Analysis Date2014-04-24 18:31:01
MD574284cb01c57990ecee293f47ea229c1
SHA11e3b37eda99ab51b95fc56b230a41ad497323b31

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 4da7f5a0c337035109648da5ed8ef5eb sha1: e05cc5c6ad46876e5a343a063434eb13b1301477 size: 47616
Section.rdata md5: 47b0badc93ee4a9e92790ef02963dc2f sha1: f35b58d5e81ae45ae509b85124ea05f631ee3b44 size: 51200
Section.data md5: c36bce2eead3b9d52f3cd2a5b1df0d77 sha1: 86e6ff7f1e345712fa9e6a8c8a678f21771f702b size: 59904
Section.rsrc md5: 6d3bd68021f04f24f35725dbadb91896 sha1: 51f8662b243935bbc0d5accac973e2f678414384 size: 1024
Section.reloc md5: ca381bf3f57bde49fcb839b70cb0c3e9 sha1: cbbef143f254121bb66e879e44c3c31962ea828a size: 4608
Sectionhhxwknz md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Sectiontxdnbwb md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.text md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Sectionukzqxmj md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Timestamp1996-06-23 18:23:22
VersionLegalCopyright: Advanced Micro Devices, Inc.
FileVersion: 0309
CompanyName: Advanced Micro Devices, Inc.
Comments: CATALYST 9-11
ProductName: CATALYST 9-11
FileDescription: 9-11_legacy_vista32-64_dd_ccc
PackerMicrosoft Visual C++ v6.0
PEhash8e2e8318e20f13f00f4facbb3efbc166da72c205
IMPhash4e8976d981155d112fc65b5f2d6c9e5e
AVavgZbot.OL
AVmcafeePWSZbot-FFZ!74284CB01C57
AVaviraTR/Crypt.ZPACK.Gen
AVclamavWin.Trojan.Zbot-8883

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\~TM1.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\~TM2.tmp
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\~TM1.tmp
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\~TM2.tmp

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

Creates Mutex{37FFFC62-FE56-017C-F492-53D69B021D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D699A61D45}
Creates Mutex{37FFF72F-FE56-017C-F492-53D699961D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D697E21D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D695A61D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D695AA1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D69B721D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D69A061D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D696DA1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D6979A1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D69A621D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D6971E1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D698FE1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D69B421D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D69C8A1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D698CE1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D69AC21D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D699BA1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D69D021D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D69ACE1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D6981A1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D697CA1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D69BBA1D45}
Creates Mutex{37FFFC62-FE56-017C-F492-53D6980E1D45}

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit ➝
C:\WINDOWS\system32\userinit.exe,,C:\Program Files\huettqja\pbvjeqsq.exe
Creates FileC:\Program Files\huettqja\pbvjeqsq.exe
Creates File\Device\Afd\AsyncConnectHlp
Creates FileC:\Program Files\huettqja\px3.tmp
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Start Menu\Programs\Startup\pbvjeqsq.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\qcvbfpbp.log
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\~TM4.tmp
Deletes FileC:\Program Files\huettqja\px3.tmp
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\~TM4.tmp
Creates Mutex{37FFF72F-FE56-017C-F492-53D69BBA1D45}
Creates Mutex{37FFEB21-FE56-017C-F492-53D695A61D45}

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1201 ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1201 ➝
NULL
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_20130508_125854937.html
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Reader9\Setup.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates Mutex{37FFF8CE-FE56-017C-F492-53D695A61D45}
Creates Mutex{37FFF72F-FE56-017C-F492-53D69C8A1D45}

Process
↳ Pid 500

Process
↳ \??\C:\WINDOWS\system32\csrss.exe

Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}
Creates Mutex{37FFF72F-FE56-017C-F492-53D697CA1D45}

Process
↳ \??\C:\WINDOWS\system32\winlogon.exe

Creates Mutex{37FFF72F-FE56-017C-F492-53D697E21D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ C:\WINDOWS\system32\services.exe

Creates Mutex{37FFF72F-FE56-017C-F492-53D6980E1D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ C:\WINDOWS\system32\lsass.exe

Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Creates FileUNC\WORKGROUP*\MAILSLOT\NET\NETLOGON
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}
Creates Mutex{37FFF72F-FE56-017C-F492-53D6981A1D45}
Winsock DNS192.168.1.1

Process
↳ C:\WINDOWS\system32\svchost.exe

Creates Mutex{37FFF72F-FE56-017C-F492-53D698CE1D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ C:\WINDOWS\system32\svchost.exe

Creates Mutex{37FFF72F-FE56-017C-F492-53D698FE1D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ C:\WINDOWS\System32\svchost.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\List of event-active namespaces ➝
NULL
Creates FileC:\WINDOWS\system32\WBEM\Repository\$WinMgmt.CFG
Creates Mutex{37FFF72F-FE56-017C-F492-53D699A61D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ C:\WINDOWS\system32\svchost.exe

Creates Mutex{37FFF72F-FE56-017C-F492-53D69A061D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ C:\WINDOWS\system32\svchost.exe

Creates Mutex{37FFF72F-FE56-017C-F492-53D69A621D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ C:\WINDOWS\system32\spoolsv.exe

RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝
7
RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝
C:\WINDOWS\System32\spool\PRINTERS\\x00
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}
Creates Mutex{37FFF72F-FE56-017C-F492-53D69AC21D45}

Process
↳ C:\WINDOWS\System32\alg.exe

Creates Mutex{37FFF72F-FE56-017C-F492-53D69D021D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ C:\WINDOWS\Explorer.EXE

Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}
Creates Mutex{37FFF72F-FE56-017C-F492-53D6971E1D45}

Process
↳ C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

Creates Mutex{37FFF72F-FE56-017C-F492-53D699BA1D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ C:\WINDOWS\system32\svchost.exe

Creates Mutex{37FFF72F-FE56-017C-F492-53D69B021D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Process
↳ Pid 1320

Process
↳ C:\WINDOWS\System32\rundll32.exe

Creates FilePIPE\lsarpc
Creates Mutex{37FFF72F-FE56-017C-F492-53D69B421D45}
Creates Mutex{37FFF118-FE56-017C-F492-53D695A61D45}

Network Details:

DNSawecerybtuitbyatr.com
Type: A
109.74.196.143
DNSgoogle.com
Type: A
62.253.3.84
DNSgoogle.com
Type: A
62.253.3.93
DNSgoogle.com
Type: A
62.253.3.99
DNSgoogle.com
Type: A
62.253.3.98
DNSgoogle.com
Type: A
62.253.3.103
DNSgoogle.com
Type: A
62.253.3.118
DNSgoogle.com
Type: A
62.253.3.94
DNSgoogle.com
Type: A
62.253.3.88
DNSgoogle.com
Type: A
62.253.3.109
DNSgoogle.com
Type: A
62.253.3.123
DNSgoogle.com
Type: A
62.253.3.89
DNSgoogle.com
Type: A
62.253.3.119
DNSgoogle.com
Type: A
62.253.3.104
DNSgoogle.com
Type: A
62.253.3.113
DNSgoogle.com
Type: A
62.253.3.108
DNSgoogle.com
Type: A
62.253.3.114
DNSawecerybtuitbyatr.com
Type: A
109.74.196.143
DNSqwevrbyitntbyjdtyhvsdtrhr.com
Type: A
198.74.50.135
Flows TCP192.168.1.1:1033 ➝ 109.74.196.143:443
Flows TCP192.168.1.1:1034 ➝ 62.253.3.84:80
Flows TCP192.168.1.1:1035 ➝ 109.74.196.143:443
Flows TCP192.168.1.1:1036 ➝ 198.74.50.135:443

Raw Pcap

Strings
...!
\
.
 ..|tld\....J
000004E4
0309
9-11_legacy_vista32-64_dd_ccc
Advanced Micro Devices, Inc.
CATALYST 9-11
Comments
CompanyName
FileDescription
FileVersion
LegalCopyright
ProductName
StringFileInfo
Translation
VarFileInfo
VS_VERSION_INFO
`     
^    =
~$    
>     
>%>@>\>
    =*<
     >
     /
     '
     )
     [
     @]	&>'`
     %]
     	
    '<
    {#.
-    #
;";/;\;
:    )
:,;;;{;
.     
'     
'     >
\<    
\     
+     {
00G0a0
&0=0W0`0
011_1~1
'040c0s0
	0?BjV.
    0|EP
.0H0V0c0i0t0
0ham     
!`0h_g
0kq"{k#~]
$0L0p0
:0;M;R;
0OL[v,(
;0;P;^;q;
~$     0q
0!q#W;
0w_f_O
0    $yT^
     1
10@0r0
101?1J1o1
111H1p1
1'1A1]1
1!1I1M1_1
1,1K1x1
1'1K1X1a1
1"222D2n2
152:2K2{2
152E2j2n2
161?1o1
1H1T1q1
;1;I;k;v;
1S    >
/   1U
1Z6>AhZ)
1z`SK0~
$2{     
20A0t0
212>2^2
2%2<2^2
2)2=2K2\2
2)282b2
2;2E2^2u2
2-2L2~2
2&3,3A3c3h3}3
2%3P3u3y3
< <2<P<
2s7   
2=%uhRT
3"3&373J3Y3
333D3d3
3)3T3g3
3    |3x
3)4?4T4
3>4H4{4
3@4h4s4
3;4y4~4
3_6q{r
3n{~'T
    3x
|}    4
404>4W4q4
405;5B5
42E	1F
4!4?4t4
444U4f4
4#474_4
4	545y5
4%5/565H5
4 5(5t5
4'5P5W5v5
4-5T5_5
495D5`5
?#?4?d?
>	?!?4?H?^?s?
+4   r
|5    
     5
5    )
505k5u5
#5:0[XE
:/55*2
5(595@5[5a5r5
5)5C5d5
5/696x6
5    A
5A5Y5}5
<5<a<l<
=5=G=}=
5H5R5n5
5M)M>>5
5   NL
'5PDl|
5q1RZC
*+5+v_n
<*=6=`=
6=    :
6    [
606:6^6e6}6
636;6\6
646?6i6w6
6*64686a6j6
6$6=6}6
6%6C6G6M6
677=7^7
`6h     
6    k
6K6r6~6
6XGLW/
     7$
{)7,0?
727]7e7
748;8z8
7!707;7S7\7m7
7&7<7N7
7%7I7O7w7
7%8\8b8
7>8`8o8
7>8G8^8
7&8Y8g8
7dUK]v>8
    7E
?7?O?v?
7     P
$    8
8    +
8*8f8{8
8<8f8t8
8&969l9
8 9%9?9
8!9:9J9c9
8?9O9p9
>8?b?g?
8D8I8c8
8H8_8c8r8
8|PCwX
:8?Z.oFq
    9'
9":3:A:t:z:
9%:3:]:o:
9*!5B%
989H9k9
999>9Q9
9#9;9X9
9=9e9q9
9%9k9}9
9*9X9~9
=#=9=a=p=
9):A:^:p:
?9?J?o?
9#:N:c:
"9nDEQi
9 :&:p:{:
=	>;>a>
     a
/     a
=   ~A
:/;A;};
A   9q
ABaWb;G=
abnormal program termination
_a,bq/
A:FIeQj
     ajk}
a_"PLP
a   {X
Ax}.fz`
	&b..	
b    ,
B   18sO&	
=  B'-%2
B5   /
bB!$]raOg
    bCi
    bot
%Bs<D3
b.#<Sj
    =b_tMk
b    %z
c     ~
c    )&
 c?27]hVT
C8b|@h 
   c9qE2
CallNextHookEx
cB    
cb2G2>
CheckDlgButton
CheckMenuRadioItem
;:<C<n<
CoInitialize
CoSuspendClassObjects
CoUninitialize
c*P(rK
CreateFileA
CreateProcessA
[CWJIn
CWZM]kg
;-<c<x<
CXnZHW
    |d
     d
;=<     @D
;$<D<~<
;D;];|;
!D     
D     
d<"3al.H
@.data
   "Db
DeferWindowPos
DeleteCriticalSection
DestroyIcon
d[gU|D
DispatchMessageW
    dJEV[
DOMAIN error
DSUVWh
^(/     d?t
   dTL
~ d'     Y
<,=d=z=
    e.
e     
     ^E
E    $
Ee     
Efucokakamux
eG    
E   H{
=E=I=M=^=
eJ     '
EndPaint
EnterCriticalSection
    e}o
eR)QZ}
es    
>'?E?S?b?
    eU
ExitProcess
{EXVqm
}Ez    
     F@
,   F~
F]     
F0    
`F\%78J^e
=F$)90
fgXtm<
FindFirstFileW
FindNextFileW
`F!L'	
- floating point not loaded
`F,   ]N
FOO')]l+
    fP
?F?P?^?l?
F$q$    =3
FreeEnvironmentStringsA
FreeEnvironmentStringsW
     fSq'
.\F<|v
fw6P~m
f}}!	wJ
g     
     G
.g0B~6
g@A"]H
GC     
Gd    
GD7\z(b
GDertm
GetACP
GetActiveWindow
GetClassNameA
GetCommandLineA
GetCPInfo
GetCurrentProcess
GetEnvironmentStrings
GetEnvironmentStringsW
GetEnvironmentVariableA
GetFileType
GetIconInfo
GetLastActivePopup
GetLocalTime
GetModuleFileNameA
GetModuleHandleA
GetOEMCP
GetProcAddress
GetProfileStringW
GetScrollPos
GetShortPathNameA
GetStartupInfoA
GetStdHandle
GetStringTypeA
GetStringTypeW
GetVersion
GetVolumeInformationA
;|G~<L
gnPY@oO|
gwH&R    
    H|
H0I4HlWi
<# +h\0S
h~BdF:
HDC5-0
>!>H>d>k>
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
hhxwknz
Hi,o'~
h?~mfY
H^W   
     i
    i$
     I
I-0 _Z:
     i4z
     $I5
\(`i5,53>
I9KzV-
    IJ
_+IM+X
InflateRect
InitializeCriticalSection
InsertMenuItemW
IntersectRect
IsDialogMessageW
IsWindowEnabled
,IV.\i
=j    
   ~j>
    .j
]j     
}(!j=     
     J
_{    J
J     
J    /
J'   /
|&J%1q
j9TFq`
*J{(Br
JH%    
JHP   Y
j=Jkfr
jL$`@O
j<lqITM
j!   T
JU`/ps
Jz-K^g2
k     
k)    
K    $
   KBP
KERNEL32.dll
^kGV/m
~K    i
:/:K:r:
(KvFrw
>'&l    
l^   : 
     L
l0     
     L1<C
$l2QV]ZEK%
LbwCn6
     {Lc
LCMapStringA
LCMapStringW
LoadLibraryA
>.?l?t?
l     Z
     M
M     "
m4   u
.m8uwA
MapVirtualKeyA
M~!<aZu
m!Bb<16q5
MessageBoxA
MF^9K@^
MF^iRL^
MF^iRM^
MF^iRP^
MF^Rich
miAB?8W1
Microsoft Visual C++ Runtime Library
MN     
|moqAY-
;M;Q;o;
Mr8dbReq
MultiByteToWideChar
     	MUN
	m     z(l
= >(>n>|>
     n
     (N
   }N!!
./N=+~
Nb}`#x	
@n+lgr
    No5
- not enough space for arguments
- not enough space for environment
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
n     u.
[ NV>ej
^n?W}c
   NYAYn'	{
    =o
    O.*
O     ~
o    1
|O'1~sz
    O'6/f
/ob_Q\E
ODI:YbJH
="=&=,=O=h=|=
O!"IJk'7
_     o?kV
ole32.dll
OleCreate
OleInitialize
OleUninitialize
+Os=wpV
oW    
     p
     @p
;#<:<p<
p     
P5Be   
    P7h
@P:7x'
*p8     
pc!/   
    pd
P!hRC/
P/Kub=
Pn+c0v!b
PostQuitMessage
PQ[-7Q
p   r0!
pR)kmZ
Program: 
<program name unknown>
ps    
P.sQdJ
- pure virtual function call
P    v\
     px
=(>,>P>X>i>q>
-    q
q,'    
   Q_/
?*Q   
'(.#\Q,
	Q    
}    Q9@v
Q A   +ET
!q(aUD
QBu:</
Q    e
qf9K%v
QF,S-/
,    qJ
q,Jk(;T
q/?V~M
/     r~
r    ?
<?<R<^<
>R    
     R8
;r;98T
|}~RAh}
   RBw
R    c
`.rdata
rE    
Re>9   
RegisterHotKey
@.reloc
RemoveDirectoryA
RemoveDirectoryW
   RE?S;
RiSDw}
^`rMdv
}R"NUb     
RtlUnwind
R[Tt2M
runtime error 
Runtime Error!
=$>R>W>n>
|&R+X}
R    z
;%;S;^;
S    "
s4"z	.
s"A}Rv
SB;T@y
S|{<BU
SendMessageTimeoutA
SetCursor
SetEvent
SetFileAttributesA
SetHandleCount
SetParent
SetWindowTextA
sf$Vl!
SING error
    	>SK
SK#    {H
sKN    
S    "'N
sP     }
SR--u>Jo
SS@SSPVSS
StgCreateDocfile
+    sw
;%;=;S;_;w;
SX    
SXErG.
SX>[zHB
     t
@#    t
t,    
t.    
     T
    +T
_t`1tz
T3_2owc$R
t668RE
T8    
T$<B^A
TerminateProcess
tg	C	$
!This program cannot be run in DOS mode.
tK     
TLOSS error
TlsAlloc
TlsGetValue
~~Tq}@
    !tr
TranslateMessage
t#SSUP
t.;t$$t(
   tu/+
T    V
t$$VSS
TwX~D8
txdnbwb
T^z    
    +_U
@[U     
U|     
u`<4}h[
Ub~a0/
u     )C%
=U=e=j=
U* f..
uG@.Pu
Ukaqovujyqucocu
ukzqxmj
=$>U>l>
Uladydes
- unable to initialize heap
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
UnhandledExceptionFilter
Unikikawuqy
@@uR'V
user32.dll
USER32.dll
)&uvft%!
uz8Olg
    :v
v     
+V    
   ^v0k
V91OY#
VC20XC00U
vI4   
|*vi5f*;
VirtualAlloc
VirtualFree
V$MX	n*
*)Voc.
vu    
v    Ux
    'w
~     W
     W
W]    
    w13
W2B'FT"
W8aj$$|r
WaitForSingleObject
w$bU m
W	c2\d
wd%:N	h
w('ECV
:@:W:f:
WF   MA
WideCharToMultiByte
W|L\m#D
w     P
wR    
WR    
WriteFile
WS2_32.dll
'wx7q	
<,=W=y=
W?y-^93
~wz~}(H
x~    
?     X
X2     G
.X6    
X8i<1l
xDP|;    N
Xegabenevukuw
xM     
    |XP
X     Q
xs    
x"	?sx
X	y*4L
xy;T     
    XzF+
y     <{
>&?<?Y?
=y_`^1
y2`    
Y    2
+Y5iqmt
yAY"M'/
?%Y:Er-
YEyB9g
:';/;Y;m;
y@    R
;*<Y<x<
_^][YY
;&;Y;z;
=$>_>z>
[    ^>z
/'Z8>S
Zazitiwebymiveq
     z<E
zN&$.%
	ZQUg$8>