.- - -----÷M÷E÷N÷U÷------------------------------------------------------------- --- ---- -------------.
! WALL ! STATS ! GOODIES ! YARA ! FAQ ! RSS ! EMV !
`-------------- - --- ---------- -------- -------- -------- -------- ----------------- - ---- ---- --'
ATM MALWARE NOTICE
5ab6358e1886655257c437ebad71b98a6575313b2f9327359661aac5d450c45a
Date...........: 2014-06-05
Family.........: Trojan.Skimer
File name......: netmgr.dll
File size......: 65.00 KB
Type file......: DLL/Windows
Virscan........: VT - HA
Documentation..: https://securelist.com/atm-infector/74772/
Entropy:
Binary Histogram:
=== PEDUMP REPORT ===
=== MZ Header ===
signature: "MZ"
bytes_in_last_block: 80 0x50
blocks_in_file: 2 2
num_relocs: 0 0
header_paragraphs: 4 4
min_extra_paragraphs: 15 0xf
max_extra_paragraphs: 65535 0xffff
ss: 0 0
sp: 184 0xb8
checksum: 0 0
ip: 0 0
cs: 0 0
reloc_table_offset: 64 0x40
overlay_number: 26 0x1a
reserved0: 0 0
oem_id: 0 0
oem_info: 0 0
reserved2: 0 0
reserved3: 0 0
reserved4: 0 0
reserved5: 0 0
reserved6: 0 0
lfanew: 256 0x100
=== DOS STUB ===
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..|
00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus|
00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W|
00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........|
00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
=== PE Header ===
signature: "PE\x00\x00"
# IMAGE_FILE_HEADER:
Machine: 332 0x14c x86
NumberOfSections: 6 6
TimeDateStamp: "1992-06-19 22:22:17"
PointerToSymbolTable: 0 0
NumberOfSymbols: 0 0
SizeOfOptionalHeader: 224 0xe0
Characteristics: 41358 0xa18e EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED
LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO
32BIT_MACHINE, DLL, BYTES_REVERSED_HI
# IMAGE_OPTIONAL_HEADER32:
Magic: 267 0x10b 32-bit executable
LinkerVersion: 2.25
SizeOfCode: 56320 0xdc00
SizeOfInitializedData: 9216 0x2400
SizeOfUninitializedData: 0 0
AddressOfEntryPoint: 59756 0xe96c
BaseOfCode: 4096 0x1000
BaseOfData: 61440 0xf000
ImageBase: 33554432 0x2000000
SectionAlignment: 4096 0x1000
FileAlignment: 512 0x200
OperatingSystemVersion: 4.0
ImageVersion: 0.0
SubsystemVersion: 4.0
Reserved1: 0 0
SizeOfImage: 90112 0x16000
SizeOfHeaders: 1024 0x400
CheckSum: 125134 0x1e8ce
Subsystem: 2 2 WINDOWS_GUI
DllCharacteristics: 1 1 0x01
SizeOfStackReserve: 0 0
SizeOfStackCommit: 0 0
SizeOfHeapReserve: 1048576 0x100000
SizeOfHeapCommit: 4096 0x1000
LoaderFlags: 0 0
NumberOfRvaAndSizes: 16 0x10
=== DATA DIRECTORY ===
EXPORT rva:0x 0 size:0x 0
IMPORT rva:0x 13000 size:0x cac
RESOURCE rva:0x 15000 size:0x 114
EXCEPTION rva:0x 0 size:0x 0
SECURITY rva:0x 0 size:0x 0
BASERELOC rva:0x 14000 size:0x db0
DEBUG rva:0x 0 size:0x 0
ARCHITECTURE rva:0x 0 size:0x 0
GLOBALPTR rva:0x 0 size:0x 0
TLS rva:0x 0 size:0x 0
LOAD_CONFIG rva:0x 0 size:0x 0
Bound_IAT rva:0x 0 size:0x 0
IAT rva:0x 0 size:0x 0
Delay_IAT rva:0x 0 size:0x 0
CLR_Header rva:0x 0 size:0x 0
rva:0x 0 size:0x 0
=== SECTIONS ===
NAME RVA VSZ RAW_SZ RAW_PTR nREL REL_PTR nLINE LINE_PTR FLAGS
CODE 1000 db78 dc00 400 0 0 0 0 60000020 R-X CODE
DATA f000 4dc 600 e000 0 0 0 0 c0000040 RW- IDATA
BSS 10000 2eb5 0 e600 0 0 0 0 c0000000 RW-
.idata 13000 cac e00 e600 0 0 0 0 c0000040 RW- IDATA
.reloc 14000 db0 e00 f400 0 0 0 0 50000040 R-- IDATA SHARED
.rsrc 15000 114 200 10200 0 0 0 0 50000040 R-- IDATA SHARED
=== RESOURCES ===
FILE_OFFSET CP LANG SIZE TYPE NAME
0x10258 1252 0 185 RCDATA #1
=== IMPORTS ===
MODULE_NAME HINT ORD FUNCTION_NAME
kernel32.dll 0 DeleteCriticalSection
kernel32.dll 0 LeaveCriticalSection
kernel32.dll 0 EnterCriticalSection
kernel32.dll 0 InitializeCriticalSection
kernel32.dll 0 VirtualFree
kernel32.dll 0 VirtualAlloc
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
kernel32.dll 0 GetVersion
kernel32.dll 0 GetCurrentThreadId
kernel32.dll 0 GetThreadLocale
kernel32.dll 0 GetStartupInfoA
kernel32.dll 0 GetLocaleInfoA
kernel32.dll 0 GetCommandLineA
kernel32.dll 0 FreeLibrary
kernel32.dll 0 ExitProcess
kernel32.dll 0 CreateThread
kernel32.dll 0 WriteFile
kernel32.dll 0 UnhandledExceptionFilter
kernel32.dll 0 RtlUnwind
kernel32.dll 0 RaiseException
kernel32.dll 0 GetStdHandle
user32.dll 0 GetKeyboardType
user32.dll 0 MessageBoxA
advapi32.dll 0 RegQueryValueExA
advapi32.dll 0 RegOpenKeyExA
advapi32.dll 0 RegCloseKey
kernel32.dll 0 TlsSetValue
kernel32.dll 0 TlsGetValue
kernel32.dll 0 TlsFree
kernel32.dll 0 TlsAlloc
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
advapi32.dll 0 RegQueryValueExA
advapi32.dll 0 RegOpenKeyExA
advapi32.dll 0 RegCloseKey
advapi32.dll 0 OpenProcessToken
advapi32.dll 0 LookupPrivilegeValueA
advapi32.dll 0 AdjustTokenPrivileges
kernel32.dll 0 lstrlenA
kernel32.dll 0 lstrcpynA
kernel32.dll 0 lstrcpyA
kernel32.dll 0 lstrcmpiW
kernel32.dll 0 lstrcmpiA
kernel32.dll 0 lstrcmpA
kernel32.dll 0 lstrcatA
kernel32.dll 0 WriteFile
kernel32.dll 0 WaitForSingleObjectEx
kernel32.dll 0 WaitForSingleObject
kernel32.dll 0 VirtualProtect
kernel32.dll 0 TerminateThread
kernel32.dll 0 SleepEx
kernel32.dll 0 Sleep
kernel32.dll 0 SizeofResource
kernel32.dll 0 SetThreadPriority
kernel32.dll 0 SetFilePointer
kernel32.dll 0 SetEvent
kernel32.dll 0 ReadFile
kernel32.dll 0 OpenProcess
kernel32.dll 0 MultiByteToWideChar
kernel32.dll 0 LocalUnlock
kernel32.dll 0 LocalSize
kernel32.dll 0 LocalReAlloc
kernel32.dll 0 LocalLock
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
kernel32.dll 0 LoadResource
kernel32.dll 0 LoadLibraryA
kernel32.dll 0 GetVolumeInformationA
kernel32.dll 0 GetTickCount
kernel32.dll 0 GetThreadPriority
kernel32.dll 0 GetTempFileNameA
kernel32.dll 0 GetSystemTimeAsFileTime
kernel32.dll 0 GetProcAddress
kernel32.dll 0 GetModuleHandleA
kernel32.dll 0 GetModuleFileNameA
kernel32.dll 0 GetLastError
kernel32.dll 0 GetFileSize
kernel32.dll 0 GetExitCodeThread
kernel32.dll 0 GetCurrentThreadId
kernel32.dll 0 GetCurrentThread
kernel32.dll 0 GetCurrentProcess
kernel32.dll 0 FormatMessageA
kernel32.dll 0 FindResourceA
kernel32.dll 0 FileTimeToSystemTime
kernel32.dll 0 FileTimeToLocalFileTime
kernel32.dll 0 ExitProcess
kernel32.dll 0 DeleteFileA
kernel32.dll 0 CreateThread
kernel32.dll 0 CreateMutexA
kernel32.dll 0 CreateFileA
kernel32.dll 0 CreateEventA
kernel32.dll 0 CopyFileA
kernel32.dll 0 CloseHandle
gdi32.dll 0 TextOutA
gdi32.dll 0 SelectObject
gdi32.dll 0 Rectangle
gdi32.dll 0 GetTextMetricsA
gdi32.dll 0 Escape
gdi32.dll 0 EndDoc
gdi32.dll 0 DeleteObject
gdi32.dll 0 DeleteDC
gdi32.dll 0 CreateSolidBrush
gdi32.dll 0 CreateDCA
user32.dll 0 CreateWindowExA
user32.dll 0 UnregisterClassA
user32.dll 0 TranslateMessage
user32.dll 0 SetTimer
user32.dll 0 SetForegroundWindow
user32.dll 0 SetFocus
user32.dll 0 SendMessageA
user32.dll 0 RegisterClassA
user32.dll 0 PostMessageA
user32.dll 0 PeekMessageA
user32.dll 0 MessageBoxA
user32.dll 0 LoadIconA
user32.dll 0 LoadCursorA
user32.dll 0 InvalidateRect
user32.dll 0 GetWindowTextA
user32.dll 0 GetWindowDC
user32.dll 0 GetMessageA
user32.dll 0 GetForegroundWindow
user32.dll 0 GetDesktopWindow
user32.dll 0 GetClientRect
user32.dll 0 FindWindowExA
user32.dll 0 FindWindowA
user32.dll 0 ExitWindowsEx
user32.dll 0 DrawTextA
user32.dll 0 DispatchMessageA
user32.dll 0 DestroyWindow
user32.dll 0 DefWindowProcA
user32.dll 0 CharUpperA
kernel32.dll 0 GetTickCount
imagehlp.dll 0 CheckSumMappedFile
winspool.drv 0 EnumPrintersA
user32.dll 0 wsprintfA
=== Strings ===
File pos Mem pos ID Text
======== ======= == ====
000000000050 000002000050 0 This program must be run under Win32
000000000270 000002000270 0 .idata
000000000298 000002000298 0 .reloc
0000000002BF 0000020002BF 0 P.rsrc
000000000884 000002001484 0 wE;\$
000000001E9F 000002002A9F 0 ~KxI[)
000000001FC8 000002002BC8 0 SOFTWARE\Borland\Delphi\RTL
000000001FE4 000002002BE4 0 FPUMaskValue
000000002031 000002002C31 0 PPRTj
0000000021AB 000002002DAB 0 YZXtp
000000002322 000002002F22 0 t=HtN
000000002744 000002003344 0 SVWUQ
000000002B00 000002003700 0 USVW1
0000000034E3 0000020040E3 0 {V,|
00000000353F 00000200413F 0 <8LaK#
000000003660 000002004260 0 /R{m6
000000003774 000002004374 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt
0000000037A8 0000020043A8 0 C:\windows\EpsStmApi.log\
000000003BFC 0000020047FC 0 WinSta0
000000003C04 000002004804 0 default
000000003C0C 00000200480C 0 DISPLAY
000000003E55 000002004A55 0 D$XPSj
000000003EEE 000002004AEE 0 D$xPj
000000003F3B 000002004B3B 0 |$,{u
000000003FF8 000002004BF8 0 WinSta0
000000004000 000002004C00 0 MyDesktop
000000004018 000002004C18 0 ATMDialog
000000004024 000002004C24 0 hello
00000000402C 000002004C2C 0 STATIC
000000004044 000002004C44 0 default
00000000405C 000002004C5C 0 Error
000000004110 000002004D10 0 Error
000000004140 000002004D40 0 $PShpM
0000000041A3 000002004DA3 0 $PVSh
0000000041D4 000002004DD4 0 %s %s
000000004480 000002005080 0 %s Error code= %d
0000000044BC 0000020050BC 0 %s Error code= %.2X
0000000044F5 0000020050F5 0 t"Jt"
000000004504 000002005104 0 Jt Jt
000000004618 000002005218 0 OpenProcessToken
00000000462C 00000200522C 0 LookupPrivilegeValue
000000004644 000002005244 0 AdjustTokenPrivileges
0000000047F8 0000020053F8 0 getProcessEntry:
00000000480C 00000200540C 0 SeDebugPrivilege
000000004820 000002005420 0 OpenProcess
00000000482C 00000200542C 0 LoadLibraryA
00000000483C 00000200543C 0 kernel32.dll
00000000484C 00000200544C 0 GetExitCodeThread
000000004860 000002005460 0 VirtualFreeEx
000000004B38 000002005738 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000004B5C 00000200575C 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ)
000000004B88 000002005788 0 EPP Complete LOCK
000000004B9C 00000200579C 0 EPP Complete ENCODE_DECODE
000000004C58 000002005858 0 SVWUQ
000000004CA2 0000020058A2 0 $ZXu>
000000004D16 000002005916 0 ~7hhY
000000004D5C 00000200595C 0 OASYS.dll
000000004D68 000002005968 0 OasPostMessage
000000004E38 000002005A38 0 DBDDevOpen
000000004E44 000002005A44 0 DbdDevRegisterCallback
File pos Mem pos ID Text
======== ======= == ====
000000004E5C 000002005A5C 0 DbdDevLock
000000004E68 000002005A68 0 DbdDevUnregisterCallback
000000004E84 000002005A84 0 DBDDevClose
000000004F00 000002005B00 0 DbdDevUnlock
000000004F10 000002005B10 0 bdDevUnregisterCallback
000000004F28 000002005B28 0 DBDDevClose
000000005010 000002005C10 0 DbdDevAPI.dll
000000005020 000002005C20 0 DbdDevOpen
00000000502C 000002005C2C 0 DbdDevClose
000000005038 000002005C38 0 DbdDevGetInfo
000000005048 000002005C48 0 DbdDevRegisterCallback
000000005060 000002005C60 0 DbdDevUnregisterCallback
00000000507C 000002005C7C 0 DbdDevLock
000000005088 000002005C88 0 DbdDevUnlock
000000005098 000002005C98 0 DbdDevExecute
0000000051C8 000002005DC8 0 AMI function don
0000000051D9 000002005DD9 0 t return in 1 sec
0000000053F4 000002005FF4 0 RECEIPT
0000000053FC 000002005FFC 0 WINSPOOL
000000005408 000002006008 0 CreateDC
000000005414 000002006014 0 hello
00000000541C 00000200601C 0 escape
000000005424 000002006024 0 TextOut
00000000542C 00000200602C 0 enddoc
0000000054E4 0000020060E4 0 DbdDevExecute(EPP4_COPY_KEY)
000000005504 000002006104 0 EPP4_COPY_KEY TimeOut
000000005620 000002006220 0 DbdDevExecute(EPP4_LOAD_KEY)
000000005640 000002006240 0 EPP4_LOAD_KEY TimeOut
0000000056F0 0000020062F0 0 DbdDevExecute(EPP4_DELETE_KEY)
000000005710 000002006310 0 EPP4_DELETE_KEY TimeOut
00000000583C 00000200643C 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000005860 000002006460 0 EPP_Encrypt TimeOut
000000005964 000002006564 0 SVWUQ
000000005C3C 00000200683C 0 LocalAlloc
000000005C48 000002006848 0 LocalLock
000000006442 000002007042 0 P CNu
0000000066D0 0000020072D0 0 SVWUQ
000000006A97 000002007697 0 u7IBF
000000006B26 000002007726 0 I+NBu
000000006EBC 000002007ABC 0 %.2d/%.2d/%.2d %.2d:%.2d
000000007038 000002007C38 0 tdHuaj
0000000070B0 000002007CB0 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI)
0000000070E0 000002007CE0 0 t LOCK EPP
0000000070EC 000002007CEC 0 RECEIPT_PRINTER_START_GDI
000000007108 000002007D08 0 DbdDevExecute(RECEIPT_PRINTER_EJECT)
00000000728C 000002007E8C 0 DbdDevExecute(AFD_DISPENCE)
0000000072A8 000002007EA8 0 CDM Complete LOCK
0000000072BC 000002007EBC 0 DbdDevExecute(AFD_PRESENT)
0000000072D8 000002007ED8 0 DbdDevExecute(AFD_RESTORE)
0000000074B4 0000020080B4 0 SeShutdownPrivilege
000000007810 000002008410 0 kernel32
00000000781C 00000200841C 0 DeleteFileA
000000007828 000002008428 0 FreeLibrary
000000007834 000002008434 0 GetModuleHandleA
000000007848 000002008448 0 CreateFileA
000000007854 000002008454 0 Sleep
00000000785C 00000200845C 0 WriteFile
000000007868 000002008468 0 CloseHandle
000000007874 000002008474 0 LocalFree
000000007880 000002008480 0 LoadLibraryA
File pos Mem pos ID Text
======== ======= == ====
000000007890 000002008490 0 user32
000000007898 000002008498 0 ExitWindowsEx
0000000078A8 0000020084A8 0 SeShutdownPrivilege
000000007A74 000002008674 0 SVWUQ
000000007B88 000002008788 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete
000000007BB4 0000020087B4 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ)
000000007EEC 000002008AEC 0 %.2X%.2X
000000007EF8 000002008AF8 0 Request Code: %.6d
000000007F0B 000002008B0B 0 Enter Responce
000000007F1C 000002008B1C 0 Autorization
000000007F2C 000002008B2C 0 1..4 - dispense cassete
000000007F44 000002008B44 0 9 - Uninstall
000000007F52 000002008B52 0 0 - Exit
000000007F5C 000002008B5C 0 Enter Command
000000008168 000002008D68 0 Diebold:OGuiFrame
00000000817C 000002008D7C 0 Enter Password
000000008190 000002008D90 0 STATIC
0000000081A0 000002008DA0 0 Supply Manager
0000000081B0 000002008DB0 0 Pripnt
0000000081B8 000002008DB8 0 View All Counts
0000000083D0 000002008FD0 0 DbdDevExecute(RESET)
0000000083E8 000002008FE8 0 DBDDEV_LOCK(CRW)
0000000083FC 000002008FFC 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
000000008424 000002009024 0 MCRW_ACCEPT_INSERTION
000000008469 000002009069 0 ;C&v=
000000008E45 000002009A45 0 L0(:L0Sv<V
000000008F94 000002009B94 0 DbdDevExecute(EPP4_LOAD_KEY)
000000008FB4 000002009BB4 0 EPP4_LOAD_KEY TimeOut
000000009088 000002009C88 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN)
0000000090BC 000002009CBC 0 EPP4_COMPUTE_VERIFICATION_PATTERN
00000000924B 000002009E4B 0 TQ,Rj
0000000093E2 000002009FE2 0 :V(t
000000009834 00000200A434 0 LoadKey %.2d @ %.2d - %.2d
000000009854 00000200A454 0 LoadKey %.2d - %.2d
00000000986C 00000200A46C 0 CopyKey %.2d -> %.2d - %.2d
00000000988C 00000200A48C 0 SVWUQ
000000009920 00000200A520 0 ComID %.2d, %X, %X - %.2d,
000000009AE0 00000200A6E0 0 No Transactions
000000009AF0 00000200A6F0 0 No Cards (PINs)
000000009D6C 00000200A96C 0 Transactions %d
000000009D7D 00000200A97D 0 Cards %d
000000009D91 00000200A991 0 Non Local %d
000000009DA5 00000200A9A5 0 MAC_ID %d
000000009DB9 00000200A9B9 0 InstrumentID %d
000000009EB0 00000200AAB0 0 Grab mode %d
000000009EC0 00000200AAC0 0 Deco mode %d
000000009ED1 00000200AAD1 0 Key mode %d
000000009EE2 00000200AAE2 0 Use locals %d
000000009EF3 00000200AAF3 0 Auto delete %d
000000009F04 00000200AB04 0 ReturnOnCode %d
000000009F50 00000200AB50 0 %d.%d.%d.%d : %d
00000000A074 00000200AC74 0 SeDebugPrivilege
00000000A1BC 00000200ADBC 0 SeDebugPrivilege
00000000A294 00000200AE94 0 Bound Import error
00000000A2A8 00000200AEA8 0 Bound Import GetProcAddress
00000000A2C4 00000200AEC4 0 EPP4API.DLL
00000000A2D0 00000200AED0 0 EppInit
00000000A2D8 00000200AED8 0 EppAttach
00000000A2E4 00000200AEE4 0 EppLock
00000000A2EC 00000200AEEC 0 CloseComPort
File pos Mem pos ID Text
======== ======= == ====
00000000A2FC 00000200AEFC 0 EppExchange
00000000A400 00000200B000 0 19200
00000000A570 00000200B170 0 version
00000000A578 00000200B178 0 SOFTWARE\Diebold\Agilis 91x
00000000A594 00000200B194 0 Product Version
00000000A5A4 00000200B1A4 0 SOFTWARE\Diebold\Agilis 91x Core
00000000A624 00000200B224 0 %s%.2X
00000000A646 00000200B246 0 tPj 3
00000000A770 00000200B370 0 version
00000000A778 00000200B378 0 SOFTWARE\Diebold\AMI for Opteva
00000000A798 00000200B398 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva
00000000A7CC 00000200B3CC 0 SOFTWARE\Diebold\Agilis XFS for Opteva
00000000A7F4 00000200B3F4 0 Agilis: %s
00000000A805 00000200B405 0 AMI: %s
00000000A813 00000200B413 0 XFS: %s
00000000A821 00000200B421 0 Firmware:
00000000A950 00000200B550 0 DbdDevExecute(MCRW_CHIP_IO)
00000000A96C 00000200B56C 0 TimeOut MCRW_CHIP_IO
00000000AB38 00000200B738 0 Invalid Sim Response
00000000AC7C 00000200B87C 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
00000000AD40 00000200B940 0 DbdDevExecute(MCRW_POWERON)
00000000AD5C 00000200B95C 0 DbdDevExecute(MCRW_POWEROFF)
00000000ADE4 00000200B9E4 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION)
00000000AE80 00000200BA80 0 DbdDevExecute(MCRW_MCRW_Eject)
00000000B0D8 00000200BCD8 0 TimeOut Reset
00000000B0E8 00000200BCE8 0 Incorrect FIle Size
00000000B498 00000200C098 0 TimeOut Reset
00000000B95F 00000200C55F 0 r AOu
00000000BB58 00000200C758 0 kernel32.dll
00000000BB68 00000200C768 0 CreateFileA
00000000BB74 00000200C774 0 GetFileTime
00000000BB80 00000200C780 0 SetFileTime
00000000BB8C 00000200C78C 0 GetFileSize
00000000BB98 00000200C798 0 ReadFile
00000000BBA4 00000200C7A4 0 WriteFile
00000000BBB0 00000200C7B0 0 SetFilePointer
00000000BBC0 00000200C7C0 0 CloseHandle
00000000BBCC 00000200C7CC 0 LocalAlloc
00000000BBD8 00000200C7D8 0 LocalFree
00000000BBE4 00000200C7E4 0 ExitThread
00000000BBF0 00000200C7F0 0 VirtualFree
00000000BBFC 00000200C7FC 0 Sleep
00000000BC04 00000200C804 0 DeleteFileA
00000000BCC8 00000200C8C8 0 SeDebugPrivilege
00000000BDFC 00000200C9FC 0 Check sum error
00000000BE0C 00000200CA0C 0 Update
00000000BE14 00000200CA14 0 Not executable file
00000000BE89 00000200CA89 0 |$0jd
00000000C107 00000200CD07 0 $ZXrM
00000000C10E 00000200CD0E 0 ZX|G3
00000000C4A4 00000200D0A4 0 c:\Program Files\Diebold\Abc\message.trc
00000000C4D0 00000200D0D0 0 c:\Diebold\css\message.trc
00000000C4EC 00000200D0EC 0 FileSize %d
00000000C4FD 00000200D0FD 0 Transactions %d
00000000C50E 00000200D10E 0 ComKeys %d
00000000C6CC 00000200D2CC 0 hook.LoadLibrary:
00000000C6E0 00000200D2E0 0 GetProcAddress
00000000C6F0 00000200D2F0 0 hook.VirtualProtect
00000000C89C 00000200D49C 0 mode6main
00000000C8B0 00000200D4B0 0 ws2_32.dll
File pos Mem pos ID Text
======== ======= == ====
00000000C8BC 00000200D4BC 0 WSASend
00000000CC6C 00000200D86C 0 Enter command:
00000000D33C 00000200DF3C 0 E PWS
00000000D3FA 00000200DFFA 0 8NTFS
00000000D668 00000200E268 0 DbdDevRegisterCallback
00000000D680 00000200E280 0 DbdDevAPI.dll
00000000D690 00000200E290 0 EppExchange
00000000D69C 00000200E29C 0 EPP4API.dll
00000000D6A8 00000200E2A8 0 DbdDevExecute
00000000D6D6 00000200E2D6 0 Pj@SV
00000000D738 00000200E338 0 VProtect1
00000000D748 00000200E348 0 SVWUQ
00000000D7F4 00000200E3F4 0 Begin
00000000D7FC 00000200E3FC 0 Error
00000000D808 00000200E408 0 t decode const
00000000D884 00000200E484 0 mu.exe
00000000D90D 00000200E50D 0 33333
00000000D92F 00000200E52F 0 UUUU3
00000000DA81 00000200E681 0 VWUSQ
00000000DAC9 00000200E6C9 0 33333
00000000DAEB 00000200E6EB 0 UUUU3
00000000DB9F 00000200E79F 0 UUUU3
00000000DBFD 00000200E7FD 0 VWUSQ
00000000DCB4 00000200E8B4 0 UUUU3
00000000DF64 00000200EB64 0 dfd6jdk
00000000DF6C 00000200EB6C 0 kdu32rbs
00000000E04C 00000200F04C 0 Error
00000000E054 00000200F054 0 Runtime error at 00000000
00000000E074 00000200F074 0 0123456789ABCDEF
00000000E0B0 00000200F0B0 0 SeTtInGs6.34.2
00000000E0C0 00000200F0C0 0 macau
00000000E1C2 00000200F1C2 0 <o:o:_;OPO
00000000E1D1 00000200F1D1 0 OLONO
00000000E1DD 00000200F1DD 0 O!O%O
00000000E390 00000200F390 0 <4,$?7/'
00000000E3D6 00000200F3D6 0 !"#$%&'()*+,-./012345678
00000000E421 00000200F421 0 (3-!0
00000000E428 00000200F428 0 ,1'8"5
00000000E954 000002013354 0 kernel32.dll
00000000E964 000002013364 0 DeleteCriticalSection
00000000E97C 00000201337C 0 LeaveCriticalSection
00000000E994 000002013394 0 EnterCriticalSection
00000000E9AC 0000020133AC 0 InitializeCriticalSection
00000000E9C8 0000020133C8 0 VirtualFree
00000000E9D6 0000020133D6 0 VirtualAlloc
00000000E9E6 0000020133E6 0 LocalFree
00000000E9F2 0000020133F2 0 LocalAlloc
00000000EA00 000002013400 0 GetVersion
00000000EA0E 00000201340E 0 GetCurrentThreadId
00000000EA24 000002013424 0 GetThreadLocale
00000000EA36 000002013436 0 GetStartupInfoA
00000000EA48 000002013448 0 GetLocaleInfoA
00000000EA5A 00000201345A 0 GetCommandLineA
00000000EA6C 00000201346C 0 FreeLibrary
00000000EA7A 00000201347A 0 ExitProcess
00000000EA88 000002013488 0 CreateThread
00000000EA98 000002013498 0 WriteFile
00000000EAA4 0000020134A4 0 UnhandledExceptionFilter
00000000EAC0 0000020134C0 0 RtlUnwind
00000000EACC 0000020134CC 0 RaiseException
File pos Mem pos ID Text
======== ======= == ====
00000000EADE 0000020134DE 0 GetStdHandle
00000000EAEC 0000020134EC 0 user32.dll
00000000EAFA 0000020134FA 0 GetKeyboardType
00000000EB0C 00000201350C 0 MessageBoxA
00000000EB18 000002013518 0 advapi32.dll
00000000EB28 000002013528 0 RegQueryValueExA
00000000EB3C 00000201353C 0 RegOpenKeyExA
00000000EB4C 00000201354C 0 RegCloseKey
00000000EB58 000002013558 0 kernel32.dll
00000000EB68 000002013568 0 TlsSetValue
00000000EB76 000002013576 0 TlsGetValue
00000000EB84 000002013584 0 TlsFree
00000000EB8E 00000201358E 0 TlsAlloc
00000000EB9A 00000201359A 0 LocalFree
00000000EBA6 0000020135A6 0 LocalAlloc
00000000EBB2 0000020135B2 0 advapi32.dll
00000000EBC2 0000020135C2 0 RegQueryValueExA
00000000EBD6 0000020135D6 0 RegOpenKeyExA
00000000EBE6 0000020135E6 0 RegCloseKey
00000000EBF4 0000020135F4 0 OpenProcessToken
00000000EC08 000002013608 0 LookupPrivilegeValueA
00000000EC20 000002013620 0 AdjustTokenPrivileges
00000000EC36 000002013636 0 kernel32.dll
00000000EC46 000002013646 0 lstrlenA
00000000EC52 000002013652 0 lstrcpynA
00000000EC5E 00000201365E 0 lstrcpyA
00000000EC6A 00000201366A 0 lstrcmpiW
00000000EC76 000002013676 0 lstrcmpiA
00000000EC82 000002013682 0 lstrcmpA
00000000EC8E 00000201368E 0 lstrcatA
00000000EC9A 00000201369A 0 WriteFile
00000000ECA6 0000020136A6 0 WaitForSingleObjectEx
00000000ECBE 0000020136BE 0 WaitForSingleObject
00000000ECD4 0000020136D4 0 VirtualProtect
00000000ECE6 0000020136E6 0 TerminateThread
00000000ECF8 0000020136F8 0 SleepEx
00000000ED02 000002013702 0 Sleep
00000000ED0A 00000201370A 0 SizeofResource
00000000ED1C 00000201371C 0 SetThreadPriority
00000000ED30 000002013730 0 SetFilePointer
00000000ED42 000002013742 0 SetEvent
00000000ED4E 00000201374E 0 ReadFile
00000000ED5A 00000201375A 0 OpenProcess
00000000ED68 000002013768 0 MultiByteToWideChar
00000000ED7E 00000201377E 0 LocalUnlock
00000000ED8C 00000201378C 0 LocalSize
00000000ED98 000002013798 0 LocalReAlloc
00000000EDA8 0000020137A8 0 LocalLock
00000000EDB4 0000020137B4 0 LocalFree
00000000EDC0 0000020137C0 0 LocalAlloc
00000000EDCE 0000020137CE 0 LoadResource
00000000EDDE 0000020137DE 0 LoadLibraryA
00000000EDEE 0000020137EE 0 GetVolumeInformationA
00000000EE06 000002013806 0 GetTickCount
00000000EE16 000002013816 0 GetThreadPriority
00000000EE2A 00000201382A 0 GetTempFileNameA
00000000EE3E 00000201383E 0 GetSystemTimeAsFileTime
00000000EE58 000002013858 0 GetProcAddress
00000000EE6A 00000201386A 0 GetModuleHandleA
00000000EE7E 00000201387E 0 GetModuleFileNameA
File pos Mem pos ID Text
======== ======= == ====
00000000EE94 000002013894 0 GetLastError
00000000EEA4 0000020138A4 0 GetFileSize
00000000EEB2 0000020138B2 0 GetExitCodeThread
00000000EEC6 0000020138C6 0 GetCurrentThreadId
00000000EEDC 0000020138DC 0 GetCurrentThread
00000000EEF0 0000020138F0 0 GetCurrentProcess
00000000EF04 000002013904 0 FormatMessageA
00000000EF16 000002013916 0 FindResourceA
00000000EF26 000002013926 0 FileTimeToSystemTime
00000000EF3E 00000201393E 0 FileTimeToLocalFileTime
00000000EF58 000002013958 0 ExitProcess
00000000EF66 000002013966 0 DeleteFileA
00000000EF74 000002013974 0 CreateThread
00000000EF84 000002013984 0 CreateMutexA
00000000EF94 000002013994 0 CreateFileA
00000000EFA2 0000020139A2 0 CreateEventA
00000000EFB2 0000020139B2 0 CopyFileA
00000000EFBE 0000020139BE 0 CloseHandle
00000000EFCA 0000020139CA 0 gdi32.dll
00000000EFD6 0000020139D6 0 TextOutA
00000000EFE2 0000020139E2 0 SelectObject
00000000EFF2 0000020139F2 0 Rectangle
00000000EFFE 0000020139FE 0 GetTextMetricsA
00000000F010 000002013A10 0 Escape
00000000F01A 000002013A1A 0 EndDoc
00000000F024 000002013A24 0 DeleteObject
00000000F034 000002013A34 0 DeleteDC
00000000F040 000002013A40 0 CreateSolidBrush
00000000F054 000002013A54 0 CreateDCA
00000000F05E 000002013A5E 0 user32.dll
00000000F06C 000002013A6C 0 CreateWindowExA
00000000F07E 000002013A7E 0 UnregisterClassA
00000000F092 000002013A92 0 TranslateMessage
00000000F0A6 000002013AA6 0 SetTimer
00000000F0B2 000002013AB2 0 SetForegroundWindow
00000000F0C8 000002013AC8 0 SetFocus
00000000F0D4 000002013AD4 0 SendMessageA
00000000F0E4 000002013AE4 0 RegisterClassA
00000000F0F6 000002013AF6 0 PostMessageA
00000000F106 000002013B06 0 PeekMessageA
00000000F116 000002013B16 0 MessageBoxA
00000000F124 000002013B24 0 LoadIconA
00000000F130 000002013B30 0 LoadCursorA
00000000F13E 000002013B3E 0 InvalidateRect
00000000F150 000002013B50 0 GetWindowTextA
00000000F162 000002013B62 0 GetWindowDC
00000000F170 000002013B70 0 GetMessageA
00000000F17E 000002013B7E 0 GetForegroundWindow
00000000F194 000002013B94 0 GetDesktopWindow
00000000F1A8 000002013BA8 0 GetClientRect
00000000F1B8 000002013BB8 0 FindWindowExA
00000000F1C8 000002013BC8 0 FindWindowA
00000000F1D6 000002013BD6 0 ExitWindowsEx
00000000F1E6 000002013BE6 0 DrawTextA
00000000F1F2 000002013BF2 0 DispatchMessageA
00000000F206 000002013C06 0 DestroyWindow
00000000F216 000002013C16 0 DefWindowProcA
00000000F228 000002013C28 0 CharUpperA
00000000F234 000002013C34 0 kernel32.dll
00000000F244 000002013C44 0 GetTickCount
File pos Mem pos ID Text
======== ======= == ====
00000000F252 000002013C52 0 imagehlp.dll
00000000F262 000002013C62 0 CheckSumMappedFile
00000000F276 000002013C76 0 winspool.drv
00000000F286 000002013C86 0 EnumPrintersA
00000000F294 000002013C94 0 user32.dll
00000000F2A2 000002013CA2 0 wsprintfA
00000000F40F 00000201400F 0 0"0*020:0B0J0R0Z0b0j0r0z0
00000000F43D 00000201403D 0 0&111
00000000F453 000002014053 0 5 6[6j6
00000000F467 000002014067 0 9"9,969@9V9\9j9
00000000F491 000002014091 0 :":G:Q:[:e:o:
00000000F4AF 0000020140AF 0 ;";n;
00000000F4BB 0000020140BB 0 <P<p<
00000000F4C5 0000020140C5 0 =Y>e>
00000000F4ED 0000020140ED 0 0#0(0
00000000F4F9 0000020140F9 0 0@1I1c1
00000000F50F 00000201410F 0 2p2x2~2
00000000F52B 00000201412B 0 3(3@3L3T3u3
00000000F545 000002014145 0 4J4~4
00000000F551 000002014151 0 4,545:5@5M5S5
00000000F587 000002014187 0 8$8=8N8c8p8
00000000F593 000002014193 0 8J9R9
00000000F59B 00000201419B 0 :9;I;_;};
00000000F5AD 0000020141AD 0 <"<*<@<X<f<
00000000F5C3 0000020141C3 0 <#=P=Y=
00000000F5D3 0000020141D3 0 =?>g>
00000000F5E9 0000020141E9 0 0L0T0_0
00000000F5F7 0000020141F7 0 1h1x1~1
00000000F61B 00000201421B 0 20282d2o2
00000000F637 000002014237 0 3%3*3J3O3q3
00000000F64D 00000201424D 0 4%424H4
00000000F65D 00000201425D 0 8!858S8\8h8o8
00000000F66D 00000201426D 0 9'939:9D9N9e9v9
00000000F697 000002014297 0 :':8:B:J:R:Z:b:j:r:
00000000F6B3 0000020142B3 0 ; ;(;X;
00000000F6BB 0000020142BB 0 ;n;s;
00000000F6D3 0000020142D3 0 < <2<?<K<X<j<r<z<
00000000F703 000002014303 0 ="=*=2=:=B=J=R=Z=b=j=r=z=
00000000F743 000002014343 0 >">*>2>:>B>J>R>Z>b>j>r>z>
00000000F783 000002014383 0 ?"?*?2?:?B?J?R?Z?b?j?r?z?
00000000F7C5 0000020143C5 0 5"50565B5K5S5f5l5
00000000F7E9 0000020143E9 0 6@6N6Y6f6k6r6w6~6
00000000F813 000002014413 0 757:7F7K7W7]7b7g7n7|7
00000000F841 000002014441 0 7.8>8L8R8a8s8y8
00000000F855 000002014455 0 8t9z9
00000000F861 000002014461 0 9):a:f:
00000000F885 000002014485 0 ;M<v<
00000000F8AD 0000020144AD 0 001E1d1
00000000F8C1 0000020144C1 0 2&3E3V3[3
00000000F8D1 0000020144D1 0 3>5Q5g5
00000000F8DD 0000020144DD 0 5#606B6J6T6e6w6
00000000F8F9 0000020144F9 0 7!7&7
00000000F905 000002014505 0 8.8K8b8s8
00000000F939 000002014539 0 :6;B;L;R;
00000000F943 000002014543 0 ;c;n;s;x;
00000000F977 000002014577 0 =B>z>
00000000F983 000002014583 0 ?*?I?V?g?}?
00000000F9C3 0000020145C3 0 2N3]3j3r3{3
00000000F9F9 0000020145F9 0 606H6_6o6
00000000FA15 000002014615 0 7D7T7x7~7
File pos Mem pos ID Text
======== ======= == ====
00000000FA39 000002014639 0 8!808
00000000FA41 000002014641 0 <6=g=
00000000FA4D 00000201464D 0 >"?r?
00000000FA6F 00000201466F 0 4d455
00000000FA81 000002014681 0 :?:M:v:
00000000FA89 000002014689 0 :O;k;
00000000FAA1 0000020146A1 0 <n<t<
00000000FAB1 0000020146B1 0 >S>\>y>
00000000FABF 0000020146BF 0 ?0?5?D?O?z?
00000000FAE0 0000020146E0 0 )090C0I0W0
00000000FAED 0000020146ED 0 0*212:2C2K2V2
00000000FAFB 0000020146FB 0 2j2y2
00000000FB15 000002014715 0 3,3<3L3\3h3{3
00000000FB25 000002014725 0 3Z5e5{5
00000000FB39 000002014739 0 6B6U6Z6
00000000FB51 000002014751 0 7,767
00000000FB5D 00000201475D 0 8H8M8p8
00000000FB6B 00000201476B 0 9)9<9a9
00000000FB77 000002014777 0 9#:=:{:
00000000FB87 000002014787 0 <8<p<
00000000FB9F 00000201479F 0 >$?1?M?[?u?|?
00000000FBD1 0000020147D1 0 : ;+;@;U;a;j;z;
00000000FBE1 0000020147E1 0 <!<6<K<W<
00000000FBEF 0000020147EF 0 <3=A=H=d=l=
00000000FBFF 0000020147FF 0 =W>q>
00000000FC21 000002014821 0 0#1L1U1[1
00000000FC33 000002014833 0 2'2.292@2E2L2Q2X2]2d2n2
00000000FC51 000002014851 0 3(3x3
00000000FC63 000002014863 0 4W5w5
00000000FC83 000002014883 0 9*989K9
00000000FC8D 00000201488D 0 91:[:
00000000FC93 000002014893 0 :B;{;
00000000FCA5 0000020148A5 0 =M=e=
00000000FCAF 0000020148AF 0 >;>g>
00000000FCB7 0000020148B7 0 ?"?G?Y?o?
00000000FCDB 0000020148DB 0 0F1K1]1b1
00000000FD05 000002014905 0 5#5+585
00000000FD17 000002014917 0 828B8P8
00000000FD27 000002014927 0 9 9)9
00000000FD39 000002014939 0 :9:B:T:d:m:
00000000FD4F 00000201494F 0 ;6;J;k;
00000000FD5F 00000201495F 0 <'<3<G<R<Z<h<
00000000FD7D 00000201497D 0 ?'?7?Q?h?|?
00000000FD9F 00000201499F 0 0#050]0i0s0
00000000FDB7 0000020149B7 0 1]1b1p1
00000000FDCB 0000020149CB 0 496E6R6
00000000FDD3 0000020149D3 0 6n6|6
00000000FDE9 0000020149E9 0 6*7/757*8Z8i8
00000000FDFD 0000020149FD 0 9!9'9H9U9v9
00000000FE0F 000002014A0F 0 9A:F:
00000000FE2D 000002014A2D 0 <s=}=
00000000FE3B 000002014A3B 0 >.>6>
00000000FE47 000002014A47 0 ?(?7?G?
00000000FE6F 000002014A6F 0 0 0.090@0G0W0c0r0x0
00000000FE83 000002014A83 0 0+1=1O1d1
00000000FE97 000002014A97 0 2B2d2
00000000FE9D 000002014A9D 0 2a3v3~3
00000000FEB5 000002014AB5 0 4.4;4L4T4Z4_4d4i4s4x4}4
00000000FED9 000002014AD9 0 4$5+5
00000000FF23 000002014B23 0 7'7?7
File pos Mem pos ID Text
======== ======= == ====
00000000FF37 000002014B37 0 8)8Y8
00000000FF53 000002014B53 0 9.999E9V9b9j9
00000000FF73 000002014B73 0 :7:Q:Z:c:i:
00000000FF8F 000002014B8F 0 ;3;z;
00000000FFAD 000002014BAD 0 <$<,<6<J<
00000000FFC1 000002014BC1 0 =+=3=;=F=
00000000FFCD 000002014BCD 0 >->5>b>n>z>
00000000FFDF 000002014BDF 0 ?2?S?_?g?~?
00000000FFFF 000002014BFF 0 0"0,020<0B0H0P0Y0b0k0v0
000000010027 000002014C27 0 1@1R1
000000010049 000002014C49 0 2#2+20252:2F2K2P2U2
000000010075 000002014C75 0 344B4Z4>5V5s5
000000010097 000002014C97 0 5+696>6
0000000100A7 000002014CA7 0 7,797A7X7
0000000100B1 000002014CB1 0 7h7p7x7
0000000100BB 000002014CBB 0 8%8-8G8R8]8c8x8~8
0000000100D5 000002014CD5 0 9.9@9D9H9L9P9T9X9\9
0000000100E9 000002014CE9 0 9h9|9
00000001010B 000002014D0B 0 :/:;:K:a:k:
00000001012F 000002014D2F 0 ;$;3;D;
000000010140 000002014D40 0 $0(0,0
000000010169 000002014D69 0 1 1$1(1,1014181<1@1D1H1L1T1X1
000000010187 000002014D87 0 1d1h1l1p1t1x1|1
00000001019F 000002014D9F 0 1L2P2T2X2\2
000000010311 000002015111 0 PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
000000000050 000002000050 0 This program must be run under Win32
000000000270 000002000270 0 .idata
000000000298 000002000298 0 .reloc
0000000002BF 0000020002BF 0 P.rsrc
000000000884 000002001484 0 wE;\$
000000001E9F 000002002A9F 0 ~KxI[)
000000001FC8 000002002BC8 0 SOFTWARE\Borland\Delphi\RTL
000000001FE4 000002002BE4 0 FPUMaskValue
000000002031 000002002C31 0 PPRTj
0000000021AB 000002002DAB 0 YZXtp
000000002322 000002002F22 0 t=HtN
000000002744 000002003344 0 SVWUQ
000000002B00 000002003700 0 USVW1
0000000034E3 0000020040E3 0 {V,|
00000000353F 00000200413F 0 <8LaK#
000000003660 000002004260 0 /R{m6
000000003774 000002004374 0 C:\Program Files\Diebold\AMI\AMITRACE\AMITrace.txt
0000000037A8 0000020043A8 0 C:\windows\EpsStmApi.log\
000000003BFC 0000020047FC 0 WinSta0
000000003C04 000002004804 0 default
000000003C0C 00000200480C 0 DISPLAY
000000003E55 000002004A55 0 D$XPSj
000000003EEE 000002004AEE 0 D$xPj
000000003F3B 000002004B3B 0 |$,{u
000000003FF8 000002004BF8 0 WinSta0
000000004000 000002004C00 0 MyDesktop
000000004018 000002004C18 0 ATMDialog
000000004024 000002004C24 0 hello
00000000402C 000002004C2C 0 STATIC
000000004044 000002004C44 0 default
00000000405C 000002004C5C 0 Error
000000004110 000002004D10 0 Error
000000004140 000002004D40 0 $PShpM
0000000041A3 000002004DA3 0 $PVSh
0000000041D4 000002004DD4 0 %s %s
File pos Mem pos ID Text
======== ======= == ====
000000004480 000002005080 0 %s Error code= %d
0000000044BC 0000020050BC 0 %s Error code= %.2X
0000000044F5 0000020050F5 0 t"Jt"
000000004504 000002005104 0 Jt Jt
000000004618 000002005218 0 OpenProcessToken
00000000462C 00000200522C 0 LookupPrivilegeValue
000000004644 000002005244 0 AdjustTokenPrivileges
0000000047F8 0000020053F8 0 getProcessEntry:
00000000480C 00000200540C 0 SeDebugPrivilege
000000004820 000002005420 0 OpenProcess
00000000482C 00000200542C 0 LoadLibraryA
00000000483C 00000200543C 0 kernel32.dll
00000000484C 00000200544C 0 GetExitCodeThread
000000004860 000002005460 0 VirtualFreeEx
000000004B38 000002005738 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000004B5C 00000200575C 0 DbdDevExecute(EPP4_ENABLE_KEYBOARD_READ)
000000004B88 000002005788 0 EPP Complete LOCK
000000004B9C 00000200579C 0 EPP Complete ENCODE_DECODE
000000004C58 000002005858 0 SVWUQ
000000004CA2 0000020058A2 0 $ZXu>
000000004D16 000002005916 0 ~7hhY
000000004D5C 00000200595C 0 OASYS.dll
000000004D68 000002005968 0 OasPostMessage
000000004E38 000002005A38 0 DBDDevOpen
000000004E44 000002005A44 0 DbdDevRegisterCallback
000000004E5C 000002005A5C 0 DbdDevLock
000000004E68 000002005A68 0 DbdDevUnregisterCallback
000000004E84 000002005A84 0 DBDDevClose
000000004F00 000002005B00 0 DbdDevUnlock
000000004F10 000002005B10 0 bdDevUnregisterCallback
000000004F28 000002005B28 0 DBDDevClose
000000005010 000002005C10 0 DbdDevAPI.dll
000000005020 000002005C20 0 DbdDevOpen
00000000502C 000002005C2C 0 DbdDevClose
000000005038 000002005C38 0 DbdDevGetInfo
000000005048 000002005C48 0 DbdDevRegisterCallback
000000005060 000002005C60 0 DbdDevUnregisterCallback
00000000507C 000002005C7C 0 DbdDevLock
000000005088 000002005C88 0 DbdDevUnlock
000000005098 000002005C98 0 DbdDevExecute
0000000051C8 000002005DC8 0 AMI function don
0000000051D9 000002005DD9 0 t return in 1 sec
0000000053F4 000002005FF4 0 RECEIPT
0000000053FC 000002005FFC 0 WINSPOOL
000000005408 000002006008 0 CreateDC
000000005414 000002006014 0 hello
00000000541C 00000200601C 0 escape
000000005424 000002006024 0 TextOut
00000000542C 00000200602C 0 enddoc
0000000054E4 0000020060E4 0 DbdDevExecute(EPP4_COPY_KEY)
000000005504 000002006104 0 EPP4_COPY_KEY TimeOut
000000005620 000002006220 0 DbdDevExecute(EPP4_LOAD_KEY)
000000005640 000002006240 0 EPP4_LOAD_KEY TimeOut
0000000056F0 0000020062F0 0 DbdDevExecute(EPP4_DELETE_KEY)
000000005710 000002006310 0 EPP4_DELETE_KEY TimeOut
00000000583C 00000200643C 0 DbdDevExecute(EPP4_ENCODE_DECODE)
000000005860 000002006460 0 EPP_Encrypt TimeOut
000000005964 000002006564 0 SVWUQ
000000005C3C 00000200683C 0 LocalAlloc
000000005C48 000002006848 0 LocalLock
File pos Mem pos ID Text
======== ======= == ====
000000006442 000002007042 0 P CNu
0000000066D0 0000020072D0 0 SVWUQ
000000006A97 000002007697 0 u7IBF
000000006B26 000002007726 0 I+NBu
000000006EBC 000002007ABC 0 %.2d/%.2d/%.2d %.2d:%.2d
000000007038 000002007C38 0 tdHuaj
0000000070B0 000002007CB0 0 DbdDevExecute(RECEIPT_PRINTER_START_GDI)
0000000070E0 000002007CE0 0 t LOCK EPP
0000000070EC 000002007CEC 0 RECEIPT_PRINTER_START_GDI
000000007108 000002007D08 0 DbdDevExecute(RECEIPT_PRINTER_EJECT)
00000000728C 000002007E8C 0 DbdDevExecute(AFD_DISPENCE)
0000000072A8 000002007EA8 0 CDM Complete LOCK
0000000072BC 000002007EBC 0 DbdDevExecute(AFD_PRESENT)
0000000072D8 000002007ED8 0 DbdDevExecute(AFD_RESTORE)
0000000074B4 0000020080B4 0 SeShutdownPrivilege
000000007810 000002008410 0 kernel32
00000000781C 00000200841C 0 DeleteFileA
000000007828 000002008428 0 FreeLibrary
000000007834 000002008434 0 GetModuleHandleA
000000007848 000002008448 0 CreateFileA
000000007854 000002008454 0 Sleep
00000000785C 00000200845C 0 WriteFile
000000007868 000002008468 0 CloseHandle
000000007874 000002008474 0 LocalFree
000000007880 000002008480 0 LoadLibraryA
000000007890 000002008490 0 user32
000000007898 000002008498 0 ExitWindowsEx
0000000078A8 0000020084A8 0 SeShutdownPrivilege
000000007A74 000002008674 0 SVWUQ
000000007B88 000002008788 0 TimeOut EPP4_DISABLE_KEYBOARD_READ complete
000000007BB4 0000020087B4 0 DbdDevExecute(EPP4_DISABLE_KEYBOARD_READ)
000000007EEC 000002008AEC 0 %.2X%.2X
000000007EF8 000002008AF8 0 Request Code: %.6d
000000007F0B 000002008B0B 0 Enter Responce
000000007F1C 000002008B1C 0 Autorization
000000007F2C 000002008B2C 0 1..4 - dispense cassete
000000007F44 000002008B44 0 9 - Uninstall
000000007F52 000002008B52 0 0 - Exit
000000007F5C 000002008B5C 0 Enter Command
000000008168 000002008D68 0 Diebold:OGuiFrame
00000000817C 000002008D7C 0 Enter Password
000000008190 000002008D90 0 STATIC
0000000081A0 000002008DA0 0 Supply Manager
0000000081B0 000002008DB0 0 Pripnt
0000000081B8 000002008DB8 0 View All Counts
0000000083D0 000002008FD0 0 DbdDevExecute(RESET)
0000000083E8 000002008FE8 0 DBDDEV_LOCK(CRW)
0000000083FC 000002008FFC 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
000000008424 000002009024 0 MCRW_ACCEPT_INSERTION
000000008469 000002009069 0 ;C&v=
000000008E45 000002009A45 0 L0(:L0Sv<V
000000008F94 000002009B94 0 DbdDevExecute(EPP4_LOAD_KEY)
000000008FB4 000002009BB4 0 EPP4_LOAD_KEY TimeOut
000000009088 000002009C88 0 DbdDevGetInfo(EPP4_COMPUTE_VERIFICATION_PATTERN)
0000000090BC 000002009CBC 0 EPP4_COMPUTE_VERIFICATION_PATTERN
00000000924B 000002009E4B 0 TQ,Rj
0000000093E2 000002009FE2 0 :V(t
000000009834 00000200A434 0 LoadKey %.2d @ %.2d - %.2d
000000009854 00000200A454 0 LoadKey %.2d - %.2d
00000000986C 00000200A46C 0 CopyKey %.2d -> %.2d - %.2d
File pos Mem pos ID Text
======== ======= == ====
00000000988C 00000200A48C 0 SVWUQ
000000009920 00000200A520 0 ComID %.2d, %X, %X - %.2d,
000000009AE0 00000200A6E0 0 No Transactions
000000009AF0 00000200A6F0 0 No Cards (PINs)
000000009D6C 00000200A96C 0 Transactions %d
000000009D7D 00000200A97D 0 Cards %d
000000009D91 00000200A991 0 Non Local %d
000000009DA5 00000200A9A5 0 MAC_ID %d
000000009DB9 00000200A9B9 0 InstrumentID %d
000000009EB0 00000200AAB0 0 Grab mode %d
000000009EC0 00000200AAC0 0 Deco mode %d
000000009ED1 00000200AAD1 0 Key mode %d
000000009EE2 00000200AAE2 0 Use locals %d
000000009EF3 00000200AAF3 0 Auto delete %d
000000009F04 00000200AB04 0 ReturnOnCode %d
000000009F50 00000200AB50 0 %d.%d.%d.%d : %d
00000000A074 00000200AC74 0 SeDebugPrivilege
00000000A1BC 00000200ADBC 0 SeDebugPrivilege
00000000A294 00000200AE94 0 Bound Import error
00000000A2A8 00000200AEA8 0 Bound Import GetProcAddress
00000000A2C4 00000200AEC4 0 EPP4API.DLL
00000000A2D0 00000200AED0 0 EppInit
00000000A2D8 00000200AED8 0 EppAttach
00000000A2E4 00000200AEE4 0 EppLock
00000000A2EC 00000200AEEC 0 CloseComPort
00000000A2FC 00000200AEFC 0 EppExchange
00000000A400 00000200B000 0 19200
00000000A570 00000200B170 0 version
00000000A578 00000200B178 0 SOFTWARE\Diebold\Agilis 91x
00000000A594 00000200B194 0 Product Version
00000000A5A4 00000200B1A4 0 SOFTWARE\Diebold\Agilis 91x Core
00000000A624 00000200B224 0 %s%.2X
00000000A646 00000200B246 0 tPj 3
00000000A770 00000200B370 0 version
00000000A778 00000200B378 0 SOFTWARE\Diebold\AMI for Opteva
00000000A798 00000200B398 0 SOFTWARE\Diebold\Agilis Module Interface for Opteva
00000000A7CC 00000200B3CC 0 SOFTWARE\Diebold\Agilis XFS for Opteva
00000000A7F4 00000200B3F4 0 Agilis: %s
00000000A805 00000200B405 0 AMI: %s
00000000A813 00000200B413 0 XFS: %s
00000000A821 00000200B421 0 Firmware:
00000000A950 00000200B550 0 DbdDevExecute(MCRW_CHIP_IO)
00000000A96C 00000200B56C 0 TimeOut MCRW_CHIP_IO
00000000AB38 00000200B738 0 Invalid Sim Response
00000000AC7C 00000200B87C 0 DbdDevExecute(MCRW_ACCEPT_INSERTION)
00000000AD40 00000200B940 0 DbdDevExecute(MCRW_POWERON)
00000000AD5C 00000200B95C 0 DbdDevExecute(MCRW_POWEROFF)
00000000ADE4 00000200B9E4 0 DbdDevExecute(MCRW_IC_CONTACT_POSITION)
00000000AE80 00000200BA80 0 DbdDevExecute(MCRW_MCRW_Eject)
00000000B0D8 00000200BCD8 0 TimeOut Reset
00000000B0E8 00000200BCE8 0 Incorrect FIle Size
00000000B498 00000200C098 0 TimeOut Reset
00000000B95F 00000200C55F 0 r AOu
00000000BB58 00000200C758 0 kernel32.dll
00000000BB68 00000200C768 0 CreateFileA
00000000BB74 00000200C774 0 GetFileTime
00000000BB80 00000200C780 0 SetFileTime
00000000BB8C 00000200C78C 0 GetFileSize
00000000BB98 00000200C798 0 ReadFile
00000000BBA4 00000200C7A4 0 WriteFile
File pos Mem pos ID Text
======== ======= == ====
00000000BBB0 00000200C7B0 0 SetFilePointer
00000000BBC0 00000200C7C0 0 CloseHandle
00000000BBCC 00000200C7CC 0 LocalAlloc
00000000BBD8 00000200C7D8 0 LocalFree
00000000BBE4 00000200C7E4 0 ExitThread
00000000BBF0 00000200C7F0 0 VirtualFree
00000000BBFC 00000200C7FC 0 Sleep
00000000BC04 00000200C804 0 DeleteFileA
00000000BCC8 00000200C8C8 0 SeDebugPrivilege
00000000BDFC 00000200C9FC 0 Check sum error
00000000BE0C 00000200CA0C 0 Update
00000000BE14 00000200CA14 0 Not executable file
00000000BE89 00000200CA89 0 |$0jd
00000000C107 00000200CD07 0 $ZXrM
00000000C10E 00000200CD0E 0 ZX|G3
00000000C4A4 00000200D0A4 0 c:\Program Files\Diebold\Abc\message.trc
00000000C4D0 00000200D0D0 0 c:\Diebold\css\message.trc
00000000C4EC 00000200D0EC 0 FileSize %d
00000000C4FD 00000200D0FD 0 Transactions %d
00000000C50E 00000200D10E 0 ComKeys %d
00000000C6CC 00000200D2CC 0 hook.LoadLibrary:
00000000C6E0 00000200D2E0 0 GetProcAddress
00000000C6F0 00000200D2F0 0 hook.VirtualProtect
00000000C89C 00000200D49C 0 mode6main
00000000C8B0 00000200D4B0 0 ws2_32.dll
00000000C8BC 00000200D4BC 0 WSASend
00000000CC6C 00000200D86C 0 Enter command:
00000000D33C 00000200DF3C 0 E PWS
00000000D3FA 00000200DFFA 0 8NTFS
00000000D668 00000200E268 0 DbdDevRegisterCallback
00000000D680 00000200E280 0 DbdDevAPI.dll
00000000D690 00000200E290 0 EppExchange
00000000D69C 00000200E29C 0 EPP4API.dll
00000000D6A8 00000200E2A8 0 DbdDevExecute
00000000D6D6 00000200E2D6 0 Pj@SV
00000000D738 00000200E338 0 VProtect1
00000000D748 00000200E348 0 SVWUQ
00000000D7F4 00000200E3F4 0 Begin
00000000D7FC 00000200E3FC 0 Error
00000000D808 00000200E408 0 t decode const
00000000D884 00000200E484 0 mu.exe
00000000D90D 00000200E50D 0 33333
00000000D92F 00000200E52F 0 UUUU3
00000000DA81 00000200E681 0 VWUSQ
00000000DAC9 00000200E6C9 0 33333
00000000DAEB 00000200E6EB 0 UUUU3
00000000DB9F 00000200E79F 0 UUUU3
00000000DBFD 00000200E7FD 0 VWUSQ
00000000DCB4 00000200E8B4 0 UUUU3
00000000DF64 00000200EB64 0 dfd6jdk
00000000DF6C 00000200EB6C 0 kdu32rbs
00000000E04C 00000200F04C 0 Error
00000000E054 00000200F054 0 Runtime error at 00000000
00000000E074 00000200F074 0 0123456789ABCDEF
00000000E0B0 00000200F0B0 0 SeTtInGs6.34.2
00000000E0C0 00000200F0C0 0 macau
00000000E1C2 00000200F1C2 0 <o:o:_;OPO
00000000E1D1 00000200F1D1 0 OLONO
00000000E1DD 00000200F1DD 0 O!O%O
00000000E390 00000200F390 0 <4,$?7/'
File pos Mem pos ID Text
======== ======= == ====
00000000E3D6 00000200F3D6 0 !"#$%&'()*+,-./012345678
00000000E421 00000200F421 0 (3-!0
00000000E428 00000200F428 0 ,1'8"5
00000000E954 000002013354 0 kernel32.dll
00000000E964 000002013364 0 DeleteCriticalSection
00000000E97C 00000201337C 0 LeaveCriticalSection
00000000E994 000002013394 0 EnterCriticalSection
00000000E9AC 0000020133AC 0 InitializeCriticalSection
00000000E9C8 0000020133C8 0 VirtualFree
00000000E9D6 0000020133D6 0 VirtualAlloc
00000000E9E6 0000020133E6 0 LocalFree
00000000E9F2 0000020133F2 0 LocalAlloc
00000000EA00 000002013400 0 GetVersion
00000000EA0E 00000201340E 0 GetCurrentThreadId
00000000EA24 000002013424 0 GetThreadLocale
00000000EA36 000002013436 0 GetStartupInfoA
00000000EA48 000002013448 0 GetLocaleInfoA
00000000EA5A 00000201345A 0 GetCommandLineA
00000000EA6C 00000201346C 0 FreeLibrary
00000000EA7A 00000201347A 0 ExitProcess
00000000EA88 000002013488 0 CreateThread
00000000EA98 000002013498 0 WriteFile
00000000EAA4 0000020134A4 0 UnhandledExceptionFilter
00000000EAC0 0000020134C0 0 RtlUnwind
00000000EACC 0000020134CC 0 RaiseException
00000000EADE 0000020134DE 0 GetStdHandle
00000000EAEC 0000020134EC 0 user32.dll
00000000EAFA 0000020134FA 0 GetKeyboardType
00000000EB0C 00000201350C 0 MessageBoxA
00000000EB18 000002013518 0 advapi32.dll
00000000EB28 000002013528 0 RegQueryValueExA
00000000EB3C 00000201353C 0 RegOpenKeyExA
00000000EB4C 00000201354C 0 RegCloseKey
00000000EB58 000002013558 0 kernel32.dll
00000000EB68 000002013568 0 TlsSetValue
00000000EB76 000002013576 0 TlsGetValue
00000000EB84 000002013584 0 TlsFree
00000000EB8E 00000201358E 0 TlsAlloc
00000000EB9A 00000201359A 0 LocalFree
00000000EBA6 0000020135A6 0 LocalAlloc
00000000EBB2 0000020135B2 0 advapi32.dll
00000000EBC2 0000020135C2 0 RegQueryValueExA
00000000EBD6 0000020135D6 0 RegOpenKeyExA
00000000EBE6 0000020135E6 0 RegCloseKey
00000000EBF4 0000020135F4 0 OpenProcessToken
00000000EC08 000002013608 0 LookupPrivilegeValueA
00000000EC20 000002013620 0 AdjustTokenPrivileges
00000000EC36 000002013636 0 kernel32.dll
00000000EC46 000002013646 0 lstrlenA
00000000EC52 000002013652 0 lstrcpynA
00000000EC5E 00000201365E 0 lstrcpyA
00000000EC6A 00000201366A 0 lstrcmpiW
00000000EC76 000002013676 0 lstrcmpiA
00000000EC82 000002013682 0 lstrcmpA
00000000EC8E 00000201368E 0 lstrcatA
00000000EC9A 00000201369A 0 WriteFile
00000000ECA6 0000020136A6 0 WaitForSingleObjectEx
00000000ECBE 0000020136BE 0 WaitForSingleObject
00000000ECD4 0000020136D4 0 VirtualProtect
00000000ECE6 0000020136E6 0 TerminateThread
File pos Mem pos ID Text
======== ======= == ====
00000000ECF8 0000020136F8 0 SleepEx
00000000ED02 000002013702 0 Sleep
00000000ED0A 00000201370A 0 SizeofResource
00000000ED1C 00000201371C 0 SetThreadPriority
00000000ED30 000002013730 0 SetFilePointer
00000000ED42 000002013742 0 SetEvent
00000000ED4E 00000201374E 0 ReadFile
00000000ED5A 00000201375A 0 OpenProcess
00000000ED68 000002013768 0 MultiByteToWideChar
00000000ED7E 00000201377E 0 LocalUnlock
00000000ED8C 00000201378C 0 LocalSize
00000000ED98 000002013798 0 LocalReAlloc
00000000EDA8 0000020137A8 0 LocalLock
00000000EDB4 0000020137B4 0 LocalFree
00000000EDC0 0000020137C0 0 LocalAlloc
00000000EDCE 0000020137CE 0 LoadResource
00000000EDDE 0000020137DE 0 LoadLibraryA
00000000EDEE 0000020137EE 0 GetVolumeInformationA
00000000EE06 000002013806 0 GetTickCount
00000000EE16 000002013816 0 GetThreadPriority
00000000EE2A 00000201382A 0 GetTempFileNameA
00000000EE3E 00000201383E 0 GetSystemTimeAsFileTime
00000000EE58 000002013858 0 GetProcAddress
00000000EE6A 00000201386A 0 GetModuleHandleA
00000000EE7E 00000201387E 0 GetModuleFileNameA
00000000EE94 000002013894 0 GetLastError
00000000EEA4 0000020138A4 0 GetFileSize
00000000EEB2 0000020138B2 0 GetExitCodeThread
00000000EEC6 0000020138C6 0 GetCurrentThreadId
00000000EEDC 0000020138DC 0 GetCurrentThread
00000000EEF0 0000020138F0 0 GetCurrentProcess
00000000EF04 000002013904 0 FormatMessageA
00000000EF16 000002013916 0 FindResourceA
00000000EF26 000002013926 0 FileTimeToSystemTime
00000000EF3E 00000201393E 0 FileTimeToLocalFileTime
00000000EF58 000002013958 0 ExitProcess
00000000EF66 000002013966 0 DeleteFileA
00000000EF74 000002013974 0 CreateThread
00000000EF84 000002013984 0 CreateMutexA
00000000EF94 000002013994 0 CreateFileA
00000000EFA2 0000020139A2 0 CreateEventA
00000000EFB2 0000020139B2 0 CopyFileA
00000000EFBE 0000020139BE 0 CloseHandle
00000000EFCA 0000020139CA 0 gdi32.dll
00000000EFD6 0000020139D6 0 TextOutA
00000000EFE2 0000020139E2 0 SelectObject
00000000EFF2 0000020139F2 0 Rectangle
00000000EFFE 0000020139FE 0 GetTextMetricsA
00000000F010 000002013A10 0 Escape
00000000F01A 000002013A1A 0 EndDoc
00000000F024 000002013A24 0 DeleteObject
00000000F034 000002013A34 0 DeleteDC
00000000F040 000002013A40 0 CreateSolidBrush
00000000F054 000002013A54 0 CreateDCA
00000000F05E 000002013A5E 0 user32.dll
00000000F06C 000002013A6C 0 CreateWindowExA
00000000F07E 000002013A7E 0 UnregisterClassA
00000000F092 000002013A92 0 TranslateMessage
00000000F0A6 000002013AA6 0 SetTimer
00000000F0B2 000002013AB2 0 SetForegroundWindow
File pos Mem pos ID Text
======== ======= == ====
00000000F0C8 000002013AC8 0 SetFocus
00000000F0D4 000002013AD4 0 SendMessageA
00000000F0E4 000002013AE4 0 RegisterClassA
00000000F0F6 000002013AF6 0 PostMessageA
00000000F106 000002013B06 0 PeekMessageA
00000000F116 000002013B16 0 MessageBoxA
00000000F124 000002013B24 0 LoadIconA
00000000F130 000002013B30 0 LoadCursorA
00000000F13E 000002013B3E 0 InvalidateRect
00000000F150 000002013B50 0 GetWindowTextA
00000000F162 000002013B62 0 GetWindowDC
00000000F170 000002013B70 0 GetMessageA
00000000F17E 000002013B7E 0 GetForegroundWindow
00000000F194 000002013B94 0 GetDesktopWindow
00000000F1A8 000002013BA8 0 GetClientRect
00000000F1B8 000002013BB8 0 FindWindowExA
00000000F1C8 000002013BC8 0 FindWindowA
00000000F1D6 000002013BD6 0 ExitWindowsEx
00000000F1E6 000002013BE6 0 DrawTextA
00000000F1F2 000002013BF2 0 DispatchMessageA
00000000F206 000002013C06 0 DestroyWindow
00000000F216 000002013C16 0 DefWindowProcA
00000000F228 000002013C28 0 CharUpperA
00000000F234 000002013C34 0 kernel32.dll
00000000F244 000002013C44 0 GetTickCount
00000000F252 000002013C52 0 imagehlp.dll
00000000F262 000002013C62 0 CheckSumMappedFile
00000000F276 000002013C76 0 winspool.drv
00000000F286 000002013C86 0 EnumPrintersA
00000000F294 000002013C94 0 user32.dll
00000000F2A2 000002013CA2 0 wsprintfA
00000000F40F 00000201400F 0 0"0*020:0B0J0R0Z0b0j0r0z0
00000000F43D 00000201403D 0 0&111
00000000F453 000002014053 0 5 6[6j6
00000000F467 000002014067 0 9"9,969@9V9\9j9
00000000F491 000002014091 0 :":G:Q:[:e:o:
00000000F4AF 0000020140AF 0 ;";n;
00000000F4BB 0000020140BB 0 <P<p<
00000000F4C5 0000020140C5 0 =Y>e>
00000000F4ED 0000020140ED 0 0#0(0
00000000F4F9 0000020140F9 0 0@1I1c1
00000000F50F 00000201410F 0 2p2x2~2
00000000F52B 00000201412B 0 3(3@3L3T3u3
00000000F545 000002014145 0 4J4~4
00000000F551 000002014151 0 4,545:5@5M5S5
00000000F587 000002014187 0 8$8=8N8c8p8
00000000F593 000002014193 0 8J9R9
00000000F59B 00000201419B 0 :9;I;_;};
00000000F5AD 0000020141AD 0 <"<*<@<X<f<
00000000F5C3 0000020141C3 0 <#=P=Y=
00000000F5D3 0000020141D3 0 =?>g>
00000000F5E9 0000020141E9 0 0L0T0_0
00000000F5F7 0000020141F7 0 1h1x1~1
00000000F61B 00000201421B 0 20282d2o2
00000000F637 000002014237 0 3%3*3J3O3q3
00000000F64D 00000201424D 0 4%424H4
00000000F65D 00000201425D 0 8!858S8\8h8o8
00000000F66D 00000201426D 0 9'939:9D9N9e9v9
00000000F697 000002014297 0 :':8:B:J:R:Z:b:j:r:
00000000F6B3 0000020142B3 0 ; ;(;X;
File pos Mem pos ID Text
======== ======= == ====
00000000F6BB 0000020142BB 0 ;n;s;
00000000F6D3 0000020142D3 0 < <2<?<K<X<j<r<z<
00000000F703 000002014303 0 ="=*=2=:=B=J=R=Z=b=j=r=z=
00000000F743 000002014343 0 >">*>2>:>B>J>R>Z>b>j>r>z>
00000000F783 000002014383 0 ?"?*?2?:?B?J?R?Z?b?j?r?z?
00000000F7C5 0000020143C5 0 5"50565B5K5S5f5l5
00000000F7E9 0000020143E9 0 6@6N6Y6f6k6r6w6~6
00000000F813 000002014413 0 757:7F7K7W7]7b7g7n7|7
00000000F841 000002014441 0 7.8>8L8R8a8s8y8
00000000F855 000002014455 0 8t9z9
00000000F861 000002014461 0 9):a:f:
00000000F885 000002014485 0 ;M<v<
00000000F8AD 0000020144AD 0 001E1d1
00000000F8C1 0000020144C1 0 2&3E3V3[3
00000000F8D1 0000020144D1 0 3>5Q5g5
00000000F8DD 0000020144DD 0 5#606B6J6T6e6w6
00000000F8F9 0000020144F9 0 7!7&7
00000000F905 000002014505 0 8.8K8b8s8
00000000F939 000002014539 0 :6;B;L;R;
00000000F943 000002014543 0 ;c;n;s;x;
00000000F977 000002014577 0 =B>z>
00000000F983 000002014583 0 ?*?I?V?g?}?
00000000F9C3 0000020145C3 0 2N3]3j3r3{3
00000000F9F9 0000020145F9 0 606H6_6o6
00000000FA15 000002014615 0 7D7T7x7~7
00000000FA39 000002014639 0 8!808
00000000FA41 000002014641 0 <6=g=
00000000FA4D 00000201464D 0 >"?r?
00000000FA6F 00000201466F 0 4d455
00000000FA81 000002014681 0 :?:M:v:
00000000FA89 000002014689 0 :O;k;
00000000FAA1 0000020146A1 0 <n<t<
00000000FAB1 0000020146B1 0 >S>\>y>
00000000FABF 0000020146BF 0 ?0?5?D?O?z?
00000000FAE0 0000020146E0 0 )090C0I0W0
00000000FAED 0000020146ED 0 0*212:2C2K2V2
00000000FAFB 0000020146FB 0 2j2y2
00000000FB15 000002014715 0 3,3<3L3\3h3{3
00000000FB25 000002014725 0 3Z5e5{5
00000000FB39 000002014739 0 6B6U6Z6
00000000FB51 000002014751 0 7,767
00000000FB5D 00000201475D 0 8H8M8p8
00000000FB6B 00000201476B 0 9)9<9a9
00000000FB77 000002014777 0 9#:=:{:
00000000FB87 000002014787 0 <8<p<
00000000FB9F 00000201479F 0 >$?1?M?[?u?|?
00000000FBD1 0000020147D1 0 : ;+;@;U;a;j;z;
00000000FBE1 0000020147E1 0 <!<6<K<W<
00000000FBEF 0000020147EF 0 <3=A=H=d=l=
00000000FBFF 0000020147FF 0 =W>q>
00000000FC21 000002014821 0 0#1L1U1[1
00000000FC33 000002014833 0 2'2.292@2E2L2Q2X2]2d2n2
00000000FC51 000002014851 0 3(3x3
00000000FC63 000002014863 0 4W5w5
00000000FC83 000002014883 0 9*989K9
00000000FC8D 00000201488D 0 91:[:
00000000FC93 000002014893 0 :B;{;
00000000FCA5 0000020148A5 0 =M=e=
00000000FCAF 0000020148AF 0 >;>g>
00000000FCB7 0000020148B7 0 ?"?G?Y?o?
File pos Mem pos ID Text
======== ======= == ====
00000000FCDB 0000020148DB 0 0F1K1]1b1
00000000FD05 000002014905 0 5#5+585
00000000FD17 000002014917 0 828B8P8
00000000FD27 000002014927 0 9 9)9
00000000FD39 000002014939 0 :9:B:T:d:m:
00000000FD4F 00000201494F 0 ;6;J;k;
00000000FD5F 00000201495F 0 <'<3<G<R<Z<h<
00000000FD7D 00000201497D 0 ?'?7?Q?h?|?
00000000FD9F 00000201499F 0 0#050]0i0s0
00000000FDB7 0000020149B7 0 1]1b1p1
00000000FDCB 0000020149CB 0 496E6R6
00000000FDD3 0000020149D3 0 6n6|6
00000000FDE9 0000020149E9 0 6*7/757*8Z8i8
00000000FDFD 0000020149FD 0 9!9'9H9U9v9
00000000FE0F 000002014A0F 0 9A:F:
00000000FE2D 000002014A2D 0 <s=}=
00000000FE3B 000002014A3B 0 >.>6>
00000000FE47 000002014A47 0 ?(?7?G?
00000000FE6F 000002014A6F 0 0 0.090@0G0W0c0r0x0
00000000FE83 000002014A83 0 0+1=1O1d1
00000000FE97 000002014A97 0 2B2d2
00000000FE9D 000002014A9D 0 2a3v3~3
00000000FEB5 000002014AB5 0 4.4;4L4T4Z4_4d4i4s4x4}4
00000000FED9 000002014AD9 0 4$5+5
00000000FF23 000002014B23 0 7'7?7
00000000FF37 000002014B37 0 8)8Y8
00000000FF53 000002014B53 0 9.999E9V9b9j9
00000000FF73 000002014B73 0 :7:Q:Z:c:i:
00000000FF8F 000002014B8F 0 ;3;z;
00000000FFAD 000002014BAD 0 <$<,<6<J<
00000000FFC1 000002014BC1 0 =+=3=;=F=
00000000FFCD 000002014BCD 0 >->5>b>n>z>
00000000FFDF 000002014BDF 0 ?2?S?_?g?~?
00000000FFFF 000002014BFF 0 0"0,020<0B0H0P0Y0b0k0v0
000000010027 000002014C27 0 1@1R1
000000010049 000002014C49 0 2#2+20252:2F2K2P2U2
000000010075 000002014C75 0 344B4Z4>5V5s5
000000010097 000002014C97 0 5+696>6
0000000100A7 000002014CA7 0 7,797A7X7
0000000100B1 000002014CB1 0 7h7p7x7
0000000100BB 000002014CBB 0 8%8-8G8R8]8c8x8~8
0000000100D5 000002014CD5 0 9.9@9D9H9L9P9T9X9\9
0000000100E9 000002014CE9 0 9h9|9
00000001010B 000002014D0B 0 :/:;:K:a:k:
00000001012F 000002014D2F 0 ;$;3;D;
000000010140 000002014D40 0 $0(0,0
000000010169 000002014D69 0 1 1$1(1,1014181<1@1D1H1L1T1X1
000000010187 000002014D87 0 1d1h1l1p1t1x1|1
00000001019F 000002014D9F 0 1L2P2T2X2\2
000000010311 000002015111 0 PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
=== DOWNLOAD ===
Mirror provided by vx-underground.org, thx!