Analysis Date2014-12-12 20:31:19
MD50bb2e6f6935b7e0367fb2bd7aee97fd6
SHA151f3af2c15d4549e602aabf46a55e62ec8448bc3

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhash7bfd043ac63ba2facdc9c3129ea88fe8c8472fd7
IMPhash
AV360 SafeTrojan.Obfus.3.Gen
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)no_virus
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99a1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!0BB2E6F6935B
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.zip
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\MQoMEIoQ.bat
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\MQoMEIoQ.bat
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.zip
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.zip

Creates FilePIPE\wkssvc
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.zip

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FileKQsY.ico
Creates FileC:\RCX2.tmp
Creates FileIYYw.ico
Creates FileIocM.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FilegwUS.ico
Creates FileQEYE.exe
Creates FilewIkO.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FilegsAc.ico
Creates FileC:\RCXF.tmp
Creates FileC:\RCX12.tmp
Creates FileswcI.exe
Creates FilewAAe.exe
Creates FileC:\RCX18.tmp
Creates FileIkQy.exe
Creates FileIIMs.ico
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileIcAK.exe
Creates FileMogO.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileC:\RCXC.tmp
Creates FileUcMA.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileC:\RCX9.tmp
Creates FileuoUA.ico
Creates FileogIc.exe
Creates FileCQka.ico
Creates FilePIPE\wkssvc
Creates FileqYYg.exe
Creates FileAEgy.ico
Creates FileogkO.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FilekYEQ.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FileEQUA.ico
Creates FileC:\RCX1D.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates Filewwgs.exe
Creates Fileukke.exe
Creates FileGMEA.exe
Creates FilekcAw.ico
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FilegcsQ.exe
Creates FileYAgA.ico
Creates FileMYQi.ico
Creates FileMAwI.exe
Creates FileAIQI.ico
Creates FileC:\RCX17.tmp
Creates FilewkYo.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates Filewogq.exe
Creates FilegwIE.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileAQQe.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FileGUAE.exe
Creates FileoIMK.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FilegEUo.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\RCX3.tmp
Creates FileC:\RCX20.tmp
Creates FileC:\RCXB.tmp
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FileuAQg.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileycQG.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FilewcwY.ico
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileUsMc.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates FileCYMo.ico
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1.tmp
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileC:\RCXA.tmp
Creates FileC:\RCX1F.tmp
Creates FileC:\RCX13.tmp
Creates FileC:\RCX11.tmp
Creates FileC:\RCX21.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileC:\RCX19.tmp
Creates FilewoYa.ico
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileC:\RCX1C.tmp
Creates FileUEIk.exe
Creates FileaksE.exe
Creates FileIwEI.exe
Creates FileC:\RCX1A.tmp
Creates FileAkcQ.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileYQQq.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FileC:\RCX8.tmp
Creates FilecUEu.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FileMMQI.ico
Creates FileYcAM.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FilePIPE\DAV RPC SERVICE
Creates FileQAgW.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FilewooC.exe
Creates FileMAUs.exe
Creates FileC:\RCX16.tmp
Creates FileUEAI.exe
Creates FileQMES.exe
Creates FilecgYm.ico
Creates Fileccck.ico
Creates FilecMMS.ico
Creates FileC:\RCX4.tmp
Creates Filecckw.ico
Creates FilecQAC.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates FileMgwK.exe
Creates FileEQQC.exe
Creates FileYkMU.exe
Creates FilewkQc.ico
Deletes FileAQQe.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FileGUAE.exe
Deletes FileoIMK.ico
Deletes FileKQsY.ico
Deletes FileIYYw.ico
Deletes FilegEUo.exe
Deletes FileIocM.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FilegwUS.ico
Deletes FileQEYE.exe
Deletes FilewIkO.ico
Deletes FilegsAc.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FileuAQg.ico
Deletes FileswcI.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FileycQG.ico
Deletes FilewAAe.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FilewcwY.ico
Deletes FileUsMc.ico
Deletes FileCYMo.ico
Deletes FileIkQy.exe
Deletes FileIIMs.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FileIcAK.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FileMogO.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileUcMA.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FilewoYa.ico
Deletes FileUEIk.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FileuoUA.ico
Deletes FileaksE.exe
Deletes FileogIc.exe
Deletes FileIwEI.exe
Deletes FileCQka.ico
Deletes FileAkcQ.ico
Deletes FileYQQq.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FileqYYg.exe
Deletes FilecUEu.exe
Deletes FileogkO.ico
Deletes FileAEgy.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FileMMQI.ico
Deletes FileYcAM.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FilekYEQ.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileEQUA.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FileQAgW.ico
Deletes Filewwgs.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes Fileukke.exe
Deletes FileGMEA.exe
Deletes FilewooC.exe
Deletes FilekcAw.ico
Deletes FileMAUs.exe
Deletes FileUEAI.exe
Deletes FilegcsQ.exe
Deletes FileQMES.exe
Deletes FileYAgA.ico
Deletes FileMYQi.ico
Deletes FileMAwI.exe
Deletes Fileccck.ico
Deletes FilecgYm.ico
Deletes FilecMMS.ico
Deletes FileAIQI.ico
Deletes FilewkYo.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes Filecckw.ico
Deletes FilecQAC.exe
Deletes FileMgwK.exe
Deletes FileEQQC.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FileYkMU.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes Filewogq.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FilegwIE.ico
Deletes FilewkQc.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.zip

Network Details:

DNSgoogle.com
Type: A
74.125.229.134
DNSgoogle.com
Type: A
74.125.229.135
DNSgoogle.com
Type: A
74.125.229.136
DNSgoogle.com
Type: A
74.125.229.137
DNSgoogle.com
Type: A
74.125.229.142
DNSgoogle.com
Type: A
74.125.229.128
DNSgoogle.com
Type: A
74.125.229.129
DNSgoogle.com
Type: A
74.125.229.130
DNSgoogle.com
Type: A
74.125.229.131
DNSgoogle.com
Type: A
74.125.229.132
DNSgoogle.com
Type: A
74.125.229.133
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 74.125.229.134:80
Flows TCP192.168.1.1:1033 ➝ 74.125.229.134:80
Flows TCP192.168.1.1:1034 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .


Strings
..
.jaX
+.
t
........................
-"!';1
.1=1
c
,?~>*\
]+/>-{
+^ ;?~[
028<4z
@0(4k@
;0aL\u
*:!0b{
0cAEk;
0``f7r
0iXybs
]"0|jr
]0%jy|
0-.P2O
 0%;QmJ
`0[ruh
0SpnGd
0z{2]X
129&Oy
1	`A~co
1aWKP4
1I82Qx1
1!j+u;
)[1Nc>5h
1+ObqL*
_.1pj)
1RbA+q
1R)U?Z
1)sds_
|1tB~D
1*W/O\n<A
='=[")2
21hx_h
2aLgra
2l!c5v@
2	MWra%gpaM
#2q1"NNK
367vTyV
/38;;[
39'C_Q
3(#_I!
3&LZ{/
&}]{3y
4B-*EB
!~4I8Oq/
*4~I%x
# 4jk}
4N{3Kh
4N{3Khh
4N{3Kh;q
4N{3[x
4pi1;V
4QLklzt`
4qT&b)
4)u0EY%
.4*u>_lR1
4vo3Kj
4vo3KjD
4vo3Kjj
4vo3Sr
4vo3Sr#
4vo3SrI
4wMW$6K
4z"K$p3
529o)*
|5_4\}
\?5~$}F
>5jWXu
5lB\oF
5sj'5?&7
5T~9!U~
5;]uk=
5vz;3CLv
5;V"Z"y
6hs>2m9
6Nx3C`
6Nx3C`3
6Nx3C`C
6@tuQS
]-6Y.b
6yyqXbv
79R\)3
=?7([b]nf
^7CX{=q
7@D!r9S
>7=i>g=
7Ny3Sp
7Ny3Spj
7'^OhIoub|d
7OuE-M
|}7Sj6
7vo3Sr
7z4J"=
85-VS_F
8.AWQl
+8CE`5
8dq!%zQ
!8$HG<GX
8Mzp:Iz
;8Q&tg_
-8.r)seZ
8TDU5%	
"8U3gA
	8uy!x6
&:8{*W%#
!9#06H
91)/@,
95^,Ph
9=)5Q*
^~9f{]
 9<Gs;{22
"*9lVQ
9#{LY:
^9.@r1,@
9rEI/28$?f
^{9Wk;
]\9x>}x
.9`y ,G
a8eGYh
(A{`[A8
a-Cr#sV
Ac(Z-S
A>-fd=
aGkDjI
a}gr	Mbra'g
a!GsOjx
>AHQ;r
aMgr1'g
An1cGJ
a nF7{
aOiSL?
a'Pbcc
A"sh~aq@
.}Atjs+
AU6:6j
@avNe$4
A W`_(r/
aYb/tC
A(zK4'
B[?|[\
	B4VFM
B7J,<uAb
.baf_g
=b#Ce}?
b(	D7S
B{f"uD
bH3NAN
B[H9|'
bji4F=
BJry1z-
)B}lXG{9Y
BrNI	(
%b:t3=
bUc4Al;{
bU	gM6
BvZ\yh
B~xQpW
bxXK7OZ|`J
,C[}2m
C9"Ny;J
c^{AA@
C;_a{N!
c|AV>t
C!Bs;*
\(CceK+3p
']C-Cw
ceW[8G
)%[cgS!W[
cH"vl	%22
*CI>ti
$CJh?H
c)KL2+&
c=LO@oi@j?
:{/,Cm
CSCW).
cxM\t-?4!
`/d=[	
d-7);Wj
D$)beb
dbp *=
|d?f:)a
`d:g>xd
dhS'/u
DIt0sj
<dKc'|/n
$Dl0&i
[]Dl;2
,`Dl>O
$/do|1
!dTPTU
[duxCV
.Dvnhd
Dw,CHy4
;dWvySpW\
=d=Y-c
e41+\X
#E6C8~
E~%8H@
_ea8<Jp
_{ebv-
ec9@A1
}.ecKC
=Eg1\e
E$G~K^
e,h7*^e
EK1H*cJ
$e.|'khT
E|O>h3
]eon=B		:9
;E)/]q
esOH/s#
Etv	`z
Evz;3CLv
{EwV#Y
,:)%	]F
&F27\p	jf
	F5u'J
f\:^6w
;"&F7`N
<F7oW4
	fa!gZ
.fDC]a/(+
F!?d{P
F!?d{Q
F!?d{R
F!?d{U
F!?d{V
F!?d{W
fE?:cv
Ff;?M,;
Fh@1&j
.fj?lk
]F/"L~%!
flI_sF
F*L--O/
`#fm3 
F	.mF0
fMgra%
FmiW]D
*fo,#u
%Fr2w{x
fSG>6j
fSG'6Q
fSGJ6U
fSGr6(
-{FUxjS%n^
F?`V/n
^	Fw|i
FY.LkY
*)fyrh
fzUi%KM
G]0mBClG
g{bz#oE
GcLUa'
g#{DT*
gE|>P.L
+GFps<
GG%._Sy
,g_gv'
{g{?II5
gJ9GK-
-Gk0k>
g~:?L5
grxD1I
,/Gs%>
]`{]|h
h55^iI
}h8f)t
hA[A01^
HbXzM{
HD2b+*D]
hgHbj'
[h])KGl
h*lUW;%<
HmH|]H
H_-m?Q
%#H.#N
(,hr~g
h]R&NM
>hT8)x
hu>Ra	
	`h{vwE.9r
^*h~wk
hXr)CK
(H"x+X
:]*I~)
I3gQGr
i54^kI
,-i8ep
IAeh~z
if)f^n
IFhf)Y
ih8d,0/	!
IiH,K(
,IkG2D/^
`IKR`GKM`RKP`TKO`5K
`IKv`pKo`eK
i|O>h3
i-/~~pN
IQ$=gi
(~i&Ra
I>tmpM#
Iw'+0U
=i.wA"
I-XJzRrJ 
IxOcul
{$+I=;YP
j57^kI
j[A6.7X
J,Ae)VZ
#jcw{"
jd0z_`
j*E*[4
JHo'xA
JJKCvm
J~pl']JR
jQ:$)#
jQV'p w
?J:'& rG
JR	juh
^JS5^E;
jT?WB'X
j`?VAE
{;j!)y
jz?nxay`
K1VSh;
k2i8\|
~K54N{
kATi7J
+K}AvPv
K^`BKk`{Kf`zKu`fK
.:$Kbz
KdmAIz
ke2&Wd
K^`eKp`zKe`gKc`xK"`
=kel_c
KEquKKY
{k`+f 
$kf:SL
[/Kg:n'
k;GNg-
kk2{:[?fl
KK.&Dd
K`kedT
KljPL?6
KPscH\1f
Kq)v^W
k$r057
~K>r28;Xe
kuFV&3
,KuHPI
kU@hq fvde@
KU}W1Y
;+K.xP
:|=-Ky
@Ky8eu
;Kzb(5Q
_.*}L=
L\4UDj
l=5Luh
_L_|$7
ldpmr9- 
l:i:9-
_?l]-K
LkH*Y3
(Ll0>&
lOy,F]D>
lrAKr~]
lr;pky
lrs@k}
lsZC |
Lt6+TQv
LT%m9\
LVbWey
',lxs!I4
lXsn,FU
l.Z-aj
`lzHIJ
M!::|1
M!22^,
m'[4)<
M5$e'2$
M#8ASm
=M9{YW
}[MAKLkV
^{:McF
mCh(eTU
MgLGeP8
mH4Ab6RD}jxaMgraMgraMgraMgraMgr
m{H{#5
M,H	d8,mNqn
m-p.Hn
mS06PX
M	Sh8Vk
\mvlsq
(m}v_T
!MVwB6'r
Mx+((*
}:mx^K
:Mzr9'zr9%z
}N_1_\
N_3|'"_
/N6fbE
\n9Z?9:
ngdb0Y
\nheB8
_;NiAv
.{NiMhc
Nj"7].
)_Nk3[
]NQ.1+l
n~!QBp
nsd-O43?
{_nu,,
}nxay`
}nxayh
nxayh8`v
N"@"X\D
nxdy`O`v
?nxey`+`v
#nxey` `v
ny`yi6av
O~';<_
o*/0W*
=O1MR(r
O1wiFS
O;9DWu
oBzj "
(o$?=D
oeP7m4
=OGQdYW5
(|O>h3
[|O>h3
 o>K//
OoP/n*
O}PN_M
opv8mb
=[Oqkq.
O)}.sf,Y
O/s	P%moeN
O T+eg
oUR4Dt
OWdp17
~Ow&KW
OW*Ol&
Ox1'ra8o
OXCF28j!lA
o"|X#FU!{
OYB}dR
#P. `$]
-P6+TWt
_P88z|
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
PAN qwy
PdHNkFN
{PEi=I
pE+x+6u
 `. piX:
.pJOds
p"{jz6d
P+K(}^
_P*~mY~S
p&NtWy
PpV<7*
PpWe<F
$pS;t*
P[uaO^
PU+o}aF
]P wF:
p[Y=K^
Q-~$["]
Q;AW)}Qp
#QdO@?
QGei^kT~
qHbeI\
)QhDv-
Q$(j%8
QJC|9g
qj	.d9u@
Qjj c%
q	{KYI
^{:QlT
"QM4&*r
qm*ND3L
qqM#h9%
q(v8_U
QvVC2g
Q}_W_1
:qwM>laS
(r}0l<2
`R1]#+7
r4vyhug
RBJXU"]
::rBy}
Rdh' N3R
r:edMz
REmNls
/R!E{v
Rich!4O
RmhZ<d
R>O+tX
RPU[y'
Rq-ot*i
RSD-7J
rvRa2TE
@rW_%=&c2
RW^@yJbJC
ry_*vls
RZinP(
*S1*Z}
s![4r.
SA]K~9WP
=^"@Sb
SC2Ouc
&se\6"
^\S *E;d2!y
_sew9Zh
&!SG"2
&SG\.S8
s(]h	qb<
s	hRhb
S}']hV
,sI/T'-
*s/Jf;
{`SmLxO}j
]smU7m
#S<Nbj
S`[.-P
;SpnGd
}~SpnGd
SrRmzo
SsiaTQ
S {tix
-SuF<Q
sy|vvl
S?ZNv;D
@t)3D7
TA9y&x
TA:y$x+
;=.TbN+t>
	^`T{@{E
!TF@aL
t,fc1[
#t/FC7Gl\
!This program cannot be run in DOS mode.
Tl#;N7
.T^O4`*
Tpsn\f9
t]Q5IF@?
tQu1tNi
  tr#7
+]t)()V
@t%=vDz
%tw.:E
T+y&AY
(u0n>cg
(%U5JL
+U}a^2
Ua,9OH>-D
UcV3Y=n
Uh+.2O
U|Ik{L
uKhhgY
ulZbhzua
UmNUf^
Un)-E~
uoNhjI=
UrB^NW
UTUzqP
uuHsLq
u-WKy1
v4XJAd|
V830JG!
v88""[W* 
`v$B3 f
 vD~PvV2
&/vf3uJ=lf
- vfL%
v`$h/>0
V&ipl"
vJcG0m9
	VL&bii
`vls[?
`vlsn~
&vlsR7<|
vMX]s/
VM?y!-"hiE
 vn{`v
 vn{`vV
vnxay`
`vnxey`
`vnxey`)`v
 vP#bv
 vP#bvVW
Vqk7>;]
(Vs5W!
`vSB,6
V(=S'sT
;vTb`v
"vv1VvV"
:"vV5#
`vVFb}
`vV@r9
`vWCoC
"vW]/o
V|wvp3
VwzOYmKA[
v+\ymK
$VY!]vW
vz;3CLv
,Vz5qr
{$w&+:
=W3)%Ad
W-[Bi[
W>csb,9
}wfFmlm
	]wGI	
~&?W"io
wJ~ap.
.:Wkc{
WL`m~I
wmN< =	
W.po`\x
}	WQsW
}Wr!	f
|Wrtu4
WTk:C[
W;>vls
wx1'raMgr
wx1'r`Mgr
wXjA.@
wz;3CLv
_WzCaS
!>;x&]
~X56Nx
/xBHT P>
Xf4e"/
XfHe"s
XJm<nu5W
Xnxayh
xrM^j[@
X^|sCE
xtisD)
-Y^?`}
]"#?|Y0.(C
Y"/2W4>
	y7qE&
Yab6+J
y:bR\xPpW
\ycNr|
yD5-0Ga
Y^fsS|
y(io@g
Y*}jtk
yJ==y7
Y<],L11g"
y>{-Lh
ymT]UN
Y(Pdo"
yPpVL:
<%#yrT&
YTy)']
YUY7\H
yy?9UX'l
Yz8WjJ'
yz;/;jVx+
.Z2[(lcW
;_z9UQa0X#
@Z_*`a
 zaMgr
ZDTOlG
}\ZHPO
z~I}*i
Z=irNAl
Zm|^P~	
Z^n4mL
`z@`?p
zQpnGd
~z{QpV
zTW\Y&-
?ZTZ ^'e
zXBpUV
z)?XEX:|
.zyPzF
,ZZ6$u
+ZzM,|