Analysis Date2014-11-22 10:29:53
MD5d38ca25e9d618b9e985bb7eba7a576e1
SHA133f3457e12c82c214f7663ac32e6d4fde4e5d961

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: d8a3360011deb4d7a8412c0ad893c6d8 sha1: 30a11088930d4012d2b0c3e1c1c4a20daf25b4b8 size: 104448
Section.rdata md5: ab5ff432716e2f74473fd1068288356d sha1: 328ac400c7ec2760ad4c16ea884e1ab26786221b size: 28160
Section.data md5: 942f5f2128c12f4b3985de3827e0d8f6 sha1: c7758e909f974530a88e76e9a0240972f4d1f68e size: 4608
Section.rsrc md5: 3491dfa6f41a8420acea7753a2865cac sha1: 5d24fd8c05f9678d437fdecd98d0cc279b93587e size: 302080
Sectionvdeijnn md5: 50615dd05bb46aafc9490a7c48391314 sha1: d955e44ff63fda3f9b18f19aa72cbba43a5d8e44 size: 31744
Sectionnleohfv md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Timestamp2010-03-21 05:30:56
PackerMicrosoft Visual C++ ?.?
PEhash3fff056a8755805f1b6878888ab461e3413c72c3
IMPhash720f62ecaae027b5c3ec6686644322e9
AV360 SafeGen:Variant.Symmi.43388
AVAd-AwareGen:Variant.Symmi.43388
AVAlwil (avast)Virtu-F:Win32:Virtu-F
AVArcabit (arcavir)no_virus
AVAuthentiumW32/A-3e7aeab6!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen
AVBullGuardGen:Variant.Symmi.43388
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. WebTrojan.Winlock.9484
AVEmsisoftGen:Variant.Symmi.43388
AVEset (nod32)MSIL/Bladabindi.Q
AVFortinetno_virus
AVFrisk (f-prot)no_virus
AVF-SecureGen:Variant.Symmi.43388
AVGrisoft (avg)Luhe.Fiha.A
AVIkarusno_virus
AVK7no_virus
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesTrojan.MSIL
AVMcafeeno_virus
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)Gen:Variant.Symmi.43388
AVRisingno_virus
AVSophosno_virus
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\Software\2b84a7ed33f26a9ef98ff459e1950594\US ➝
!\\x00
RegistryHKEY_CURRENT_USER\Environment\SEE_MASK_NOZONECHECKS ➝
1\\x00
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FilePIPE\wkssvc
Creates FileC:\Documents and Settings\Administrator\Application Data\WINDOWS.exe
Creates FilePIPE\lsarpc
Creates Process"C:\Documents and Settings\Administrator\Application Data\WINDOWS.exe"

Process
↳ "C:\Documents and Settings\Administrator\Application Data\WINDOWS.exe"

Network Details:


Raw Pcap

Strings
..;.*.**A. d
..=....h.v.4...x..o.
.'...."W.!W:..[...{
.v.4...x..o.
.8...0eG.);V..[...{
.v.4...x..o.
.
.u.DK#.E;V..[...{
.v.4...x..o.
.'...!.
.)WV..[...{
.v.4...x..o.
...6.!*W.
U%..5...{
.v.4...x..o.
.1.6...Z.1^;..)....}.v.4...x..o.
xaf3it.b
..
w
..@
`@
CC
00-+ 
.
\
 
.
..
.
.
.
 ..
]
.F
.-U
y
.
.

!1Aa
#+3;CScs
B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
                                 H
         (((((                  H
         h((((                  H
jjjj
KERNEL32.DLL
mscoree.dll
mscorlib.dll
(null)
                          
'>!*>%-> +>
								
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
020EG3FI.@D
02#8:,?B->A);<
0,2`DO
0?3Nb5KR
05/BI-GM%@D
`	05Q6
-0%8:(:>%8=$7<#49"36
08&:?%9:
'0 9C*EO2MY9[o7[n/Se+I[,FX-BS->P
0A@@Ju
0;%AN&ET
0B)Sl(Ts
0>)D\2Km
0DU`nw;CFw
0>'K^5I\
0L4K~A^
}+0!n?
;0	s^c
0Ss'B^
0SSSSS
0WWWWW
 0:X#{
0(XW1!q
(<$,<!1<
1["}\<
&% 12"GU$H[(Ng
-1!37(<@5HL7GL.=?!-0
(/"15#/1
1;7JQ$7<
18'@D+AL3HW3JS=U[:P[2FW.GW$;K$6M'7T'8Y"4Y
)@"->&1C
1</CN0EN
1fM3w{
1h0O?d
%1&=H8P^7O_2KY
1H*TjAi}0Sf3Rd5Ob0HZ3K[4TgAn
1Sk(KmMs
1t`\|+
1"{V8w
1vX[Bq9
1Xt!@W.EU%6?	
}1YsF\
`1Z dQ*
+*2+#?
"$&25#16(=J
.?!2@#8L
%2!9D1HT*BN,GS/JV
2A#7F!/G
,2&BM)K[ Gb
2b}S+g
2BZI}";
,-*;>2C@
2Da|Dg
2FZ&<L 6E
2>-GW1DK
	2H>dvDbm
2}l[Y4
2m?F(h
2o'?~s:J
2T+OqCn
 2/Vo>k
_(:2wd
2Z$X}6_|
_)>3)0`
339mDO
386IG#30
(-#38'9<
3:&;A'<C$9@
.3&<A-CH9KN4GJ
(3"BN5[h@gt>i|5[r$C^,Hc$AX
3d:=` *D
3H%Pf0i
3I!6c)8
3k3km}
3K K^,L_
3&Ln"Y
'3%<M3DU
3QR{c=
`|3t-*jZ7mmd
3Xn%J`&M\
3ysI&y5
4?0FS+>D
4`	4a	0^
45/c+o
$+"4:$9;$9;!56
(- 49':A'=C)@H*DK*DK)?D!6>
.4&9?-AG-@F'7=
4:&>B*@H)<M.CP-DI*BN,CR/EV*CM)BJ%<K(<T"=K#<J"5F 0C&6J->T/CX$7X
4E$D\$Aa
4F+Uh3^w-Xs$Lh/Ws>f
4?-O_8d
4QEd{>Vh
4.>_]t
4t4Da1Ed
4vMLDh#
4V[rM7J
4Xs'Ga >X+Lg-Xy Rs
=_\5\&
;5$3EA
58Ijl}
/5&9>+?E1DJ/?E$37
5B(DP1LX2MY?Zf9TaE_m:Yj.Rh
5G'@N!5@
5_"J{3Y
5J,DY1Fd9Js4Fm-@b)>V2Fb3Gc&>N(CJ%?J'?O!7P#7R
5R">^)D\
5wn8%6
<{	5z*m
$(6:'<=
6+5y>U
 ,-(6:$8C
%6 &9".C
$)"6?#CP
6D-Na3CZ
6En5Jz :g
6|h0IFPH{a
6kTU	l
6P0Ma3IX
;6,S{F
6V(Lj-Nh
"*	(70Q`DewZ}
,/$7:):<!11
!&$7>4GN$7?
7)5k;@
7'6k@N
7A#M`6_~ Jl
7G(@L 29
7G&<Z",v**
,7$;H,IX0O`/ObB]o<Xj!>Q
7I&Zq7n
7J(Ws!\
7<,pjR
7Q4Vm&AS
;7RNVl
7uX[IT
7w:=hG
);!':&)8
 8 $@#);!0: .A
#8 +?!1H
8"21	&
!!)8;4CF<KN5DG#25
$8A @M
>*8b'9RKayUr
8b	Iu	Dq
8bz)Nc*K\(FU.M_-Pf5]z2c
8	*D$F]
=8Dvbr
8H!?O2M^9Sb>WeNdqE_lB`r0Uj)Sj/]{
8i7+	n
/8MNa~e
8!Mu0M
8|n~G|
#8	%?)Pf
8VVVVV
]8WwH}e
)9#2B,HS.Mb
"95*B:
95y&]C
(9#6@	
%9:awLw
)9 <G#3:
%9GH_r
9]#P|2h
9R,Nc'?P	
^(9^$u
~(9~$u
#> *<'-@#/A
?A37dI
]a$6vR
).(;>/AB&89
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
A'BsCQ
Ab(Z{$_
(..AD ,.*36&4:
,A(D\'C]9UqIe
&A%D[.Z
AE4H!N
AFe{0G*
:?(AH0EL8OV4NU)EK(>G!7@
a"''hN
?ai3b{
A%J8:I]
A,_Lf:~
An application has made an attempt to load the C runtime library incorrectly.
AN)L[-Pe&Mg)So(Vq(Wr.Yx%Qp
-}a!QO
=a#R~&[
%@aR7'
Arg list too long
<at9<rt,<wt
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
August
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
Ay!2s:E
az1`+6u
#B	!@	%@
Bad address
bad allocation
Bad file descriptor
 Base Class Array'
 Base Class Descriptor at (
__based(
Bf%Mp+Wy>u
B\i7NV4MVPlx
bK/GWH
B['Ml#Pv
(BR9Yp=d
b>rnYB
Broken pipe
:b"S{)[
!BV$Lh
bVYj,\q
'+*<C"5;
C,7w<G
%C_"B[2Yu,Xw+Zz
__cdecl
C=d|F3gl
cdmu7K
Cf#Jp'Qv)T{(V
^cFk:[
?c!Gq+R~)X
$CKmn8
 Class Hierarchy Descriptor'
CloseHandle
__clrcall
Cm+LF%
cO,7Qq
CompareStringA
CompareStringW
 Complete Object Locator'
CONOUT$
`copy constructor closure'
CorExitProcess
CP_^][
/:/CQ0JX,FV1Vd2We0Sa4Tc4Q`)FU'AQ0MV+HQ'@L
CreateFileA
CreateFileW
CreateToolhelp32Snapshot
- CRT not initialized
'@ctKS.!
CU$;K'8D"7>
.(":C)@V
<["CWBYh
'C:wc:
#CY/HW':B
D$0^][_
D$ )D$
D$(+D$
dddd, MMMM dd, yyyy
Dd Ik'Ns
December
DecodePointer
+D=eE7Y
`default constructor closure'
 delete
 delete[]
Delete
DeleteCriticalSection
D$$)G@
&}Di&9j
Directory not empty
D\%Jd!Hd;g
%%!<D"=J/Mb%Ok
Dj*QwIh
.>/DK2A@`sw
<`$Dmg
D#N|8n
$D`@^o
DoH?x3
Domain error
DOMAIN error
DS(O^(P_
dt(H1X
D'T=l@s
:d+Tr"Jh
D$Tt*;
!,'DU5[p6a{4e
d	VSHv
d<v[Z+
`dynamic atexit destructor for '
`dynamic initializer for '
e<2vk}d?D
E5#:U]
 E^(AM
E_anr&u
@e AU#;G
E#+E/_^ZY
-EFgx5MW
Ef[=P*F
`eh vector constructor iterator'
`eh vector copy constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`eh vector vbase copy constructor iterator'
ek4e1Q
<E&K[4]t
<^e?KZZ
EncodePointer
EnterCriticalSection
E\!@R#7C
 >$Er*O
+;&EU#J^6_z1\
Euq;o7c
evl[Cj
}<e~wc
ewh/?y
Exec format error
"%EXFc~Ws
ExitProcess
~EX{!^n
!eZ^Y+
=+=..{f
f"5g\^
f>A'	q
__fastcall
FD)np)nl
February
Fe"Ie'Ia
_fhJVM
fh^Nb'
Fh.\~$Sr
File exists
Filename too long
File too large
FindResourceA
FL9~Xu	V
- floating point support not loaded
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
F&mAdR
Fm Gr	0YDp
ForceRemove
~{fQZ	
FreeEnvironmentStringsA
FreeEnvironmentStringsW
FreeLibrary
FreeResource
Friday
f	s`pX
ftw:NT$3@";Q
Function not implemented
f#"v1#(
'F+WuBi
 fYjoQ
Fy@se6(
g7'EO5
g.7-$j
g7LC{]w
GAA6R$E
Gc^qW,
GDMgW<
GetACP
GetActiveWindow
GetCommandLineA
GetConsoleCP
GetConsoleMode
GetConsoleOutputCP
GetCPInfo
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStrings
GetEnvironmentStringsW
GetFileType
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetProcessWindowStation
GetStartupInfoA
GetStdHandle
GetStringTypeA
GetStringTypeW
GetSystemTimeAsFileTime
GetTickCount
GetUserObjectInformationA
?g*[|%F_
!(Gf(\
Gf#Ll#Lm)Tx Vu4f
Gh9Ghr
Gi+Y{#Qz
G{!\j:i"x
}-gKMF
gld8M>
GQqHmd
G^rD]hT_
GSN@T,
,*GV6Wg7[m:[o=_v;^u:\s%FZ
GW##0/,n@$
gWG~v)+
?gy5Qd2IY.EU;Uc2M[6VmBm
GzW?=>G1
`h````
H*0"ZOW
 H1L3]
(H+Bo6Gz
HeapAlloc
HeapCreate
HeapFree
HeapReAlloc
HeapSize
`hhgUJL
`h`hhh
HH:mm:ss
HHtXHHt
/!.HIVy^l
H})J m
h$`jo1
h_\n"H
hQfzO0fD?
Hu"R~H
/I!4B&8H,?TZl
I#7{)P
>If90t
IiGM>nw
-I;iUi b"
Illegal byte sequence
Improper link
=%iN3o3I
Inappropriate I/O control operation
InitializeCriticalSectionAndSpinCount
Input/output error
InterlockedDecrement
InterlockedIncrement
Interrupted function call
Invalid argument
Invalid seek
I]"Ru$Rr"Fh
Is a directory
IsBadReadPtr
IsDebuggerPresent
Is"Ow8^
IsValidCodePage
iUIs1k
I{wP;y%
^i:yv:X
#IZ3Sa
`j0~%`
/J+0Nf_
J	2a1b
j4R.$J
JanFebMarAprMayJunJulAugSepOctNovDec
January
.=&Ja+Xx"St Oo
-"(Jcg
J.CMRS
Jc-[u"Oo#St'Z{
%&JeN}
Jf$Vr&Ms
Jg/[t;av8Wi2KV
j@j ^V
j{&K'~
%jN%}C
Jn*Xz2\|
j"^SSSSS
,j"V'{
J~w[Y$#@"h	
:"Jx/^
kAs=%s!$
Ke+jF4
kernel32.dll
KERNEL32.dll
?_$Kk%Sr
KmAzb59	
KoM-3`
kRHmsWs
/?'K].Ti3Yo4\u0Xs3Zt3Zq
Ku-Os[r
_?k`uW
L$4;D$Ts<)D$T
 L	5i<l
L$(9ODv
l!;b	F
LCMapStringA
LCMapStringW
;L$DW-Ug*Qg4\w+Sp)Qn4\x1Zs"Kd&Rj<e~ G] @S5N^
LeaveCriticalSection
(LE`{`w
~>l={H
.L%Hb(G`
liaG5Ow
ljsaD:
.?L,J`$Yz3`
=l#K| Bw
Lk%Wy-On
L$(+L$
[-&LMb#{'
:L Ng#\}
LoadLibraryA
LoadResource
`local static guard'
`local static thread guard'
`local vftable'
`local vftable constructor closure'
LockResource
lOPgpm
$!;L<_q9`t(Rf0Pb5Oa>P_@Q_AWf?\lFhw6a{-_|#]~
;L/Qc,Qf$Ma!K`"Ke,Us1Yv+Sn)Pj*Rk2[t
lstrlenA
lstrlenW
;l$TsY)l$T
M-1T=&
M21b~6A{D
.M7"'m
`managed vector constructor iterator'
`managed vector copy constructor iterator'
`managed vector destructor iterator'
mB9$n~yb9
,M Bj"Co(FmG`
/M Cc)Ki
MessageBoxA
)mF[C#.Q
"Mh&2D
mHCj_=
mIA|>OR
M,)iCM!
Microsoft Visual C++ Runtime Library
`mj;1d
mj>zjZ
M?K;IC
MM/dd/yy
Module32First
Module32Next
Monday
Mp'Su<`}3Rh2GU 05
mT@m\A5
*=-mtx<
MultiByteToWideChar
#m>v1[
}m<vNy
mYd(b6
n:5c9`[
]N7|0"5
,:&=N&BU!?S
)Nd)Vh
%@%Ne+L\
 new[]
nE:WOMZ
nji/fQ
nleohfv
nl+)g)
nmm5$>
No child processes
No error
No locks available
NoRemove
No space left on device
No such device
No such device or address
No such file or directory
No such process
Not a directory
Not enough space
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
+Nskxua1
&Nu3UzYz
N(Uh0%
(null)
&Nv!Ei
Nv#Qz$Py
O$^)*;
O(9O$u
OcJaj+
October
~+od\_
\o]DjF
oDkob0
 `o}G|
oG?Bk=
oh#g8,
Oh;O\sN
O@;H s
O@;H(s
;[o*IY%Jc7Ycq
)Oj#F_%Jd*Qm6`~
"<ok";
`omni callsig'
;_o}^P
Operation not permitted
operator
{oww9bA
OZw3(?
+)}p6S
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
@PAQBR
__pascal
Permission denied
&P&!Fdin*
pI66@c
`placement delete closure'
`placement delete[] closure'
Please contact the application's support team for more information.
'$> pN_\
$-{'Pn
p<O#|$
&Po%Lk&Mm/Yz#Tw8c
Pp"Pn2\w7Yn3N]%5=
PPPPPPPP
pR:b!5
Program: 
<program name unknown>
__ptr64
- pure virtual function call
pv6HV8o
-P!;Y"5P
Q0NX>7I
-Qc/tG
qd$s2Vu
*Qe-JY+EU)F[*Ke-Wr-^x
?Q!EW"6F%4@
@Q$FV,Pe,So
qiiFRdG
/](Q~Iu
Q/jBzW
Qkkbal
=Q%Le+Vy&U
q}^Q>p
 .QS8Hl
Qs)\|)Wt
!Qt#Ru
QueryPerformanceCounter
;R%6_;
RaiseException
.rdata
ReadFile
Read-only file system
Resource deadlock avoided
Resource device
Resource temporarily unavailable
__restrict
Result too large
RKt(IKn
<Rn;dq
+rS6,?
RtlUnwind
runtime error 
Runtime Error!
\R,Uw$
Rx"X~=k
S1&u^bz
;s%5v1<
Saturday
`scalar deleting destructor'
S=Ej~Sh
September
SetEndOfFile
SetEnvironmentVariableA
SetFilePointer
SetHandleCount
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
>S$F\&G^#D]!B\#C_&Eb#C_
(Sh"I_-Of/IW&BP(JZ1[n4a|5h
SING error
SizeofResource
S^k=HU
SL"mm{
@SLuY@
sqs`DH
SRTrEo
^SSSSS
__stdcall
`string'
Sunday
SunMonTueWedThuFriSat
$T8HB#
t*9Qlu%
t.9Vlt)
tB=]A-
^tC5Jd
teh=8A
TerminateProcess
]T)[|F
tGHt.Ht&
T$h9T$
This application has requested the Runtime to terminate it in an unusual way.
__thiscall
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
!This program cannot be run in DOS mode.
t$H;t$8
Thursday
< tK<	tG
.-Tl<'
TL	L&m
TLOSS error
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
Too many links
Too many open files
Too many open files in system
.T P~/f
T$<PQR
T$$QUR
tr9_ tm9_$th
tre-Q}
~`t,RN*A i
%Ts Ok0XqEc|Kh
t"SS9]
Tuesday
;t$,v-
$T	%Vo
t:<wuE
t+WWVPV
tx9"P{AX]
 Type Descriptor'
`typeof'
[T<Ypg
u6>krv
U	9v'D
:U%Aa 8P
U[_,C?`
uc',cJ
uD]>@9
`udt returning'
ui}*<g
uITw$f'juFW
/Uj(K\
Ujvy`"
- unable to initialize heap
- unable to open console device
__unaligned
- unexpected heap error
- unexpected multithread lock error
UnhandledExceptionFilter
UNICODE
Unknown error
Unknown exception
UNSja+`
UQPXY]Y[
uRH35v1
URPQQh
USER32.DLL
UTF-16LE
 ,UV4T
uV=D{mL
\UV]u-
v/\	=	
v$;5$0B
`vbase destructor'
&$]vB/k
`vbtable'
`vcall'
vdeijnn
)Vd)Nh
`vector constructor iterator'
`vector copy constructor iterator'
`vector deleting destructor'
`vector destructor iterator'
`vector vbase constructor iterator'
`vector vbase copy constructor iterator'
`vftable'
Vg<<b?>
VirtualAlloc
`virtual displacement map'
VirtualFree
VirtualProtect
Visual C++ CRT: Not enough memory to complete call to strerror.
vL;2.$
Vlf+Vd
Vlf+Vp
vlk\e`
v	N+D$
vuu]D{b
(VvAQ_|
VV$ny,Gl
V_:X1:
{%[+:w
w6K/	w@
;W8`s$Rd
w<9G,s
+wdN,=
Wednesday
Wf(DWD
w]iD5r
WideCharToMultiByte
wkEb1k
WN7/tW 
w+OQvr
WriteConsoleA
WriteConsoleW
WriteFile
|$ WSPV
wu"HI]
~\wu(j
wV#([W
 w(Yp]
Wy S~ Fr
X1Cl`[
x2	1&Q9
x@*%2nw9
X4Im4'!
xB aT&
xc[Xs$iA
:X+Ji%C`
>X+Ld7Rd+?K%/8 )0
XLKzd)
x\n5yd
xppwpp
xpxxxx
XT<15`%x
xW	2V^Yn
&Xx#Qq
XZ#g/OS
<}y+%K
y{,=K	
#yl9@p
y[lgDD
;Y'Lh_
y}OW O
YPsC<@
>=Yt1j
)\ZEo^m/
:Z#N|*^
-%ZOh>
ZqPF/*
zrAdg*
z^T_Bb
Z=x/qu_%^i4
;Z*Z{$Pt