Analysis Date2014-10-06 10:35:52
MD51e076133e2e6573d1537afee530a7a53
SHA1466a67b532a0598d3ace397f93bd79196d72bc23

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
SectionUPX0 md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
SectionUPX1 md5: 3b001ac404965a0998cd706958937333 sha1: fce5dbf64e9623597a28662fc1f0746627a7733c size: 217600
SectionUPX2 md5: bf7aef12f9ab1a21aa165814ad5b2dfb sha1: 1a7f55a28c06d9f01f4bd884ffbffeeef6d83fa7 size: 1024
Timestamp2014-09-29 05:18:28
PackerUPX -> www.upx.sourceforge.net
PEhashdff82cfb0296a611589f5b80c5979cb6bdecb77c
IMPhash12949835d0cda9d5836fa2fbd6c55e3c

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page ➝
http://www.2345.com/?k98792151\\x00
RegistryHKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\HomePage ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue ➝
NULL
Creates FileC:\WINDOWS\system32\drivers\etc\hosts
Creates FileC:\Program Files\Common Files\Microsoft Shared\p3_kbaidu888888_jg04OunlF483lZatm6Ir5_v14.7.1.exe
Creates FileC:\Program Files\Common Files\gqbb24_mt1.exe
Creates FileC:\Program Files\Common Files\tqrl_97_1957.exe
Creates FileC:\Program Files\Common Files\KQ.jpg
Creates FileC:\Program Files\Common Files\YoudaoDict_silent3.exe
Creates FileC:\Program Files\Common Files\OfficeAssist.0195.80.1054.exe
Creates FileC:\Program Files\Common Files\qhse_7654_5943.jpg
Creates FileC:\Program Files\Common Files\setup_t10303.exe
Creates FileC:\Program Files\Common Files\setup_s1020.exe
Creates FileC:\Program Files\Common Files\bdws.jpg
Creates FileC:\Program Files\Common Files\asdqw_3104-48740.JPG
Creates FileC:\WINDOWS\system32\unrar.dll
Creates FileC:\Program Files\Common Files\bdsd.jpg
Creates FileC:\Program Files\Common Files\baiduse.jpg
Creates FileC:\Program Files\Common Files\appers_7_1958.exe
Creates FileC:\Program Files\Common Files\uc.jpg
Creates FileC:\Program Files\Common Files\shanhu_7654_356.jpg
Deletes FileC:\Program Files\Common Files\qhse_7654_5943.jpg
Deletes FileC:\Program Files\Common Files\bdsd.jpg
Deletes FileC:\Program Files\Common Files\Microsoft Shared\p3_kbaidu888888_jg04OunlF483lZatm6Ir5_v14.7.1.exe
Winsock URLhttp://d2.freep.cn/3tb_140910182900qy6q538987.jpg
Winsock URLhttp://d2.freep.cn/3tb_140910185403kcyo538987.jpg
Winsock URLhttp://jifendownload.2345.cn/jifen_2345/p3_kbaidu888888_jg04OunlF483lZatm6Ir5_v14.7.1.exe
Winsock URLhttp://d3.freep.cn/3tb_140910184804w6i0538987.jpg
Winsock URLhttp://d3.freep.cn/3tb_140923192942q71f538987.jpg
Winsock URLhttp://d3.freep.cn/3tb_1409101837529hro538987.jpg
Winsock URLhttp://cdn.pcbeta.attachment.inimc.com/data/attachment/forum/201409/12/173937imav9yvcycn3akua.jpg
Winsock URLhttp://codown.youdao.com/cidian/YoudaoDict_silent3.exe
Winsock URLhttp://xz.dianxinshu.com/download/setup_s1020.exe
Winsock URLhttp://d3.freep.cn/3tb_140917191931o0a2538987.jpg
Winsock URLhttp://down.9vh.net/appers_7_1958.exe
Winsock URLhttp://d3.freep.cn/3tb_1409101919002w55538987.jpg
Winsock URLhttp://wdl1.cache.wps.cn/wps/download/OfficeAssist.0195.80.1054.exe
Winsock URLhttp://down.xiaoxinrili.com/hezi/jm/setup_t10303.exe
Winsock URLhttp://guangqu924.oss-cn-hangzhou.aliyuncs.com/gqbb24_mt1.exe
Winsock URLhttp://www.3n8n.com/xin8/mail.asp?qqnumber=&qqpassword= 6
Winsock URLhttp://down.tianyunxj.com/tqrl_97_1957.exe

Network Details:

DNSwebmirror.pcbeta.com
Type: A
113.107.42.25
DNSdown.9vh.net
Type: A
222.186.60.3
DNSc06.i06.arnic.hadns.net
Type: A
183.57.148.246
DNSc06.i06.arnic.hadns.net
Type: A
116.11.254.249
DNSguangqu924.oss-cn-hangzhou.aliyuncs.com
Type: A
42.120.230.9
DNSdown.xiaoxinrili.band.glb0.ldcache.net
Type: A
183.61.19.169
DNSdown.xiaoxinrili.band.glb0.ldcache.net
Type: A
202.97.174.82
DNSbgp5.yandui.com
Type: A
222.186.60.11
DNSbgp5.yandui.com
Type: A
222.186.60.10
DNSopt.dl.glb0.lxdns.com
Type: A
70.39.191.87
DNSdownload012.rdb.cnc.ccgslb.com.cn
Type: A
221.194.130.10
DNSimg.freep.cn
Type: A
221.234.36.242
DNSimg.freep.cn
Type: A
221.234.42.184
DNSdownload.2345.com
Type: A
61.147.127.202
DNSdownload.2345.com
Type: A
61.147.127.203
DNSdownload.2345.com
Type: A
61.160.245.8
DNSdownload.2345.com
Type: A
61.160.245.11
DNSdownload.2345.com
Type: A
61.160.245.14
DNSdownload.2345.com
Type: A
122.228.248.3
DNSdownload.2345.com
Type: A
218.75.155.244
DNSdownload.2345.com
Type: A
60.191.187.15
DNSdownload.2345.com
Type: A
60.191.223.2
DNSdownload.2345.com
Type: A
60.191.223.4
DNSdownload.2345.com
Type: A
60.191.223.15
DNSimg.freep.cn
Type: A
221.234.36.242
DNSimg.freep.cn
Type: A
221.234.42.184
DNSwww.3n8n.com
Type: A
118.193.155.117
DNScdn.pcbeta.attachment.inimc.com
Type: A
DNSdown.tianyunxj.com
Type: A
DNSdown.xiaoxinrili.com
Type: A
DNSxz.dianxinshu.com
Type: A
DNScodown.youdao.com
Type: A
DNSwdl1.cache.wps.cn
Type: A
DNSd3.freep.cn
Type: A
DNSjifendownload.2345.cn
Type: A
DNSd2.freep.cn
Type: A
HTTP GEThttp://cdn.pcbeta.attachment.inimc.com/data/attachment/forum/201409/12/173937imav9yvcycn3akua.jpg
User-Agent:
HTTP GEThttp://down.9vh.net/appers_7_1958.exe
User-Agent:
HTTP GEThttp://down.tianyunxj.com/tqrl_97_1957.exe
User-Agent:
HTTP GEThttp://guangqu924.oss-cn-hangzhou.aliyuncs.com/gqbb24_mt1.exe
User-Agent:
HTTP GEThttp://down.xiaoxinrili.com/hezi/jm/setup_t10303.exe
User-Agent:
HTTP GEThttp://xz.dianxinshu.com/download/setup_s1020.exe
User-Agent:
HTTP GEThttp://codown.youdao.com/cidian/YoudaoDict_silent3.exe
User-Agent:
HTTP GEThttp://wdl1.cache.wps.cn/wps/download/OfficeAssist.0195.80.1054.exe
User-Agent:
HTTP GEThttp://d3.freep.cn/3tb_140923192942q71f538987.jpg
User-Agent:
HTTP GEThttp://d3.freep.cn/3tb_1409101837529hro538987.jpg
User-Agent:
HTTP GEThttp://d3.freep.cn/3tb_140910184804w6i0538987.jpg
User-Agent:
HTTP GEThttp://jifendownload.2345.cn/jifen_2345/p3_kbaidu888888_jg04OunlF483lZatm6Ir5_v14.7.1.exe
User-Agent:
HTTP GEThttp://d2.freep.cn/3tb_140910185403kcyo538987.jpg
User-Agent:
HTTP GEThttp://d3.freep.cn/3tb_1409101919002w55538987.jpg
User-Agent:
HTTP GEThttp://d2.freep.cn/3tb_140910182900qy6q538987.jpg
User-Agent:
HTTP GEThttp://d3.freep.cn/3tb_140917191931o0a2538987.jpg
User-Agent:
HTTP GEThttp://www.3n8n.com/xin8/mail.asp?qqnumber=&qqpassword=%20%206
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Flows TCP192.168.1.1:1031 ➝ 113.107.42.25:80
Flows TCP192.168.1.1:1032 ➝ 222.186.60.3:80
Flows TCP192.168.1.1:1033 ➝ 183.57.148.246:80
Flows TCP192.168.1.1:1034 ➝ 42.120.230.9:80
Flows TCP192.168.1.1:1035 ➝ 183.61.19.169:80
Flows TCP192.168.1.1:1036 ➝ 222.186.60.11:80
Flows TCP192.168.1.1:1037 ➝ 70.39.191.87:80
Flows TCP192.168.1.1:1038 ➝ 221.194.130.10:80
Flows TCP192.168.1.1:1039 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1040 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1041 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1042 ➝ 61.147.127.202:80
Flows TCP192.168.1.1:1043 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1044 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1045 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1046 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1047 ➝ 118.193.155.117:80

Raw Pcap

Strings
^G>
r.
.o.
00
.
n.P..
..v..n$
sv
5.
C
.~..
`..
g
.
..
.
.,}.
..
.S
.
fF
k
8 cX~
.
.
.g.u
^G>
r.
.o.
00
.
n.P..
..v..n$
sv
5.
C
.~..
`..
g
.
..
.
.,}.
..
.S
.
fF
k
8 cX~
.
.
.g.u

>	>">.
&^({[#
#$%&'()*+,-.//:;
0 0&0,025
010:0G0S0g0m0
@&@& $@&@&(,@&@&04@&@&<8@&@&@HB&@&LP
&%070K0_R
 (08@P`p
[09$2!%Ek
0A@@JX
$`0d\(
0h	R[)
0IB|NR
0{mlj0@PS
0P]RjT
0@P`T[
0r;3B,
0s32ftaNpK0
0x0Y(p
;1;?;{;
:">(1"
1 1$1(1,
1%1B1U1^1
1c8g8k8o8s8w8{8
1(d(dJW
1dfBl;`
}1h%H:%M
@1I,bB
<*>1>j>q
1K)3X8
1q2	2C2
1#QNAN
1r1v1z1~1
@1T9p`t
2(252;2O2
2 3-4a
?"?&?*?.?2?6?:
275622D8D
(2,$,&8
2B88P*
2fc|9%)
2g:HTTP+
2hWe`L
.2i,9M
2%IE(:+I
2p*S?f
2q~8!8
2QK( @b`
2uh#7hk
32@3L3X:dP
32\taskmgr.exe
33'E0xK
35138b9a
:(>->3>8>Y>w>
3c5W7J
	3\*Hp<
'3tb_~23
3#YE&!
40.JPG
456789abcdef
465p5X
4804w6i03
4,84<4\4`
4C4444
4D<4,$
4\<`<d<h
(4e&3F
4~f9.u
4h88[e
4n85h'
4+PPR?
4RUv! !
4v11(pQ
4-)Z>M
538f494a2afdb0c
5(54~H5h
"57-1546-4l
59@9y9
5A'O)t
5AqX0A:vsXU	F
-5d9fbd-8
5DbSdT
.5{j9ika
];5v7mX,
!5YCHO
60[awbw
60/?k9879215
6@@+3;
6(6/6N6U6\6c6
6,686<
6"7-7Q6"
6A(hC+u!h-
:6doOxIM|[
6k>o>s
	6l7hl-sms=
6Q617]7
6Rmo_P
6TJ)pl
<6Z2ea
7$:(:,
7^3&0J(W
75f06e
7654\r
77>7E7L
7/7Sr"
7)8j<A=X=u=
7J-%$J
7K8\8j8
7 SL,-
7uL4``
7V;,0,27Ah
7xky.we(dw
818;9X9
<840,(y
:8642fc
8"8(8.848:
8`@8Vf
]8.9|9
8au'ru!!u
]8bj)Fe
	"8bY;@
<8C8J8Q8X8_8f8
8-DUA,
@8ge;S
(8l@03
8l2F`	
8R9-_m
`8	ULP
#8UP*$Jt
+8Xk/'X
=8XObYF
`8Z8d8
9@%1#i
91\N$2
92.e:$:
942q71fF
98:T:\:
9F^Hbl=v
="=9=J=
9 NT *x3Y
?&9T$~
9Y:2D<5
(<$'-A
A0;8<l
a0X`H-
a3^(A$*
\aal`e
<=>?@ABCDE
%A/CJG$
@ACL@TM
ACPgR/S
ACUc|0S
ADVAPI32.dll
ADVAPIa
AfxOldk
ah0wN;
Ah1S2fI
%AH70b
ais#"T
aj\[K`
A:/Kv`
#]a`l	
and Object
%a%p+$
Array<char>
as about o
ATL.DLL
\+A*-u
	AU!M8
B127.0
>B>_2.
b,2Nqk
B-2tp$
 @B8TK/U
ba4,PR
::bad_a2v
* B(B6
/bbsWF<
**BCCxh1
"~b.c: L
+BE!'n
b.fdf4
b<F<Hi
BfJcG GH
bfndmm
^(bg_T
BitBlt
bJ~6kf
'']bkI
B\l==%J
B!!?m|
:B>n9<f
Bn&WPw
Bp#Q_y!
,B$$R.
bR@<@u
BsM.\8
Buff#Uppw
BWideC
-B,z>>
Bz:F(a
,B,,`ZP
%<BZ$=YvW
c4 f	f
,C4Q4a4p4
c71cb684l2c4511da95
c87C`;5
CB;Zu$&
`,Cd/4
CDt<yl
CH[D	}
}ciI/m
^*}}CJ
++cK`u
ClosePrinter
?CmdTar*t
COMCTL32.dll
CONO1F
CoUV[Zk
CPPZbugHook
cripth.
cs{dsJ
|C/smJ
curityP
$Cv;m{
CWinApp
d,000TL!'00
D0J0P0V0\
[:d0x|
d1.0">
.D2qP&
D<4,TB
D6@4R2
d7gAqE
D7m7yW
D7@]Z/u
D9_Pt?
dBc*m>r[s
=%dcx+t)
	|DeawmS
DefaultI0nB,%7
d\Fold
&D~j2H
D}^J:Z
]DoD4t
dqw_3104-4
DragFinish
DWORD4
dXP^D@
)dxu2h=
E7 -a5
|?Ee'7l
EE`xTb	
@e\=Fx\
 Eh595b64144ccf
EH=u$C%
~`eh %V
?EINSZy
@ejz9#3
ek(&/(
EnumDis
e)$@Q 
-]erFg
&ER)i!S
ew_9d"MA
%e_`)X
||ex7,
e>X86"6
ExitProcess
F0Rjh"
f1r3|3v3
f22HuH
f7j7w7
f9]8	f
\FbT?A
FCzp~P
FfnwQh=
ffs)M)
FFX.8TS
?'fg?t
F]ht_Y
F?J?N?R?V?Z?^?b?f?j?n?r?v?z?~?
/Flmat
f{mbA91
F-.nns
frm(b$|
FR}'NY:
}F,tv(V
Fu@7R&Z
f*x.85
=f;*YF
#g@=+}
G)0+XR
>g5H|+
+G731o0a2
G8*a{=
%}Gbis
GDI32.dll
GetM i
GetProcAddress
Gh5M p
GhProc423' 
:Gj"NY
__GLOBAL_HEAP_SELECTED
}~%GM+
g{+-(O
,G]ST?94952
@guo5tqr
gUQPXY]
gXF*d7
$	gxJv)
g}ZvooB9(
%<GZ|w
H0GPR1=P
H3E{D8
'~,h%4
h6l Dlg
	h/8xr!'
H9NvZz9f9l9r9z9
HA?@[ 
}haZp~
HCun_1'
"H#D$@'
@H)E+jR
h?I|(i
HKEY_LOC
"hKp{oj' 
"(>H>L>l>p>
H:mm:ss
h<P(S2
h(T:\a
`^>Htx
huK&9m
i5h"/@
I9hlkF
`IBck_/
IB.J#;^
ibL4saF
[IjcpP
IJj1>$w$
ileNameW
+i!l'P
InternetOpenA
i:r:~:
IR(K`p
@ise,rp
[IT(_j
).iU2A
ivJJ@%
i\WLf6
IXrHyNZ
i:Y`Gv
IYI\QiyiI
^IYK	?
j8j ^EHvN
-japoO7notzW
j{AS	7
{j{dxLH
jf,;;&
_jg04Ou\F483lZatm6Ir5_v
;j`h8N
j,hROR
j\HZ,$%
JiLUR1
jmx#i-
^J@][N
jO57q2
:jp:e/
jW!A'WClose
j.W)uQ
jXB4&y
jXI-B@8D
 JyO$|
K0[|ub.al
+k7hPD
KbCryptKeyCacheI
K&B&`l 
Kb<,n	
K"@d|%E"F
kd	wVJ
\@KERN8
KERNEL32.DLL
KGD!#U
K?;hPb
+[K#*J6
.k JN%#
;k=o=s=w
kp7qE"
`kQ_7_1958=oP`
k Source D
K{,u7V
 k?uFF
K\w1SX6KP#
kWwktZ
K >xZ[
K_Z4:P
k[Z`m[G
k	z` U
l1M_9/7M
l\3Hf$
L6d6h6
la/4.0 (
LE(PjB
/LfarV
Lgju}\W-,M
`(`;l&I
LJt|f+
;#<l<-<=<J<z<
.lnkw 
LoadLibraryA
Lo$upYC
;L|x#U
,<L<X<x<
l.yi85
_>|l^Z|[
M{+00T
M0s041
M#;61k
@m7!Qc^C-
MACHjE\SOFTWAR
-!MA(+i
MaM/=Z
m/bC1RQ
%M<<<c4
Md 7:.
?-mEpg8
m<G;||
MGWM( 
?m"i&d
MiscSt
MjVBN9
_mKE|%
mL\vJb\0
m'#njV
{mNotf
M~O4n4v4
=MODULE_?h
mPgBH,(.Y
m$qqri1Free3pv51k
]mRYPQ
mS (j6
mt1CY?
&+MTo*P
MU'`FdjB[
MuQlQp
?mU!(r
m'utomcn
|m"~X=
n3SZ/B
\nb;"{O
NcS9X])d
nDbev+
NDh&%X
nG8`/s
NG_NO&
NH-6>Y
N@kKjE
nN}>mJ
n%O"8P
no"IlX
No such.
NotSupp
@NP0B"
nPS }>v`~p,g 
N$R8Nd?
#nrO-uID
}$-N&s
ntf :Fx
nt>j,BU
n:*>v+
!Nv[.D
NW@8)l
n_X$\0t	0
nxj{U8Cw
 (Nx>X
&$o0Ei
O2AYf|y
o6rdon
<O#9Oe{
o.a0)Q
OEOLEPRO
OffHA4|
OK gC(Y
ole32.dll
OLEAUT32.dll
oledlg.dll
OleRun
omPoiz
'oO{$B
Oo!+Ba
 oOl7Y"
opyright 19
o;|qyJ
oRFxEN
*osdBE+8d
,$]OT[
oud:<=b4{
OW_of@
OWS\s/
oZav9yvcycn3aku
p{4LC2U
p5pxEo
P90H3Q
PathMatchSpecA
pDNI a
^_PeIa/
?PHA.;
)'PHea7U\
piW0gS
)P+"'JpO
PJ\TAO@
?P,K_|<
pkcW@$
<? p\[;`l
#PL-(;=
play/L
Pm0-'u
pn`P,R
>PPADDm
P~P<j`
pT__LB`+
~Pu"hi
puX_b!j	=
P'XA!P;
 p@yAp
Pz::@@A	
pZp~d2t
q0x%lR
QAuto=1
qAuzj<I
|qcW.P
qdb':O
[qd!EAI	
\QI6N$
`qi7gq
q.I@c@
|@QlR 
qptfV?X-
	qtn,=
(%)|QW
 R_0X.
";R83`$
R8F196
r,9Y`Q
RA1Ffg1w1
r\Adv~Ml
Rc?THREAD@
rd0}k?s
rdhlptr
`:R/*Drz
RegFlushKey
reviewPages
rf2w!*
;_rF3i
r<%GPi
:'RH_k
r: m.v1"
RoRuun
RPyHSy
rs0~2+
rs\etc\ho(s
rwiqa^
rXtR99
RxY rU
/%<rYRV
'R.Z8w
^%S0WM
S3Y3d3p3
S6`JDk
Saf1Dhk
s+-AIS
S )Augus
SB`>H^0-
-sc7_P
:sch&b#
sctorgk
sf8002*<>|"
s"F+,d
S_g	S(
shadu007qsd.k
SHELL32.dll
shHNGm"
ShL]'W
shlw47D
SHLWAPI.dll
si!9, %8
_SIMULATE_TLS: 
si)xf"0o!
}sl\C$
sO;>|C;
s	Py$h
SSES_ROOT
!s#u{#?
Svc?P`
*Sy*o&
syP <$ `
.,$s/z \
s_ZDWQ
-t,0tRC
t|18P<
T2X2h2x2
t44 ,;
T4b}B.S
`t4=Ft
T5`5ltA
t 6zVhDJP
t8lBar%'MD
~t^9(uZ
$T:a*s>zP
?T($CQ
tdTJ:,{
tfk('T
TG3NtR
!This program cannot be run in DOS mode.
Th spa
Th$s'Wed
~T$*L$
tNJ@p	GQZ7i
t+\nPj
TNXwX\
t;,oxA
>$T@p<
TP3|/I
)TP8BF
TpcLC|
t*SWp7
ttp://
tUZ\PT
t&=,VgD
TV`\W8uU
tw\E|"*
?T?X?h?
t=ZVP	
}tZ|vy
u09=`^u
U0s(VS
\U]2&%
[U_88|
.u8(Q(
uA ( HH
U.hU5R
uhWQQv
um;219.235
?Upbe%c
?Us6Ex
USE`64
USER32
USER32.dll
uvwxyz
uwdlhc
UWh!MC
V2% Cn
v4s+^,(8	7
V50vi(8PX
!Value
VC20XC00
vc521s`fs
@ |.VD
+VdU8P
V|EHVP-H
VERROR)
v'Frre
VFY	0U
!Vge&N
VirtualAlloc
VirtualFree
VirtualProtect
 VisUC++ RA
VR".~DN@t
,&[vrH
  vRichEdi
V\`\s/o
VSPLAY&m|rl_DZ}u
>VUSWY
W)1930,H
(wbe*!
w@FBC(|
W*GRFF+
whU2G6
WININET.dll
WINSPOOL.DRV
wi}sjxun
-wj-la
wLVSPl
.wr,mjv
Wr=Y6kt
wsgwdnI13
	(Wt#6
@Wtcf/
w	 UPdR,lP
W',*VeT0;
WW>.m7
X<4F0!'
<xbRD6i>
X%C@+X 
xiGtt4
xijklm&pqb
xJS>h:V
,XKtU?
XLHXVc.`
xmlns="
x ^N._
XPTPSW
~XtB+<9
xt@H6&y
X tnj=
XTPLHDy
;=x}W=7
XYZ[\X`?
y@<840
\*@Yf+
  %Y}I
Y>pDc_WL
yPibly@
y~p`L8
{<:y&q?	
.y-upp;
=YuqD[o
Y+vl+^+:2X
ywf>?77m:
  Y"y$YS>
]< }z"
z64lbt4xk
z6adkC
Z?_AFX&
zBjP AR
zi/j!m0
(ZLAEa
Z,MD[6
Zmi7DFl
,,ZN0Mt
ZN	9h<d
z{$ vt
ZwKO`]F