.- - -----÷M÷E÷N÷U÷------------------------------------------------------------- --- ----  -------------.
!  WALL ! STATS ! GOODIES ! YARA ! FAQ ! RSS                                                            !
`--------------  - ---  ---------- -------- -------- -------- -------- ----------------- -  ---- ---- --'

                                           ATM MALWARE NOTICE 
                    05a00a4b2d07780021bcd1a4abe84dc0ee28531136414f0ee631fa0d9844d479
 
Date...........: 2020-05-15
Family.........: DispCash.10
File name......: xfs_cuinfo.exe
File size......: 89.50 KB
Type file......: EXE/Windows
Virscan........: VT - HA
Documentation..: https://twitter.com/s4tan/status/1262356066203041793
Additional note: Drop 98e7fe52634c9ed9105a1604169e29d797419cb89ae863c2178999f34abd1497.
Seem infected by 'Neshta', see strings.
Similar to: 5f70c76b6771b7c56bc5da34e424eb9a090cedeb807c795795a88c415a2e772c.

Entropy:


Binary Histogram:


=== PEDUMP REPORT === 
=== MZ Header === signature: "MZ" bytes_in_last_block: 80 0x50 blocks_in_file: 2 2 num_relocs: 0 0 header_paragraphs: 4 4 min_extra_paragraphs: 15 0xf max_extra_paragraphs: 65535 0xffff ss: 0 0 sp: 184 0xb8 checksum: 0 0 ip: 0 0 cs: 0 0 reloc_table_offset: 64 0x40 overlay_number: 26 0x1a reserved0: 0 0 oem_id: 0 0 oem_info: 0 0 reserved2: 0 0 reserved3: 0 0 reserved4: 0 0 reserved5: 0 0 reserved6: 0 0 lfanew: 256 0x100 === DOS STUB === 00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| === PE Header === signature: "PE\x00\x00" # IMAGE_FILE_HEADER: Machine: 332 0x14c x86 NumberOfSections: 8 8 TimeDateStamp: "1992-06-19 22:22:17" PointerToSymbolTable: 0 0 NumberOfSymbols: 0 0 SizeOfOptionalHeader: 224 0xe0 Characteristics: 33166 0x818e EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO 32BIT_MACHINE, BYTES_REVERSED_HI # IMAGE_OPTIONAL_HEADER32: Magic: 267 0x10b 32-bit executable LinkerVersion: 2.25 SizeOfCode: 29696 0x7400 SizeOfInitializedData: 10752 0x2a00 SizeOfUninitializedData: 0 0 AddressOfEntryPoint: 32996 0x80e4 BaseOfCode: 4096 0x1000 BaseOfData: 36864 0x9000 ImageBase: 4194304 0x400000 SectionAlignment: 4096 0x1000 FileAlignment: 512 0x200 OperatingSystemVersion: 4.0 ImageVersion: 0.0 SubsystemVersion: 4.0 Reserved1: 0 0 SizeOfImage: 110592 0x1b000 SizeOfHeaders: 1024 0x400 CheckSum: 0 0 Subsystem: 2 2 WINDOWS_GUI DllCharacteristics: 0 0 SizeOfStackReserve: 1048576 0x100000 SizeOfStackCommit: 16384 0x4000 SizeOfHeapReserve: 1048576 0x100000 SizeOfHeapCommit: 4096 0x1000 LoaderFlags: 0 0 NumberOfRvaAndSizes: 16 0x10 === DATA DIRECTORY === EXPORT rva:0x 0 size:0x 0 IMPORT rva:0x 15000 size:0x 864 RESOURCE rva:0x 19000 size:0x 1400 EXCEPTION rva:0x 0 size:0x 0 SECURITY rva:0x 0 size:0x 0 BASERELOC rva:0x 18000 size:0x 5cc DEBUG rva:0x 0 size:0x 0 ARCHITECTURE rva:0x 0 size:0x 0 GLOBALPTR rva:0x 0 size:0x 0 TLS rva:0x 17000 size:0x 18 LOAD_CONFIG rva:0x 0 size:0x 0 Bound_IAT rva:0x 0 size:0x 0 IAT rva:0x 0 size:0x 0 Delay_IAT rva:0x 0 size:0x 0 CLR_Header rva:0x 0 size:0x 0 rva:0x 0 size:0x 0 === SECTIONS === NAME RVA VSZ RAW_SZ RAW_PTR nREL REL_PTR nLINE LINE_PTR FLAGS CODE 1000 722c 7400 400 0 0 0 0 60000020 R-X CODE DATA 9000 218 400 7800 0 0 0 0 c0000040 RW- IDATA BSS a000 a899 0 7c00 0 0 0 0 c0000000 RW- .idata 15000 864 a00 7c00 0 0 0 0 c0000040 RW- IDATA .tls 16000 8 0 8600 0 0 0 0 c0000000 RW- .rdata 17000 18 200 8600 0 0 0 0 50000040 R-- IDATA SHARED .reloc 18000 5cc 600 8800 0 0 0 0 50000040 R-- IDATA SHARED .rsrc 19000 1400 1400 8e00 0 0 0 0 50000040 R-- IDATA SHARED === TLS === RAW_START RAW_END INDEX CALLBKS ZEROFILL FLAGS 416000 416008 409090 417010 0 0 [?] ignoring invalid PEdump::BITMAPINFOHEADER === RESOURCES === FILE_OFFSET CP LANG SIZE TYPE NAME 0x8f50 0 0x419 4264 ICON #1 0x9ff8 0 0 16 RCDATA DVCLAL 0xa008 0 0 172 RCDATA PACKAGEINFO 0xa0b4 0 0x419 20 GROUP_ICON MAINICON === IMPORTS === MODULE_NAME HINT ORD FUNCTION_NAME kernel32.dll 0 DeleteCriticalSection kernel32.dll 0 LeaveCriticalSection kernel32.dll 0 EnterCriticalSection kernel32.dll 0 InitializeCriticalSection kernel32.dll 0 VirtualFree kernel32.dll 0 VirtualAlloc kernel32.dll 0 LocalFree kernel32.dll 0 LocalAlloc kernel32.dll 0 GetVersion kernel32.dll 0 GetCurrentThreadId kernel32.dll 0 GetThreadLocale kernel32.dll 0 GetStartupInfoA kernel32.dll 0 GetLocaleInfoA kernel32.dll 0 GetCommandLineA kernel32.dll 0 FreeLibrary kernel32.dll 0 ExitProcess kernel32.dll 0 WriteFile kernel32.dll 0 UnhandledExceptionFilter kernel32.dll 0 RtlUnwind kernel32.dll 0 RaiseException kernel32.dll 0 GetStdHandle user32.dll 0 GetKeyboardType user32.dll 0 MessageBoxA advapi32.dll 0 RegQueryValueExA advapi32.dll 0 RegOpenKeyExA advapi32.dll 0 RegCloseKey oleaut32.dll 0 SysFreeString oleaut32.dll 0 SysReAllocStringLen kernel32.dll 0 TlsSetValue kernel32.dll 0 TlsGetValue kernel32.dll 0 LocalAlloc kernel32.dll 0 GetModuleHandleA advapi32.dll 0 RegSetValueExA advapi32.dll 0 RegOpenKeyExA advapi32.dll 0 RegCloseKey kernel32.dll 0 WriteFile kernel32.dll 0 WinExec kernel32.dll 0 SetFilePointer kernel32.dll 0 SetFileAttributesA kernel32.dll 0 SetEndOfFile kernel32.dll 0 SetCurrentDirectoryA kernel32.dll 0 ReleaseMutex kernel32.dll 0 ReadFile kernel32.dll 0 GetWindowsDirectoryA kernel32.dll 0 GetTempPathA kernel32.dll 0 GetShortPathNameA kernel32.dll 0 GetModuleFileNameA kernel32.dll 0 GetLogicalDriveStringsA kernel32.dll 0 GetLocalTime kernel32.dll 0 GetLastError kernel32.dll 0 GetFileSize kernel32.dll 0 GetFileAttributesA kernel32.dll 0 GetDriveTypeA kernel32.dll 0 GetCommandLineA kernel32.dll 0 FreeLibrary kernel32.dll 0 FindNextFileA kernel32.dll 0 FindFirstFileA kernel32.dll 0 FindClose kernel32.dll 0 DeleteFileA kernel32.dll 0 CreateMutexA kernel32.dll 0 CreateFileA kernel32.dll 0 CreateDirectoryA kernel32.dll 0 CloseHandle gdi32.dll 0 StretchDIBits gdi32.dll 0 SetDIBits gdi32.dll 0 SelectObject gdi32.dll 0 GetObjectA gdi32.dll 0 GetDIBits gdi32.dll 0 DeleteObject gdi32.dll 0 DeleteDC gdi32.dll 0 CreateSolidBrush gdi32.dll 0 CreateDIBSection gdi32.dll 0 CreateCompatibleDC gdi32.dll 0 CreateCompatibleBitmap gdi32.dll 0 BitBlt user32.dll 0 ReleaseDC user32.dll 0 GetSysColor user32.dll 0 GetIconInfo user32.dll 0 GetDC user32.dll 0 FillRect user32.dll 0 DestroyIcon user32.dll 0 CopyImage user32.dll 0 CharLowerBuffA shell32.dll 0 ShellExecuteA shell32.dll 0 ExtractIconA === Packer / Compiler === Borland Delphi v6.0 - v7.0
=== Strings ===
File pos Mem pos ID Text ======== ======= == ==== 000000000050 000000400050 0 This program must be run under Win32 000000000270 000000400270 0 .idata 0000000002C0 0000004002C0 0 .rdata 0000000002E7 0000004002E7 0 P.reloc 00000000030F 00000040030F 0 P.rsrc 00000000059C 00000040119C 0 SVWUQ 0000000007BD 0000004013BD 0 w;;t$ 0000000008C8 0000004014C8 0 SVWUQ 0000000017AD 0000004023AD 0 Uh5$@ 000000001B17 000000402717 0 ~KxI[) 000000001CD0 0000004028D0 0 SOFTWARE\Borland\Delphi\RTL 000000001CEC 0000004028EC 0 FPUMaskValue 000000001D39 000000402939 0 PPRTj 000000001EB3 000000402AB3 0 YZXtp 00000000202A 000000402C2A 0 t=HtN 000000002204 000000402E04 0 Uh2.@ 0000000026CC 0000004032CC 0 SVWRP 0000000028F2 0000004034F2 0 t1SVW 000000003009 000000403C09 0 Uhd<@ 00000000312D 000000403D2D 0 Uhr=@ 00000000335D 000000403F5D 0 Uh}?@ 0000000033CE 000000403FCE 0 HBITMAP 000000003615 000000404215 0 Uh5B@ 00000000365D 00000040425D 0 Uh}B@ 000000003705 000000404305 0 Uh%C@ 00000000373D 00000040433D 0 Uh]C@ 0000000038E0 0000004044E0 0 YXZQRPR 0000000039F0 0000004045F0 0 R;P P| 000000003AB4 0000004046B4 0 IVXLCDMT 000000003C52 000000404852 0 t=8!u 000000003C64 000000404864 0 ,8"t& 000000003EF0 000000404AF0 0 Uh(K@ 00000000400F 000000404C0F 0 UhfL@ 0000000041E5 000000404DE5 0 QQQQS 00000000441E 00000040501E 0 UhrP@ 000000004605 000000405205 0 QQQQS 000000004E35 000000405A35 0 XH;XH~ P 000000004E50 000000405A50 0 9PD}-RP 000000004E83 000000405A83 0 PH9PL~ 000000004E9D 000000405A9D 0 KH+KLQ 000000004EBB 000000405ABB 0 ;CHRQ~ 00000000502A 000000405C2A 0 ;GHv 000000005210 000000405E10 0 @t:HS 00000000523A 000000405E3A 0 Z[XR1 000000005335 000000405F35 0 RP;P ~ 0000000053EB 000000405FEB 0 SPRQj 0000000060E5 000000406CE5 0 Uh/m@ 0000000062A5 000000406EA5 0 Uh"o@ 0000000063E9 000000406FE9 0 QQQQQS 000000006407 000000407007 0 Uhdp@ 0000000064E3 0000004070E3 0 Uh&q@ 0000000068A8 0000004074A8 0 \PROGRA~1\ 0000000068B9 0000004074B9 0 QQQQQQSVW 0000000069A8 0000004075A8 0 Uh\v@ 000000006DA5 0000004079A5 0 QQQQQQS3 000000006ED5 000000407AD5 0 QQQQQQ 0000000070A2 000000407CA2 0 UhJ}@ 0000000071A1 000000407DA1 0 QQQQQQSV 0000000071B6 000000407DB6 0 Uhu~@ 000000007858 000000409058 0 Error File pos Mem pos ID Text ======== ======= == ==== 000000007860 000000409060 0 Runtime error at 00000000 000000007880 000000409080 0 0123456789ABCDEF 000000007E58 000000415258 0 kernel32.dll 000000007E68 000000415268 0 DeleteCriticalSection 000000007E80 000000415280 0 LeaveCriticalSection 000000007E98 000000415298 0 EnterCriticalSection 000000007EB0 0000004152B0 0 InitializeCriticalSection 000000007ECC 0000004152CC 0 VirtualFree 000000007EDA 0000004152DA 0 VirtualAlloc 000000007EEA 0000004152EA 0 LocalFree 000000007EF6 0000004152F6 0 LocalAlloc 000000007F04 000000415304 0 GetVersion 000000007F12 000000415312 0 GetCurrentThreadId 000000007F28 000000415328 0 GetThreadLocale 000000007F3A 00000041533A 0 GetStartupInfoA 000000007F4C 00000041534C 0 GetLocaleInfoA 000000007F5E 00000041535E 0 GetCommandLineA 000000007F70 000000415370 0 FreeLibrary 000000007F7E 00000041537E 0 ExitProcess 000000007F8C 00000041538C 0 WriteFile 000000007F98 000000415398 0 UnhandledExceptionFilter 000000007FB4 0000004153B4 0 RtlUnwind 000000007FC0 0000004153C0 0 RaiseException 000000007FD2 0000004153D2 0 GetStdHandle 000000007FE0 0000004153E0 0 user32.dll 000000007FEE 0000004153EE 0 GetKeyboardType 000000008000 000000415400 0 MessageBoxA 00000000800C 00000041540C 0 advapi32.dll 00000000801C 00000041541C 0 RegQueryValueExA 000000008030 000000415430 0 RegOpenKeyExA 000000008040 000000415440 0 RegCloseKey 00000000804C 00000041544C 0 oleaut32.dll 00000000805C 00000041545C 0 SysFreeString 00000000806C 00000041546C 0 SysReAllocStringLen 000000008080 000000415480 0 kernel32.dll 000000008090 000000415490 0 TlsSetValue 00000000809E 00000041549E 0 TlsGetValue 0000000080AC 0000004154AC 0 LocalAlloc 0000000080BA 0000004154BA 0 GetModuleHandleA 0000000080CC 0000004154CC 0 advapi32.dll 0000000080DC 0000004154DC 0 RegSetValueExA 0000000080EE 0000004154EE 0 RegOpenKeyExA 0000000080FE 0000004154FE 0 RegCloseKey 00000000810A 00000041550A 0 kernel32.dll 00000000811A 00000041551A 0 WriteFile 000000008126 000000415526 0 WinExec 000000008130 000000415530 0 SetFilePointer 000000008142 000000415542 0 SetFileAttributesA 000000008158 000000415558 0 SetEndOfFile 000000008168 000000415568 0 SetCurrentDirectoryA 000000008180 000000415580 0 ReleaseMutex 000000008190 000000415590 0 ReadFile 00000000819C 00000041559C 0 GetWindowsDirectoryA 0000000081B4 0000004155B4 0 GetTempPathA 0000000081C4 0000004155C4 0 GetShortPathNameA 0000000081D8 0000004155D8 0 GetModuleFileNameA 0000000081EE 0000004155EE 0 GetLogicalDriveStringsA 000000008208 000000415608 0 GetLocalTime 000000008218 000000415618 0 GetLastError 000000008228 000000415628 0 GetFileSize File pos Mem pos ID Text ======== ======= == ==== 000000008236 000000415636 0 GetFileAttributesA 00000000824C 00000041564C 0 GetDriveTypeA 00000000825C 00000041565C 0 GetCommandLineA 00000000826E 00000041566E 0 FreeLibrary 00000000827C 00000041567C 0 FindNextFileA 00000000828C 00000041568C 0 FindFirstFileA 00000000829E 00000041569E 0 FindClose 0000000082AA 0000004156AA 0 DeleteFileA 0000000082B8 0000004156B8 0 CreateMutexA 0000000082C8 0000004156C8 0 CreateFileA 0000000082D6 0000004156D6 0 CreateDirectoryA 0000000082EA 0000004156EA 0 CloseHandle 0000000082F6 0000004156F6 0 gdi32.dll 000000008302 000000415702 0 StretchDIBits 000000008312 000000415712 0 SetDIBits 00000000831E 00000041571E 0 SelectObject 00000000832E 00000041572E 0 GetObjectA 00000000833C 00000041573C 0 GetDIBits 000000008348 000000415748 0 DeleteObject 000000008358 000000415758 0 DeleteDC 000000008364 000000415764 0 CreateSolidBrush 000000008378 000000415778 0 CreateDIBSection 00000000838C 00000041578C 0 CreateCompatibleDC 0000000083A2 0000004157A2 0 CreateCompatibleBitmap 0000000083BC 0000004157BC 0 BitBlt 0000000083C4 0000004157C4 0 user32.dll 0000000083D2 0000004157D2 0 ReleaseDC 0000000083DE 0000004157DE 0 GetSysColor 0000000083EC 0000004157EC 0 GetIconInfo 0000000083FA 0000004157FA 0 GetDC 000000008402 000000415802 0 FillRect 00000000840E 00000041580E 0 DestroyIcon 00000000841C 00000041581C 0 CopyImage 000000008428 000000415828 0 CharLowerBuffA 000000008438 000000415838 0 shell32.dll 000000008446 000000415846 0 ShellExecuteA 000000008456 000000415856 0 ExtractIconA 00000000880F 00000041800F 0 0"0*020:0B0J0R0Z0b0j0r0z0 00000000883F 00000041803F 0 0 1(1 000000008857 000000418057 0 4-595T5 00000000885F 00000041805F 0 567r7 00000000887D 00000041807D 0 8&8,848F8R8a8m8u8 0000000088AB 0000004180AB 0 9/9:9[9s9 0000000088BD 0000004180BD 0 :W:w: 0000000088CD 0000004180CD 0 <'<0<;<D<K<Z<a< 0000000088F1 0000004180F1 0 >b>k> 000000008901 000000418101 0 ?2?\?e?u?}? 00000000892B 00000041812B 0 0(0@0L0T0k0z0 000000008945 000000418145 0 0,1P1n1~1 00000000895B 00000041815B 0 2$2u2|2 00000000897D 00000041817D 0 4#4+4O4o4 00000000899B 00000041819B 0 8A8Q8g8 0000000089AD 0000004181AD 0 9*929H9 0000000089C3 0000004181C3 0 9+:X:a: 0000000089D3 0000004181D3 0 :G;o; 0000000089DF 0000004181DF 0 < =T=\=g= 0000000089F1 0000004181F1 0 >N>R>X>\>a>h>n>v> 000000008A11 000000418211 0 ?%?/?7?=?K?f?{? 000000008A38 000000418238 0 N0W0}0 000000008A41 000000418241 0 466?6:7C7 File pos Mem pos ID Text ======== ======= == ==== 000000008A53 000000418253 0 <)<2<><E< 000000008A5F 00000041825F 0 =/=;=B=L=V=m=~= 000000008A89 000000418289 0 >/>@>J>R>Z>b>j> 000000008AA7 0000004182A7 0 ?&?+?0?7?>?H?_?k?x? 000000008ADD 0000004182DD 0 0:0B0J0R0Z0b0j0r0z0 000000008B17 000000418317 0 1"1*121:1B1J1R1Z1b1j1r1z1 000000008B47 000000418347 0 2#202B2J2R2_2k2x2 000000008B6D 00000041836D 0 3 323?3K3X3j3w3 000000008B93 000000418393 0 4$4(4,484<4@4L4P4T4 000000008BA7 0000004183A7 0 4d4h4t4x4|4 000000008C15 000000418415 0 6_8H9 000000008C1B 00000041841B 0 9,;:;A;H;c;o; 000000008C51 000000418451 0 :(;=;c; 000000008C6B 00000041846B 0 =*=:=Z= 000000008C75 000000418475 0 >A>v> 000000008C90 000000418490 0 040R0 000000008CB1 0000004184B1 0 2_3n3 000000008CC5 0000004184C5 0 5 6J6 000000008CD1 0000004184D1 0 7U7w7 000000008CDD 0000004184DD 0 9_9d9w9 000000008CEB 0000004184EB 0 :.:E:c:z: 000000008D07 000000418507 0 <==u= 000000008D0D 00000041850D 0 =.>c> 000000008D29 000000418529 0 030F0X0\0 000000008D33 000000418533 0 0d0h0l0p0t0x0|0 000000008D77 000000418577 0 1%191M1a1 000000008D90 000000418590 0 004080 000000008DAD 0000004185AD 0 1 1$1(1 00000000A023 00000041A223 0 RsZLZ 00000000A096 00000041A296 0 Uag%N 00000000A0E0 00000041A2E0 0 Delphi-the best. Fuck off all the rest. Neshta 1.0 Made in Belarus. 00000000A1A8 00000041A3A8 0 ! Best regards 2 Tommy Salo. [Nov-2005] yours [Dziadulja Apanas] 00000000BAAA 00000040BAAA 0 DeleteCriticalSection 00000000BAC2 00000040BAC2 0 EnterCriticalSection 00000000BADA 00000040BADA 0 ExitProcess 00000000BAE8 00000040BAE8 0 GetCommandLineA 00000000BAFA 00000040BAFA 0 GetLastError 00000000BB0A 00000040BB0A 0 GetModuleHandleA 00000000BB1E 00000040BB1E 0 GetProcAddress 00000000BB30 00000040BB30 0 InitializeCriticalSection 00000000BB4C 00000040BB4C 0 InterlockedExchange 00000000BB62 00000040BB62 0 IsDBCSLeadByteEx 00000000BB76 00000040BB76 0 LeaveCriticalSection 00000000BB8E 00000040BB8E 0 MultiByteToWideChar 00000000BBA4 00000040BBA4 0 SetUnhandledExceptionFilter 00000000BBC2 00000040BBC2 0 Sleep 00000000BBCA 00000040BBCA 0 TlsGetValue 00000000BBD8 00000040BBD8 0 VirtualProtect 00000000BBEA 00000040BBEA 0 VirtualQuery 00000000BBFA 00000040BBFA 0 WideCharToMultiByte 00000000BC10 00000040BC10 0 _strdup 00000000BC1A 00000040BC1A 0 _stricoll 00000000BC26 00000040BC26 0 __getmainargs 00000000BC36 00000040BC36 0 __mb_cur_max 00000000BC46 00000040BC46 0 __p__environ 00000000BC56 00000040BC56 0 __p__fmode 00000000BC64 00000040BC64 0 __set_app_type 00000000BC76 00000040BC76 0 _cexit 00000000BC80 00000040BC80 0 _errno 00000000BC8A 00000040BC8A 0 _findclose File pos Mem pos ID Text ======== ======= == ==== 00000000BC98 00000040BC98 0 _findfirst 00000000BCA6 00000040BCA6 0 _findnext 00000000BCB2 00000040BCB2 0 _fullpath 00000000BCC6 00000040BCC6 0 _onexit 00000000BCD0 00000040BCD0 0 _setmode 00000000BCDC 00000040BCDC 0 abort 00000000BCE4 00000040BCE4 0 atexit 00000000BCF6 00000040BCF6 0 calloc 00000000BD00 00000040BD00 0 fputc 00000000BD10 00000040BD10 0 fwrite 00000000BD1A 00000040BD1A 0 getenv 00000000BD24 00000040BD24 0 isspace 00000000BD2E 00000040BD2E 0 localeconv 00000000BD3C 00000040BD3C 0 malloc 00000000BD46 00000040BD46 0 mbstowcs 00000000BD52 00000040BD52 0 memcpy 00000000BD5C 00000040BD5C 0 realloc 00000000BD66 00000040BD66 0 setlocale 00000000BD72 00000040BD72 0 signal 00000000BD7C 00000040BD7C 0 strchr 00000000BD86 00000040BD86 0 strcoll 00000000BD90 00000040BD90 0 strlen 00000000BD9A 00000040BD9A 0 strncpy 00000000BDA4 00000040BDA4 0 tolower 00000000BDAE 00000040BDAE 0 vfprintf 00000000BDBA 00000040BDBA 0 wcslen 00000000BDC4 00000040BDC4 0 wcstombs 00000000BDCE 00000040BDCE 0 MSXFS.dll 00000000BDDA 00000040BDDA 0 WFSStartUp 00000000BDEE 00000040BDEE 0 WFSOpen 00000000BDFE 00000040BDFE 0 WFSLock 00000000BE0E 00000040BE0E 0 WFSFreeResult 00000000BE22 00000040BE22 0 WFSGetInfo 00000000BE36 00000040BE36 0 WFSCleanUp 00000000BE4A 00000040BE4A 0 WFSClose 00000000BE5A 00000040BE5A 0 WFSUnlock 00000000BEB0 00000040BEB0 0 kernel32.dll 00000000BEC8 00000040BEC8 0 msvcrt.dll 00000000BF6C 00000040BF6C 0 msvcrt.dll 00000000C409 00000040C409 0 "w1N] 00000000C4F2 00000040C4F2 0 Ll8];; 00000000C629 00000040C629 0 1tov] 00000000C6A7 00000040C6A7 0 cS+!t\ 00000000C6B7 00000040C6B7 0 *u(;1 00000000C6E8 00000040C6E8 0 lm\1A 00000000D052 00000040D052 0 SUBKf 00000000D08D 00000040D08D 0 VALUf 00000000D0CA 00000040D0CA 0 EMPTf 00000000D101 00000040D101 0 _LONf 00000000D13A 00000040D13A 0 ITEMf 00000000D171 00000040D171 0 O_LOf 00000000D1A5 00000040D1A5 0 READf 00000000D1D5 00000040D1D5 0 _ERRf 00000000D209 00000040D209 0 _ERRf 00000000D27A 00000040D27A 0 HANDf 00000000D2B3 00000040D2B3 0 BUFFf 00000000D3BC 00000040D3BC 0 VIDEf 00000000D483 00000040D483 0 REQ_f 00000000D4B7 00000040D4B7 0 RESUf 00000000D523 00000040D523 0 TIMEf File pos Mem pos ID Text ======== ======= == ==== 00000000D55A 00000040D55A 0 ELEVf 00000000D585 00000040D585 0 LOCKf 00000000D613 00000040D613 0 THREf 00000000D664 00000040D664 0 LOCKf 00000000D6F3 00000040D6F3 0 STERf 00000000D727 00000040D727 0 OGREf 00000000D75B 00000040D75B 0 EMORf 00000000D792 00000040D792 0 FOUNf 00000000D82A 00000040D82A 0 _HIGf 00000000D8E3 00000040D8E3 0 OMMAf 00000000D925 00000040D925 0 _SRVf 00000000D983 00000040D983 0 _ERRf 00000000D9DE 00000040D9DE 0 _ERRf 00000000DAAF 00000040DAAF 0 ERROf 00000000DB6A 00000040DB6A 0 CYMIf 00000000DBA1 00000040DBA1 0 NSABf 00000000DC0E 00000040DC0E 0 ITIOf 00000000DC7C 00000040DC7C 0 OTOPf 00000000DCEA 00000040DCEA 0 LOSEf 00000000DD81 00000040DD81 0 ACTIf 00000000DE3A 00000040DE3A 0 OITEf 00000000DEAC 00000040DEAC 0 NKNOf 00000000DEE3 00000040DEE3 0 STAKf 00000000DFA8 00000040DFA8 0 SITIf 00000000DFEA 00000040DFEA 0 CTARf 00000000E0AA 00000040E0AA 0 TAKEf 00000000E0DA 00000040E0DA 0 SLEFf 00000000F34E 00000040F34E 0 <\t?</t; 000000011919 000000411919 0 D$p9D$0 0000000125FD 0000004125FD 0 )D$,) 0000000129B9 0000004129B9 0 L$\9L$ 0000000135BE 0000004135BE 0 9l$Xv, 00000001363C 00000041363C 0 9|$Xv7 000000014CB3 000000414CB3 0 r/9D$ 0000000151E1 0000004151E1 0 EMPTf 000000015600 000000415600 0 libgcc_s_dw2-1.dll 000000015613 000000415613 0 __register_frame_info 000000015629 000000415629 0 libgcj-13.dll 000000015637 000000415637 0 _Jv_RegisterClasses 00000001564B 00000041564B 0 __deregister_frame_info 000000015BA8 000000415BA8 0 Please enter service name! 000000015BC8 000000415BC8 0 WFSStartUp failed with error: %s 000000015BEC 000000415BEC 0 WFSVERSION: 000000015BF8 000000415BF8 0 wVersion: 0x%X 000000015C08 000000415C08 0 wLowVersion: 0x%X 000000015C1B 000000415C1B 0 wHighVersion: 0x%X 000000015C2F 000000415C2F 0 szDescription: %s 000000015C42 000000415C42 0 szSystemStatus: %s 000000015C58 000000415C58 0 WFSOpen(%s) failed with error: %s 000000015C7C 000000415C7C 0 WFSLock failed with error: %s 000000015C9C 000000415C9C 0 WFSFreeResult failed with error: %s 000000015CC4 000000415CC4 0 WFSGetInfo (WFS_INF_CDM_CASH_UNIT_INFO) failed with error: %s 000000015D03 000000415D03 0 REJECTCASSETTE 000000015D12 000000415D12 0 BILLCASSETTE 000000015D1F 000000415D1F 0 COINCYLINDER 000000015D2C 000000415D2C 0 COINDISPENSER 000000015D3A 000000415D3A 0 RETRACTCASSETTE 000000015D4A 000000415D4A 0 COUPON 000000015D51 000000415D51 0 DOCUMENT 000000015D5A 000000415D5A 0 REPCONTAINER File pos Mem pos ID Text ======== ======= == ==== 000000015D67 000000415D67 0 RECYCLINGCASSETTE 000000015D79 000000415D79 0 NOTAPPLICABLE 000000015D87 000000415D87 0 NOVALUES 000000015D90 000000415D90 0 NOREFERENCE 000000015D9C 000000415D9C 0 MANIPULATED 000000015DA8 000000415DA8 0 INOPERATIVE 000000015DB4 000000415DB4 0 ---------------------------- 000000015DD4 000000415DD4 0 Cash Unit # %d 000000015DE3 000000415DE3 0 Type: %s 000000015DEC 000000415DEC 0 Status: %s 000000015DF7 000000415DF7 0 Currency ID: %.3s 000000015E09 000000415E09 0 Note Value: %u 000000015E18 000000415E18 0 Notes Count: %u 000000015E28 000000415E28 0 Notes Initial Count: %u 000000015E40 000000415E40 0 Notes Minimum Count: %u 000000015E58 000000415E58 0 Notes Maximum Count: %u 000000015E74 000000415E74 0 WFSUnlock failed with error: %s 000000015E98 000000415E98 0 WFSClose failed with error: %s 000000015EB8 000000415EB8 0 WFSCleanUp failed with error: %s 000000015EDB 000000415EDB 0 Success 000000015F40 000000415F40 0 Mingw runtime failure: 000000015F58 000000415F58 0 VirtualQuery failed for %d bytes at address %p 000000015F8C 000000415F8C 0 Unknown pseudo relocation protocol version %d. 000000015FC0 000000415FC0 0 Unknown pseudo relocation bit size %d. 000000015FEE 000000415FEE 0 glob-1.0-mingw32 00000001601E 00000041601E 0 (null) 000000016025 000000416025 0 PRINTF_EXPONENT_DIGITS 0000000161A8 0000004161A8 0 Infinity 0000000161CF 0000004161CF 0 ?aCoc 0000000161EF 0000004161EF 0 <2ZGU 000000016380 000000416380 0 GCC: (GNU) 4.8.1 000000016394 000000416394 0 GCC: (GNU) 4.8.1 0000000163A8 0000004163A8 0 GCC: (GNU) 4.8.1 0000000163BC 0000004163BC 0 GCC: (GNU) 4.8.1 0000000163D0 0000004163D0 0 GCC: (GNU) 4.8.1 0000000163E4 0000004163E4 0 GCC: (GNU) 4.8.1 0000000163F8 0000004163F8 0 GCC: (GNU) 4.8.1 00000001640C 00000041640C 0 GCC: (GNU) 4.8.1 000000016420 000000416420 0 GCC: (GNU) 4.8.1 000000016434 000000416434 0 GCC: (GNU) 4.8.1 000000016448 000000416448 0 GCC: (GNU) 4.8.1 00000001645C 00000041645C 0 GCC: (GNU) 4.8.1 000000016470 000000416470 0 GCC: (GNU) 4.8.1 000000016484 000000416484 0 GCC: (GNU) 4.8.1 000000016498 000000416498 0 GCC: (GNU) 4.8.1 0000000164AC 0000004164AC 0 GCC: (GNU) 4.8.1 0000000164C0 0000004164C0 0 GCC: (GNU) 4.8.1 0000000164D4 0000004164D4 0 GCC: (GNU) 4.8.1 0000000164E8 0000004164E8 0 GCC: (GNU) 4.8.1 0000000164FC 0000004164FC 0 GCC: (GNU) 4.8.1 000000016510 000000416510 0 GCC: (GNU) 4.8.1 000000016524 000000416524 0 GCC: (GNU) 4.8.1 000000016538 000000416538 0 GCC: (GNU) 4.8.1 00000001654C 00000041654C 0 GCC: (GNU) 4.8.1 000000016560 000000416560 0 GCC: (GNU) 4.8.1 000000016574 000000416574 0 GCC: (GNU) 4.8.1 000000016588 000000416588 0 GCC: (GNU) 4.8.1 00000001659C 00000041659C 0 GCC: (GNU) 4.8.1 0000000165B0 0000004165B0 0 GCC: (GNU) 4.8.1 000000008F40 000000419140 0 MAINICON File pos Mem pos ID Text ======== ======= == ==== 00000001600F 00000041600F 0 f(null) 000000000050 000000400050 0 This program must be run under Win32 000000000270 000000400270 0 .idata 0000000002C0 0000004002C0 0 .rdata 0000000002E7 0000004002E7 0 P.reloc 00000000030F 00000040030F 0 P.rsrc 00000000059C 00000040119C 0 SVWUQ 0000000007BD 0000004013BD 0 w;;t$ 0000000008C8 0000004014C8 0 SVWUQ 0000000017AD 0000004023AD 0 Uh5$@ 000000001B17 000000402717 0 ~KxI[) 000000001CD0 0000004028D0 0 SOFTWARE\Borland\Delphi\RTL 000000001CEC 0000004028EC 0 FPUMaskValue 000000001D39 000000402939 0 PPRTj 000000001EB3 000000402AB3 0 YZXtp 00000000202A 000000402C2A 0 t=HtN 000000002204 000000402E04 0 Uh2.@ 0000000026CC 0000004032CC 0 SVWRP 0000000028F2 0000004034F2 0 t1SVW 000000003009 000000403C09 0 Uhd<@ 00000000312D 000000403D2D 0 Uhr=@ 00000000335D 000000403F5D 0 Uh}?@ 0000000033CE 000000403FCE 0 HBITMAP 000000003615 000000404215 0 Uh5B@ 00000000365D 00000040425D 0 Uh}B@ 000000003705 000000404305 0 Uh%C@ 00000000373D 00000040433D 0 Uh]C@ 0000000038E0 0000004044E0 0 YXZQRPR 0000000039F0 0000004045F0 0 R;P P| 000000003AB4 0000004046B4 0 IVXLCDMT 000000003C52 000000404852 0 t=8!u 000000003C64 000000404864 0 ,8"t& 000000003EF0 000000404AF0 0 Uh(K@ 00000000400F 000000404C0F 0 UhfL@ 0000000041E5 000000404DE5 0 QQQQS 00000000441E 00000040501E 0 UhrP@ 000000004605 000000405205 0 QQQQS 000000004E35 000000405A35 0 XH;XH~ P 000000004E50 000000405A50 0 9PD}-RP 000000004E83 000000405A83 0 PH9PL~ 000000004E9D 000000405A9D 0 KH+KLQ 000000004EBB 000000405ABB 0 ;CHRQ~ 00000000502A 000000405C2A 0 ;GHv 000000005210 000000405E10 0 @t:HS 00000000523A 000000405E3A 0 Z[XR1 000000005335 000000405F35 0 RP;P ~ 0000000053EB 000000405FEB 0 SPRQj 0000000060E5 000000406CE5 0 Uh/m@ 0000000062A5 000000406EA5 0 Uh"o@ 0000000063E9 000000406FE9 0 QQQQQS 000000006407 000000407007 0 Uhdp@ 0000000064E3 0000004070E3 0 Uh&q@ 0000000068A8 0000004074A8 0 \PROGRA~1\ 0000000068B9 0000004074B9 0 QQQQQQSVW 0000000069A8 0000004075A8 0 Uh\v@ 000000006DA5 0000004079A5 0 QQQQQQS3 000000006ED5 000000407AD5 0 QQQQQQ 0000000070A2 000000407CA2 0 UhJ}@ 0000000071A1 000000407DA1 0 QQQQQQSV 0000000071B6 000000407DB6 0 Uhu~@ File pos Mem pos ID Text ======== ======= == ==== 000000007858 000000409058 0 Error 000000007860 000000409060 0 Runtime error at 00000000 000000007880 000000409080 0 0123456789ABCDEF 000000007E58 000000415258 0 kernel32.dll 000000007E68 000000415268 0 DeleteCriticalSection 000000007E80 000000415280 0 LeaveCriticalSection 000000007E98 000000415298 0 EnterCriticalSection 000000007EB0 0000004152B0 0 InitializeCriticalSection 000000007ECC 0000004152CC 0 VirtualFree 000000007EDA 0000004152DA 0 VirtualAlloc 000000007EEA 0000004152EA 0 LocalFree 000000007EF6 0000004152F6 0 LocalAlloc 000000007F04 000000415304 0 GetVersion 000000007F12 000000415312 0 GetCurrentThreadId 000000007F28 000000415328 0 GetThreadLocale 000000007F3A 00000041533A 0 GetStartupInfoA 000000007F4C 00000041534C 0 GetLocaleInfoA 000000007F5E 00000041535E 0 GetCommandLineA 000000007F70 000000415370 0 FreeLibrary 000000007F7E 00000041537E 0 ExitProcess 000000007F8C 00000041538C 0 WriteFile 000000007F98 000000415398 0 UnhandledExceptionFilter 000000007FB4 0000004153B4 0 RtlUnwind 000000007FC0 0000004153C0 0 RaiseException 000000007FD2 0000004153D2 0 GetStdHandle 000000007FE0 0000004153E0 0 user32.dll 000000007FEE 0000004153EE 0 GetKeyboardType 000000008000 000000415400 0 MessageBoxA 00000000800C 00000041540C 0 advapi32.dll 00000000801C 00000041541C 0 RegQueryValueExA 000000008030 000000415430 0 RegOpenKeyExA 000000008040 000000415440 0 RegCloseKey 00000000804C 00000041544C 0 oleaut32.dll 00000000805C 00000041545C 0 SysFreeString 00000000806C 00000041546C 0 SysReAllocStringLen 000000008080 000000415480 0 kernel32.dll 000000008090 000000415490 0 TlsSetValue 00000000809E 00000041549E 0 TlsGetValue 0000000080AC 0000004154AC 0 LocalAlloc 0000000080BA 0000004154BA 0 GetModuleHandleA 0000000080CC 0000004154CC 0 advapi32.dll 0000000080DC 0000004154DC 0 RegSetValueExA 0000000080EE 0000004154EE 0 RegOpenKeyExA 0000000080FE 0000004154FE 0 RegCloseKey 00000000810A 00000041550A 0 kernel32.dll 00000000811A 00000041551A 0 WriteFile 000000008126 000000415526 0 WinExec 000000008130 000000415530 0 SetFilePointer 000000008142 000000415542 0 SetFileAttributesA 000000008158 000000415558 0 SetEndOfFile 000000008168 000000415568 0 SetCurrentDirectoryA 000000008180 000000415580 0 ReleaseMutex 000000008190 000000415590 0 ReadFile 00000000819C 00000041559C 0 GetWindowsDirectoryA 0000000081B4 0000004155B4 0 GetTempPathA 0000000081C4 0000004155C4 0 GetShortPathNameA 0000000081D8 0000004155D8 0 GetModuleFileNameA 0000000081EE 0000004155EE 0 GetLogicalDriveStringsA 000000008208 000000415608 0 GetLocalTime 000000008218 000000415618 0 GetLastError File pos Mem pos ID Text ======== ======= == ==== 000000008228 000000415628 0 GetFileSize 000000008236 000000415636 0 GetFileAttributesA 00000000824C 00000041564C 0 GetDriveTypeA 00000000825C 00000041565C 0 GetCommandLineA 00000000826E 00000041566E 0 FreeLibrary 00000000827C 00000041567C 0 FindNextFileA 00000000828C 00000041568C 0 FindFirstFileA 00000000829E 00000041569E 0 FindClose 0000000082AA 0000004156AA 0 DeleteFileA 0000000082B8 0000004156B8 0 CreateMutexA 0000000082C8 0000004156C8 0 CreateFileA 0000000082D6 0000004156D6 0 CreateDirectoryA 0000000082EA 0000004156EA 0 CloseHandle 0000000082F6 0000004156F6 0 gdi32.dll 000000008302 000000415702 0 StretchDIBits 000000008312 000000415712 0 SetDIBits 00000000831E 00000041571E 0 SelectObject 00000000832E 00000041572E 0 GetObjectA 00000000833C 00000041573C 0 GetDIBits 000000008348 000000415748 0 DeleteObject 000000008358 000000415758 0 DeleteDC 000000008364 000000415764 0 CreateSolidBrush 000000008378 000000415778 0 CreateDIBSection 00000000838C 00000041578C 0 CreateCompatibleDC 0000000083A2 0000004157A2 0 CreateCompatibleBitmap 0000000083BC 0000004157BC 0 BitBlt 0000000083C4 0000004157C4 0 user32.dll 0000000083D2 0000004157D2 0 ReleaseDC 0000000083DE 0000004157DE 0 GetSysColor 0000000083EC 0000004157EC 0 GetIconInfo 0000000083FA 0000004157FA 0 GetDC 000000008402 000000415802 0 FillRect 00000000840E 00000041580E 0 DestroyIcon 00000000841C 00000041581C 0 CopyImage 000000008428 000000415828 0 CharLowerBuffA 000000008438 000000415838 0 shell32.dll 000000008446 000000415846 0 ShellExecuteA 000000008456 000000415856 0 ExtractIconA 00000000880F 00000041800F 0 0"0*020:0B0J0R0Z0b0j0r0z0 00000000883F 00000041803F 0 0 1(1 000000008857 000000418057 0 4-595T5 00000000885F 00000041805F 0 567r7 00000000887D 00000041807D 0 8&8,848F8R8a8m8u8 0000000088AB 0000004180AB 0 9/9:9[9s9 0000000088BD 0000004180BD 0 :W:w: 0000000088CD 0000004180CD 0 <'<0<;<D<K<Z<a< 0000000088F1 0000004180F1 0 >b>k> 000000008901 000000418101 0 ?2?\?e?u?}? 00000000892B 00000041812B 0 0(0@0L0T0k0z0 000000008945 000000418145 0 0,1P1n1~1 00000000895B 00000041815B 0 2$2u2|2 00000000897D 00000041817D 0 4#4+4O4o4 00000000899B 00000041819B 0 8A8Q8g8 0000000089AD 0000004181AD 0 9*929H9 0000000089C3 0000004181C3 0 9+:X:a: 0000000089D3 0000004181D3 0 :G;o; 0000000089DF 0000004181DF 0 < =T=\=g= 0000000089F1 0000004181F1 0 >N>R>X>\>a>h>n>v> 000000008A11 000000418211 0 ?%?/?7?=?K?f?{? 000000008A38 000000418238 0 N0W0}0 File pos Mem pos ID Text ======== ======= == ==== 000000008A41 000000418241 0 466?6:7C7 000000008A53 000000418253 0 <)<2<><E< 000000008A5F 00000041825F 0 =/=;=B=L=V=m=~= 000000008A89 000000418289 0 >/>@>J>R>Z>b>j> 000000008AA7 0000004182A7 0 ?&?+?0?7?>?H?_?k?x? 000000008ADD 0000004182DD 0 0:0B0J0R0Z0b0j0r0z0 000000008B17 000000418317 0 1"1*121:1B1J1R1Z1b1j1r1z1 000000008B47 000000418347 0 2#202B2J2R2_2k2x2 000000008B6D 00000041836D 0 3 323?3K3X3j3w3 000000008B93 000000418393 0 4$4(4,484<4@4L4P4T4 000000008BA7 0000004183A7 0 4d4h4t4x4|4 000000008C15 000000418415 0 6_8H9 000000008C1B 00000041841B 0 9,;:;A;H;c;o; 000000008C51 000000418451 0 :(;=;c; 000000008C6B 00000041846B 0 =*=:=Z= 000000008C75 000000418475 0 >A>v> 000000008C90 000000418490 0 040R0 000000008CB1 0000004184B1 0 2_3n3 000000008CC5 0000004184C5 0 5 6J6 000000008CD1 0000004184D1 0 7U7w7 000000008CDD 0000004184DD 0 9_9d9w9 000000008CEB 0000004184EB 0 :.:E:c:z: 000000008D07 000000418507 0 <==u= 000000008D0D 00000041850D 0 =.>c> 000000008D29 000000418529 0 030F0X0\0 000000008D33 000000418533 0 0d0h0l0p0t0x0|0 000000008D77 000000418577 0 1%191M1a1 000000008D90 000000418590 0 004080 000000008DAD 0000004185AD 0 1 1$1(1 00000000A023 00000041A223 0 RsZLZ 00000000A096 00000041A296 0 Uag%N 00000000A0E0 00000041A2E0 0 Delphi-the best. Fuck off all the rest. Neshta 1.0 Made in Belarus. 00000000A1A8 00000041A3A8 0 ! Best regards 2 Tommy Salo. [Nov-2005] yours [Dziadulja Apanas] 00000000BAAA 00000040BAAA 0 DeleteCriticalSection 00000000BAC2 00000040BAC2 0 EnterCriticalSection 00000000BADA 00000040BADA 0 ExitProcess 00000000BAE8 00000040BAE8 0 GetCommandLineA 00000000BAFA 00000040BAFA 0 GetLastError 00000000BB0A 00000040BB0A 0 GetModuleHandleA 00000000BB1E 00000040BB1E 0 GetProcAddress 00000000BB30 00000040BB30 0 InitializeCriticalSection 00000000BB4C 00000040BB4C 0 InterlockedExchange 00000000BB62 00000040BB62 0 IsDBCSLeadByteEx 00000000BB76 00000040BB76 0 LeaveCriticalSection 00000000BB8E 00000040BB8E 0 MultiByteToWideChar 00000000BBA4 00000040BBA4 0 SetUnhandledExceptionFilter 00000000BBC2 00000040BBC2 0 Sleep 00000000BBCA 00000040BBCA 0 TlsGetValue 00000000BBD8 00000040BBD8 0 VirtualProtect 00000000BBEA 00000040BBEA 0 VirtualQuery 00000000BBFA 00000040BBFA 0 WideCharToMultiByte 00000000BC10 00000040BC10 0 _strdup 00000000BC1A 00000040BC1A 0 _stricoll 00000000BC26 00000040BC26 0 __getmainargs 00000000BC36 00000040BC36 0 __mb_cur_max 00000000BC46 00000040BC46 0 __p__environ 00000000BC56 00000040BC56 0 __p__fmode 00000000BC64 00000040BC64 0 __set_app_type 00000000BC76 00000040BC76 0 _cexit 00000000BC80 00000040BC80 0 _errno File pos Mem pos ID Text ======== ======= == ==== 00000000BC8A 00000040BC8A 0 _findclose 00000000BC98 00000040BC98 0 _findfirst 00000000BCA6 00000040BCA6 0 _findnext 00000000BCB2 00000040BCB2 0 _fullpath 00000000BCC6 00000040BCC6 0 _onexit 00000000BCD0 00000040BCD0 0 _setmode 00000000BCDC 00000040BCDC 0 abort 00000000BCE4 00000040BCE4 0 atexit 00000000BCF6 00000040BCF6 0 calloc 00000000BD00 00000040BD00 0 fputc 00000000BD10 00000040BD10 0 fwrite 00000000BD1A 00000040BD1A 0 getenv 00000000BD24 00000040BD24 0 isspace 00000000BD2E 00000040BD2E 0 localeconv 00000000BD3C 00000040BD3C 0 malloc 00000000BD46 00000040BD46 0 mbstowcs 00000000BD52 00000040BD52 0 memcpy 00000000BD5C 00000040BD5C 0 realloc 00000000BD66 00000040BD66 0 setlocale 00000000BD72 00000040BD72 0 signal 00000000BD7C 00000040BD7C 0 strchr 00000000BD86 00000040BD86 0 strcoll 00000000BD90 00000040BD90 0 strlen 00000000BD9A 00000040BD9A 0 strncpy 00000000BDA4 00000040BDA4 0 tolower 00000000BDAE 00000040BDAE 0 vfprintf 00000000BDBA 00000040BDBA 0 wcslen 00000000BDC4 00000040BDC4 0 wcstombs 00000000BDCE 00000040BDCE 0 MSXFS.dll 00000000BDDA 00000040BDDA 0 WFSStartUp 00000000BDEE 00000040BDEE 0 WFSOpen 00000000BDFE 00000040BDFE 0 WFSLock 00000000BE0E 00000040BE0E 0 WFSFreeResult 00000000BE22 00000040BE22 0 WFSGetInfo 00000000BE36 00000040BE36 0 WFSCleanUp 00000000BE4A 00000040BE4A 0 WFSClose 00000000BE5A 00000040BE5A 0 WFSUnlock 00000000BEB0 00000040BEB0 0 kernel32.dll 00000000BEC8 00000040BEC8 0 msvcrt.dll 00000000BF6C 00000040BF6C 0 msvcrt.dll 00000000C409 00000040C409 0 "w1N] 00000000C4F2 00000040C4F2 0 Ll8];; 00000000C629 00000040C629 0 1tov] 00000000C6A7 00000040C6A7 0 cS+!t\ 00000000C6B7 00000040C6B7 0 *u(;1 00000000C6E8 00000040C6E8 0 lm\1A 00000000D052 00000040D052 0 SUBKf 00000000D08D 00000040D08D 0 VALUf 00000000D0CA 00000040D0CA 0 EMPTf 00000000D101 00000040D101 0 _LONf 00000000D13A 00000040D13A 0 ITEMf 00000000D171 00000040D171 0 O_LOf 00000000D1A5 00000040D1A5 0 READf 00000000D1D5 00000040D1D5 0 _ERRf 00000000D209 00000040D209 0 _ERRf 00000000D27A 00000040D27A 0 HANDf 00000000D2B3 00000040D2B3 0 BUFFf 00000000D3BC 00000040D3BC 0 VIDEf 00000000D483 00000040D483 0 REQ_f 00000000D4B7 00000040D4B7 0 RESUf File pos Mem pos ID Text ======== ======= == ==== 00000000D523 00000040D523 0 TIMEf 00000000D55A 00000040D55A 0 ELEVf 00000000D585 00000040D585 0 LOCKf 00000000D613 00000040D613 0 THREf 00000000D664 00000040D664 0 LOCKf 00000000D6F3 00000040D6F3 0 STERf 00000000D727 00000040D727 0 OGREf 00000000D75B 00000040D75B 0 EMORf 00000000D792 00000040D792 0 FOUNf 00000000D82A 00000040D82A 0 _HIGf 00000000D8E3 00000040D8E3 0 OMMAf 00000000D925 00000040D925 0 _SRVf 00000000D983 00000040D983 0 _ERRf 00000000D9DE 00000040D9DE 0 _ERRf 00000000DAAF 00000040DAAF 0 ERROf 00000000DB6A 00000040DB6A 0 CYMIf 00000000DBA1 00000040DBA1 0 NSABf 00000000DC0E 00000040DC0E 0 ITIOf 00000000DC7C 00000040DC7C 0 OTOPf 00000000DCEA 00000040DCEA 0 LOSEf 00000000DD81 00000040DD81 0 ACTIf 00000000DE3A 00000040DE3A 0 OITEf 00000000DEAC 00000040DEAC 0 NKNOf 00000000DEE3 00000040DEE3 0 STAKf 00000000DFA8 00000040DFA8 0 SITIf 00000000DFEA 00000040DFEA 0 CTARf 00000000E0AA 00000040E0AA 0 TAKEf 00000000E0DA 00000040E0DA 0 SLEFf 00000000F34E 00000040F34E 0 <\t?</t; 000000011919 000000411919 0 D$p9D$0 0000000125FD 0000004125FD 0 )D$,) 0000000129B9 0000004129B9 0 L$\9L$ 0000000135BE 0000004135BE 0 9l$Xv, 00000001363C 00000041363C 0 9|$Xv7 000000014CB3 000000414CB3 0 r/9D$ 0000000151E1 0000004151E1 0 EMPTf 000000015600 000000415600 0 libgcc_s_dw2-1.dll 000000015613 000000415613 0 __register_frame_info 000000015629 000000415629 0 libgcj-13.dll 000000015637 000000415637 0 _Jv_RegisterClasses 00000001564B 00000041564B 0 __deregister_frame_info 000000015BA8 000000415BA8 0 Please enter service name! 000000015BC8 000000415BC8 0 WFSStartUp failed with error: %s 000000015BEC 000000415BEC 0 WFSVERSION: 000000015BF8 000000415BF8 0 wVersion: 0x%X 000000015C08 000000415C08 0 wLowVersion: 0x%X 000000015C1B 000000415C1B 0 wHighVersion: 0x%X 000000015C2F 000000415C2F 0 szDescription: %s 000000015C42 000000415C42 0 szSystemStatus: %s 000000015C58 000000415C58 0 WFSOpen(%s) failed with error: %s 000000015C7C 000000415C7C 0 WFSLock failed with error: %s 000000015C9C 000000415C9C 0 WFSFreeResult failed with error: %s 000000015CC4 000000415CC4 0 WFSGetInfo (WFS_INF_CDM_CASH_UNIT_INFO) failed with error: %s 000000015D03 000000415D03 0 REJECTCASSETTE 000000015D12 000000415D12 0 BILLCASSETTE 000000015D1F 000000415D1F 0 COINCYLINDER 000000015D2C 000000415D2C 0 COINDISPENSER 000000015D3A 000000415D3A 0 RETRACTCASSETTE 000000015D4A 000000415D4A 0 COUPON 000000015D51 000000415D51 0 DOCUMENT File pos Mem pos ID Text ======== ======= == ==== 000000015D5A 000000415D5A 0 REPCONTAINER 000000015D67 000000415D67 0 RECYCLINGCASSETTE 000000015D79 000000415D79 0 NOTAPPLICABLE 000000015D87 000000415D87 0 NOVALUES 000000015D90 000000415D90 0 NOREFERENCE 000000015D9C 000000415D9C 0 MANIPULATED 000000015DA8 000000415DA8 0 INOPERATIVE 000000015DB4 000000415DB4 0 ---------------------------- 000000015DD4 000000415DD4 0 Cash Unit # %d 000000015DE3 000000415DE3 0 Type: %s 000000015DEC 000000415DEC 0 Status: %s 000000015DF7 000000415DF7 0 Currency ID: %.3s 000000015E09 000000415E09 0 Note Value: %u 000000015E18 000000415E18 0 Notes Count: %u 000000015E28 000000415E28 0 Notes Initial Count: %u 000000015E40 000000415E40 0 Notes Minimum Count: %u 000000015E58 000000415E58 0 Notes Maximum Count: %u 000000015E74 000000415E74 0 WFSUnlock failed with error: %s 000000015E98 000000415E98 0 WFSClose failed with error: %s 000000015EB8 000000415EB8 0 WFSCleanUp failed with error: %s 000000015EDB 000000415EDB 0 Success 000000015F40 000000415F40 0 Mingw runtime failure: 000000015F58 000000415F58 0 VirtualQuery failed for %d bytes at address %p 000000015F8C 000000415F8C 0 Unknown pseudo relocation protocol version %d. 000000015FC0 000000415FC0 0 Unknown pseudo relocation bit size %d. 000000015FEE 000000415FEE 0 glob-1.0-mingw32 00000001601E 00000041601E 0 (null) 000000016025 000000416025 0 PRINTF_EXPONENT_DIGITS 0000000161A8 0000004161A8 0 Infinity 0000000161CF 0000004161CF 0 ?aCoc 0000000161EF 0000004161EF 0 <2ZGU 000000016380 000000416380 0 GCC: (GNU) 4.8.1 000000016394 000000416394 0 GCC: (GNU) 4.8.1 0000000163A8 0000004163A8 0 GCC: (GNU) 4.8.1 0000000163BC 0000004163BC 0 GCC: (GNU) 4.8.1 0000000163D0 0000004163D0 0 GCC: (GNU) 4.8.1 0000000163E4 0000004163E4 0 GCC: (GNU) 4.8.1 0000000163F8 0000004163F8 0 GCC: (GNU) 4.8.1 00000001640C 00000041640C 0 GCC: (GNU) 4.8.1 000000016420 000000416420 0 GCC: (GNU) 4.8.1 000000016434 000000416434 0 GCC: (GNU) 4.8.1 000000016448 000000416448 0 GCC: (GNU) 4.8.1 00000001645C 00000041645C 0 GCC: (GNU) 4.8.1 000000016470 000000416470 0 GCC: (GNU) 4.8.1 000000016484 000000416484 0 GCC: (GNU) 4.8.1 000000016498 000000416498 0 GCC: (GNU) 4.8.1 0000000164AC 0000004164AC 0 GCC: (GNU) 4.8.1 0000000164C0 0000004164C0 0 GCC: (GNU) 4.8.1 0000000164D4 0000004164D4 0 GCC: (GNU) 4.8.1 0000000164E8 0000004164E8 0 GCC: (GNU) 4.8.1 0000000164FC 0000004164FC 0 GCC: (GNU) 4.8.1 000000016510 000000416510 0 GCC: (GNU) 4.8.1 000000016524 000000416524 0 GCC: (GNU) 4.8.1 000000016538 000000416538 0 GCC: (GNU) 4.8.1 00000001654C 00000041654C 0 GCC: (GNU) 4.8.1 000000016560 000000416560 0 GCC: (GNU) 4.8.1 000000016574 000000416574 0 GCC: (GNU) 4.8.1 000000016588 000000416588 0 GCC: (GNU) 4.8.1 00000001659C 00000041659C 0 GCC: (GNU) 4.8.1 0000000165B0 0000004165B0 0 GCC: (GNU) 4.8.1 File pos Mem pos ID Text ======== ======= == ==== 000000008F40 000000419140 0 MAINICON 00000001600F 00000041600F 0 f(null)
=== DOWNLOAD ===