Analysis Date2014-07-22 19:18:07
MD5f142f03bd5d8262299d1de58852579f7
SHA14114d1f3f7e5cad23cdcbea77df5aae89562b19f

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: b1ae6dcdc3a7ba319c6d5e0b1a2eadbc sha1: 35a4c8038c5866c6a7b999aafac36f430c5a5bbd size: 7680
Section.rdata md5: cd4f20f041a2da05dfe5974fe61bd4ec sha1: 32dba388b7a093695342afde8ac4904196ff5055 size: 2048
Section.data md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.rsrc md5: 5c6416e417de0cc598b8925f92b3795c sha1: 0ef7ddd14a95b0d18ee63543ecfd3fabee6dc4d9 size: 8704
Section.reloc md5: 938152484b33bca77bd622973abb524e sha1: 6681044b06d2b4c698e751baf66c69ce242a4529 size: 512
Section.tsustub md5: 0a583ae44793191459662970ad5b1c96 sha1: 2f1dc083813e5c55649e52f9ce812a73795c7da3 size: 121344
Section.tsuarch md5: 3a178bcf197640a836026b95f28eee91 sha1: 670f488e2b20b4a59e167dc7cd30bec0ab6bb285 size: 165376
Timestamp2013-03-12 08:51:45
Pdb pathD:\Dev\Tin7\InstallDir\vc80-win32u\Loader.pdb
VersionLegalCopyright: Copyright © 2013 QuickSet
WebSite:
InternalName: TSULoader
FileVersion: 2013.12.11.1430
CompanyName: QuickSet
SpecialBuild:
PackageCode: {B710D044-F52F-4CD7-AE3C-BD0D6CF3F2B2}
Comments: WinNT (x86) Unicode Lib Rel
ProductName: QuickSet
ProductVersion: 1.0.0.1
FileDescription: Installer for QuickSet
ProductCode: {1298F6E9-9E4C-4B3B-9549-0E50C623D394}
Email:
OriginalFilename: TSULoader.exe
Arguments: /x
PEhasheb9d7b63375cbab7633c8a6454c00795b213f651
IMPhasha8286b574ff850cd002ea6282d15aa40
AV360 Safeno_virus
AVAd-Awareno_virus
AVAlwil (avast)no_virus
AVArcabit (arcavir)no_virus
AVAuthentiumno_virus
AVAvira (antivir)Adware/InstallRex.S
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)no_virus
AVClamAVWin.Adware.Installerex-4
AVDr. WebAdware.Downware.1719
AVEmsisoftno_virus
AVEset (nod32)no_virus
AVFortinetRiskware/InstalleRex
AVFrisk (f-prot)no_virus
AVF-Secureno_virus
AVGrisoft (avg)no_virus
AVIkarusPUP.InstallRex
AVK7Unwanted-Program ( 0040f83e1 )
AVKasperskyTrojan.Win32.AntiFW.a
AVMalwareBytesPUP.Optional.InstalleRex
AVMcafeeno_virus
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)no_virus
AVNormanno_virus
AVRisingno_virus
AVSophosno_virus
AVSymantecSuspicious.B.UMH.PUA
AVTrend Microno_virus
AVVirusBlokAda (vba32)Downware.TSU

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\All Users\Application Data\InstallMate\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\Custom.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\Setup.ico
Creates FileC:\Documents and Settings\All Users\Application Data\InstallMate\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\_Setup.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\All Users\Application Data\InstallMate\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\Readme.txt
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\Setup.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\x64\regsvr32.exe
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\4114d1f3f7e5cad23cdcbea77df5aae89562b19f.log
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\_Setup.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\x86\regsvr32.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\4E0391BF.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\Custom.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\Readme.txt
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\TsuC08383EB.dll
Creates FileC:\Documents and Settings\All Users\Application Data\InstallMate\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\TsuDll.dll
Creates FileC:\Documents and Settings\All Users\Application Data\InstallMate\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\InstallMate\{C479CBBF-8988-440E-A6E5-C1AA1F9AE949}\Setup.ico
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\4E0391BF.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates Mutex{B710D044-F52F-4CD7-AE3C-BD0D6CF3F2B2}
Winsock DNSc2.styleapp.info
Winsock DNSc1.stylefun.info
Winsock DNSr1.stylefun.info
Winsock DNSr2.styleapp.info

Network Details:

DNSr1.stylefun.info
Type: A
DNSr2.styleapp.info
Type: A
DNSc1.stylefun.info
Type: A
DNSc2.styleapp.info
Type: A

Raw Pcap

Strings
..
i
.
 
)
EA
0
..
.
.r
.+
.
..
..
.1
I.V.
.
$
.
.+.

000004b0
1.0.0.1
{1298F6E9-9E4C-4B3B-9549-0E50C623D394}
2013.12.11.1430
 2013 QuickSet
333f3
Arguments
{B710D044-F52F-4CD7-AE3C-BD0D6CF3F2B2}
Comments
CompanyName
Copyright 
 /d:"%s"
Email
f3fff
FileDescription
FileVersion
Installer for QuickSet
InternalName
LegalCopyright
OriginalFilename
PackageCode
ProductCode
ProductName
ProductVersion
QuickSet
SpecialBuild
StringFileInfo
\StringFileInfo\%04x%04x\Arguments
Translation
Tsu%08lX.dll
TSULoader
TSULoader.exe
VarFileInfo
\VarFileInfo\Translation
VS_VERSION_INFO
WebSite
WinNT (x86) Unicode Lib Rel
=%. "-
"""""/
031701
&0[+3@x
050607080910Z
0D1i1x1
\*0:%h;7
0http://crl.comodoca.com/COMODOCodeSigningCA2.crl0r
0http://crt.comodoca.com/COMODOCodeSigningCA2.crt0$
0i9\EH
0I)(jdj
0KkVed
0RCp%1
0s6LAV
0uhfy8
0uWx}0
110824000000Z
1#2=2o2x2
130825000000Z
140825235959Z0}1
1bikf7
1dHB8.
1http://crl.usertrust.com/UTN-USERFirst-Object.crl0t
1http://crt.usertrust.com/UTNAddTrustObject_CA.crt0%
1!MtMB
$1ql8s
1(u:F%
        <$1vJpiAWMgP24XG+xztjaXh2ykwXoAt6X37UtVY3Sq+kb0nm7RlfqWS0tFjkv3kQqor55S3QJt2bcNfQCM8h/NXi+1BUnJNNUkrBuI6g7ynsI3FjOQSE8V804G7Y27XcqMhWqNChqnls05I8EUTPqeyZaPY3AIan6+I59gPnY/p0/up8nznIsaP/GL5D5ckNX5WvqBw4t4b2x2Mm40OaWlOq5nExGH1cSeKdvEfYNxljavERH0aATEw3Nwf+8JVoybBKllOqF0uHSxSxmMlRfd3JmEfYM3xwgpoFaFu6czQrjNOhxy8TgUknZNWefpBZ8a2LT7X8bsYcj2kqOrrZsYrYEXVc/mUxKjoaDOiLOPZ+9wfoUYmBpJNKi7GEf7A0MECqMUNV309FGEnyebgOqWaQkwHeOiodEj80Aj3PEgdv8gZuizzsCxii3vcUpd08BiQ5AxsBIpD4QSnmIi+jWvw770NS2HwLOrTEPvHPsriC4nC71GQe4SiS9x1DCrv4QVh4oTfvWZOU25RDqCShz9JhIvJknMzLx8C0NC9JVSal5RUnErN4sg9CeNTlOf9jpu1V1u2OO6KI6+mFdQk0/vkRLlUdB/JUFJiMC04f+hNXg9iAAyHlNdHLQ8lxdzE64WSB5be4dj0JnbUSrAj2TeOd8SINk8F91M8aCPIuhTp3b+CmCGS0rOGnFdkpMSebAhBBUL4Tbj8TMesVZLA1SgQV0JACAykVwuWkMTXdmfVLSqJoPUCUpzz4B2qePjeUO5dpM83cQmM7RwNPYxNmrapFKTVVAN1cj3Ns75PRo3N+BegGcdjMg1/H2ULXgYAS2Tp6YIlPe2IFXCKgrDxLdxAYq8Y5ofeCSWwE60R8qb4NYHUJjMawuvW6EEahyBXEyGA0pgWFA4lJ8wdEbnvexY2LE9fRyn7pBdjDfJIA0U7YjBHG2dkvUqFPREXbh2Ob51X1mSDYsnJp7EDZsxjQnkfjrfeSt23jEEFMiO+5/kgOEeIzXRZuiFsN9ZImr230IH9XKECPQDhYzDmz3DymKtLgexRaIGd5dJzDV09zBocBkgchIDsy+iExVAG+/kX6GJEQH9zGtNUtStQwMf0D26i4/pBjOtIo1RrAJNDB1X1+21OExgMRm2wjcm1VGSKr5bTHlq1WlHu0RQUhVTSgzhKU/l5mqPF76LM4P5cvzGFYUcrDY6yhV88UE+OJa0OnnpwMfn7quFGxciaudbRZx7EQGMGXUEIheDj9TETE9UiotBXLwaS0FnTLVVSZ8hcpi8D+LDbfyYsDpF/oeRv4WpLtvIIkFO0hdF1wQK2BsjxVeaM0cVCbMeM/M/Rck+NjsdLplEJqjwsbfyyOUopDQ7PoPF3JQOo0Qiu1yG4In1Wsu1jlYeJz+dAjFgC1dxKttYiD5wZNyy0g8yQ8Cst9xutwC+fwVnMgRZBxKKie3BenHaFYn/MkN$>
1_W/p!
1wWE>]2
1|X `#w
1yL1sC
:+:1zr >
200530104838Z0
200530104838Z0{1
)|2?4^
2i^JE+Z
.2r1VG
!2RecbPu
2Y3=ph
3*c|Gm'>WL
3http://crl.usertrust.com/AddTrustExternalCARoot.crl05
.3h;Y8
3kF>nB
3n:Dk5
.	"3pV
>"3!R4
-( 4]:
40-&oI;J
<4%F*F?
[4fyE%
4}ha&K
4jy]|/j
,4@p,)
4$`[P8
_4=>Qj9
4wJ<O|
4Yf	fk]
5!5>5H5R5^5m5z5
575N68
57Dw{!/0m
{5~8(%
5C[jv:
5hoT|d+3q+
5tOY[@=
>6@~2_
\6\ 3p,
6$6H6M6
6	7>7N7U7a7t7~7
$6B ; 
6&CN	>
6Jn_Iw
6o^9iI-
6Ph\%[
6S*9dq
6wM)9j
7;8Y8,9i9
7 c (AcG Q
7>G:6<
7K++oc
7LsH9M
7nV@CL
7$O?;*#m
7QM"n'
)7r$#a=
7SIJm3
7uIerY
 7':@v
7,+/?V
8AtC-bZl
8B!e!<
+8!=ef
8*N?v(
=8}V@8
{9}0MI
92j%Xv
9f*<Z,m
%9"HOS
'/9pO;1
9v=j@q
%9Yfq|R# 98
a!#>;^
~_(;A*
.>A_ %
A9pWJh
a=AW3,
AddTrust AB1&0$
AddTrust External CA Root0
AddTrust External TTP Network1"0 
A%Dv<`0
AiHV_P
aJsK#)
~aJ]z.
a}qfIi5
as;1>'c
</assembly>
	<assemblyIdentity
			<assemblyIdentity
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
A>V9c?
AyJbnr[
A;y@P\
b4@{>6
B;/7r7
bE+UnMT
bE y>$
^bK}Aq
bOa[c	
BOKq~d#
]<bP<#A
B.tsuarch
B.tsustub
	bW	iK
Bwr!B"
BZ!6nW 
C'4}5j
c|6GW^
|c#?#8/
c-aC-!.
CCMF"KS
cC%*+O
'ceJZT
C`F@}e
c,ft$X
,Cg)xbx
CloseHandle
CnN:	l.
c^nny_
COMODO CA Limited1!0
COMODO Code Signing CA 2
COMODO Code Signing CA 20
c+ooUZDb
CreateFileMappingW
CreateFileW
cr~U%0H|
D\-`?2{
D8@6eg=b
@*"da=C
@.data
D!B	fvd,g
dBZLG	
D:\Dev\Tin7\InstallDir\vc80-win32u\Loader.pdb
DeleteFileW
	</dependency>
	<dependency>
		</dependentAssembly>
		<dependentAssembly>
	<description>Tarma InstallMate v7 Setup Loader</description>
=D*fE")
]d-f@,{o
d!]*gh
d+g?m*
DH9^{l)
dh(u_tokn0_b
DizH50
dL9#M8
DmH!8j<
d,PCq?5}i*
/&d`~PLu
d^tGqF
DtQiy7
dWt`^9
)'#dydG
E1j!VG
/(EBl'wZ
e\.cE6
$ E, d
+E<;EHv
E@	ELf
E\;EXu-
E\;EXu0
E$jC0'
Error %u while extracting TSU.DLL to %ls
Error %u while loading TSU.DLL %ls
Error %u while retrieving entry point from %ls
eS"$hqcK
EsZUPg
;";=;><E<t<
ET,D'ty
ET+EL;
ET+EL;E,r
Ev5/m[
[EwE1R"oWt{C
EX9E\u(
Executable has no .tsustub section
Executable has no valid MZ signature
ExitProcess
E?;xLt#
eYc1o[/So
e'Y#<p~
E>ySUc	b
Ey;t{(q
"- ]^f
F94k8&O
FaLFyS
Fb>?dG_
F!B?rO
'f$CAz
fg)H`o
,><FI4	
|fJr;@
FK5;r8
,fkEjKN
%fKgOp
Fkh%dG
<_f|~l
]f#n~$
f^!(}O
FreeLibrary
[F.u/,
G(6;X	(?D
G_9O3sA
-GCl50%
<g&eB3
GetCommandLineW
GetCurrentProcessId
GetCurrentThreadId
GetFileAttributesW
GetFileSize
GetFileVersionInfoSizeW
GetFileVersionInfoW
GetLastError
GetModuleFileName() failed => %u
GetModuleFileNameW
GetModuleHandleW
GetProcAddress
GetProcessHeap
GetSystemTimeAsFileTime
GetTempPath() failed => %u
GetTempPathW
GetTickCount
G|'GjQ
^G-JUz
G%[)KE|
GkVd}6
.gN1kl(
Greater Manchester1
>G/tD3
/gT"%Hj#
gx57uC+
Gx!D(rp
G#Z1wKUT
,G>z,7
(';H\#
&_h3~x
hbr]~[
"%hC!_
h@cMc @
HeapAlloc
HeapFree
H;g'	5
H+iJh!
:+=Hm J
*!\H	o"l50
{h?q~e
http://ocsp.comodoca.com0
http://ocsp.usertrust.com0
https://secure.comodo.net/CPS0A
http://www.usertrust.com1
=HVksV
~h^w_4
H$	W(*B
HwHAh-
H%xm3b
H+YC7v
H`'ZY+
i\1>bO<
 i2bfA
$I3Gs9qs
I3`jny
i8(eu5
iCcN>	
(i<e\4
If<)E@Q.R|
<ifgY3
ihD47)Xg
IHwJ&]
i *i|5
I/<"ko_
.IL8BD
I<OCiT
 ip * 
iqEeTdq&
=-&iQ[f(
\iSg%5)
I&SYjKM
{IUT\T(
ivan7@bookfullzip.in0
Ivan Kostin0
Ivan Kostin1
IxJh$W
iz`j#K9Y
:J'~1 'l)V
j|3m;(
j$[6hq
*j7%:$
"^jCNa
Jf|4)_
Jf{\L(
jK=OS 
j=lVCm
j[^MW)
}jok<X
jwsm.>
j^wx	)y
j"XB!nX
$jYBeY
!,;/K^
K^)):=
k*aMJ8
KAt|b4/,\
KC6+/Ek
*@\kEQ,
KERNEL32.dll
KfAU|cHX
KJ4Jw}
kl<+0$
kLWZfm
Ko?6E?L
ksK~\<
k>t~OU
KYb;(h
K#z5sI
):(!L^
 .l!%/%8[>
				language="*"
lBl:p.
l~d0*K
	L-&DX
LiT	p,s
^l|%K'
LoadLibraryW
\*^\L]OQK
L!P7N6t
lstrcpynW
lstrlenW
L<:~[T
LT+(dm
~\lWeo!
ly_itCH
`m}@~[
m\$*'>?
M8;Mxs5
MapViewOfFile
MD)'i+[C
M}e9R;CB
MessageBoxA
mG9U+ 
m"}#|		I
mJW%]W
MmAaB`
M\;MXu-
M\;MXu)
M\;MXu0
M\sD;MXu-
M{t["s2+
MultiByteToWideChar
mV{qn? 
m$xAah
m*yPOwT8
n0c'Mr
.$|N;2t!
NA~!E%Na	
+n>AJQ
				name="Microsoft.Windows.Common-Controls"
		name="Tarma.InstallMate7.Loader"
nc*5BN
-)\N:d
%<nf$g
N	&H&p
:nn7S5_h
NNh.q$
n>oUwg
NPb.	;	
nq)BtQ
)nRu(]
NS.v#6g
N~TI:b
O0Zf_w
OcoCgT
	O]{{H
OOHze"
'O#\S6
os+Y_"
OutputDebugStringA
ow.~Fc
O_wo	^KM
o[<y@{,
oyjb8V
p81u;]
;p8t/s;
P94D&*5
PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
pAq`,[
p,az[E
p_\.""b
p	C)5zg
p!CF=@8
pCo!^h
PCxPcl
pE$(=l
P>.FY`5
P$gUOVr
Ph-`[7A
p}hFuT
PHnAS;
p<l6Rh<
PNW%]8
Pobedy 33/11
PostMessageW
				processorArchitecture="*"
		processorArchitecture="*"
P{SNB<
				publicKeyToken="6595b64144ccf1df"
Pvp NT~
q1R_Gm
Q]4h^ES
q_8%b=R
Q#A5Ew<
qHWmJf<
QhyL8E
Qjv6fY/2|
QK1>V 
QL[3H55t,
*q?\.m
q<nj7l
qP [v{
QQ(d2j
Q"t`h{6
qUh9f;
Qv2M=(0
qV(&F\
qvy!8r
r'&@(	
r0/	\+m1
:R]0`vTJ+2.
r6F WD
	RBBDe\mh
)rB%qP
~]rcfH
`.rdata
\/r	+dEfC
*$r/>E
ReadFile
@.reloc
				<requestedExecutionLevel level="requireAdministrator"/>
			</requestedPrivileges>
			<requestedPrivileges>
r [j~*A
R?Ptcg
R[qpE2
))RSvH
]}^R[vgE-
R><Vz=Z
RZjCLwDB
s~5w <
S7FX!	*]
-`?s?8
SaaPWE
Salford1
Salt Lake City1
^S^)cr[A
sD<ZM]{
		</security>
		<security>
SetFileAttributesW
SetFilePointer
SetFileTime
se=w*v
S./HC	(
%sjWXj
S~UAk`*
_s)VIcr
sYc8sO1
T|b3k6O
TD gYB
t}gnkC$
The USERTRUST Network1!0
This installer is for Windows 2000 and later
!This program cannot be run in DOS mode.
TJ(7Ph
<|tKO)
Tl;-x[
TMF4Nn
[t^N7`eW
_t<+O2
tQ~<k~C
tQMm_6!
T;{r!<eA
tRuQ<$
	</trustInfo>
	<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
T~sfU=M
TSU Loader
_TsuMainW@8
.tsustub
TTtGpK
|=tu2u
tVN+~(
tw`EJ\
TwG\@!
TWK_^k
~tXo2/
				type="win32"
		type="win32"
?tzf3t
t"ZK`Z
tZtr56A
U1"Ge4K
u3,.yX
!U5)EP
^U8W]j2<
UAb\3l
U	cu;Qz
}?'u==f
U}iD[A|
)]`	ULOu
UnmapViewOfFile
u]S|^|
USER32.dll
U:~_tD
UTN-USERFirst-Object0
UX'q:41
V61WP)
V8g??;
	v&$a1
v=BHMAA
VerQueryValueW
				version="6.0.0.0"
		version="7.2.0.0"
VERSION.dll
	V*G:E
^,&vHM
!vk94_	
Vk]hT4R
\|V.k=q
VNZUiq
V/pEQc
VrB)Qv
VrfIs8
^vTt3W
VTVvHO>I
#]?VW2
Vw'9t3S
v.ym%i
*}}/|W
 ?W&97
W9}mA$*
wBdV22
w'#e0bk
weyq`$
wIo[+]
W<n+^8
^WplC@b
WriteFile
wr=v(Uiw
WsJsy|
wsprintfW
?+w:sx
wVK#1A
wvsprintfA
wwwwwwww
wwwwwwwxp
w?]+=X
wzZ/KX
X4iL"|
X	^<B<
|xD G4%	
,x/H-$
"Xh,&]~
x?]H X*vcB
XI#"WR
xkE4Ve
Xkph%l
x[$|&L
X%]L:[$
x:l0],
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
x:*muh
Xn	FlL
X,O7w3u
XQB*E7l
x@%SU*
xUv0To
Xv[5+3D
xW7JQM
X+X='Z
}~x\ZU]	
y2,o8"w
-Y6:Lf%
y&}BT^
y+eW>Ln
YGiu;p
YiDLk5>h
y]$+Ku4Z/
)ymiNB
y_&mVPBA;
yPs}PQ
(*z0Lhu
~"z5!6
 %@Z#8
Zd!T'h
|@`zEd
>ZE&+\G~
ZfAc',
Z	!IW@3
|zmGoDj8
zn&g""t
zn\*t3
zr	YJg5
+"!!Z/us{
#zv/wko
z&w.a*
zw"r~]eU
ZXMMIH
ZZ<oiG