000002013585 0 ;);@;V;u;
00000000ED91 000002013591 0 <3<H<T<d<t<T=_=t=
00000000EDA9 0000020135A9 0 =9>D>Y>n>z>
00000000EDBD 0000020135BD 0 ?'?,?;?B?H?R?c?n?
00000000EDE7 0000020135E7 0 1M1R1
00000000EDFD 0000020135FD 0 2.2>2Q2a2t2
00000000EE15 000002013615 0 3$3*323A3L3R3Z3f3
00000000EE47 000002013647 0 ;R?f?
00000000EE61 000002013661 0 161V1
00000000EE67 000002013667 0 2+2?2h2
00000000EE7D 00000201367D 0 3.343_3x4
00000000EEA3 0000020136A3 0 6:6O6T6_6r6
00000000EEBD 0000020136BD 0 7,757
00000000EED3 0000020136D3 0 9(93999N9
00000000EEDD 0000020136DD 0 9j9w9
00000000EF01 000002013701 0 <1<@<
00000000EF15 000002013715 0 =6=F=t=y=
00000000EF51 000002013751 0 0\0s0
00000000EF5B 00000201375B 0 0+101{2
00000000EF73 000002013773 0 4I5V5f5
00000000EF87 000002013787 0 6%6,696E6O6h6m6s;
00000000EFF9 0000020137F9 0 <1===B=H=
00000000F005 000002013805 0 =!>4?
00000000F01F 00000201381F 0 0!1K1z122k2
00000000F037 000002013837 0 3=4U4
00000000F041 000002013841 0 5+5W5
00000000F04B 00000201384B 0 676I6_6q6
00000000F059 000002013859 0 6Q7Z7e7{7
00000000F065 000002013865 0 7&8+8=8B8
00000000F083 000002013883 0 9$:{;
00000000F095 000002013895 0 <#<0<
00000000F0A5 0000020138A5 0 ?*?:?H?
00000000F0D1 0000020138D1 0 0!1*1<1L1U1
00000000F0E9 0000020138E9 0 222S2x2
00000000F0FB 0000020138FB 0 3/3:3B3P3{3
00000000F115 000002013915 0 6/6?6Y6p6
00000000F12D 00000201392D 0 7'7/7A7u7
00000000F145 000002013945 0 ;5<A<N<\<j<x<
00000000F163 000002013963 0 <&=+=1=&>V>e>
00000000F179 000002013979 0 ?#?D?Q?
00000000F195 000002013995 0 0t0~0
00000000F19B 00000201399B 0 1d1j1p1
00000000F1AB 0000020139AB 0 3)313:3G3
00000000F1C9 0000020139C9 0 4"5.5W5
File pos Mem pos ID Text
======== ======= == ====
00000000F1D1 0000020139D1 0 5e5j5t5y5
00000000F1F9 0000020139F9 0 6:7B7G7\7t7
00000000F215 000002013A15 0 959V9
00000000F21B 000002013A1B 0 9f9q9
00000000F23D 000002013A3D 0 :P:g:n:w:|:
00000000F25F 000002013A5F 0 ;#;';+;/;3;7;;;?;C;G;K;O;S;W;
00000000F27F 000002013A7F 0 <*<:<J<b<
00000000F293 000002013A93 0 =&=V=
00000000F2B7 000002013AB7 0 >&>1>=>N>Z>b>
00000000F2D7 000002013AD7 0 ?/?I?R?[?a?x?
00000000F2FD 000002013AFD 0 0+0u0
00000000F31D 000002013B1D 0 1%1/1C1
00000000F331 000002013B31 0 2#2+232>2
00000000F33D 000002013B3D 0 3%3-3Z3f3r3z3
00000000F34F 000002013B4F 0 4*4K4W4_4v4
00000000F367 000002013B67 0 5'5-575=5C5K5Q5W5]5d5j5p5u5{5
00000000F38F 000002013B8F 0 6%636O6U6c6n6}6
00000000F3BD 000002013BBD 0 7 7%7
00000000F3C9 000002013BC9 0 718;8A8H8p8~8
00000000F3EF 000002013BEF 0 :+:9:g:u:z:
00000000F3FD 000002013BFD 0 :9;A;[;h;u;};
00000000F415 000002013C15 0 ;I<a<i<
00000000F42F 000002013C2F 0 <W=j=|=
00000000F45B 000002013C5B 0 >'>,>1>M>R>b>n>~>
00000000F483 000002013C83 0 ?,?:?H?R?a?r?
00000000F498 000002013C98 0 $0(0,0
00000000F4C5 000002013CC5 0 1 1$1(1,1014181<1@1D1L1P1X1\1
00000000F4E3 000002013CE3 0 1d1h1l1p1t1x1|1
00000000F4F7 000002013CF7 0 1@2D2H2L2P2T2
00000000F6CE 0000020140CE 0 netmgr
00000000F6D6 0000020140D6 0 UTypes
00000000F6DF 0000020140DF 0 System
00000000F6E8 0000020140E8 0 SysInit
00000000F6F1 0000020140F1 0 KWindows
00000000F698 000002014098 0 PACKAGEINFO
000000000050 000002000050 0 This program must be run under Win32
000000000270 000002000270 0 .idata
000000000298 000002000298 0 .reloc
0000000002BF 0000020002BF 0 P.rsrc
000000000594 000002001194 0 SVWUQ
0000000007B5 0000020013B5 0 w;;t$
0000000008C0 0000020014C0 0 SVWUQ
000000001B23 000002002723 0 ~KxI[)
000000001C4C 00000200284C 0 SOFTWARE\Borland\Delphi\RTL
000000001C68 000002002868 0 FPUMaskValue
000000001CB5 0000020028B5 0 PPRTj
000000001E2F 000002002A2F 0 YZXtp
000000001FA6 000002002BA6 0 t=HtN
00000000275C 00000200335C 0 USVW1
0000000030CC 000002003CCC 0 TagConstBegin
0000000030DC 000002003CDC 0 kernel32.dll
0000000030EC 000002003CEC 0 VirtualAllocEx
0000000030FC 000002003CFC 0 VirtualFreeEx
00000000310C 000002003D0C 0 WriteProcessMemory
000000003120 000002003D20 0 CreateRemoteThread
000000003134 000002003D34 0 GetWindowsDirectoryA
00000000314C 000002003D4C 0 TerminateProcess
000000003160 000002003D60 0 CreateToolhelp32Snapshot
00000000317C 000002003D7C 0 Process32First
00000000318C 000002003D8C 0 Process32Next
File pos Mem pos ID Text
======== ======= == ====
00000000319C 000002003D9C 0 Module32First
0000000031AC 000002003DAC 0 user32.dll
0000000031B8 000002003DB8 0 CloseDesktop
0000000031C8 000002003DC8 0 CloseWindowStation
0000000031DC 000002003DDC 0 CreateDesktopA
0000000031EC 000002003DEC 0 EnumDisplayMonitors
000000003200 000002003E00 0 GetMonitorInfoA
000000003210 000002003E10 0 GetProcessWindowStation
000000003228 000002003E28 0 GetSystemMetrics
00000000323C 000002003E3C 0 GetThreadDesktop
000000003250 000002003E50 0 OpenDesktopA
000000003260 000002003E60 0 OpenWindowStationA
000000003274 000002003E74 0 SetProcessWindowStation
00000000328C 000002003E8C 0 SetThreadDesktop
0000000032A0 000002003EA0 0 SwitchDesktop
0000000032B0 000002003EB0 0 iphlpapi.dll
0000000032C0 000002003EC0 0 GetExtendedTcpTable
0000000032D4 000002003ED4 0 SpiService.exe
0000000032E4 000002003EE4 0 C:\Program files\Diebold\AgilisXFS\bin\spiservice.exe
00000000331C 000002003F1C 0 DbdDevService.exe
000000003330 000002003F30 0 \Temp\attrib1
000000003340 000002003F40 0 \Temp\attrib4
000000003350 000002003F50 0 \Temp\mk32
00000000335C 000002003F5C 0 \Temp:attrib1
00000000336C 000002003F6C 0 \Temp:attrib4
00000000337C 000002003F7C 0 \Temp:mk32
000000003388 000002003F88 0 \Temp:opt
000000003394 000002003F94 0 TagConstEnd
0000000033A0 000002003FA0 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt
0000000033D4 000002003FD4 0 C:\windows\EpsStmApi.log\
000000003824 000002004424 0 WinSta0
00000000382C 00000200442C 0 default
000000003834 000002004434 0 DISPLAY
000000003A7D 00000200467D 0 D$XPSj
000000003B16 000002004716 0 D$xPj
000000003B63 000002004763 0 |$,{u
000000003C20 000002004820 0 WinSta0
000000003C28 000002004828 0 MyDesktop
000000003C40 000002004840 0 ATMDialog
000000003C4C 00000200484C 0 hello
000000003C54 000002004854 0 STATIC
000000003C6C 00000200486C 0 default
000000003C84 000002004884 0 Error
000000003D38 000002004938 0 Error
000000003DCB 0000020049CB 0 $PVSh
000000003DFC 0000020049FC 0 %s %s
000000004012 000002004C12 0 RPh4L
000000004034 000002004C34 0 %s Error code= %d
00000000404E 000002004C4E 0 RPhpL
000000004070 000002004C70 0 %s Error code= %.2X
0000000040A9 000002004CA9 0 t"Jt"
0000000040B8 000002004CB8 0 Jt Jt
0000000041CC 000002004DCC 0 OpenProcessToken
0000000041E0 000002004DE0 0 LookupPrivilegeValue
0000000041F8 000002004DF8 0 AdjustTokenPrivileges
0000000043AC 000002004FAC 0 getProcessEntry:
0000000043C0 000002004FC0 0 SeDebugPrivilege
0000000043D4 000002004FD4 0 OpenProcess
0000000043E0 000002004FE0 0 LoadLibraryA
0000000043F0 000002004FF0 0 kernel32.dll
File pos Mem pos ID Text
======== ======= == ====
000000004400 000002005000 0 GetExitCodeThread
000000004414 000002005014 0 VirtualFreeEx
0000000046EC 0000020052EC 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000004710 000002005310 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ)
00000000473C 00000200533C 0 EPP Complete LOCK
000000004750 000002005350 0 EPP Complete ENCODE_DECODE
00000000480C 00000200540C 0 SVWUQ
000000004856 000002005456 0 $ZXu>
000000004910 000002005510 0 OASYS.dll
00000000491C 00000200551C 0 OasPostMessage
0000000049EC 0000020055EC 0 DBDDevOpen
0000000049F8 0000020055F8 0 DbdDevRegisterCallback
000000004A10 000002005610 0 DbdDevLock
000000004A1C 00000200561C 0 DbdDevUnregisterCallback
000000004A38 000002005638 0 DBDDevClose
000000004AB4 0000020056B4 0 DbdDevUnlock
000000004AC4 0000020056C4 0 bdDevUnregisterCallback
000000004ADC 0000020056DC 0 DBDDevClose
000000004BC4 0000020057C4 0 DbdDevAPI.dll
000000004BD4 0000020057D4 0 DbdDevOpen
000000004BE0 0000020057E0 0 DbdDevClose
000000004BEC 0000020057EC 0 DbdDevGetInfo
000000004BFC 0000020057FC 0 DbdDevRegisterCallback
000000004C14 000002005814 0 DbdDevUnregisterCallback
000000004C30 000002005830 0 DbdDevLock
000000004C3C 00000200583C 0 DbdDevUnlock
000000004C4C 00000200584C 0 DbdDevExecute
000000004D74 000002005974 0 AMI function don
000000004D85 000002005985 0 t return in 1 sec
000000004FA0 000002005BA0 0 RECEIPT
000000004FA8 000002005BA8 0 WINSPOOL
000000004FB4 000002005BB4 0 CreateDC
000000004FC0 000002005BC0 0 hello
000000004FC8 000002005BC8 0 escape
000000004FD0 000002005BD0 0 TextOut
000000004FD8 000002005BD8 0 enddoc
000000005090 000002005C90 0 DbdDevExecute(EPP4_COPY_KEY)
0000000050B0 000002005CB0 0 EPP4_COPY_KEY TimeOut
0000000051CC 000002005DCC 0 DbdDevExecute(EPP4_LOAD_KEY)
0000000051EC 000002005DEC 0 EPP4_LOAD_KEY TimeOut
00000000529C 000002005E9C 0 DbdDevExecute(EPP4_DELETE_KEY)
0000000052BC 000002005EBC 0 EPP4_DELETE_KEY TimeOut
0000000053E8 000002005FE8 0 DbdDevExecute(EPP4_ENCODE_DECODE)
00000000540C 00000200600C 0 EPP_Encrypt TimeOut
000000005510 000002006110 0 SVWUQ
0000000057E8 0000020063E8 0 LocalAlloc
0000000057F4 0000020063F4 0 LocalLock
000000005A1A 00000200661A 0 E;,$|
000000005D90 000002006990 0 SVWUQ
000000006157 000002006D57 0 u7IBF
0000000061E6 000002006DE6 0 I+NBu
00000000657C 00000200717C 0 %.2d/%.2d/%.2d %.2d:%.2d
0000000066F8 0000020072F8 0 tdHuaj
000000006770 000002007370 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI)
0000000067A0 0000020073A0 0 t LOCK EPP
0000000067AC 0000020073AC 0 RECEIPT_PRINTER_START_GDI
0000000067C8 0000020073C8 0 DbdDevExecute(RECEIPT_PRINTER_EJECT)
00000000694C 00000200754C 0 DbdDevExecute(AFD_DISPENCE)
000000006968 000002007568 0 CDM Complete LOCK
00000000697C 00000200757C 0 DbdDevExecute(AFD_PRESENT)
File pos Mem pos ID Text
======== ======= == ====
000000006998 000002007598 0 DbdDevExecute(AFD_RESTORE)
000000006B58 000002007758 0 SeShutdownPrivilege
000000006E88 000002007A88 0 kernel32
000000006E94 000002007A94 0 DeleteFileA
000000006EA0 000002007AA0 0 FreeLibrary
000000006EAC 000002007AAC 0 GetModuleHandleA
000000006EC0 000002007AC0 0 CreateFileA
000000006ECC 000002007ACC 0 Sleep
000000006ED4 000002007AD4 0 WriteFile
000000006EE0 000002007AE0 0 CloseHandle
000000006EEC 000002007AEC 0 LocalFree
000000006EF8 000002007AF8 0 LoadLibraryA
000000006F08 000002007B08 0 user32
000000006F10 000002007B10 0 ExitWindowsEx
000000006F20 000002007B20 0 SeShutdownPrivilege
000000007070 000002007C70 0 DB11Stored
000000007124 000002007D24 0 SVWUQ
000000007238 000002007E38 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete
000000007264 000002007E64 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ)
00000000759C 00000200819C 0 %.2X%.2X
0000000075A8 0000020081A8 0 Request Code: %.6d
0000000075BB 0000020081BB 0 Enter Responce
0000000075CC 0000020081CC 0 Autorization
0000000075DC 0000020081DC 0 1..4 - dispense cassete
0000000075F4 0000020081F4 0 9 - Uninstall
000000007602 000002008202 0 0 - Exit
00000000760C 00000200820C 0 Enter Command
000000007818 000002008418 0 Diebold:OGuiFrame
00000000782C 00000200842C 0 Enter Password
000000007840 000002008440 0 STATIC
000000007850 000002008450 0 Supply Manager
000000007860 000002008460 0 Pripnt
000000007868 000002008468 0 View All Counts
000000007A80 000002008680 0 DbdDevExecute(RESET)
000000007A98 000002008698 0 DBDDEV_LOCK(CRW)
000000007AAC 0000020086AC 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
000000007AD4 0000020086D4 0 MCRW_ACCEPT_INSERTION
000000007B19 000002008719 0 ;C&v=
0000000084F5 0000020090F5 0 L0(:L0Sv<V
000000008644 000002009244 0 DbdDevExecute(EPP4_LOAD_KEY)
000000008664 000002009264 0 EPP4_LOAD_KEY TimeOut
000000008738 000002009338 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN)
00000000876C 00000200936C 0 EPP4_COMPUTE_VERIFICATION_PATTERN
00000000897D 00000200957D 0 TQ,Rj
000000008ED4 000002009AD4 0 No Transactions
000000008EE4 000002009AE4 0 No Cards (PINs)
000000009250 000002009E50 0 %s LoadKey %.2d @ %.2d - %.2d
000000009270 000002009E70 0 %s CopyKey %.2d -> %.2d - %.2d
000000009358 000002009F58 0 %s ComID %.2d - %.2d
00000000945C 00000200A05C 0 Transactions %d
00000000946D 00000200A06D 0 Cards %d
000000009481 00000200A081 0 Non Local %d
000000009495 00000200A095 0 Master KEYs %d
0000000094A9 00000200A0A9 0 MAC_ID %d
0000000095A0 00000200A1A0 0 Grab mode %d
0000000095B0 00000200A1B0 0 Deco mode %d
0000000095C1 00000200A1C1 0 Key mode %d
0000000095D2 00000200A1D2 0 Use locals %d
0000000095E3 00000200A1E3 0 Auto delete %d
0000000095F4 00000200A1F4 0 ReturnOnCode %d
File pos Mem pos ID Text
======== ======= == ====
000000009640 00000200A240 0 %d.%d.%d.%d : %d
000000009764 00000200A364 0 SeDebugPrivilege
0000000098AC 00000200A4AC 0 SeDebugPrivilege
000000009984 00000200A584 0 Bound Import error
000000009998 00000200A598 0 Bound Import GetProcAddress
0000000099B4 00000200A5B4 0 EPP4API.DLL
0000000099C0 00000200A5C0 0 EppInit
0000000099C8 00000200A5C8 0 EppAttach
0000000099D4 00000200A5D4 0 EppLock
0000000099DC 00000200A5DC 0 CloseComPort
0000000099EC 00000200A5EC 0 EppExchange
000000009AF0 00000200A6F0 0 19200
000000009C50 00000200A850 0 version
000000009C58 00000200A858 0 SOFTWARE\Diebold\Agilis 91x
000000009C74 00000200A874 0 Product Version
000000009C84 00000200A884 0 SOFTWARE\Diebold\Agilis 91x Core
000000009D0C 00000200A90C 0 %s%.2X
000000009D32 00000200A932 0 t]j 3
000000009E68 00000200AA68 0 version
000000009E70 00000200AA70 0 SOFTWARE\Diebold\AMI for Opteva
000000009E90 00000200AA90 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva
000000009EC4 00000200AAC4 0 SOFTWARE\Diebold\Agilis XFS for Opteva
000000009EEC 00000200AAEC 0 Agilis: %s
000000009EFD 00000200AAFD 0 AMI: %s
000000009F0B 00000200AB0B 0 XFS: %s
000000009F19 00000200AB19 0 Firmware:
00000000A048 00000200AC48 0 DbdDevExecute(MCRW_CHIP_IO)
00000000A064 00000200AC64 0 TimeOut MCRW_CHIP_IO
00000000A230 00000200AE30 0 Invalid Sim Response
00000000A374 00000200AF74 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
00000000A428 00000200B028 0 DbdDevExecute(MCRW_POWERON)
00000000A444 00000200B044 0 DbdDevExecute(MCRW_POWEROFF)
00000000A4CC 00000200B0CC 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION)
00000000A568 00000200B168 0 DbdDevExecute(MCRW_MCRW_Eject)
00000000A7C0 00000200B3C0 0 TimeOut Reset
00000000A7D0 00000200B3D0 0 Incorrect FIle Size
00000000ABB0 00000200B7B0 0 TimeOut Reset
00000000AC94 00000200B894 0 No Decoded Info.
00000000B154 00000200BD54 0 kernel32.dll
00000000B164 00000200BD64 0 CreateFileA
00000000B170 00000200BD70 0 GetFileTime
00000000B17C 00000200BD7C 0 SetFileTime
00000000B188 00000200BD88 0 GetFileSize
00000000B194 00000200BD94 0 ReadFile
00000000B1A0 00000200BDA0 0 WriteFile
00000000B1AC 00000200BDAC 0 SetFilePointer
00000000B1BC 00000200BDBC 0 CloseHandle
00000000B1C8 00000200BDC8 0 LocalAlloc
00000000B1D4 00000200BDD4 0 LocalFree
00000000B1E0 00000200BDE0 0 ExitThread
00000000B1EC 00000200BDEC 0 VirtualFree
00000000B1F8 00000200BDF8 0 Sleep
00000000B200 00000200BE00 0 DeleteFileA
00000000B2C4 00000200BEC4 0 SeDebugPrivilege
00000000B3BC 00000200BFBC 0 Not executable file !
00000000B435 00000200C035 0 |$0jd
00000000B6B3 00000200C2B3 0 $ZXrM
00000000B6BA 00000200C2BA 0 ZX|G3
00000000BA24 00000200C624 0 c:\Program Files\Diebold\Abc\message.trc
00000000BA50 00000200C650 0 c:\Diebold\css\message.trc
File pos Mem pos ID Text
======== ======= == ====
00000000BA6C 00000200C66C 0 FileSize %d
00000000BA7D 00000200C67D 0 Transactions %d
00000000BA8E 00000200C68E 0 ComKeys %d
00000000BC4C 00000200C84C 0 hook.LoadLibrary:
00000000BC60 00000200C860 0 GetProcAddress
00000000BC70 00000200C870 0 hook.VirtualProtect
00000000BE1C 00000200CA1C 0 mode6main
00000000BE30 00000200CA30 0 ws2_32.dll
00000000BE3C 00000200CA3C 0 WSASend
00000000C164 00000200CD64 0 Enter command:
00000000C834 00000200D434 0 E PWS
00000000C8F5 00000200D4F5 0 8NTFS
00000000CB38 00000200D738 0 DbdDevRegisterCallback
00000000CB50 00000200D750 0 DbdDevAPI.dll
00000000CB60 00000200D760 0 EppExchange
00000000CB6C 00000200D76C 0 EPP4API.dll
00000000CB78 00000200D778 0 DbdDevExecute
00000000CBAA 00000200D7AA 0 Pj@SW
00000000CCC0 00000200D8C0 0 mu.exe
00000000CD49 00000200D949 0 33333
00000000CD6B 00000200D96B 0 UUUU3
00000000CEBD 00000200DABD 0 VWUSQ
00000000CF05 00000200DB05 0 33333
00000000CF27 00000200DB27 0 UUUU3
00000000CFDB 00000200DBDB 0 UUUU3
00000000D039 00000200DC39 0 VWUSQ
00000000D0F0 00000200DCF0 0 UUUU3
00000000D394 00000200DF94 0 dfd6jdk
00000000D39C 00000200DF9C 0 kdu32rbs
00000000D44C 00000200E04C 0 Error
00000000D454 00000200E054 0 Runtime error at 00000000
00000000D474 00000200E074 0 0123456789ABCDEF
00000000D4B0 00000200E0B0 0 SeTtInGs6.29
00000000D5BA 00000200E1BA 0 <o:o:_;OPO
00000000D5C9 00000200E1C9 0 OLONO
00000000D5D5 00000200E1D5 0 O!O%O
00000000D784 00000200E384 0 <4,$?7/'
00000000D7CA 00000200E3CA 0 !"#$%&'()*+,-./012345678
00000000D815 00000200E415 0 (3-!0
00000000D81C 00000200E41C 0 ,1'8"5
00000000DD40 000002012340 0 kernel32.dll
00000000DD50 000002012350 0 DeleteCriticalSection
00000000DD68 000002012368 0 LeaveCriticalSection
00000000DD80 000002012380 0 EnterCriticalSection
00000000DD98 000002012398 0 InitializeCriticalSection
00000000DDB4 0000020123B4 0 VirtualFree
00000000DDC2 0000020123C2 0 VirtualAlloc
00000000DDD2 0000020123D2 0 LocalFree
00000000DDDE 0000020123DE 0 LocalAlloc
00000000DDEC 0000020123EC 0 GetVersion
00000000DDFA 0000020123FA 0 GetCurrentThreadId
00000000DE10 000002012410 0 GetThreadLocale
00000000DE22 000002012422 0 GetStartupInfoA
00000000DE34 000002012434 0 GetLocaleInfoA
00000000DE46 000002012446 0 GetCommandLineA
00000000DE58 000002012458 0 FreeLibrary
00000000DE66 000002012466 0 ExitProcess
00000000DE74 000002012474 0 CreateThread
00000000DE84 000002012484 0 WriteFile
00000000DE90 000002012490 0 UnhandledExceptionFilter
File pos Mem pos ID Text
======== ======= == ====
00000000DEAC 0000020124AC 0 RtlUnwind
00000000DEB8 0000020124B8 0 RaiseException
00000000DECA 0000020124CA 0 GetStdHandle
00000000DED8 0000020124D8 0 user32.dll
00000000DEE6 0000020124E6 0 GetKeyboardType
00000000DEF8 0000020124F8 0 MessageBoxA
00000000DF04 000002012504 0 advapi32.dll
00000000DF14 000002012514 0 RegQueryValueExA
00000000DF28 000002012528 0 RegOpenKeyExA
00000000DF38 000002012538 0 RegCloseKey
00000000DF44 000002012544 0 kernel32.dll
00000000DF54 000002012554 0 TlsSetValue
00000000DF62 000002012562 0 TlsGetValue
00000000DF70 000002012570 0 TlsFree
00000000DF7A 00000201257A 0 TlsAlloc
00000000DF86 000002012586 0 LocalFree
00000000DF92 000002012592 0 LocalAlloc
00000000DF9E 00000201259E 0 advapi32.dll
00000000DFAE 0000020125AE 0 RegQueryValueExA
00000000DFC2 0000020125C2 0 RegOpenKeyExA
00000000DFD2 0000020125D2 0 RegCloseKey
00000000DFE0 0000020125E0 0 OpenProcessToken
00000000DFF4 0000020125F4 0 LookupPrivilegeValueA
00000000E00C 00000201260C 0 AdjustTokenPrivileges
00000000E022 000002012622 0 kernel32.dll
00000000E032 000002012632 0 lstrlenA
00000000E03E 00000201263E 0 lstrcpynA
00000000E04A 00000201264A 0 lstrcpyA
00000000E056 000002012656 0 lstrcmpiW
00000000E062 000002012662 0 lstrcmpiA
00000000E06E 00000201266E 0 lstrcmpA
00000000E07A 00000201267A 0 lstrcatA
00000000E086 000002012686 0 WriteFile
00000000E092 000002012692 0 WaitForSingleObjectEx
00000000E0AA 0000020126AA 0 WaitForSingleObject
00000000E0C0 0000020126C0 0 VirtualProtect
00000000E0D2 0000020126D2 0 TerminateThread
00000000E0E4 0000020126E4 0 SleepEx
00000000E0EE 0000020126EE 0 Sleep
00000000E0F6 0000020126F6 0 SizeofResource
00000000E108 000002012708 0 SetThreadPriority
00000000E11C 00000201271C 0 SetFilePointer
00000000E12E 00000201272E 0 SetEvent
00000000E13A 00000201273A 0 ReadFile
00000000E146 000002012746 0 OpenProcess
00000000E154 000002012754 0 OpenEventA
00000000E162 000002012762 0 MultiByteToWideChar
00000000E178 000002012778 0 LocalUnlock
00000000E186 000002012786 0 LocalSize
00000000E192 000002012792 0 LocalReAlloc
00000000E1A2 0000020127A2 0 LocalLock
00000000E1AE 0000020127AE 0 LocalFree
00000000E1BA 0000020127BA 0 LocalAlloc
00000000E1C8 0000020127C8 0 LoadResource
00000000E1D8 0000020127D8 0 LoadLibraryA
00000000E1E8 0000020127E8 0 GetVolumeInformationA
00000000E200 000002012800 0 GetTickCount
00000000E210 000002012810 0 GetThreadPriority
00000000E224 000002012824 0 GetTempFileNameA
00000000E238 000002012838 0 GetSystemTimeAsFileTime
File pos Mem pos ID Text
======== ======= == ====
00000000E252 000002012852 0 GetProcAddress
00000000E264 000002012864 0 GetModuleHandleA
00000000E278 000002012878 0 GetModuleFileNameA
00000000E28E 00000201288E 0 GetLastError
00000000E29E 00000201289E 0 GetFileSize
00000000E2AC 0000020128AC 0 GetExitCodeThread
00000000E2C0 0000020128C0 0 GetCurrentThreadId
00000000E2D6 0000020128D6 0 GetCurrentThread
00000000E2EA 0000020128EA 0 GetCurrentProcess
00000000E2FE 0000020128FE 0 FormatMessageA
00000000E310 000002012910 0 FindResourceA
00000000E320 000002012920 0 FileTimeToSystemTime
00000000E338 000002012938 0 FileTimeToLocalFileTime
00000000E352 000002012952 0 ExitProcess
00000000E360 000002012960 0 DeleteFileA
00000000E36E 00000201296E 0 CreateThread
00000000E37E 00000201297E 0 CreateMutexA
00000000E38E 00000201298E 0 CreateFileA
00000000E39C 00000201299C 0 CreateEventA
00000000E3AC 0000020129AC 0 CopyFileA
00000000E3B8 0000020129B8 0 CloseHandle
00000000E3C4 0000020129C4 0 gdi32.dll
00000000E3D0 0000020129D0 0 TextOutA
00000000E3DC 0000020129DC 0 SelectObject
00000000E3EC 0000020129EC 0 Rectangle
00000000E3F8 0000020129F8 0 GetTextMetricsA
00000000E40A 000002012A0A 0 Escape
00000000E414 000002012A14 0 EndDoc
00000000E41E 000002012A1E 0 DeleteObject
00000000E42E 000002012A2E 0 DeleteDC
00000000E43A 000002012A3A 0 CreateSolidBrush
00000000E44E 000002012A4E 0 CreateDCA
00000000E458 000002012A58 0 user32.dll
00000000E466 000002012A66 0 CreateWindowExA
00000000E478 000002012A78 0 UnregisterClassA
00000000E48C 000002012A8C 0 TranslateMessage
00000000E4A0 000002012AA0 0 SetTimer
00000000E4AC 000002012AAC 0 SetForegroundWindow
00000000E4C2 000002012AC2 0 SetFocus
00000000E4CE 000002012ACE 0 SendMessageA
00000000E4DE 000002012ADE 0 RegisterClassA
00000000E4F0 000002012AF0 0 PostMessageA
00000000E500 000002012B00 0 PeekMessageA
00000000E510 000002012B10 0 MessageBoxA
00000000E51E 000002012B1E 0 LoadIconA
00000000E52A 000002012B2A 0 LoadCursorA
00000000E538 000002012B38 0 InvalidateRect
00000000E54A 000002012B4A 0 GetWindowTextA
00000000E55C 000002012B5C 0 GetWindowDC
00000000E56A 000002012B6A 0 GetMessageA
00000000E578 000002012B78 0 GetForegroundWindow
00000000E58E 000002012B8E 0 GetDesktopWindow
00000000E5A2 000002012BA2 0 GetClientRect
00000000E5B2 000002012BB2 0 FindWindowExA
00000000E5C2 000002012BC2 0 FindWindowA
00000000E5D0 000002012BD0 0 ExitWindowsEx
00000000E5E0 000002012BE0 0 DrawTextA
00000000E5EC 000002012BEC 0 DispatchMessageA
00000000E600 000002012C00 0 DestroyWindow
00000000E610 000002012C10 0 DefWindowProcA
File pos Mem pos ID Text
======== ======= == ====
00000000E622 000002012C22 0 CharUpperA
00000000E62E 000002012C2E 0 kernel32.dll
00000000E63E 000002012C3E 0 GetTickCount
00000000E64E 000002012C4E 0 VirtualProtect
00000000E65E 000002012C5E 0 winspool.drv
00000000E66E 000002012C6E 0 EnumPrintersA
00000000E67C 000002012C7C 0 user32.dll
00000000E68A 000002012C8A 0 wsprintfA
00000000E80F 00000201300F 0 0"0*020:0B0J0R0Z0b0j0r0z0
00000000E855 000002013055 0 4%515L5
00000000E85D 00000201305D 0 5.7j7
00000000E87D 00000201307D 0 8$8,8>8J8Y8e8m8x8~8
00000000E8A9 0000020130A9 0 9'929S9k9
00000000E8BB 0000020130BB 0 :O:o:
00000000E8CD 0000020130CD 0 <(<3<<<C<R<Y<{<
00000000E8EF 0000020130EF 0 >Z>c>y>
00000000E8FF 0000020130FF 0 ?*?T?]?m?u?{?
00000000E92B 00000201312B 0 0 080D0L0c0r0
00000000E945 000002013145 0 0$1H1f1v1|1
00000000E95D 00000201315D 0 2m2t2
00000000E97F 00000201317F 0 4#4G4g4
00000000E997 000002013197 0 5%6~7
00000000E9A5 0000020131A5 0 8.8C8}8
00000000E9B9 0000020131B9 0 9:9F9Z9d9w9
00000000E9CD 0000020131CD 0 :M:T:v:
00000000E9D7 0000020131D7 0 :3<[<b<z<
00000000E9E9 0000020131E9 0 =$=o=
00000000EA07 000002013207 0 >!>&>4>>>i>r>y>
00000000EA23 000002013223 0 ?)?3?;?A?O?j?
00000000EA55 000002013255 0 0%464v4}4
00000000EA69 000002013269 0 5M5o5{5
00000000EA8F 00000201328F 0 6)636Z6o6
00000000EAAB 0000020132AB 0 7'717<7O7W7|7
00000000EACD 0000020132CD 0 8+878D8V8c8o8|8
00000000EAF9 0000020132F9 0 9&9.969>9F9N9V9
00000000EB09 000002013309 0 9f9n9v9~9
00000000EB39 000002013339 0 :&:.:6:>:F:N:V:
00000000EB49 000002013349 0 :f:n:v:~:
00000000EB79 000002013379 0 ;&;.;6;>;F;N;V;
00000000EB89 000002013389 0 ;f;n;v;~;
00000000EBBB 0000020133BB 0 1*121:1B1J1R1
00000000EBC9 0000020133C9 0 1e1k1w1
00000000EBDD 0000020133DD 0 2*272G2h2v2
00000000EC03 000002013403 0 3#3+353;3D3]3b3n3s3
00000000EC3B 00000201343B 0 4V4f4t4z4
00000000EC8F 00000201348F 0 :,;V;
00000000ECA5 0000020134A5 0 =L=k=
00000000ECE3 0000020134E3 0 2+2@2R2m2
00000000ED05 000002013505 0 4'4C4]4p4w4
00000000ED17 000002013517 0 4O5Z5n5y5
00000000ED3F 00000201353F 0 7"7'7,777<7A7L7Q7V7a7f7k7v7{7
00000000ED85 000002013585 0 ;);@;V;u;
00000000ED91 000002013591 0 <3<H<T<d<t<T=_=t=
00000000EDA9 0000020135A9 0 =9>D>Y>n>z>
00000000EDBD 0000020135BD 0 ?'?,?;?B?H?R?c?n?
00000000EDE7 0000020135E7 0 1M1R1
00000000EDFD 0000020135FD 0 2.2>2Q2a2t2
00000000EE15 000002013615 0 3$3*323A3L3R3Z3f3
00000000EE47 000002013647 0 ;R?f?
00000000EE61 000002013661 0 161V1
File pos Mem pos ID Text
======== ======= == ====
00000000EE67 000002013667 0 2+2?2h2
00000000EE7D 00000201367D 0 3.343_3x4
00000000EEA3 0000020136A3 0 6:6O6T6_6r6
00000000EEBD 0000020136BD 0 7,757
00000000EED3 0000020136D3 0 9(93999N9
00000000EEDD 0000020136DD 0 9j9w9
00000000EF01 000002013701 0 <1<@<
00000000EF15 000002013715 0 =6=F=t=y=
00000000EF51 000002013751 0 0\0s0
00000000EF5B 00000201375B 0 0+101{2
00000000EF73 000002013773 0 4I5V5f5
00000000EF87 000002013787 0 6%6,696E6O6h6m6s;
00000000EFF9 0000020137F9 0 <1===B=H=
00000000F005 000002013805 0 =!>4?
00000000F01F 00000201381F 0 0!1K1z122k2
00000000F037 000002013837 0 3=4U4
00000000F041 000002013841 0 5+5W5
00000000F04B 00000201384B 0 676I6_6q6
00000000F059 000002013859 0 6Q7Z7e7{7
00000000F065 000002013865 0 7&8+8=8B8
00000000F083 000002013883 0 9$:{;
00000000F095 000002013895 0 <#<0<
00000000F0A5 0000020138A5 0 ?*?:?H?
00000000F0D1 0000020138D1 0 0!1*1<1L1U1
00000000F0E9 0000020138E9 0 222S2x2
00000000F0FB 0000020138FB 0 3/3:3B3P3{3
00000000F115 000002013915 0 6/6?6Y6p6
00000000F12D 00000201392D 0 7'7/7A7u7
00000000F145 000002013945 0 ;5<A<N<\<j<x<
00000000F163 000002013963 0 <&=+=1=&>V>e>
00000000F179 000002013979 0 ?#?D?Q?
00000000F195 000002013995 0 0t0~0
00000000F19B 00000201399B 0 1d1j1p1
00000000F1AB 0000020139AB 0 3)313:3G3
00000000F1C9 0000020139C9 0 4"5.5W5
00000000F1D1 0000020139D1 0 5e5j5t5y5
00000000F1F9 0000020139F9 0 6:7B7G7\7t7
00000000F215 000002013A15 0 959V9
00000000F21B 000002013A1B 0 9f9q9
00000000F23D 000002013A3D 0 :P:g:n:w:|:
00000000F25F 000002013A5F 0 ;#;';+;/;3;7;;;?;C;G;K;O;S;W;
00000000F27F 000002013A7F 0 <*<:<J<b<
00000000F293 000002013A93 0 =&=V=
00000000F2B7 000002013AB7 0 >&>1>=>N>Z>b>
00000000F2D7 000002013AD7 0 ?/?I?R?[?a?x?
00000000F2FD 000002013AFD 0 0+0u0
00000000F31D 000002013B1D 0 1%1/1C1
00000000F331 000002013B31 0 2#2+232>2
00000000F33D 000002013B3D 0 3%3-3Z3f3r3z3
00000000F34F 000002013B4F 0 4*4K4W4_4v4
00000000F367 000002013B67 0 5'5-575=5C5K5Q5W5]5d5j5p5u5{5
00000000F38F 000002013B8F 0 6%636O6U6c6n6}6
00000000F3BD 000002013BBD 0 7 7%7
00000000F3C9 000002013BC9 0 718;8A8H8p8~8
00000000F3EF 000002013BEF 0 :+:9:g:u:z:
00000000F3FD 000002013BFD 0 :9;A;[;h;u;};
00000000F415 000002013C15 0 ;I<a<i<
00000000F42F 000002013C2F 0 <W=j=|=
00000000F45B 000002013C5B 0 >'>,>1>M>R>b>n>~>
00000000F483 000002013C83 0 ?,?:?H?R?a?r?
File pos Mem pos ID Text
======== ======= == ====
00000000F498 000002013C98 0 $0(0,0
00000000F4C5 000002013CC5 0 1 1$1(1,1014181<1@1D1L1P1X1\1
00000000F4E3 000002013CE3 0 1d1h1l1p1t1x1|1
00000000F4F7 000002013CF7 0 1@2D2H2L2P2T2
00000000F6CE 0000020140CE 0 netmgr
00000000F6D6 0000020140D6 0 UTypes
00000000F6DF 0000020140DF 0 System
00000000F6E8 0000020140E8 0 SysInit
00000000F6F1 0000020140F1 0 KWindows
00000000F698 000002014098 0 PACKAGEINFO
=== DOWNLOAD ===
Mirror provided by vx-underground.org, thx!