.- - -----÷M÷E÷N÷U÷------------------------------------------------------------- --- ---- -------------.
! WALL ! STATS ! GOODIES ! YARA ! FAQ ! RSS ! EMV !
`-------------- - --- ---------- -------- -------- -------- -------- ----------------- - ---- ---- --'
ATM MALWARE NOTICE
05a00a4b2d07780021bcd1a4abe84dc0ee28531136414f0ee631fa0d9844d479
Date...........: 2020-05-15
Family.........: DispCash.10
File name......: xfs_cuinfo.exe
File size......: 89.50 KB
Type file......: EXE/Windows
Virscan........: VT - HA
Documentation..: https://twitter.com/s4tan/status/1262356066203041793
Additional note: Drop 98e7fe52634c9ed9105a1604169e29d797419cb89ae863c2178999f34abd1497.
Seem infected by 'Neshta', see strings.
Similar to: 5f70c76b6771b7c56bc5da34e424eb9a090cedeb807c795795a88c415a2e772c.
Entropy:
Binary Histogram:
=== PEDUMP REPORT ===
=== MZ Header ===
signature: "MZ"
bytes_in_last_block: 80 0x50
blocks_in_file: 2 2
num_relocs: 0 0
header_paragraphs: 4 4
min_extra_paragraphs: 15 0xf
max_extra_paragraphs: 65535 0xffff
ss: 0 0
sp: 184 0xb8
checksum: 0 0
ip: 0 0
cs: 0 0
reloc_table_offset: 64 0x40
overlay_number: 26 0x1a
reserved0: 0 0
oem_id: 0 0
oem_info: 0 0
reserved2: 0 0
reserved3: 0 0
reserved4: 0 0
reserved5: 0 0
reserved6: 0 0
lfanew: 256 0x100
=== DOS STUB ===
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..|
00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus|
00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W|
00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........|
00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
=== PE Header ===
signature: "PE\x00\x00"
# IMAGE_FILE_HEADER:
Machine: 332 0x14c x86
NumberOfSections: 8 8
TimeDateStamp: "1992-06-19 22:22:17"
PointerToSymbolTable: 0 0
NumberOfSymbols: 0 0
SizeOfOptionalHeader: 224 0xe0
Characteristics: 33166 0x818e EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED
LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO
32BIT_MACHINE, BYTES_REVERSED_HI
# IMAGE_OPTIONAL_HEADER32:
Magic: 267 0x10b 32-bit executable
LinkerVersion: 2.25
SizeOfCode: 29696 0x7400
SizeOfInitializedData: 10752 0x2a00
SizeOfUninitializedData: 0 0
AddressOfEntryPoint: 32996 0x80e4
BaseOfCode: 4096 0x1000
BaseOfData: 36864 0x9000
ImageBase: 4194304 0x400000
SectionAlignment: 4096 0x1000
FileAlignment: 512 0x200
OperatingSystemVersion: 4.0
ImageVersion: 0.0
SubsystemVersion: 4.0
Reserved1: 0 0
SizeOfImage: 110592 0x1b000
SizeOfHeaders: 1024 0x400
CheckSum: 0 0
Subsystem: 2 2 WINDOWS_GUI
DllCharacteristics: 0 0
SizeOfStackReserve: 1048576 0x100000
SizeOfStackCommit: 16384 0x4000
SizeOfHeapReserve: 1048576 0x100000
SizeOfHeapCommit: 4096 0x1000
LoaderFlags: 0 0
NumberOfRvaAndSizes: 16 0x10
=== DATA DIRECTORY ===
EXPORT rva:0x 0 size:0x 0
IMPORT rva:0x 15000 size:0x 864
RESOURCE rva:0x 19000 size:0x 1400
EXCEPTION rva:0x 0 size:0x 0
SECURITY rva:0x 0 size:0x 0
BASERELOC rva:0x 18000 size:0x 5cc
DEBUG rva:0x 0 size:0x 0
ARCHITECTURE rva:0x 0 size:0x 0
GLOBALPTR rva:0x 0 size:0x 0
TLS rva:0x 17000 size:0x 18
LOAD_CONFIG rva:0x 0 size:0x 0
Bound_IAT rva:0x 0 size:0x 0
IAT rva:0x 0 size:0x 0
Delay_IAT rva:0x 0 size:0x 0
CLR_Header rva:0x 0 size:0x 0
rva:0x 0 size:0x 0
=== SECTIONS ===
NAME RVA VSZ RAW_SZ RAW_PTR nREL REL_PTR nLINE LINE_PTR FLAGS
CODE 1000 722c 7400 400 0 0 0 0 60000020 R-X CODE
DATA 9000 218 400 7800 0 0 0 0 c0000040 RW- IDATA
BSS a000 a899 0 7c00 0 0 0 0 c0000000 RW-
.idata 15000 864 a00 7c00 0 0 0 0 c0000040 RW- IDATA
.tls 16000 8 0 8600 0 0 0 0 c0000000 RW-
.rdata 17000 18 200 8600 0 0 0 0 50000040 R-- IDATA SHARED
.reloc 18000 5cc 600 8800 0 0 0 0 50000040 R-- IDATA SHARED
.rsrc 19000 1400 1400 8e00 0 0 0 0 50000040 R-- IDATA SHARED
=== TLS ===
RAW_START RAW_END INDEX CALLBKS ZEROFILL FLAGS
416000 416008 409090 417010 0 0
[?] ignoring invalid PEdump::BITMAPINFOHEADER
=== RESOURCES ===
FILE_OFFSET CP LANG SIZE TYPE NAME
0x8f50 0 0x419 4264 ICON #1
0x9ff8 0 0 16 RCDATA DVCLAL
0xa008 0 0 172 RCDATA PACKAGEINFO
0xa0b4 0 0x419 20 GROUP_ICON MAINICON
=== IMPORTS ===
MODULE_NAME HINT ORD FUNCTION_NAME
kernel32.dll 0 DeleteCriticalSection
kernel32.dll 0 LeaveCriticalSection
kernel32.dll 0 EnterCriticalSection
kernel32.dll 0 InitializeCriticalSection
kernel32.dll 0 VirtualFree
kernel32.dll 0 VirtualAlloc
kernel32.dll 0 LocalFree
kernel32.dll 0 LocalAlloc
kernel32.dll 0 GetVersion
kernel32.dll 0 GetCurrentThreadId
kernel32.dll 0 GetThreadLocale
kernel32.dll 0 GetStartupInfoA
kernel32.dll 0 GetLocaleInfoA
kernel32.dll 0 GetCommandLineA
kernel32.dll 0 FreeLibrary
kernel32.dll 0 ExitProcess
kernel32.dll 0 WriteFile
kernel32.dll 0 UnhandledExceptionFilter
kernel32.dll 0 RtlUnwind
kernel32.dll 0 RaiseException
kernel32.dll 0 GetStdHandle
user32.dll 0 GetKeyboardType
user32.dll 0 MessageBoxA
advapi32.dll 0 RegQueryValueExA
advapi32.dll 0 RegOpenKeyExA
advapi32.dll 0 RegCloseKey
oleaut32.dll 0 SysFreeString
oleaut32.dll 0 SysReAllocStringLen
kernel32.dll 0 TlsSetValue
kernel32.dll 0 TlsGetValue
kernel32.dll 0 LocalAlloc
kernel32.dll 0 GetModuleHandleA
advapi32.dll 0 RegSetValueExA
advapi32.dll 0 RegOpenKeyExA
advapi32.dll 0 RegCloseKey
kernel32.dll 0 WriteFile
kernel32.dll 0 WinExec
kernel32.dll 0 SetFilePointer
kernel32.dll 0 SetFileAttributesA
kernel32.dll 0 SetEndOfFile
kernel32.dll 0 SetCurrentDirectoryA
kernel32.dll 0 ReleaseMutex
kernel32.dll 0 ReadFile
kernel32.dll 0 GetWindowsDirectoryA
kernel32.dll 0 GetTempPathA
kernel32.dll 0 GetShortPathNameA
kernel32.dll 0 GetModuleFileNameA
kernel32.dll 0 GetLogicalDriveStringsA
kernel32.dll 0 GetLocalTime
kernel32.dll 0 GetLastError
kernel32.dll 0 GetFileSize
kernel32.dll 0 GetFileAttributesA
kernel32.dll 0 GetDriveTypeA
kernel32.dll 0 GetCommandLineA
kernel32.dll 0 FreeLibrary
kernel32.dll 0 FindNextFileA
kernel32.dll 0 FindFirstFileA
kernel32.dll 0 FindClose
kernel32.dll 0 DeleteFileA
kernel32.dll 0 CreateMutexA
kernel32.dll 0 CreateFileA
kernel32.dll 0 CreateDirectoryA
kernel32.dll 0 CloseHandle
gdi32.dll 0 StretchDIBits
gdi32.dll 0 SetDIBits
gdi32.dll 0 SelectObject
gdi32.dll 0 GetObjectA
gdi32.dll 0 GetDIBits
gdi32.dll 0 DeleteObject
gdi32.dll 0 DeleteDC
gdi32.dll 0 CreateSolidBrush
gdi32.dll 0 CreateDIBSection
gdi32.dll 0 CreateCompatibleDC
gdi32.dll 0 CreateCompatibleBitmap
gdi32.dll 0 BitBlt
user32.dll 0 ReleaseDC
user32.dll 0 GetSysColor
user32.dll 0 GetIconInfo
user32.dll 0 GetDC
user32.dll 0 FillRect
user32.dll 0 DestroyIcon
user32.dll 0 CopyImage
user32.dll 0 CharLowerBuffA
shell32.dll 0 ShellExecuteA
shell32.dll 0 ExtractIconA
=== Packer / Compiler ===
Borland Delphi v6.0 - v7.0
=== Strings ===
File pos Mem pos ID Text
======== ======= == ====
000000000050 000000400050 0 This program must be run under Win32
000000000270 000000400270 0 .idata
0000000002C0 0000004002C0 0 .rdata
0000000002E7 0000004002E7 0 P.reloc
00000000030F 00000040030F 0 P.rsrc
00000000059C 00000040119C 0 SVWUQ
0000000007BD 0000004013BD 0 w;;t$
0000000008C8 0000004014C8 0 SVWUQ
0000000017AD 0000004023AD 0 Uh5$@
000000001B17 000000402717 0 ~KxI[)
000000001CD0 0000004028D0 0 SOFTWARE\Borland\Delphi\RTL
000000001CEC 0000004028EC 0 FPUMaskValue
000000001D39 000000402939 0 PPRTj
000000001EB3 000000402AB3 0 YZXtp
00000000202A 000000402C2A 0 t=HtN
000000002204 000000402E04 0 Uh2.@
0000000026CC 0000004032CC 0 SVWRP
0000000028F2 0000004034F2 0 t1SVW
000000003009 000000403C09 0 Uhd<@
00000000312D 000000403D2D 0 Uhr=@
00000000335D 000000403F5D 0 Uh}?@
0000000033CE 000000403FCE 0 HBITMAP
000000003615 000000404215 0 Uh5B@
00000000365D 00000040425D 0 Uh}B@
000000003705 000000404305 0 Uh%C@
00000000373D 00000040433D 0 Uh]C@
0000000038E0 0000004044E0 0 YXZQRPR
0000000039F0 0000004045F0 0 R;P P|
000000003AB4 0000004046B4 0 IVXLCDMT
000000003C52 000000404852 0 t=8!u
000000003C64 000000404864 0 ,8"t&
000000003EF0 000000404AF0 0 Uh(K@
00000000400F 000000404C0F 0 UhfL@
0000000041E5 000000404DE5 0 QQQQS
00000000441E 00000040501E 0 UhrP@
000000004605 000000405205 0 QQQQS
000000004E35 000000405A35 0 XH;XH~ P
000000004E50 000000405A50 0 9PD}-RP
000000004E83 000000405A83 0 PH9PL~
000000004E9D 000000405A9D 0 KH+KLQ
000000004EBB 000000405ABB 0 ;CHRQ~
00000000502A 000000405C2A 0 ;GHv
000000005210 000000405E10 0 @t:HS
00000000523A 000000405E3A 0 Z[XR1
000000005335 000000405F35 0 RP;P ~
0000000053EB 000000405FEB 0 SPRQj
0000000060E5 000000406CE5 0 Uh/m@
0000000062A5 000000406EA5 0 Uh"o@
0000000063E9 000000406FE9 0 QQQQQS
000000006407 000000407007 0 Uhdp@
0000000064E3 0000004070E3 0 Uh&q@
0000000068A8 0000004074A8 0 \PROGRA~1\
0000000068B9 0000004074B9 0 QQQQQQSVW
0000000069A8 0000004075A8 0 Uh\v@
000000006DA5 0000004079A5 0 QQQQQQS3
000000006ED5 000000407AD5 0 QQQQQQ
0000000070A2 000000407CA2 0 UhJ}@
0000000071A1 000000407DA1 0 QQQQQQSV
0000000071B6 000000407DB6 0 Uhu~@
000000007858 000000409058 0 Error
File pos Mem pos ID Text
======== ======= == ====
000000007860 000000409060 0 Runtime error at 00000000
000000007880 000000409080 0 0123456789ABCDEF
000000007E58 000000415258 0 kernel32.dll
000000007E68 000000415268 0 DeleteCriticalSection
000000007E80 000000415280 0 LeaveCriticalSection
000000007E98 000000415298 0 EnterCriticalSection
000000007EB0 0000004152B0 0 InitializeCriticalSection
000000007ECC 0000004152CC 0 VirtualFree
000000007EDA 0000004152DA 0 VirtualAlloc
000000007EEA 0000004152EA 0 LocalFree
000000007EF6 0000004152F6 0 LocalAlloc
000000007F04 000000415304 0 GetVersion
000000007F12 000000415312 0 GetCurrentThreadId
000000007F28 000000415328 0 GetThreadLocale
000000007F3A 00000041533A 0 GetStartupInfoA
000000007F4C 00000041534C 0 GetLocaleInfoA
000000007F5E 00000041535E 0 GetCommandLineA
000000007F70 000000415370 0 FreeLibrary
000000007F7E 00000041537E 0 ExitProcess
000000007F8C 00000041538C 0 WriteFile
000000007F98 000000415398 0 UnhandledExceptionFilter
000000007FB4 0000004153B4 0 RtlUnwind
000000007FC0 0000004153C0 0 RaiseException
000000007FD2 0000004153D2 0 GetStdHandle
000000007FE0 0000004153E0 0 user32.dll
000000007FEE 0000004153EE 0 GetKeyboardType
000000008000 000000415400 0 MessageBoxA
00000000800C 00000041540C 0 advapi32.dll
00000000801C 00000041541C 0 RegQueryValueExA
000000008030 000000415430 0 RegOpenKeyExA
000000008040 000000415440 0 RegCloseKey
00000000804C 00000041544C 0 oleaut32.dll
00000000805C 00000041545C 0 SysFreeString
00000000806C 00000041546C 0 SysReAllocStringLen
000000008080 000000415480 0 kernel32.dll
000000008090 000000415490 0 TlsSetValue
00000000809E 00000041549E 0 TlsGetValue
0000000080AC 0000004154AC 0 LocalAlloc
0000000080BA 0000004154BA 0 GetModuleHandleA
0000000080CC 0000004154CC 0 advapi32.dll
0000000080DC 0000004154DC 0 RegSetValueExA
0000000080EE 0000004154EE 0 RegOpenKeyExA
0000000080FE 0000004154FE 0 RegCloseKey
00000000810A 00000041550A 0 kernel32.dll
00000000811A 00000041551A 0 WriteFile
000000008126 000000415526 0 WinExec
000000008130 000000415530 0 SetFilePointer
000000008142 000000415542 0 SetFileAttributesA
000000008158 000000415558 0 SetEndOfFile
000000008168 000000415568 0 SetCurrentDirectoryA
000000008180 000000415580 0 ReleaseMutex
000000008190 000000415590 0 ReadFile
00000000819C 00000041559C 0 GetWindowsDirectoryA
0000000081B4 0000004155B4 0 GetTempPathA
0000000081C4 0000004155C4 0 GetShortPathNameA
0000000081D8 0000004155D8 0 GetModuleFileNameA
0000000081EE 0000004155EE 0 GetLogicalDriveStringsA
000000008208 000000415608 0 GetLocalTime
000000008218 000000415618 0 GetLastError
000000008228 000000415628 0 GetFileSize
File pos Mem pos ID Text
======== ======= == ====
000000008236 000000415636 0 GetFileAttributesA
00000000824C 00000041564C 0 GetDriveTypeA
00000000825C 00000041565C 0 GetCommandLineA
00000000826E 00000041566E 0 FreeLibrary
00000000827C 00000041567C 0 FindNextFileA
00000000828C 00000041568C 0 FindFirstFileA
00000000829E 00000041569E 0 FindClose
0000000082AA 0000004156AA 0 DeleteFileA
0000000082B8 0000004156B8 0 CreateMutexA
0000000082C8 0000004156C8 0 CreateFileA
0000000082D6 0000004156D6 0 CreateDirectoryA
0000000082EA 0000004156EA 0 CloseHandle
0000000082F6 0000004156F6 0 gdi32.dll
000000008302 000000415702 0 StretchDIBits
000000008312 000000415712 0 SetDIBits
00000000831E 00000041571E 0 SelectObject
00000000832E 00000041572E 0 GetObjectA
00000000833C 00000041573C 0 GetDIBits
000000008348 000000415748 0 DeleteObject
000000008358 000000415758 0 DeleteDC
000000008364 000000415764 0 CreateSolidBrush
000000008378 000000415778 0 CreateDIBSection
00000000838C 00000041578C 0 CreateCompatibleDC
0000000083A2 0000004157A2 0 CreateCompatibleBitmap
0000000083BC 0000004157BC 0 BitBlt
0000000083C4 0000004157C4 0 user32.dll
0000000083D2 0000004157D2 0 ReleaseDC
0000000083DE 0000004157DE 0 GetSysColor
0000000083EC 0000004157EC 0 GetIconInfo
0000000083FA 0000004157FA 0 GetDC
000000008402 000000415802 0 FillRect
00000000840E 00000041580E 0 DestroyIcon
00000000841C 00000041581C 0 CopyImage
000000008428 000000415828 0 CharLowerBuffA
000000008438 000000415838 0 shell32.dll
000000008446 000000415846 0 ShellExecuteA
000000008456 000000415856 0 ExtractIconA
00000000880F 00000041800F 0 0"0*020:0B0J0R0Z0b0j0r0z0
00000000883F 00000041803F 0 0 1(1
000000008857 000000418057 0 4-595T5
00000000885F 00000041805F 0 567r7
00000000887D 00000041807D 0 8&8,848F8R8a8m8u8
0000000088AB 0000004180AB 0 9/9:9[9s9
0000000088BD 0000004180BD 0 :W:w:
0000000088CD 0000004180CD 0 <'<0<;<D<K<Z<a<
0000000088F1 0000004180F1 0 >b>k>
000000008901 000000418101 0 ?2?\?e?u?}?
00000000892B 00000041812B 0 0(0@0L0T0k0z0
000000008945 000000418145 0 0,1P1n1~1
00000000895B 00000041815B 0 2$2u2|2
00000000897D 00000041817D 0 4#4+4O4o4
00000000899B 00000041819B 0 8A8Q8g8
0000000089AD 0000004181AD 0 9*929H9
0000000089C3 0000004181C3 0 9+:X:a:
0000000089D3 0000004181D3 0 :G;o;
0000000089DF 0000004181DF 0 < =T=\=g=
0000000089F1 0000004181F1 0 >N>R>X>\>a>h>n>v>
000000008A11 000000418211 0 ?%?/?7?=?K?f?{?
000000008A38 000000418238 0 N0W0}0
000000008A41 000000418241 0 466?6:7C7
File pos Mem pos ID Text
======== ======= == ====
000000008A53 000000418253 0 <)<2<><E<
000000008A5F 00000041825F 0 =/=;=B=L=V=m=~=
000000008A89 000000418289 0 >/>@>J>R>Z>b>j>
000000008AA7 0000004182A7 0 ?&?+?0?7?>?H?_?k?x?
000000008ADD 0000004182DD 0 0:0B0J0R0Z0b0j0r0z0
000000008B17 000000418317 0 1"1*121:1B1J1R1Z1b1j1r1z1
000000008B47 000000418347 0 2#202B2J2R2_2k2x2
000000008B6D 00000041836D 0 3 323?3K3X3j3w3
000000008B93 000000418393 0 4$4(4,484<4@4L4P4T4
000000008BA7 0000004183A7 0 4d4h4t4x4|4
000000008C15 000000418415 0 6_8H9
000000008C1B 00000041841B 0 9,;:;A;H;c;o;
000000008C51 000000418451 0 :(;=;c;
000000008C6B 00000041846B 0 =*=:=Z=
000000008C75 000000418475 0 >A>v>
000000008C90 000000418490 0 040R0
000000008CB1 0000004184B1 0 2_3n3
000000008CC5 0000004184C5 0 5 6J6
000000008CD1 0000004184D1 0 7U7w7
000000008CDD 0000004184DD 0 9_9d9w9
000000008CEB 0000004184EB 0 :.:E:c:z:
000000008D07 000000418507 0 <==u=
000000008D0D 00000041850D 0 =.>c>
000000008D29 000000418529 0 030F0X0\0
000000008D33 000000418533 0 0d0h0l0p0t0x0|0
000000008D77 000000418577 0 1%191M1a1
000000008D90 000000418590 0 004080
000000008DAD 0000004185AD 0 1 1$1(1
00000000A023 00000041A223 0 RsZLZ
00000000A096 00000041A296 0 Uag%N
00000000A0E0 00000041A2E0 0 Delphi-the best. Fuck off all the rest. Neshta 1.0 Made in Belarus.
00000000A1A8 00000041A3A8 0 ! Best regards 2 Tommy Salo. [Nov-2005] yours [Dziadulja Apanas]
00000000BAAA 00000040BAAA 0 DeleteCriticalSection
00000000BAC2 00000040BAC2 0 EnterCriticalSection
00000000BADA 00000040BADA 0 ExitProcess
00000000BAE8 00000040BAE8 0 GetCommandLineA
00000000BAFA 00000040BAFA 0 GetLastError
00000000BB0A 00000040BB0A 0 GetModuleHandleA
00000000BB1E 00000040BB1E 0 GetProcAddress
00000000BB30 00000040BB30 0 InitializeCriticalSection
00000000BB4C 00000040BB4C 0 InterlockedExchange
00000000BB62 00000040BB62 0 IsDBCSLeadByteEx
00000000BB76 00000040BB76 0 LeaveCriticalSection
00000000BB8E 00000040BB8E 0 MultiByteToWideChar
00000000BBA4 00000040BBA4 0 SetUnhandledExceptionFilter
00000000BBC2 00000040BBC2 0 Sleep
00000000BBCA 00000040BBCA 0 TlsGetValue
00000000BBD8 00000040BBD8 0 VirtualProtect
00000000BBEA 00000040BBEA 0 VirtualQuery
00000000BBFA 00000040BBFA 0 WideCharToMultiByte
00000000BC10 00000040BC10 0 _strdup
00000000BC1A 00000040BC1A 0 _stricoll
00000000BC26 00000040BC26 0 __getmainargs
00000000BC36 00000040BC36 0 __mb_cur_max
00000000BC46 00000040BC46 0 __p__environ
00000000BC56 00000040BC56 0 __p__fmode
00000000BC64 00000040BC64 0 __set_app_type
00000000BC76 00000040BC76 0 _cexit
00000000BC80 00000040BC80 0 _errno
00000000BC8A 00000040BC8A 0 _findclose
File pos Mem pos ID Text
======== ======= == ====
00000000BC98 00000040BC98 0 _findfirst
00000000BCA6 00000040BCA6 0 _findnext
00000000BCB2 00000040BCB2 0 _fullpath
00000000BCC6 00000040BCC6 0 _onexit
00000000BCD0 00000040BCD0 0 _setmode
00000000BCDC 00000040BCDC 0 abort
00000000BCE4 00000040BCE4 0 atexit
00000000BCF6 00000040BCF6 0 calloc
00000000BD00 00000040BD00 0 fputc
00000000BD10 00000040BD10 0 fwrite
00000000BD1A 00000040BD1A 0 getenv
00000000BD24 00000040BD24 0 isspace
00000000BD2E 00000040BD2E 0 localeconv
00000000BD3C 00000040BD3C 0 malloc
00000000BD46 00000040BD46 0 mbstowcs
00000000BD52 00000040BD52 0 memcpy
00000000BD5C 00000040BD5C 0 realloc
00000000BD66 00000040BD66 0 setlocale
00000000BD72 00000040BD72 0 signal
00000000BD7C 00000040BD7C 0 strchr
00000000BD86 00000040BD86 0 strcoll
00000000BD90 00000040BD90 0 strlen
00000000BD9A 00000040BD9A 0 strncpy
00000000BDA4 00000040BDA4 0 tolower
00000000BDAE 00000040BDAE 0 vfprintf
00000000BDBA 00000040BDBA 0 wcslen
00000000BDC4 00000040BDC4 0 wcstombs
00000000BDCE 00000040BDCE 0 MSXFS.dll
00000000BDDA 00000040BDDA 0 WFSStartUp
00000000BDEE 00000040BDEE 0 WFSOpen
00000000BDFE 00000040BDFE 0 WFSLock
00000000BE0E 00000040BE0E 0 WFSFreeResult
00000000BE22 00000040BE22 0 WFSGetInfo
00000000BE36 00000040BE36 0 WFSCleanUp
00000000BE4A 00000040BE4A 0 WFSClose
00000000BE5A 00000040BE5A 0 WFSUnlock
00000000BEB0 00000040BEB0 0 kernel32.dll
00000000BEC8 00000040BEC8 0 msvcrt.dll
00000000BF6C 00000040BF6C 0 msvcrt.dll
00000000C409 00000040C409 0 "w1N]
00000000C4F2 00000040C4F2 0 Ll8];;
00000000C629 00000040C629 0 1tov]
00000000C6A7 00000040C6A7 0 cS+!t\
00000000C6B7 00000040C6B7 0 *u(;1
00000000C6E8 00000040C6E8 0 lm\1A
00000000D052 00000040D052 0 SUBKf
00000000D08D 00000040D08D 0 VALUf
00000000D0CA 00000040D0CA 0 EMPTf
00000000D101 00000040D101 0 _LONf
00000000D13A 00000040D13A 0 ITEMf
00000000D171 00000040D171 0 O_LOf
00000000D1A5 00000040D1A5 0 READf
00000000D1D5 00000040D1D5 0 _ERRf
00000000D209 00000040D209 0 _ERRf
00000000D27A 00000040D27A 0 HANDf
00000000D2B3 00000040D2B3 0 BUFFf
00000000D3BC 00000040D3BC 0 VIDEf
00000000D483 00000040D483 0 REQ_f
00000000D4B7 00000040D4B7 0 RESUf
00000000D523 00000040D523 0 TIMEf
File pos Mem pos ID Text
======== ======= == ====
00000000D55A 00000040D55A 0 ELEVf
00000000D585 00000040D585 0 LOCKf
00000000D613 00000040D613 0 THREf
00000000D664 00000040D664 0 LOCKf
00000000D6F3 00000040D6F3 0 STERf
00000000D727 00000040D727 0 OGREf
00000000D75B 00000040D75B 0 EMORf
00000000D792 00000040D792 0 FOUNf
00000000D82A 00000040D82A 0 _HIGf
00000000D8E3 00000040D8E3 0 OMMAf
00000000D925 00000040D925 0 _SRVf
00000000D983 00000040D983 0 _ERRf
00000000D9DE 00000040D9DE 0 _ERRf
00000000DAAF 00000040DAAF 0 ERROf
00000000DB6A 00000040DB6A 0 CYMIf
00000000DBA1 00000040DBA1 0 NSABf
00000000DC0E 00000040DC0E 0 ITIOf
00000000DC7C 00000040DC7C 0 OTOPf
00000000DCEA 00000040DCEA 0 LOSEf
00000000DD81 00000040DD81 0 ACTIf
00000000DE3A 00000040DE3A 0 OITEf
00000000DEAC 00000040DEAC 0 NKNOf
00000000DEE3 00000040DEE3 0 STAKf
00000000DFA8 00000040DFA8 0 SITIf
00000000DFEA 00000040DFEA 0 CTARf
00000000E0AA 00000040E0AA 0 TAKEf
00000000E0DA 00000040E0DA 0 SLEFf
00000000F34E 00000040F34E 0 <\t?</t;
000000011919 000000411919 0 D$p9D$0
0000000125FD 0000004125FD 0 )D$,)
0000000129B9 0000004129B9 0 L$\9L$
0000000135BE 0000004135BE 0 9l$Xv,
00000001363C 00000041363C 0 9|$Xv7
000000014CB3 000000414CB3 0 r/9D$
0000000151E1 0000004151E1 0 EMPTf
000000015600 000000415600 0 libgcc_s_dw2-1.dll
000000015613 000000415613 0 __register_frame_info
000000015629 000000415629 0 libgcj-13.dll
000000015637 000000415637 0 _Jv_RegisterClasses
00000001564B 00000041564B 0 __deregister_frame_info
000000015BA8 000000415BA8 0 Please enter service name!
000000015BC8 000000415BC8 0 WFSStartUp failed with error: %s
000000015BEC 000000415BEC 0 WFSVERSION:
000000015BF8 000000415BF8 0 wVersion: 0x%X
000000015C08 000000415C08 0 wLowVersion: 0x%X
000000015C1B 000000415C1B 0 wHighVersion: 0x%X
000000015C2F 000000415C2F 0 szDescription: %s
000000015C42 000000415C42 0 szSystemStatus: %s
000000015C58 000000415C58 0 WFSOpen(%s) failed with error: %s
000000015C7C 000000415C7C 0 WFSLock failed with error: %s
000000015C9C 000000415C9C 0 WFSFreeResult failed with error: %s
000000015CC4 000000415CC4 0 WFSGetInfo (WFS_INF_CDM_CASH_UNIT_INFO) failed with error: %s
000000015D03 000000415D03 0 REJECTCASSETTE
000000015D12 000000415D12 0 BILLCASSETTE
000000015D1F 000000415D1F 0 COINCYLINDER
000000015D2C 000000415D2C 0 COINDISPENSER
000000015D3A 000000415D3A 0 RETRACTCASSETTE
000000015D4A 000000415D4A 0 COUPON
000000015D51 000000415D51 0 DOCUMENT
000000015D5A 000000415D5A 0 REPCONTAINER
File pos Mem pos ID Text
======== ======= == ====
000000015D67 000000415D67 0 RECYCLINGCASSETTE
000000015D79 000000415D79 0 NOTAPPLICABLE
000000015D87 000000415D87 0 NOVALUES
000000015D90 000000415D90 0 NOREFERENCE
000000015D9C 000000415D9C 0 MANIPULATED
000000015DA8 000000415DA8 0 INOPERATIVE
000000015DB4 000000415DB4 0 ----------------------------
000000015DD4 000000415DD4 0 Cash Unit # %d
000000015DE3 000000415DE3 0 Type: %s
000000015DEC 000000415DEC 0 Status: %s
000000015DF7 000000415DF7 0 Currency ID: %.3s
000000015E09 000000415E09 0 Note Value: %u
000000015E18 000000415E18 0 Notes Count: %u
000000015E28 000000415E28 0 Notes Initial Count: %u
000000015E40 000000415E40 0 Notes Minimum Count: %u
000000015E58 000000415E58 0 Notes Maximum Count: %u
000000015E74 000000415E74 0 WFSUnlock failed with error: %s
000000015E98 000000415E98 0 WFSClose failed with error: %s
000000015EB8 000000415EB8 0 WFSCleanUp failed with error: %s
000000015EDB 000000415EDB 0 Success
000000015F40 000000415F40 0 Mingw runtime failure:
000000015F58 000000415F58 0 VirtualQuery failed for %d bytes at address %p
000000015F8C 000000415F8C 0 Unknown pseudo relocation protocol version %d.
000000015FC0 000000415FC0 0 Unknown pseudo relocation bit size %d.
000000015FEE 000000415FEE 0 glob-1.0-mingw32
00000001601E 00000041601E 0 (null)
000000016025 000000416025 0 PRINTF_EXPONENT_DIGITS
0000000161A8 0000004161A8 0 Infinity
0000000161CF 0000004161CF 0 ?aCoc
0000000161EF 0000004161EF 0 <2ZGU
000000016380 000000416380 0 GCC: (GNU) 4.8.1
000000016394 000000416394 0 GCC: (GNU) 4.8.1
0000000163A8 0000004163A8 0 GCC: (GNU) 4.8.1
0000000163BC 0000004163BC 0 GCC: (GNU) 4.8.1
0000000163D0 0000004163D0 0 GCC: (GNU) 4.8.1
0000000163E4 0000004163E4 0 GCC: (GNU) 4.8.1
0000000163F8 0000004163F8 0 GCC: (GNU) 4.8.1
00000001640C 00000041640C 0 GCC: (GNU) 4.8.1
000000016420 000000416420 0 GCC: (GNU) 4.8.1
000000016434 000000416434 0 GCC: (GNU) 4.8.1
000000016448 000000416448 0 GCC: (GNU) 4.8.1
00000001645C 00000041645C 0 GCC: (GNU) 4.8.1
000000016470 000000416470 0 GCC: (GNU) 4.8.1
000000016484 000000416484 0 GCC: (GNU) 4.8.1
000000016498 000000416498 0 GCC: (GNU) 4.8.1
0000000164AC 0000004164AC 0 GCC: (GNU) 4.8.1
0000000164C0 0000004164C0 0 GCC: (GNU) 4.8.1
0000000164D4 0000004164D4 0 GCC: (GNU) 4.8.1
0000000164E8 0000004164E8 0 GCC: (GNU) 4.8.1
0000000164FC 0000004164FC 0 GCC: (GNU) 4.8.1
000000016510 000000416510 0 GCC: (GNU) 4.8.1
000000016524 000000416524 0 GCC: (GNU) 4.8.1
000000016538 000000416538 0 GCC: (GNU) 4.8.1
00000001654C 00000041654C 0 GCC: (GNU) 4.8.1
000000016560 000000416560 0 GCC: (GNU) 4.8.1
000000016574 000000416574 0 GCC: (GNU) 4.8.1
000000016588 000000416588 0 GCC: (GNU) 4.8.1
00000001659C 00000041659C 0 GCC: (GNU) 4.8.1
0000000165B0 0000004165B0 0 GCC: (GNU) 4.8.1
000000008F40 000000419140 0 MAINICON
File pos Mem pos ID Text
======== ======= == ====
00000001600F 00000041600F 0 f(null)
000000000050 000000400050 0 This program must be run under Win32
000000000270 000000400270 0 .idata
0000000002C0 0000004002C0 0 .rdata
0000000002E7 0000004002E7 0 P.reloc
00000000030F 00000040030F 0 P.rsrc
00000000059C 00000040119C 0 SVWUQ
0000000007BD 0000004013BD 0 w;;t$
0000000008C8 0000004014C8 0 SVWUQ
0000000017AD 0000004023AD 0 Uh5$@
000000001B17 000000402717 0 ~KxI[)
000000001CD0 0000004028D0 0 SOFTWARE\Borland\Delphi\RTL
000000001CEC 0000004028EC 0 FPUMaskValue
000000001D39 000000402939 0 PPRTj
000000001EB3 000000402AB3 0 YZXtp
00000000202A 000000402C2A 0 t=HtN
000000002204 000000402E04 0 Uh2.@
0000000026CC 0000004032CC 0 SVWRP
0000000028F2 0000004034F2 0 t1SVW
000000003009 000000403C09 0 Uhd<@
00000000312D 000000403D2D 0 Uhr=@
00000000335D 000000403F5D 0 Uh}?@
0000000033CE 000000403FCE 0 HBITMAP
000000003615 000000404215 0 Uh5B@
00000000365D 00000040425D 0 Uh}B@
000000003705 000000404305 0 Uh%C@
00000000373D 00000040433D 0 Uh]C@
0000000038E0 0000004044E0 0 YXZQRPR
0000000039F0 0000004045F0 0 R;P P|
000000003AB4 0000004046B4 0 IVXLCDMT
000000003C52 000000404852 0 t=8!u
000000003C64 000000404864 0 ,8"t&
000000003EF0 000000404AF0 0 Uh(K@
00000000400F 000000404C0F 0 UhfL@
0000000041E5 000000404DE5 0 QQQQS
00000000441E 00000040501E 0 UhrP@
000000004605 000000405205 0 QQQQS
000000004E35 000000405A35 0 XH;XH~ P
000000004E50 000000405A50 0 9PD}-RP
000000004E83 000000405A83 0 PH9PL~
000000004E9D 000000405A9D 0 KH+KLQ
000000004EBB 000000405ABB 0 ;CHRQ~
00000000502A 000000405C2A 0 ;GHv
000000005210 000000405E10 0 @t:HS
00000000523A 000000405E3A 0 Z[XR1
000000005335 000000405F35 0 RP;P ~
0000000053EB 000000405FEB 0 SPRQj
0000000060E5 000000406CE5 0 Uh/m@
0000000062A5 000000406EA5 0 Uh"o@
0000000063E9 000000406FE9 0 QQQQQS
000000006407 000000407007 0 Uhdp@
0000000064E3 0000004070E3 0 Uh&q@
0000000068A8 0000004074A8 0 \PROGRA~1\
0000000068B9 0000004074B9 0 QQQQQQSVW
0000000069A8 0000004075A8 0 Uh\v@
000000006DA5 0000004079A5 0 QQQQQQS3
000000006ED5 000000407AD5 0 QQQQQQ
0000000070A2 000000407CA2 0 UhJ}@
0000000071A1 000000407DA1 0 QQQQQQSV
0000000071B6 000000407DB6 0 Uhu~@
File pos Mem pos ID Text
======== ======= == ====
000000007858 000000409058 0 Error
000000007860 000000409060 0 Runtime error at 00000000
000000007880 000000409080 0 0123456789ABCDEF
000000007E58 000000415258 0 kernel32.dll
000000007E68 000000415268 0 DeleteCriticalSection
000000007E80 000000415280 0 LeaveCriticalSection
000000007E98 000000415298 0 EnterCriticalSection
000000007EB0 0000004152B0 0 InitializeCriticalSection
000000007ECC 0000004152CC 0 VirtualFree
000000007EDA 0000004152DA 0 VirtualAlloc
000000007EEA 0000004152EA 0 LocalFree
000000007EF6 0000004152F6 0 LocalAlloc
000000007F04 000000415304 0 GetVersion
000000007F12 000000415312 0 GetCurrentThreadId
000000007F28 000000415328 0 GetThreadLocale
000000007F3A 00000041533A 0 GetStartupInfoA
000000007F4C 00000041534C 0 GetLocaleInfoA
000000007F5E 00000041535E 0 GetCommandLineA
000000007F70 000000415370 0 FreeLibrary
000000007F7E 00000041537E 0 ExitProcess
000000007F8C 00000041538C 0 WriteFile
000000007F98 000000415398 0 UnhandledExceptionFilter
000000007FB4 0000004153B4 0 RtlUnwind
000000007FC0 0000004153C0 0 RaiseException
000000007FD2 0000004153D2 0 GetStdHandle
000000007FE0 0000004153E0 0 user32.dll
000000007FEE 0000004153EE 0 GetKeyboardType
000000008000 000000415400 0 MessageBoxA
00000000800C 00000041540C 0 advapi32.dll
00000000801C 00000041541C 0 RegQueryValueExA
000000008030 000000415430 0 RegOpenKeyExA
000000008040 000000415440 0 RegCloseKey
00000000804C 00000041544C 0 oleaut32.dll
00000000805C 00000041545C 0 SysFreeString
00000000806C 00000041546C 0 SysReAllocStringLen
000000008080 000000415480 0 kernel32.dll
000000008090 000000415490 0 TlsSetValue
00000000809E 00000041549E 0 TlsGetValue
0000000080AC 0000004154AC 0 LocalAlloc
0000000080BA 0000004154BA 0 GetModuleHandleA
0000000080CC 0000004154CC 0 advapi32.dll
0000000080DC 0000004154DC 0 RegSetValueExA
0000000080EE 0000004154EE 0 RegOpenKeyExA
0000000080FE 0000004154FE 0 RegCloseKey
00000000810A 00000041550A 0 kernel32.dll
00000000811A 00000041551A 0 WriteFile
000000008126 000000415526 0 WinExec
000000008130 000000415530 0 SetFilePointer
000000008142 000000415542 0 SetFileAttributesA
000000008158 000000415558 0 SetEndOfFile
000000008168 000000415568 0 SetCurrentDirectoryA
000000008180 000000415580 0 ReleaseMutex
000000008190 000000415590 0 ReadFile
00000000819C 00000041559C 0 GetWindowsDirectoryA
0000000081B4 0000004155B4 0 GetTempPathA
0000000081C4 0000004155C4 0 GetShortPathNameA
0000000081D8 0000004155D8 0 GetModuleFileNameA
0000000081EE 0000004155EE 0 GetLogicalDriveStringsA
000000008208 000000415608 0 GetLocalTime
000000008218 000000415618 0 GetLastError
File pos Mem pos ID Text
======== ======= == ====
000000008228 000000415628 0 GetFileSize
000000008236 000000415636 0 GetFileAttributesA
00000000824C 00000041564C 0 GetDriveTypeA
00000000825C 00000041565C 0 GetCommandLineA
00000000826E 00000041566E 0 FreeLibrary
00000000827C 00000041567C 0 FindNextFileA
00000000828C 00000041568C 0 FindFirstFileA
00000000829E 00000041569E 0 FindClose
0000000082AA 0000004156AA 0 DeleteFileA
0000000082B8 0000004156B8 0 CreateMutexA
0000000082C8 0000004156C8 0 CreateFileA
0000000082D6 0000004156D6 0 CreateDirectoryA
0000000082EA 0000004156EA 0 CloseHandle
0000000082F6 0000004156F6 0 gdi32.dll
000000008302 000000415702 0 StretchDIBits
000000008312 000000415712 0 SetDIBits
00000000831E 00000041571E 0 SelectObject
00000000832E 00000041572E 0 GetObjectA
00000000833C 00000041573C 0 GetDIBits
000000008348 000000415748 0 DeleteObject
000000008358 000000415758 0 DeleteDC
000000008364 000000415764 0 CreateSolidBrush
000000008378 000000415778 0 CreateDIBSection
00000000838C 00000041578C 0 CreateCompatibleDC
0000000083A2 0000004157A2 0 CreateCompatibleBitmap
0000000083BC 0000004157BC 0 BitBlt
0000000083C4 0000004157C4 0 user32.dll
0000000083D2 0000004157D2 0 ReleaseDC
0000000083DE 0000004157DE 0 GetSysColor
0000000083EC 0000004157EC 0 GetIconInfo
0000000083FA 0000004157FA 0 GetDC
000000008402 000000415802 0 FillRect
00000000840E 00000041580E 0 DestroyIcon
00000000841C 00000041581C 0 CopyImage
000000008428 000000415828 0 CharLowerBuffA
000000008438 000000415838 0 shell32.dll
000000008446 000000415846 0 ShellExecuteA
000000008456 000000415856 0 ExtractIconA
00000000880F 00000041800F 0 0"0*020:0B0J0R0Z0b0j0r0z0
00000000883F 00000041803F 0 0 1(1
000000008857 000000418057 0 4-595T5
00000000885F 00000041805F 0 567r7
00000000887D 00000041807D 0 8&8,848F8R8a8m8u8
0000000088AB 0000004180AB 0 9/9:9[9s9
0000000088BD 0000004180BD 0 :W:w:
0000000088CD 0000004180CD 0 <'<0<;<D<K<Z<a<
0000000088F1 0000004180F1 0 >b>k>
000000008901 000000418101 0 ?2?\?e?u?}?
00000000892B 00000041812B 0 0(0@0L0T0k0z0
000000008945 000000418145 0 0,1P1n1~1
00000000895B 00000041815B 0 2$2u2|2
00000000897D 00000041817D 0 4#4+4O4o4
00000000899B 00000041819B 0 8A8Q8g8
0000000089AD 0000004181AD 0 9*929H9
0000000089C3 0000004181C3 0 9+:X:a:
0000000089D3 0000004181D3 0 :G;o;
0000000089DF 0000004181DF 0 < =T=\=g=
0000000089F1 0000004181F1 0 >N>R>X>\>a>h>n>v>
000000008A11 000000418211 0 ?%?/?7?=?K?f?{?
000000008A38 000000418238 0 N0W0}0
File pos Mem pos ID Text
======== ======= == ====
000000008A41 000000418241 0 466?6:7C7
000000008A53 000000418253 0 <)<2<><E<
000000008A5F 00000041825F 0 =/=;=B=L=V=m=~=
000000008A89 000000418289 0 >/>@>J>R>Z>b>j>
000000008AA7 0000004182A7 0 ?&?+?0?7?>?H?_?k?x?
000000008ADD 0000004182DD 0 0:0B0J0R0Z0b0j0r0z0
000000008B17 000000418317 0 1"1*121:1B1J1R1Z1b1j1r1z1
000000008B47 000000418347 0 2#202B2J2R2_2k2x2
000000008B6D 00000041836D 0 3 323?3K3X3j3w3
000000008B93 000000418393 0 4$4(4,484<4@4L4P4T4
000000008BA7 0000004183A7 0 4d4h4t4x4|4
000000008C15 000000418415 0 6_8H9
000000008C1B 00000041841B 0 9,;:;A;H;c;o;
000000008C51 000000418451 0 :(;=;c;
000000008C6B 00000041846B 0 =*=:=Z=
000000008C75 000000418475 0 >A>v>
000000008C90 000000418490 0 040R0
000000008CB1 0000004184B1 0 2_3n3
000000008CC5 0000004184C5 0 5 6J6
000000008CD1 0000004184D1 0 7U7w7
000000008CDD 0000004184DD 0 9_9d9w9
000000008CEB 0000004184EB 0 :.:E:c:z:
000000008D07 000000418507 0 <==u=
000000008D0D 00000041850D 0 =.>c>
000000008D29 000000418529 0 030F0X0\0
000000008D33 000000418533 0 0d0h0l0p0t0x0|0
000000008D77 000000418577 0 1%191M1a1
000000008D90 000000418590 0 004080
000000008DAD 0000004185AD 0 1 1$1(1
00000000A023 00000041A223 0 RsZLZ
00000000A096 00000041A296 0 Uag%N
00000000A0E0 00000041A2E0 0 Delphi-the best. Fuck off all the rest. Neshta 1.0 Made in Belarus.
00000000A1A8 00000041A3A8 0 ! Best regards 2 Tommy Salo. [Nov-2005] yours [Dziadulja Apanas]
00000000BAAA 00000040BAAA 0 DeleteCriticalSection
00000000BAC2 00000040BAC2 0 EnterCriticalSection
00000000BADA 00000040BADA 0 ExitProcess
00000000BAE8 00000040BAE8 0 GetCommandLineA
00000000BAFA 00000040BAFA 0 GetLastError
00000000BB0A 00000040BB0A 0 GetModuleHandleA
00000000BB1E 00000040BB1E 0 GetProcAddress
00000000BB30 00000040BB30 0 InitializeCriticalSection
00000000BB4C 00000040BB4C 0 InterlockedExchange
00000000BB62 00000040BB62 0 IsDBCSLeadByteEx
00000000BB76 00000040BB76 0 LeaveCriticalSection
00000000BB8E 00000040BB8E 0 MultiByteToWideChar
00000000BBA4 00000040BBA4 0 SetUnhandledExceptionFilter
00000000BBC2 00000040BBC2 0 Sleep
00000000BBCA 00000040BBCA 0 TlsGetValue
00000000BBD8 00000040BBD8 0 VirtualProtect
00000000BBEA 00000040BBEA 0 VirtualQuery
00000000BBFA 00000040BBFA 0 WideCharToMultiByte
00000000BC10 00000040BC10 0 _strdup
00000000BC1A 00000040BC1A 0 _stricoll
00000000BC26 00000040BC26 0 __getmainargs
00000000BC36 00000040BC36 0 __mb_cur_max
00000000BC46 00000040BC46 0 __p__environ
00000000BC56 00000040BC56 0 __p__fmode
00000000BC64 00000040BC64 0 __set_app_type
00000000BC76 00000040BC76 0 _cexit
00000000BC80 00000040BC80 0 _errno
File pos Mem pos ID Text
======== ======= == ====
00000000BC8A 00000040BC8A 0 _findclose
00000000BC98 00000040BC98 0 _findfirst
00000000BCA6 00000040BCA6 0 _findnext
00000000BCB2 00000040BCB2 0 _fullpath
00000000BCC6 00000040BCC6 0 _onexit
00000000BCD0 00000040BCD0 0 _setmode
00000000BCDC 00000040BCDC 0 abort
00000000BCE4 00000040BCE4 0 atexit
00000000BCF6 00000040BCF6 0 calloc
00000000BD00 00000040BD00 0 fputc
00000000BD10 00000040BD10 0 fwrite
00000000BD1A 00000040BD1A 0 getenv
00000000BD24 00000040BD24 0 isspace
00000000BD2E 00000040BD2E 0 localeconv
00000000BD3C 00000040BD3C 0 malloc
00000000BD46 00000040BD46 0 mbstowcs
00000000BD52 00000040BD52 0 memcpy
00000000BD5C 00000040BD5C 0 realloc
00000000BD66 00000040BD66 0 setlocale
00000000BD72 00000040BD72 0 signal
00000000BD7C 00000040BD7C 0 strchr
00000000BD86 00000040BD86 0 strcoll
00000000BD90 00000040BD90 0 strlen
00000000BD9A 00000040BD9A 0 strncpy
00000000BDA4 00000040BDA4 0 tolower
00000000BDAE 00000040BDAE 0 vfprintf
00000000BDBA 00000040BDBA 0 wcslen
00000000BDC4 00000040BDC4 0 wcstombs
00000000BDCE 00000040BDCE 0 MSXFS.dll
00000000BDDA 00000040BDDA 0 WFSStartUp
00000000BDEE 00000040BDEE 0 WFSOpen
00000000BDFE 00000040BDFE 0 WFSLock
00000000BE0E 00000040BE0E 0 WFSFreeResult
00000000BE22 00000040BE22 0 WFSGetInfo
00000000BE36 00000040BE36 0 WFSCleanUp
00000000BE4A 00000040BE4A 0 WFSClose
00000000BE5A 00000040BE5A 0 WFSUnlock
00000000BEB0 00000040BEB0 0 kernel32.dll
00000000BEC8 00000040BEC8 0 msvcrt.dll
00000000BF6C 00000040BF6C 0 msvcrt.dll
00000000C409 00000040C409 0 "w1N]
00000000C4F2 00000040C4F2 0 Ll8];;
00000000C629 00000040C629 0 1tov]
00000000C6A7 00000040C6A7 0 cS+!t\
00000000C6B7 00000040C6B7 0 *u(;1
00000000C6E8 00000040C6E8 0 lm\1A
00000000D052 00000040D052 0 SUBKf
00000000D08D 00000040D08D 0 VALUf
00000000D0CA 00000040D0CA 0 EMPTf
00000000D101 00000040D101 0 _LONf
00000000D13A 00000040D13A 0 ITEMf
00000000D171 00000040D171 0 O_LOf
00000000D1A5 00000040D1A5 0 READf
00000000D1D5 00000040D1D5 0 _ERRf
00000000D209 00000040D209 0 _ERRf
00000000D27A 00000040D27A 0 HANDf
00000000D2B3 00000040D2B3 0 BUFFf
00000000D3BC 00000040D3BC 0 VIDEf
00000000D483 00000040D483 0 REQ_f
00000000D4B7 00000040D4B7 0 RESUf
File pos Mem pos ID Text
======== ======= == ====
00000000D523 00000040D523 0 TIMEf
00000000D55A 00000040D55A 0 ELEVf
00000000D585 00000040D585 0 LOCKf
00000000D613 00000040D613 0 THREf
00000000D664 00000040D664 0 LOCKf
00000000D6F3 00000040D6F3 0 STERf
00000000D727 00000040D727 0 OGREf
00000000D75B 00000040D75B 0 EMORf
00000000D792 00000040D792 0 FOUNf
00000000D82A 00000040D82A 0 _HIGf
00000000D8E3 00000040D8E3 0 OMMAf
00000000D925 00000040D925 0 _SRVf
00000000D983 00000040D983 0 _ERRf
00000000D9DE 00000040D9DE 0 _ERRf
00000000DAAF 00000040DAAF 0 ERROf
00000000DB6A 00000040DB6A 0 CYMIf
00000000DBA1 00000040DBA1 0 NSABf
00000000DC0E 00000040DC0E 0 ITIOf
00000000DC7C 00000040DC7C 0 OTOPf
00000000DCEA 00000040DCEA 0 LOSEf
00000000DD81 00000040DD81 0 ACTIf
00000000DE3A 00000040DE3A 0 OITEf
00000000DEAC 00000040DEAC 0 NKNOf
00000000DEE3 00000040DEE3 0 STAKf
00000000DFA8 00000040DFA8 0 SITIf
00000000DFEA 00000040DFEA 0 CTARf
00000000E0AA 00000040E0AA 0 TAKEf
00000000E0DA 00000040E0DA 0 SLEFf
00000000F34E 00000040F34E 0 <\t?</t;
000000011919 000000411919 0 D$p9D$0
0000000125FD 0000004125FD 0 )D$,)
0000000129B9 0000004129B9 0 L$\9L$
0000000135BE 0000004135BE 0 9l$Xv,
00000001363C 00000041363C 0 9|$Xv7
000000014CB3 000000414CB3 0 r/9D$
0000000151E1 0000004151E1 0 EMPTf
000000015600 000000415600 0 libgcc_s_dw2-1.dll
000000015613 000000415613 0 __register_frame_info
000000015629 000000415629 0 libgcj-13.dll
000000015637 000000415637 0 _Jv_RegisterClasses
00000001564B 00000041564B 0 __deregister_frame_info
000000015BA8 000000415BA8 0 Please enter service name!
000000015BC8 000000415BC8 0 WFSStartUp failed with error: %s
000000015BEC 000000415BEC 0 WFSVERSION:
000000015BF8 000000415BF8 0 wVersion: 0x%X
000000015C08 000000415C08 0 wLowVersion: 0x%X
000000015C1B 000000415C1B 0 wHighVersion: 0x%X
000000015C2F 000000415C2F 0 szDescription: %s
000000015C42 000000415C42 0 szSystemStatus: %s
000000015C58 000000415C58 0 WFSOpen(%s) failed with error: %s
000000015C7C 000000415C7C 0 WFSLock failed with error: %s
000000015C9C 000000415C9C 0 WFSFreeResult failed with error: %s
000000015CC4 000000415CC4 0 WFSGetInfo (WFS_INF_CDM_CASH_UNIT_INFO) failed with error: %s
000000015D03 000000415D03 0 REJECTCASSETTE
000000015D12 000000415D12 0 BILLCASSETTE
000000015D1F 000000415D1F 0 COINCYLINDER
000000015D2C 000000415D2C 0 COINDISPENSER
000000015D3A 000000415D3A 0 RETRACTCASSETTE
000000015D4A 000000415D4A 0 COUPON
000000015D51 000000415D51 0 DOCUMENT
File pos Mem pos ID Text
======== ======= == ====
000000015D5A 000000415D5A 0 REPCONTAINER
000000015D67 000000415D67 0 RECYCLINGCASSETTE
000000015D79 000000415D79 0 NOTAPPLICABLE
000000015D87 000000415D87 0 NOVALUES
000000015D90 000000415D90 0 NOREFERENCE
000000015D9C 000000415D9C 0 MANIPULATED
000000015DA8 000000415DA8 0 INOPERATIVE
000000015DB4 000000415DB4 0 ----------------------------
000000015DD4 000000415DD4 0 Cash Unit # %d
000000015DE3 000000415DE3 0 Type: %s
000000015DEC 000000415DEC 0 Status: %s
000000015DF7 000000415DF7 0 Currency ID: %.3s
000000015E09 000000415E09 0 Note Value: %u
000000015E18 000000415E18 0 Notes Count: %u
000000015E28 000000415E28 0 Notes Initial Count: %u
000000015E40 000000415E40 0 Notes Minimum Count: %u
000000015E58 000000415E58 0 Notes Maximum Count: %u
000000015E74 000000415E74 0 WFSUnlock failed with error: %s
000000015E98 000000415E98 0 WFSClose failed with error: %s
000000015EB8 000000415EB8 0 WFSCleanUp failed with error: %s
000000015EDB 000000415EDB 0 Success
000000015F40 000000415F40 0 Mingw runtime failure:
000000015F58 000000415F58 0 VirtualQuery failed for %d bytes at address %p
000000015F8C 000000415F8C 0 Unknown pseudo relocation protocol version %d.
000000015FC0 000000415FC0 0 Unknown pseudo relocation bit size %d.
000000015FEE 000000415FEE 0 glob-1.0-mingw32
00000001601E 00000041601E 0 (null)
000000016025 000000416025 0 PRINTF_EXPONENT_DIGITS
0000000161A8 0000004161A8 0 Infinity
0000000161CF 0000004161CF 0 ?aCoc
0000000161EF 0000004161EF 0 <2ZGU
000000016380 000000416380 0 GCC: (GNU) 4.8.1
000000016394 000000416394 0 GCC: (GNU) 4.8.1
0000000163A8 0000004163A8 0 GCC: (GNU) 4.8.1
0000000163BC 0000004163BC 0 GCC: (GNU) 4.8.1
0000000163D0 0000004163D0 0 GCC: (GNU) 4.8.1
0000000163E4 0000004163E4 0 GCC: (GNU) 4.8.1
0000000163F8 0000004163F8 0 GCC: (GNU) 4.8.1
00000001640C 00000041640C 0 GCC: (GNU) 4.8.1
000000016420 000000416420 0 GCC: (GNU) 4.8.1
000000016434 000000416434 0 GCC: (GNU) 4.8.1
000000016448 000000416448 0 GCC: (GNU) 4.8.1
00000001645C 00000041645C 0 GCC: (GNU) 4.8.1
000000016470 000000416470 0 GCC: (GNU) 4.8.1
000000016484 000000416484 0 GCC: (GNU) 4.8.1
000000016498 000000416498 0 GCC: (GNU) 4.8.1
0000000164AC 0000004164AC 0 GCC: (GNU) 4.8.1
0000000164C0 0000004164C0 0 GCC: (GNU) 4.8.1
0000000164D4 0000004164D4 0 GCC: (GNU) 4.8.1
0000000164E8 0000004164E8 0 GCC: (GNU) 4.8.1
0000000164FC 0000004164FC 0 GCC: (GNU) 4.8.1
000000016510 000000416510 0 GCC: (GNU) 4.8.1
000000016524 000000416524 0 GCC: (GNU) 4.8.1
000000016538 000000416538 0 GCC: (GNU) 4.8.1
00000001654C 00000041654C 0 GCC: (GNU) 4.8.1
000000016560 000000416560 0 GCC: (GNU) 4.8.1
000000016574 000000416574 0 GCC: (GNU) 4.8.1
000000016588 000000416588 0 GCC: (GNU) 4.8.1
00000001659C 00000041659C 0 GCC: (GNU) 4.8.1
0000000165B0 0000004165B0 0 GCC: (GNU) 4.8.1
File pos Mem pos ID Text
======== ======= == ====
000000008F40 000000419140 0 MAINICON
00000001600F 00000041600F 0 f(null)
=== DOWNLOAD ===
Mirror provided by vx-underground.org, thx!