Analysis Date2015-01-14 11:57:43
MD5445cf7e4be095ed2df4a6c97d331d903
SHA125ad8e583b5531ae953214b3258a4ba2c1117e36

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhash974bc9441def75c8e71476d423c97867b2f9edff
IMPhash
AV360 Safeno_virus
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)VirLock-A:Win32:VirLock-A
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)Ransom.VirLock.A2
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99f1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!445CF7E4BE09
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecW32.Ransomlock.AO!inf
AVTrend MicroPE_FINALDO.F
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\UisIQYgc.bat
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\UisIQYgc.bat
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Creates FilePIPE\wkssvc
Creates Process"C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates Mutex_SHuassist.mtx
Creates MutexShell.CMruPidlList

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FilewMge.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FilewUwi.ico
Creates FileC:\RCX15.tmp
Creates FilesAgU.exe
Creates FileC:\RCX14.tmp
Creates FileC:\RCX2.tmp
Creates FileMwwg.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FilewgsU.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FileYQMW.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FilekwcM.ico
Creates FilewMka.ico
Creates FilecEgc.ico
Creates FileAYAi.exe
Creates FileC:\RCXF.tmp
Creates FileC:\RCX12.tmp
Creates FileoAAG.ico
Creates Filesgos.ico
Creates FileC:\RCX18.tmp
Creates FileIYom.exe
Creates FilemgYU.ico
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileEcEc.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileC:\RCXC.tmp
Creates FilesAAQ.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileC:\RCX9.tmp
Creates FileEQAk.exe
Creates FileEgow.exe
Creates FileoYwC.exe
Creates FilePIPE\wkssvc
Creates FileQYAe.ico
Creates FileAcQW.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileEkga.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates Fileccko.exe
Creates FileYcgy.exe
Creates FileC:\RCX1D.tmp
Creates FileCIYu.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileQAAa.exe
Creates FileC:\RCX17.tmp
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FilecUUO.ico
Creates FileIsIi.exe
Creates FileqYYu.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FilegYsu.exe
Creates FileYsEG.ico
Creates FileMwAs.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FilegEcK.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileUUUY.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\RCX3.tmp
Creates FileC:\RCX20.tmp
Creates FilewokS.ico
Creates FileccME.ico
Creates FileC:\RCXB.tmp
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FilecwMm.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileAgAo.ico
Creates FilegIoK.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FileEowK.ico
Creates FilecAYA.exe
Creates FileDYIK.exe
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileAoAO.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates FileUocg.ico
Creates FileEkMo.exe
Creates FileC:\RCX1.tmp
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileC:\RCXA.tmp
Creates FileC:\RCX1F.tmp
Creates FilewYEe.exe
Creates FileQoIO.exe
Creates FileC:\RCX13.tmp
Creates FileC:\RCX11.tmp
Creates FileC:\RCX21.tmp
Creates Filekkkg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileC:\RCX19.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileC:\RCX1C.tmp
Creates FilegoEO.ico
Creates FileoYUa.ico
Creates FilegwYy.ico
Creates FileUkgE.exe
Creates FileC:\RCX1A.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileUoUc.ico
Creates FilewMIC.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FilesAsa.ico
Creates FileoMwK.exe
Creates FileC:\RCX8.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FileMkAE.exe
Creates FilecQIo.exe
Creates FileYUsA.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FileUEwY.ico
Creates FileQoEG.ico
Creates FilePIPE\DAV RPC SERVICE
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FileIswa.exe
Creates FileC:\RCX16.tmp
Creates FilegQIW.exe
Creates FileoAAW.exe
Creates FiledQkk.ico
Creates FileC:\RCX4.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates FilewEIy.exe
Deletes FileMwAs.ico
Deletes FilewMge.exe
Deletes FilegEcK.exe
Deletes FilewUwi.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FileUUUY.exe
Deletes FilesAgU.exe
Deletes FileMwwg.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FilewgsU.exe
Deletes FilewokS.ico
Deletes FileYQMW.ico
Deletes FileccME.ico
Deletes FilekwcM.ico
Deletes FilewMka.ico
Deletes FilecwMm.ico
Deletes FilecEgc.ico
Deletes FileAYAi.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FileAgAo.ico
Deletes FileoAAG.ico
Deletes FilegIoK.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes Filesgos.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FileEowK.ico
Deletes FileDYIK.exe
Deletes FilecAYA.exe
Deletes FileAoAO.ico
Deletes FileEkMo.exe
Deletes FileUocg.ico
Deletes FileIYom.exe
Deletes FilemgYU.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FilewYEe.exe
Deletes FileEcEc.exe
Deletes FileQoIO.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes Filekkkg.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FilesAAQ.ico
Deletes FilegoEO.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FileoYUa.ico
Deletes FilegwYy.ico
Deletes FileEQAk.exe
Deletes FileUkgE.exe
Deletes FileUoUc.ico
Deletes FileEgow.exe
Deletes FileoYwC.exe
Deletes FilewMIC.ico
Deletes FilesAsa.ico
Deletes FileQYAe.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FileoMwK.exe
Deletes FileMkAE.exe
Deletes FileAcQW.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FilecQIo.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FileYUsA.ico
Deletes FileEkga.ico
Deletes Fileccko.exe
Deletes FileUEwY.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileYcgy.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FileQoEG.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FileCIYu.exe
Deletes FileIswa.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FileQAAa.exe
Deletes FilegQIW.exe
Deletes FileoAAW.exe
Deletes FiledQkk.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes FilecUUO.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FileIsIi.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FileqYYu.exe
Deletes FilegYsu.exe
Deletes FilewEIy.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileYsEG.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Network Details:

DNSgoogle.com
Type: A
173.194.125.71
DNSgoogle.com
Type: A
173.194.125.70
DNSgoogle.com
Type: A
173.194.125.69
DNSgoogle.com
Type: A
173.194.125.68
DNSgoogle.com
Type: A
173.194.125.67
DNSgoogle.com
Type: A
173.194.125.66
DNSgoogle.com
Type: A
173.194.125.65
DNSgoogle.com
Type: A
173.194.125.64
DNSgoogle.com
Type: A
173.194.125.78
DNSgoogle.com
Type: A
173.194.125.73
DNSgoogle.com
Type: A
173.194.125.72
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 173.194.125.71:80
Flows TCP192.168.1.1:1033 ➝ 173.194.125.71:80
Flows TCP192.168.1.1:1034 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .


Strings
.5
K
..
...
.?6.
Qtt....j
.
G
9}
.
.
x...
:
.
,#/$-&
0/6f~vc`/
06&j&u9
06&U8t
,0^!931
+0>)ch
+\0:)E
=0H{h'
0l(XjIF
0?o-Fg
%=*0=V
0<Z/uy}/
_1[(/-
,"1\<;
13I[-4
13I[-8
:1DG(a
1	"G/5
1H[*j	
\1i)_6
1{jg5!\
^1-{\qj
1Tmquu
^1u,*b<"ET
1-#!w5f#
1/x;~"
1'X5>Z
1Z/$vb
2+01a?-9;
]2@		1
 ?21;y
[2-{[2mnDs*
#/29'9#
2ax)JE
2\az>T
2J/pRK
/;^2-n^
2o1&$8
2](Wt[
}}:2YJ
?38{238
3B2&5W
3cYxLfu
^3EQLCpPz#Cu
'3/I96
3iG9}*
3j(Ehsp^
3j(Ehsp\
3jhEhsp
3ji[h3n_
3jiL3hj
3jiO3h
3LO~=)
<3NCb&D*
3:ovZo
$/3]PXc
3~q9ga
3UdH`2<
3U}fpnk
:3X)GT
3Xht6(
'3xm138p
3"X:TaO
4`d~~e
4peoeh
4SW3?{
4Tlyb':-
|.4ty~/
4uA:81,!7
|4\`&w
~4wS6E
4$zYV0
5a5@M6K
5`d;(V-1
5!D:Yk-\
5*'.Fh
5j{{&3M>'i3
5JUu?+^
5lzxk+3B
*5N;uA
'5rHwVy&0
5T@:6?
<&5tFy
5{$>U|
5,V7]h
5W9|J<T:
:5wyt/
/6>2w:
6H;%c]
%~6i(.d
6o6x-PHL)a
6RB*?F
{@6rjEJ
6u,"84/
6@WX[[Lx
6>XBXs
6zNKY?M
6zNKY?O
6zTKY?
74+"%Cv
75YtU`[
77J,A!
7f&x l(
.7L]Qof
7m%_v-;
7oYyw2(
7-;\q**
~7q{o5
(7t&8(/oD
7u5J=|
7Uc<JX
7;VB@!\
:#7x2!
7_XOv:
8A;p	:C
8eaKc.bj
8&`h<A
8k+3Wn
8ms7Ebm
>8t)LV
%>8W /
*/8Z/*
9b5Z/_M$
>9DHSg
9_feh=
=9G_w	
9ho\bx
9NVPe`
(9SV$[b
{9t5r!
9#ud7l
@/9X7I
A4O(L]bnz
A/$8&w
&+aEgC
,afD:B[V
aFn?x^
A $\}h
Ai:~d|}
a(Iv*n
#ak]s-
a~o<oiu^7
AQx1SH
aTA>kj
au]GG!AL
"AuRPHSb
#aVpk`
Av|)ZQ.F
&awlH[
B-0VJe
b)[1j.]h
B~'2p-,
B/2u&S22
<b-5r,
B~6pF.g
_#%}B8
B|}8QO9F_
bbD,9W
	<b*bj,
BD++B5r
b&E-A^
+beANb
;b~EM,
.&BKD5
bssAZ:
BuuJ=u,(4WuJ
bVERc*
B~Wvrw
~b-} z
b-zW$~
c1?GFlC
}~C90`
+cbr	cz
Cbx&rS
CD#c/1
Cd"L2x
CFb~\*
CgP}peiB.
C_:)$kK
c{K#mm
clj_qh)\
cm*^1-
%cO4^9
CO.a<V
cpTh,]
c!"r7j
CW`+FA
c$~YDy.
cyIQuR
 c^{Y$m
;d/7;$L
^D81_k
d~b8b/j
]D/c~k
>Dd/$<
DdB$U77A;5
;_ddhB
dDmPoL
/Dh'Y8<,pK
dOb[/5
dOpm%F
do]uy?
dO?^@ V
Dp}V6P
D]%:rY
dRYS[4!
du{G~5'
d}WIp	
d*:yT/
Dz5Z_0
?d&_+zNY
,^e6o1e*
e $6wB
E8GF><*
"<'E8v
eBa0]h
EBE-|dp
EC)>\a
E;>Cn|j
e dh4E
e d|r>w
eeUu\-
E,evz.
-e~]F8
E*FbE~
eF	e(C
Efe<>E
e*}Gdp;E
Eg}p[h3f_
e^h %=
&==Ehsp
Ei 1i0%
ej89Z/
ej]fd*
eJ=ZuJ
EK,;wf
]ElBwU
E#=Lna
e"Lqs7
'eLV99
e<;O2-
e>Q6O-
#Eqjp_
eqvwG\
exo-tx
E*]zd'
f3O+P#
$f7<w{
*f8Z/*
fb$`v"
F'cqC1
FdU6"w
fg|7B7/?
'Fh9~B
f~)irl
F%J1](
f*JC:9
=f{Kpo
 f.(|L
fqB`>[
F>ud(c
F)U:kwZ
fw'(&w
_	{Fxu
%FZ/5W
g2q}IhV}I
G3uwBO
_g$7^x
]g;a9-3
GDPu`&~
-|G!?Dq
GDs\*o
g<E	.O
'?[&gf
g]LM!`
G[p;<_
-gRd%Z
gT4I98
g>TVci
GV?:a&p
*"g(W#
g,W!;]8{
%GXEpKw7(.
g	$Xpb 7m
gYAx<7
H^6~L;3!
,~H7]h
"H86B	A"D.
=]{h-e
hE6kp]h3
hg|),&
hG<\|=
*hi:bJ0uF
h[j	9Z/
+HjeT\UD	
Hj[J[>
hJs;}4_
HjyKz4
)HlIXZGsg
hn{76@
"&HNqb
hO[r>,
]hpScN
h*[r*n_
-H[@=S
 \hsf[qlj
,hSK/dfV't
Hs%>m_
hSmUSG(
H$v:9l
H|WV'"
hyD:\/ &
h-yL;W
#+I';~
(I*19Z/
_>i5	l
i[&6e	-
	-i7Ym
.i9DY5
I9e7{-
IDcx)&
i d(_stF
ig|),&
IGdD	&
Igw+[p
</I_j~
 ik^q-
Ip;:_ueh
){Iqjj
){Iqjj\gz%_
IQM2uN
ir4z8N
$I	sw&
'I	Sw&
iTe)Sc	e-
;=iubjLm
,IU}DJN
'I	vw&
+:]~IY>
J{03O%W
J0!M=LE
)j_1h+
#`j[2m)R
J383;/
J?3ut$
([j.9Z/
JcS5y$~
!J,.E3
Jf\2 [S
J*&G"K
;jiYhs
j MsMz
jnHv`F"
JOv3b{/5
j`$\q8
j+_r).
J>rcj,
/J"rR1
js~RB'Yw/L
jw/p7)
`JX4>BK
-JZ8:.m
JZj_b$>
J=([Zo
#*``?K
)k0gp7q
K3bwQ#x
K%6:Al
*(K6h*V
"k([*)9Z/
'Ka5([
|Ka?,a
K}a>}s
K.c({[
K_)cHJSmA
'kdEXW
KeVe+j
K=EWzL
kg0~gp
K;GwG_
khEqjp
'K!I9~
:KighZ*
K I`V>
K}:sas8ip
k+s-+N
k+s*+N
k?)s)y
K# td*%`
ktJT[/
kTQns.]
K&uo<|
kV+)6A
L0'S'X
L.2g"/
l8Y-)(
lCbTI,
+LdniT`
leX'ym	
Lh#DX(
~LI.&I
ljE2ip
:LjQ>,
L'jv$1
LKJ\h{g>
- lM9m
"-;Lsh
<Lslj]h3
LSS1#"@
_] L	w
>M7cZ(
m8Ms>a
M92Iz!2\
m]c5y\
^ ?MCD
MCpZPu
#mCtP<"Z
`mdh[1
MHN6]h
]M\I:r
MMMMMM333333333333
mN?O:"
Mq8g|}.
MQ[LfC
ms"{f 
m/sHapKe
mU<<~>
M*;U)J}1
M"up~qnS
mV#y#TR
!,M%w]
&MX-h2
!m:x^P:8pl:
Mxu_aX
My`5)2
Mzty?u
n'1N'V
N26;<-
N2zZO,
/N5120
/N512Xq
n5p/]h
=n\8_=j
<'&n8v/
N|9dZ|
nb>L9l
_~nBp\
 _nd<`
Nf*98:
nfg4 c>}
nGAfdh
n]gY_6
Ni<_0j
!"*\Nkb
!"*\Nkm
nKP5d 
n@*_M:
NN~Ncm
nNNgTt
/n|pPw
/.Nq&@@	
)nQqg2
+'	.nS@I
NvrsPC
n`Xr'u
nY~	/8
O${$`)
o1i0>Ez
o)4>pO
O7+7x)
\@O-a.g$C
OAs}0wa
o{B+ed
"oB>]h
?oB~Z9
_ocQ# 
oE*9)o`
~o{E|M[
O`\GYss 
Oh:A$cn
Oi;]43
-ojZE	n
ojZE	n
/O	KD.
OKXJ<h|4
On"[C*4
o+n.Ui,=Y
o`{$ o
o$<O75
-oO;pp
O	=%Q]p
o_r-{\
oT2IaI
oT2Ka	
oT2KaI`
oT2K!I`
oTFS}5 
Ou4Y X
? oubc
o('%[(%W
(o[wcp
owJDpq
OXXFTeta
OYQ"V@
!oZ`yZ
!p55$d
p9d+vjC
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
P`'a*{l
Pd|H$5
pFGhBg
pmcm0,
p?>NTT
P-p>PRW]R
pv|~%5F
=p&w*=^[
p(Z/59Z/
pz.Ehsp
pz.EhspRy
p*.Zh3
pZ	NMt
p&Z/u,
p<Z/u9|/
p&Z/uo
&_Q%|(
q1i]nV"
q\2hi]
Q483W4x<W4xVW4
~Q.6zQKY?>#
!q%d.d
_)Q"e6[
Q&\eE@
qeUmbi
/Qh*1"xz'
qi1te"
Q=jIf~
QK(,dm
)Q$|L]
+[q*n[
qNiH$9
q-?o4\
qpIn._
|qqu:E
q;	TvP*
!{R2,;^
#R5l#U
R9i,t4B
RadDKaQ
R%^bOh
RcVq?l
R d.\`
Rich!4O
([rijS
rjAc65
rm)D3!
rm)L3)m
`*[r*nE
);[r*nM
?Ro+gd
roJgDu\
%^Ro_s
?R:?>	#P
R|:_Rc
$#?Rs?X
+rT7=r
r}@([(u
rv}{qp
+RZ/5C
+RZ/5F
Rz@fB&
-S,&(!(
.s_&_0Z
s]2H!K
+S-2)M
s\8T@8
S!/8]Y
";S:afO
sd8w_"Z
sF.;~%
SGdp;{
$SkbUj
s+>k#ZC.)
\sm)_h
s?o$(n&w
~Spd9D8I
S!T@h(s
sTmf)b
stssm;Rj
[	SWUI
Sz9 |z
/t!)1D#`
.T2Iaw
:t2!VC"
'T8B&h
Tap=W~
tE~Kx]9N
*]t}\h
!This program cannot be run in DOS mode.
T*hK'9'
</tK_2
TK\iDp
TldI>Au
toU!D/
to]uy?
^>TP`3
]t($U5_
T"#\V8/
t=WR|d1
U-0jK/
U"5xih}@
![uCiX
&u),$d
+<^/uF
+|%/uF
uGdp;$
uGdp;7
ui7_slw_3kw_
\/uJ!d
uL(*q%ON
UnKzX([*
uNxoy\
UO(Fd/
UOfP6>
upYt4~
U[{R\S
utzKu6>
UuGdp;
@-uuJ=.
uuJ=uuJ=uuJ=uuJ=.
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
uY>mhv
`|*+V-
)@-v0<
@v(4hgy"Z
V`4N|HCe
`V]5)$
/"v5EVP
$<v,5F
V6-@B|]
$]%})vA
vce[Q,
vC	,eY
VDdY*\ccu
v<E*O5YH
V.fFI^"N*}
?.]V:gxrc
v!&]h3
vihDFB
Vi/i?o$l
v+>kvZB.+
v+>k#ZW.)
VNiGDQ
V):"ofa-
@<v/:P]
VpzuN]2
VQnIdo
#v`UXa
_v"/XAD`
vzp^hsa
vz%_v-;
w1'h?X)
w*1L$>
w3Z{PJ
w>]84/j
Wa:\0 
wc<tb0fv
]!+Wd:
_wdhUQt
wD  w5
[,WhZ5Y
WI@f~ 
wikW2-{\
WK3!u.g
wLH3f\
W/#nZ(Z-
w@;}O;
wo_\6/
Wp;)_\
+Wq*{\
W~Q2/ 
?.\wQ8
W{!;^sj
,.w,V4
wwwUUU
wwwwwwUUU
wy!k<hK
wz%_v-;
x7Omi#
]:x9\:
x9fMLo
xau{G~5'
x?*D31
!x/d&f
XDJWsp
]x<}dK
xdm_<]h
x";Egbp]h3
XE%Gx*g
[)}X?F
X=f%ra
XHt?,0
x#}#i8,~I
xJ NJ&
|>X;kD
Xp;)K_R7[j
xvNS{:|
xZic&E
y[	!^}
 *+#Y;&
.%Y-][
$Y`%% 
Y2KaI`
y	,~*5
{y?5<du
]{y?5-t5
YA%m5{p
(y%C1:V
YcI):t
)yG7]h
;YG^wAn
@<yI&C
YiE}3t
YK;<(Z
ylw9TxQ
ymfKc4s
\y?^n*
YO`(#k
Y}PnR{
YqB.N>wL<
Y*	qR3l
,Y>tw(
y-_v-;
y-^v-{Oqj
Z>1D[	
Z.1H;/!]
Z3b	NG
Z/5A$>
Z/5Zd>
<Z6!}`
z*+.*8
)Z^8iWF
Z/9.Ty
:#z9u/
zgwpA{
Z/H514
Zhiw!^
(Zj#9Z/
Z\Ky~/
<Z\Kyy/
Z%l\.?
Z @nF\
ZNpYc{
}:ZN@S
zOd<t2u
Zr-;_3-
zs`t<"
<Z/uy~/
z:*W< 
ZYa^GP
ZZ6LiKh|
&ZZ"p(
Z`,#Zq