_WinMain16(): KERNEL32.GetCommandLineA KERNEL32.GetCurrentThreadId KERNEL32.lstrcmpi KERNEL32.CreateEventA KERNEL32.CreateThread USER32.GetDesktopWindow USER32.CreateDialogParamA USER32.ShowWindow USER32.GetMessageA USER32.IsDialogMessage USER32.DispatchMessageA KERNEL32.Sleep |
sub_outside(): KERNEL32.GetVersionExA KERNEL32.InterlockedExchange KERNEL32.RaiseException KERNEL32.GetCurrentThreadId NTDLL.RtlEnterCriticalSection NTDLL.RtlLeaveCriticalSection ADVAPI32.RegOpenKeyExA ADVAPI32.RegQueryValueExA ADVAPI32.RegCloseKey KERNEL32.DeleteFileA ADVAPI32.RegDeleteKeyA MSVCRT._exit USER32.SetWindowLongA KERNEL32.lstrcmpi USER32.GetClassWord USER32.GetWindowLongA USER32.ShowWindow USER32.SetForegroundWindow USER32.SetFocus NTDLL.RtlDeleteCriticalSection |
sub_401000(045c): KERNEL32.WaitForSingleObject KERNEL32.CloseHandle USER32.PostThreadMessageA |
sub_401810(056b): USER32.CharNextA |
sub_401BB0(05bb): KERNEL32.RaiseException |
sub_409D70(0c69): KERNEL32.Sleep |
sub_406110(0ebe): USER32.SendDlgItemMessageA USER32.SetTimer |
sub_403CA0(111b): KERNEL32.lstrlenW |
sub_40A2B0(11d2): ADVAPI32.RegOpenKeyExA ADVAPI32.RegQueryValueExA ADVAPI32.RegCloseKey |
sub_4065D0(1414): "%s" |
sub_407D40(14a3): USER32.SetWindowLongA USER32.GetClassWord USER32.GetWindowLongA USER32.EnumWindows USER32.DestroyWindow USER32.PostQuitMessage USER32.SetWindowTextA NTDLL.RtlGetLastWin32Error KERNEL32.lstrcmp USER32.SendDlgItemMessageA USER32.GetDlgItem USER32.EnableWindow USER32.SetFocus USER32.LoadImageA USER32.SendMessageA USER32.PostMessageA "open" "xx" ".\\BsdMainDlg.cpp" "modem" "isdn" |
sub_4014D0(19ad): ADVAPI32.RegCloseKey |
sub_40A110(1b12): KERNEL32.MultiByteToWideChar |
sub_407AA0(1fd7): USER32.GetDlgItemTextA |
sub_401950(2065): KERNEL32.lstrcmpi "TypeLib" |
sub_403050(23bb): NTDLL.RtlDeleteCriticalSection |
sub_409190(23f8): KERNEL32.lstrlen KERNEL32.lstrcpy |
sub_405440(262e): KERNEL32.GetModuleFileNameA KERNEL32.lstrlen KERNEL32.GetModuleHandleA KERNEL32.lstrlenW "Module" "Module" "Module_Raw" "REGISTRY" |
sub_40A040(27c1): ADVAPI32.RegOpenKeyExA ADVAPI32.RegQueryValueExA ADVAPI32.RegCloseKey ADVAPI32.RegSetValueExA |
sub_403BB0(2966): KERNEL32.lstrlen KERNEL32.lstrlenW |
sub_403D70(2d08): KERNEL32.lstrlen ADVAPI32.RegSetValueExA USER32.CharNextA KERNEL32.IsDBCSLeadByte |
sub_402730(2e06): KERNEL32.GetModuleFileNameA KERNEL32.lstrlenW KERNEL32.lstrlen KERNEL32.lstrcpy |
sub_4097C0(2f83): KERNEL32.Sleep |
sub_4094D0(301c): KERNEL32.lstrcmp |
sub_401060(31a4): USER32.CharNextA |
sub_403030(3309): KERNEL32.GetProcessHeap NTDLL.RtlFreeHeap |
sub_409FE0(370d): KERNEL32.LoadLibraryA KERNEL32.GetProcAddress KERNEL32.FreeLibrary KERNEL32.lstrcpyn "SHGetFolderPathA" |
sub_401C00(3aae): KERNEL32.GetProcessHeap NTDLL.RtlAllocateHeap KERNEL32.GetCurrentProcess KERNEL32.FlushInstructionCache |
sub_403350(3c47): KERNEL32.GetFileAttributesA KERNEL32.SetFileAttributesA KERNEL32.lstrcmp KERNEL32.CopyFileA ADVAPI32.RegCreateKeyExA ADVAPI32.RegSetValueExA ADVAPI32.RegCloseKey "\\" "c:\\" "\\" "." "\\" ".exe" "\\" ".lnk" "Internet Dialer" "SOFTWARE\\Microsoft\\Windows\\CurrentVersi"... "Carlson Dialer" "DisplayName" " -u" "UninstallString" |
sub_401990(4684): ADVAPI32.RegQueryInfoKeyA |
sub_401EF0(4744): ADVAPI32.RegOpenKeyExA ADVAPI32.RegCloseKey ADVAPI32.RegEnumKeyExA ADVAPI32.RegDeleteKeyA |
sub_406390(4806): KERNEL32.lstrlen "\\" |
sub_405CC0(4cdb): USER32.DestroyWindow USER32.PostQuitMessage |
sub_4066F0(4e76): WININET.InternetCheckConnectionA WININET.InternetAutodial WININET.InternetOpenA WININET.InternetOpenUrlA WININET.InternetReadFile ADVAPI32.RegCreateKeyExA ADVAPI32.RegSetValueExA ADVAPI32.RegCloseKey WININET.InternetCloseHandle "http://prs.payperdownload.nl" "http://prs.payperdownload.nl" "del" "http://prs.payperdownload.nl/radius/dia"... "callrecords" "call" "realnumber" "price" "countrycode" "xx" "XX" "\\" "phonenumber1" "phonenumber2" "price1" "price2" "cc" |
sub_407AF0(4fb3): ADVAPI32.RegOpenKeyExA ADVAPI32.RegQueryValueExA ADVAPI32.RegCloseKey KERNEL32.lstrlen ADVAPI32.RegSetValueExA "\\" |
sub_404BA0(5014): KERNEL32.lstrcmpi |
sub_401590(506d): KERNEL32.lstrlen ADVAPI32.RegSetValueExA |
sub_401560(52eb): KERNEL32.lstrlen ADVAPI32.RegSetValueExA |
sub_407980(5f4d): ADVAPI32.RegOpenKeyExA ADVAPI32.RegQueryValueExA ADVAPI32.RegCloseKey "\\" "cc" "cc" |
sub_4014F0(623e): ADVAPI32.RegOpenKeyExA ADVAPI32.RegCloseKey |
sub_404CD0(6248): KERNEL32.lstrlenW KERNEL32.WideCharToMultiByte KERNEL32.LoadLibraryExA KERNEL32.FindResourceA KERNEL32.LoadResource KERNEL32.SizeofResource KERNEL32.FreeLibrary |
sub_405FB0(634b): "open" |
sub_4090B0(6508): KERNEL32.lstrcmp |
sub_408FD0(66b4): USER32.LoadStringA KERNEL32.lstrlen KERNEL32.lstrcpy |
sub_408F20(66b4): USER32.LoadStringA KERNEL32.lstrlen KERNEL32.lstrcpy |
sub_401E30(66bc): KERNEL32.MultiByteToWideChar |
sub_4096E0(696b): KERNEL32.lstrcpyn KERNEL32.lstrcpy KERNEL32.lstrlen KERNEL32.lstrcat "," |
sub_409530(6aca): KERNEL32.lstrcpyn " " |
sub_4030B0(6b3a): ADVAPI32.RegCreateKeyExA ADVAPI32.RegSetValueExA ADVAPI32.RegCloseKey "\\" "uninstExe" "uninstShortcut" |
sub_401240(6e05): KERNEL32.WideCharToMultiByte |
sub_4020E0(6e6b): USER32.UnregisterClassA NTDLL.RtlDeleteCriticalSection KERNEL32.RaiseException |
sub_409780(7235): KERNEL32.lstrcpyn |
sub_4097A0(7235): KERNEL32.lstrcpyn |
sub_402170(74a7): NTDLL.RtlDeleteCriticalSection |
sub_404100(75b5): KERNEL32.lstrcmpi USER32.CharNextA KERNEL32.lstrlen ADVAPI32.RegDeleteValueA ADVAPI32.RegCloseKey ADVAPI32.RegOpenKeyExA ADVAPI32.RegCreateKeyExA KERNEL32.lstrcpyn ADVAPI32.RegDeleteKeyA "Delete" "ForceRemove" "NoRemove" "Val" |
sub_4099A0(75eb): KERNEL32.FreeLibrary KERNEL32.LoadLibraryA KERNEL32.GetProcAddress "RASAPI32.DLL" "RasEnumDevicesA" "RasDialA" "RasGetErrorStringA" "RasGetEntryPropertiesA" "RasSetEntryPropertiesA" "RasHangUpA" "RasEnumConnectionsA" "RasGetConnectStatusA" "RasSetEntryDialParamsA" |
sub_405CE0(786b): KERNEL32.lstrcmp USER32.SendDlgItemMessageA KERNEL32.lstrcpyn |
sub_406FE0(791c): WININET.InternetCheckConnectionA WININET.InternetAutodial WININET.InternetOpenA WININET.InternetOpenUrlA WININET.InternetReadFile ADVAPI32.RegCreateKeyExA ADVAPI32.RegSetValueExA ADVAPI32.RegCloseKey WININET.InternetCloseHandle "http://prs.payperdownload.nl" "http://prs.payperdownload.nl" "del" "http://prs.payperdownload.nl/radius/dia"... "callrecords" "call" "realnumber" "price" "\\" "xx" "phonenumber2" "price2" "phonenumber1" "price1" |
sub_402410(7c27): KERNEL32.lstrlenW KERNEL32.lstrlen |
sub_404A20(7d77): USER32.SetWindowLongA |
sub_402370(808e): KERNEL32.InterlockedIncrement |
sub_405BC0(831d): "open" |
sub_401200(8718): KERNEL32.MultiByteToWideChar |
sub_402EC0(88aa): NTDLL.RtlEnterCriticalSection KERNEL32.GetCurrentThreadId NTDLL.RtlLeaveCriticalSection |
sub_408A10(8d65): USER32.LoadStringA |
sub_401140(8e17): KERNEL32.GetThreadLocale KERNEL32.GetLocaleInfoA KERNEL32.GetACP |
sub_40AF44(8fc6): KERNEL32.CreateDirectoryA NTDLL.RtlGetLastWin32Error |
sub_408A80(939b): ADVAPI32.RegQueryValueExA |
sub_409730(995f): KERNEL32.lstrcpyn KERNEL32.lstrcpy KERNEL32.lstrlen KERNEL32.lstrcat "," |
sub_408CF0(999b): ADVAPI32.RegCreateKeyExA KERNEL32.lstrlen ADVAPI32.RegSetValueExA ADVAPI32.RegCloseKey "version" "serial" "username1" "username2" "password1" "password2" "connecttime" |
sub_408CC0(a2c1): KERNEL32.lstrlen ADVAPI32.RegSetValueExA |
sub_401C80(a392): KERNEL32.lstrcmpi |
sub_405EB0(a3f3): USER32.DestroyWindow USER32.PostQuitMessage |
sub_407540(acb7): ADVAPI32.RegOpenKeyExA ADVAPI32.RegQueryValueExA ADVAPI32.RegCloseKey ADVAPI32.RegCreateKeyExA KERNEL32.lstrlen ADVAPI32.RegSetValueExA "\\" |
sub_405E80(b164): USER32.SetDlgItemTextA |
sub_406210(b300): USER32.wvsprintfA USER32.MessageBoxA USER32.DestroyWindow USER32.PostQuitMessage "?" "&" "error=fatal&filename=" "&linenumber=" "&lasterror=" "open" |
sub_402570(b70b): KERNEL32.RaiseException |
sub_40A260(b773): KERNEL32.lstrcpyn |
sub_406060(b7f8): USER32.SetDlgItemTextA |
sub_40B393(b873): KERNEL32.DeleteFileA NTDLL.RtlGetLastWin32Error |
sub_40E979(b875): NTDLL.RtlDeleteCriticalSection |
sub_407750(b963): ADVAPI32.RegCreateKeyExA ADVAPI32.RegSetValueExA ADVAPI32.RegCloseKey "\\" "Prefix" |
sub_401280(c101): KERNEL32.lstrlenW |
sub_401770(c174): USER32.CharNextA |
sub_4089B0(c885): KERNEL32.lstrlen KERNEL32.lstrcpy |
sub_401DD0(ca51): KERNEL32.FindResourceA |
sub_409AD0(cba9): KERNEL32.lstrcmp KERNEL32.lstrcpyn "modem" "isdn" |
sub_401300(cde2): KERNEL32.InitializeCriticalSection |
sub_405800(cdf0): KERNEL32.lstrlenW |
sub_401540(d1dd): ADVAPI32.RegSetValueExA |
sub_401D50(d643): KERNEL32.InterlockedDecrement KERNEL32.SetEvent |
sub_401380(d9ab): KERNEL32.LoadResource KERNEL32.LockResource KERNEL32.SizeofResource |
sub_408350(db60): USER32.KillTimer USER32.DestroyWindow USER32.PostQuitMessage USER32.ShowWindow USER32.SetTimer USER32.SendDlgItemMessageA "Dial: %d - %s" "xx" |
sub_405E40(e063): USER32.wvsprintfA |
sub_4025B0(e15c): KERNEL32.lstrlen USER32.CharNextA KERNEL32.lstrcpyn |
sub_4056E0(e2d4): KERNEL32.lstrlenW |
sub_404FC0(e4aa): KERNEL32.lstrlenW KERNEL32.WideCharToMultiByte |
sub_404EC0(e4aa): KERNEL32.lstrlenW KERNEL32.WideCharToMultiByte |
sub_40A3B0(e5ee): KERNEL32.FreeLibrary "Shell32.dll" "SHFolder.dll" |
sub_4050C0(e6e8): KERNEL32.GetModuleFileNameA KERNEL32.lstrlen KERNEL32.GetModuleHandleA KERNEL32.lstrlenW "Module" "Module" "Module_Raw" "REGISTRY" |
sub_4017B0(e725): USER32.CharNextA |
sub_409050(ecd2): KERNEL32.lstrlen KERNEL32.lstrcpy "2.0" "2.0" |
sub_405F00(eef4): USER32.SendDlgItemMessageA |
sub_409E10(f145): KERNEL32.lstrcpyn |
sub_409F60(f15a): KERNEL32.WideCharToMultiByte |
sub_401650(f1f5): KERNEL32.lstrcmpi "S" "M" "D" "B" |
sub_408B20(f4cb): ADVAPI32.RegCreateKeyExA ADVAPI32.RegCloseKey "version" "serial" "username1" "username2" "password1" "password2" "phonenumber1" "phonenumber2" "connecttime" |
sub_40A645(f736): KERNEL32.GetVersionExA |
sub_405D70(f769): USER32.LoadStringA USER32.wsprintfA USER32.wvsprintfA "resource %ld not found" |
sub_402B60(f7d9): KERNEL32.lstrlenW KERNEL32.lstrcpy KERNEL32.lstrcat ADVAPI32.RegQueryInfoKeyA ADVAPI32.RegDeleteKeyA "CLSID\\" "\\Required Categories" "CLSID\\" "\\Implemented Categories" |
sub_402A90(f83b): KERNEL32.lstrlenW |
sub_40A4B0(f895): KERNEL32.lstrlen USER32.wsprintfA "%%%2x" |
sub_4013E0(f94b): NTDLL.RtlGetLastWin32Error |
sub_407820(fc5f): ADVAPI32.RegOpenKeyExA ADVAPI32.RegQueryValueExA ADVAPI32.RegCloseKey "\\" "Prefix" "Prefix" |
sub_401ED0(fe10): ADVAPI32.RegCloseKey |