Analysis Date2015-01-14 13:29:58
MD5b9d6c54e85c17acd3efad1ec1a83539e
SHA10407cc04a0eca85ecce4d3e973a0f0d5905fa750

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhash7bfd043ac63ba2facdc9c3129ea88fe8c8472fd7
IMPhash
AV360 Safeno_virus
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)VirLock-A:Win32:VirLock-A
AVArcabit (arcavir)Error Scanning File
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)Ransom.VirLock.A2
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99f1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!B9D6C54E85C1
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecW32.Ransomlock.AO!inf
AVTrend MicroPE_FINALDO.F
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\vAEYQEMk.bat
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\vAEYQEMk.bat
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Creates FilePIPE\wkssvc
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Process"C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileecoE.ico
Creates FileesQI.ico
Creates FileSokS.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FileyooW.exe
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FileWgYw.ico
Creates FilewMgk.exe
Creates FileC:\RCX2.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileC:\RCXF.tmp
Creates FileqwoY.ico
Creates FileKAIk.ico
Creates FileOkEg.exe
Creates FileygIC.exe
Creates FileC:\RCX12.tmp
Creates FileuUkk.exe
Creates FileOAIY.ico
Creates FileSIYy.exe
Creates FileC:\RCX18.tmp
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileWAgU.ico
Creates FileC:\RCXC.tmp
Creates FileeoAg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileC:\RCX9.tmp
Creates FilePIPE\wkssvc
Creates FileyQgK.ico
Creates FileOAIe.ico
Creates FileiEEK.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FileIAsQ.ico
Creates FileC:\RCX1D.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FileYMAM.exe
Creates FilesEgu.ico
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileycEa.ico
Creates Filecgoa.ico
Creates FileakoK.ico
Creates FileyMse.exe
Creates FileC:\RCX17.tmp
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FileyQcu.ico
Creates FileiAwq.exe
Creates FileOcsc.exe
Creates FileioYi.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FileaQMq.ico
Creates FileMwUG.ico
Creates FileeIEc.exe
Creates FileeEYY.exe
Creates FileeMYA.exe
Creates FileGgEY.exe
Creates FilemowY.ico
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileaUUK.exe
Creates FileaAQe.exe
Creates FileC:\RCX3.tmp
Creates FileC:\RCX20.tmp
Creates FileC:\RCXB.tmp
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FileqkcO.exe
Creates FilemUEw.ico
Creates FilegkEY.exe
Creates FileccsG.ico
Creates FileqEYs.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileGUAM.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FilekssU.ico
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates FileQEgg.ico
Creates FileC:\RCX1.tmp
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileC:\RCXA.tmp
Creates FileC:\RCX1F.tmp
Creates FilemIMA.exe
Creates FileC:\RCX13.tmp
Creates FileC:\RCX11.tmp
Creates FileC:\RCX21.tmp
Creates FileuEMi.exe
Creates FilemQMU.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileC:\RCX19.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileC:\RCX1C.tmp
Creates FileaAYC.exe
Creates FileOAAs.ico
Creates FileWEMs.ico
Creates FileC:\RCX1A.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileaIMO.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FileSoYu.ico
Creates FilemsUs.exe
Creates FileC:\RCX8.tmp
Creates FileQMoc.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FileKYUY.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FileqwoK.ico
Creates FileSsEi.ico
Creates FilePIPE\DAV RPC SERVICE
Creates FileWcwo.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FileYEIk.exe
Creates FileC:\RCX16.tmp
Creates FileC:\RCX4.tmp
Creates FileysIa.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates FileocgK.exe
Creates FileKssa.ico
Creates FileuAoM.exe
Creates FileeEsA.ico
Deletes FileecoE.ico
Deletes FileesQI.ico
Deletes FileSokS.exe
Deletes FileyooW.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FileWgYw.ico
Deletes FilewMgk.exe
Deletes FileaQMq.ico
Deletes FileeIEc.exe
Deletes FileMwUG.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FileeMYA.exe
Deletes FileeEYY.exe
Deletes FilemowY.ico
Deletes FileGgEY.exe
Deletes FileaUUK.exe
Deletes FileaAQe.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileqwoY.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FileKAIk.ico
Deletes FilemUEw.ico
Deletes FileqkcO.exe
Deletes FileOkEg.exe
Deletes FileygIC.exe
Deletes FilegkEY.exe
Deletes FileuUkk.exe
Deletes FileqEYs.exe
Deletes FileccsG.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FileGUAM.exe
Deletes FileOAIY.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FilekssU.ico
Deletes FileQEgg.ico
Deletes FileSIYy.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FilemIMA.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FileuEMi.exe
Deletes FilemQMU.exe
Deletes FileWAgU.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FileeoAg.exe
Deletes FileaAYC.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FileOAAs.ico
Deletes FileWEMs.ico
Deletes FileaIMO.ico
Deletes FileyQgK.ico
Deletes FileOAIe.ico
Deletes FileSoYu.ico
Deletes FilemsUs.exe
Deletes FileiEEK.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FileQMoc.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FileKYUY.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FileqwoK.ico
Deletes FileIAsQ.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileSsEi.ico
Deletes FileWcwo.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FileYMAM.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FilesEgu.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FileYEIk.exe
Deletes FileycEa.ico
Deletes Filecgoa.ico
Deletes FileyMse.exe
Deletes FileakoK.ico
Deletes FileysIa.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes FileyQcu.ico
Deletes FileiAwq.exe
Deletes FileocgK.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FileioYi.exe
Deletes FileOcsc.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FileKssa.ico
Deletes FileuAoM.exe
Deletes FileeEsA.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Network Details:

DNSgoogle.com
Type: A
173.194.125.72
DNSgoogle.com
Type: A
173.194.125.73
DNSgoogle.com
Type: A
173.194.125.78
DNSgoogle.com
Type: A
173.194.125.64
DNSgoogle.com
Type: A
173.194.125.65
DNSgoogle.com
Type: A
173.194.125.66
DNSgoogle.com
Type: A
173.194.125.67
DNSgoogle.com
Type: A
173.194.125.68
DNSgoogle.com
Type: A
173.194.125.69
DNSgoogle.com
Type: A
173.194.125.70
DNSgoogle.com
Type: A
173.194.125.71
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 173.194.125.72:80
Flows TCP192.168.1.1:1033 ➝ 173.194.125.72:80
Flows TCP192.168.1.1:1034 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .


Strings
..
t.Wf...
.
..&..

^[:&=#
0/0cAua
08c|d!
08S<<s
0&:f7Kw
0kRfARaM
0<L,M0
0\Qic\
0~Q%wTa
0s9v1za
0ujdAa
0Ve`5t
0.,!^W
1#?@1eH
1(/~35
1[8OCWv%PC
 1]Bij
?:1f_l
1i=wLk
1m3g_f
-1mGBf
1mS0Zi o@!
@1R=EOv
1SsCz$
1{ZX3)
*21D{U
 {2,5J
@26xc"
28It5n
{2IDg:;N"o
#?#2IF
2-+NVa
2p3h^}T
2rcqbP
2taiDu]
2%Z\f9D
37?@Q_
38s<tV
3b|`0D
<?3f75f
3GrB'S
3n'CQ!h
3?	R<)
^3}T5#
41u(D&
(?\&44;+
47%c$s)
4>AmT=V
4MA:zq
4pRY1[
4q'V-n
4 RKg#b
`';4S d9.
4s)dX3H
4si!(a@
4SYGU3
4SYh+3
4T~F1a,
4>zM+4
54pB1R
59F&"=
5kFqG9@
	{5(^mK
5N=7_*
6444bc
6[R~QP
6tf_#p
6uIX>P#
6_x0oH
6X?I}s
6z^fB>
77Sy]{
+ +7Ad
{7#c4s9lT
7g~Da	\
7ROBe2
~\7UQh
7V^ 6ek
7WFSPK
7XZD'K
7Zg>x7
85_X63
.876$[
8CM.z$
=>8dueV
8jJiA1{
.8{L<O
8M%1u)
'8m!Q_
8M+YZO
8O^+s:
8\>RtI
8WIi/aV
9=0A;}
)92^9Tj(
9=N4}n
9oQ%*!
9s9QF0
9u	?n6
.9]Uo9@b
$9]v#3
+9V<+u
9)w2h|
(9yTu4
A<63JN
aaL$~.Zu
AejDaU
A:-,.F
A?@`FD
%Ag{Hsuz
))A/Ht
Ah|WPr
`aIfx'
a#j4xE
|.AJ.Vu
A	kg,3
a;nNX`a
[aNz8=
'Ao$!G:
a's8[z%g=s
-?).a(u5
aW\s|2
b`08-@
B1J"*x
B2'N0j
<B<8or:
-!&bb6BWU
B=bZq3H
b$jLcQ
-bk.9I
blT)se
!'_BmARS
B(>=No
bqs0dr
br@Cr[
br\ ^Fr
b}t^R`
,Bvo."
#>bx#n
BxpB2d
 byQU7
c18S<X}
^C?2N8@
'c4|)h
c4s	Dl
c*5Ao=w
c	8+Gh
CB}E:7
CbG*Cckp
_CD~n`E
C%=.&g
cjKxF7
Cl$R%e
C}M>7w
cM#u!J
.CN01K
C"n<{uN
='&c$S
c|`S0B2wIt
c$syzgZi
;c|T$\
)"cT]8
;cT.wCr}
C(U	?2=
C%v,0F
Cv)9Cv
CVS(1@
'cWmMq
cX+?8#
$Cy;y3H
d3'"95
,D6C%[~
d6I%3]`
D7p]tKK;W
d9< QV
)dDPq<\d
 dGYzV
[DLi*X
d~-\Ly
%D==nI
d-@nP<
d%O>H9,N@h
doje/T=
@D~.pU
\d	TM#
Dt"n/9A=
 `\Dw6
|$DxkGG
e:%1Frku
e@1M"[
e1ty;>
e9fYso>	);?iQYi
ea;HCQ
Eb{/O'
eciY>(j
E?F$ >
e{;`I:
e{;`I:K
>eMI2q*
e		nAp
\]Eo5.G
{e@,#OGb
EO.)P+
e[+Pi:[
eq=*gw
E#{)q! ^R;B
e%:S[*
esTpj~S
eT8MFR@
exfo>i
E[{#y:
[F1Q3g
f4iFLu
}F4uIe
F}5lh;
`f5YX*
f7F`EO
F7fopJ
f!9JQ%
&{f-9/M
FaQ>TA
fbCDAvwn
FBCoR0
fbsFAv
!F\e`4
f][F~0
FF6z:Jt
fI:i=(l
fI*Uw[
fIuzc?z
f*;js)n
.FK0&8
{-f*m@
=Fr%%1
fx8z`|
)[f!!y
f\y'WJbG+
f*Zm\Y
FzS|v\
[|g~&|
g:28S)
G4H(JN
G"c4S	
Gc>Pi{o
\#GE9T~H
G+}f[!
Gf>_8&
gI>;0Bt]
gk9f=d
G?sY'M
G^?TFQ
:#gTW%
G=z7pN0
gZC _S
h14(2`
h7~iS-
=h*bk@
_hIF{?
hKlDrl
HlWz2KA
h?;NfO
Hn"\J(Ge`$
\(h>poi
)Hr	k#
hrvBbK
! htpN
:hW/g9
hxjbMBm2
hY$Bv=
]HZ*B{
"!i1dO
I5eK)\
$i6IiQ
I(c:<c]`
ICT#1t
,IdLZ 
iH/G0R9y
IHV5^A
iI^	[y
%|~{(Iql
(Iqnq_
Is0LW7
i&T9N~
IT!_YD[1
	Iu@);?
iv:(2D"
iV5z8t
`Iv\<8
iZSS%<
):}>'j
-J;_|#
j*2Nd^
j3};f1W
j4p#csX
j,~GC"A
j|PMD?
J		SzZ%]
jtqS7F
j/YfDiP
k\[4D1
"@%K,4YT
K7]\H~
K7Hl\FM
k7.;^J
K}A`_(
kCK/hWB'
k!<Cu`
KD7|N+
KDq3hl[
KG"	FeLt
;KgKGOt
kHXn)W
kLO(->*
kLOk)>
kLO(->*t
,kp(m	g
(k(Ps	
KQ-%Q;
/kr#</
Ks^>-L
ku	p4$
~K(->*w
kwL?jG
KwX(E'
l0SC()7
L=>2hCC
L3+cC9
L/3J|<
L4sY/I
L8?afupx[
 L9b?.
l>a?F<M
Lfq;hm
L}FV4W
"?LhOD
LI3K*A
~lIkB8x
LL[W[@y#}
LnFII%6
lsnbT}
'ltD<0
LZGa32|
:m}#0__J
MB+^au!"
m-\(	C
MC*\* 
me0qX{
m'F0K^>
m F(2q
Mgy]O~
)MI+_f
[(][M\L
MMMMMM333333333333
|(M/N0
MN[\P8
Mn`VBN
-M.qKO
#mt}%f
mT[zyj)
=mZv,1
=mZvl0
=mZvl7
/+?N.@
(]N1X>c
N4sY1t4
N4SYz[
n&;Bok
{N_EJ(
	n-]IA
n(Jg||O%
N$#|k,
nkg]2TO
nk.Z@=
nPBO>3
NTUeK`
Nw'>8sy
%}%+O7
o98@?W
'O@AU@
oBsY)?
%%o*)Fra*s
{.OH4^
Oh'LaRha*EG
@oJJm,
o?kRh1
ola]@\
_*<O$M
OQeI<O
}or,[ao#W.
oR	tb3rh
oSP'!O
o.TuUm(
O^~V{`2
?OvF_l
O!vy# *
OWN{VW-
O:y3(	dX
p50gT!
$:p5#n
P8hsZ0,
%p940'
?p@A[3v_
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
.P}A[i
PATzs!Q
PD'o:2
pe[#XA
P\FMHN
PhLeQN
pi:{~;
&PIF:&p
pK[FMHv
p-mCa!
p=>ny=A
*'@pqD
Pv@@75)
<(P-W4C
pX\FMJ>:
pz$	}&p
!)&$"q;
Q@08?3oMh
q+0kPl
Q/_2`r
.q4mAWN
q4xhVj4
`*]q8F
qblB$f
QBmT#dnD`
qc\4_=
$Qe{dAa
@qj%AE
q*k)BW{
]qk,pn
ql.@XV
Q|n|$ 
";#qn`M='{\B
{}Q'O,
*q	ob(
]/@qR!$9^P
q=-RzxG
Qs>dR 
Qwy!|o
%^,q)y
q;#[Z	`
_r2yQW
R6:~Jo
RbNDi[
,RBoifr
<RdxZhO
Rg*}E9
Rich!4O
R$SI!!
$rUR.5
{>Ry{,I
rZKZY^C
$s)!~@
s?3gv_zN
&S4"!,
S9Brnj
[ S9;P
=sCIv:{2
s/~f$&#
s/~f$&#/
s/~f9&#/y
sFr;A%[
s?/g{_
s[g=j+
S{GnKD
SHgu#i
s>I"d+
$SI.P38
slfL5(
SLMgct
S;_^^M?
sM<IT.A
s	$M.u
sNX`aD:
SP-i#/@a
sq1Mi?
)^sqpJ
~SR	N2uO>
SWAR<C
+Swq,?
*sy\Qt
szu9W0
SZXgU"
T1ZFM?r<rF
T/5#H>
t>}5>W
ta"5"6w
tbsKAv
tb`ZL@
TCz(]/wx
TF[yuv
t(g|#~#
{t(g|#n#
TGx-pT
;/_" tH
!This program cannot be run in DOS mode.
tL4sI)
tL$sy7
TpOXRx
tqG:FaQ
,TQ&,\Z
^tS^[,
Ts8wpv
T)VU'3t
TVuc7[
tYgq{u
$[(u*>
Ua-`wL"
\uCB1r
U-Dh9Y
U-di9y2
uDv0I2}
<uExY/ 
U(}F"H	
U[{#I*
u;!>iD
U~m)GH
'.]u>n
uN;8bF
U-$n9y2
=uo#2P
u(QH?G
UQ}!~I6y
;UR09\
U-tg9Y
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
uvWqe0s
UwK9bl
u{;@Y:
UZNsxV
V@+&~3A
V6xA@g
v7,3%g
v%9&H+
vaemFA
v@A^t V!t+
vcBl#Fc
]:Vc[g
-vcVP>
Vdd+sE
`vf#N%
vgM+:s
vJQ-,spr
VR\)i9o
vS>5Pk
vtjgnQI*7
v~u<}B
W0ahzD?}%
*=w#{\2
W5Fe7S
wB	_*%/
wbyZRL
=w;c\sH
We:5`^
wE^SyK
W(FmZI
w_H;KmhK
WIw*S)"H3
Wj*n]H
.-]w^k
w?N?S<
wo!2"UK
_WO,Xs
WPq@!/@
WPW@6@G
wqhF;b
wq}v~VP
Wr6f*E
	w>r8>c
]W|rQi
WRsCWg
Wt`0s9
[wtfe1
wU%eZ?
WuSMyN
wwwUUU
wwwwwwUUU
{.]WyEH
~_;x,}
{[]\X=
X@3x[aQV
	=X"6-m5^y
$$xbI<
X\:Cq=
xFy^)Jpn>
xGW:wD	
Xk %5G
x+KB^g
/XKgBnRY
x;K<j,
#X>$KUo*3@
|xlC{e\d
*xQQ+}
xSO=xms
xT0b\w
xTr	w$.9
+xUsO'
\xU$w;
xy"=e}(
;y1X,DI
Y-4pEn
Y C3i7
?yeH~-
 <y=Eh
yip-|m
+%$YK<>
yL$sY X
:ymt}qqm
#Y<mzB
y`n(/?
-!{y'Or
Yp()|J
/Y(&t,
yt3h$~
#Yt7UX^
yU#e&ge
Yv'F?}
YvWR_<_
YYl?.D9\r
?{@z	#
Z1 ~*ex
Z1 ~Jux
&Z48yr
Z4X,Kd
z5+ z5
ZAoi=5
zFJ!OW
ZguL$s
ZJ{NJ:{
'Z~MJ(
z:{Nj:
ZR:G{iJl
:ZtzQ>
zU^m}t
~ZVhw/r
?z[>w&03H
>[Z^~z7
Zz~^ju