Analysis Date2014-12-12 20:57:19
MD50b1666f20ef6bf087eb9e2f7e2222a6a
SHA15720bcc2991038948b63062daf3a3cd158dafd90

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhash7bfd043ac63ba2facdc9c3129ea88fe8c8472fd7
IMPhash
AV360 SafeTrojan.Obfus.3.Gen
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)no_virus
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99a1 )
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!0B1666F20EF6
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\FAIQQgwU.bat
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\FAIQQgwU.bat
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates Mutex_SHuassist.mtx
Creates MutexShell.CMruPidlList

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Creates FilePIPE\wkssvc
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Process"C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileyUMC.exe
Creates FileSsoE.ico
Creates FileyUAK.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FileaQwO.ico
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FileqskM.ico
Creates FileC:\RCX2.tmp
Creates FileGAAG.exe
Creates FileOIYs.exe
Creates FileiwoA.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FileWIEE.ico
Creates FileeYUO.exe
Creates FileSUoK.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FileSgsG.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileqUoA.ico
Creates FileC:\RCXF.tmp
Creates FileC:\RCX12.tmp
Creates FileeAwE.exe
Creates Fileikso.ico
Creates FileWgsk.exe
Creates FileSEIu.ico
Creates FileWgwk.exe
Creates FileC:\RCX18.tmp
Creates FileSwEi.ico
Creates FileWwsM.ico
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileOcUo.exe
Creates FileCIMO.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileC:\RCXC.tmp
Creates FileGUUA.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileC:\RCX9.tmp
Creates FilePIPE\wkssvc
Creates Fileessc.exe
Creates FileeYIk.exe
Creates FileOYYQ.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FileIAIU.exe
Creates FileeQwA.exe
Creates FileC:\RCX1D.tmp
Creates FileeoUI.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FileeEwA.ico
Creates FileGosk.ico
Creates FileEEUG.exe
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileC:\RCX17.tmp
Creates FilemUwY.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FileWQsw.ico
Creates FileOoEs.ico
Creates FileaMoG.ico
Creates FileGsEo.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FileioQC.exe
Creates FileOEQk.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FileSUge.exe
Creates FileisUi.ico
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileGYUw.exe
Creates FileC:\RCX3.tmp
Creates FileC:\RCX20.tmp
Creates FileC:\RCXB.tmp
Creates FileC:\RCX10.tmp
Creates FilemoEs.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FileSoIq.exe
Creates FileGcEo.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FileyAwO.exe
Creates FileC:\RCXD.tmp
Creates FileeMsE.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates FilecAMC.ico
Creates FileOgwI.exe
Creates FileBsIo.ico
Creates FileC:\RCX1.tmp
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileC:\RCXA.tmp
Creates FileC:\RCX1F.tmp
Creates FileC:\RCX13.tmp
Creates FileC:\RCX11.tmp
Creates FileCYQe.exe
Creates FileC:\RCX21.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileGkEw.ico
Creates FileC:\RCX19.tmp
Creates FileWMUM.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileC:\RCX1C.tmp
Creates FileuwYE.ico
Creates FileyUgK.ico
Creates FileCoMG.ico
Creates FileaYIq.ico
Creates FileucAs.ico
Creates FileC:\RCX1A.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FileqkAK.exe
Creates FileC:\RCX8.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FilePIPE\DAV RPC SERVICE
Creates FileSgwO.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FileC:\RCX16.tmp
Creates FileksYe.ico
Creates FileqsUS.exe
Creates FileC:\RCX4.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates FileAwAS.ico
Creates FileOgkk.ico
Creates FilemAUU.exe
Creates FileogcM.exe
Deletes FileyUMC.exe
Deletes FileSsoE.ico
Deletes FileyUAK.ico
Deletes FileOEQk.exe
Deletes FileioQC.exe
Deletes FileaQwO.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FileqskM.ico
Deletes FileGAAG.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileOIYs.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileiwoA.exe
Deletes FileSUge.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FileisUi.ico
Deletes FileWIEE.ico
Deletes FileeYUO.exe
Deletes FileSUoK.ico
Deletes FileGYUw.exe
Deletes FileSgsG.exe
Deletes FilemoEs.exe
Deletes FileqUoA.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FileGcEo.exe
Deletes FileSoIq.exe
Deletes FileeAwE.exe
Deletes Fileikso.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FileWgsk.exe
Deletes FileyAwO.exe
Deletes FileSEIu.ico
Deletes FileeMsE.ico
Deletes FileOgwI.exe
Deletes FilecAMC.ico
Deletes FileWgwk.exe
Deletes FileBsIo.ico
Deletes FileSwEi.ico
Deletes FileWwsM.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FileOcUo.exe
Deletes FileCIMO.ico
Deletes FileCYQe.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FileGkEw.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FileWMUM.exe
Deletes FileGUUA.exe
Deletes FileyUgK.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FileuwYE.ico
Deletes FileCoMG.ico
Deletes FileaYIq.ico
Deletes FileucAs.ico
Deletes Fileessc.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FileqkAK.exe
Deletes FileeYIk.exe
Deletes FileOYYQ.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FileeQwA.exe
Deletes FileIAIU.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileeoUI.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FileSgwO.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FileeEwA.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FileGosk.ico
Deletes FileksYe.ico
Deletes FileEEUG.exe
Deletes FileqsUS.exe
Deletes FilemUwY.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes FileWQsw.ico
Deletes FileOoEs.ico
Deletes FileaMoG.ico
Deletes FileOgkk.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FileAwAS.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FileGsEo.exe
Deletes FilemAUU.exe
Deletes FileogcM.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Network Details:

DNSgoogle.com
Type: A
173.194.125.39
DNSgoogle.com
Type: A
173.194.125.38
DNSgoogle.com
Type: A
173.194.125.37
DNSgoogle.com
Type: A
173.194.125.36
DNSgoogle.com
Type: A
173.194.125.35
DNSgoogle.com
Type: A
173.194.125.34
DNSgoogle.com
Type: A
173.194.125.33
DNSgoogle.com
Type: A
173.194.125.32
DNSgoogle.com
Type: A
173.194.125.46
DNSgoogle.com
Type: A
173.194.125.41
DNSgoogle.com
Type: A
173.194.125.40
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 173.194.125.39:80
Flows TCP192.168.1.1:1033 ➝ 173.194.125.39:80
Flows TCP192.168.1.1:1034 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .


Strings
.
..
..
x.
.
$.WH.
.
.
E
.
)
_
r..m.'
k.3
k
..S..<
T..
X}....f.
..
]
..
r...
.
.
<.{
>[&*'/?
|"&_^'
 )[||\`
,06)dpP
06}!&?wb
;06yl1v
0e]M@1
:0f7C4
;0F7e4FR
0F7oWF'T
;0f}a;Fw
;0F)C8F2
:0FGg?
0Fgml(
;0&:g7F
(0Hp'jx3
0HrAhN
_0Jow|
0&|m4v
&0M NTQ
0~]uN&
+@0v_@0
-@0vg@
*@0vg@
+@0vo@0
*@0vO@0
*@0vO@4
 ]0!wf
0\Yy2j/X
14F'Dhv
1Dk3it#
)1[fvn
1+JOLRyq
1K?H|X
1.?Pt+_/
1saX&p
.	1&Z&
(25=Di
2&;$7f
29Apt{
?@2cEi
2L$OWS
2<&<"oj
2R7\f,
2scVl;
,;2sq&
;2TpjX
2(X_Yb
,38!'^M
/3/Fu`05
3M\-Av
&3M`vy
]3O?G[
3^oPdj
3	qTTJ
3[SI|1
}3v9IifD
[3VR|_[VK
@@4.?+
.406(L0v
$>44?8i
46_4MN
 4B-|&{
4b02<Or
4B3goJ
4F2DAP
4F2DHP
4F7D5N`d
4F7DD&g
4F7DD?n
:4F7DoI
4F"D	}
4F"D	L
4F'DWf
*4F'DWF
4F'DWF"D)FV
4F'DzG
4$kr-J
`4m#ng
4vA<Dgy<O
"'4V"D]
4V"D'#
4V"D#5
4V"Da`
4V"D&B
4V"Ds<&
4V"DTlF	>
4V"D"y
[,5}?{,'
 5)~0lC
5A2v7l
5A9;.s
5j[mRq
^5kw*&
5Lvd!b
5m&{W8
5Qnv9{F
5\VT\'
.5X2O^8-
@~5z;\
62UB`k
6$3s~7
#%69t5
}6:+D2
6[fl%y
6G[Lu=
`6iq}YJ
{6\J_!
6j3 y5
6JO[[u
6@+KdXD/
/6y3/1f7&
7[6{nk
7aD[I~
7C4F'D
7D0Vo`k
7\,H$<
7hfgXRR
":\}7I#@
7'!K6y	O&/
7'-K&WP
<7~)l	0D\e
7-	MuU
7 ps'*V
7qT)`_a
7}wQBW
[]-7Z$
/(88MO
"8AMBn
8b?bhzM
8D37IQ
~8j(.Jmz
,;8j^Y
+)8k*~
,8WexO
9]5pH`
.9*Am,
9D6 l2
9mr{='#Ss\
9!O]4GRJ
9P1;FQ
;9pa[w?
9VGp=)
9W^VbE
a0gtN'
A&?0q	I
"A*3><k)x
a/4Rbo
A4V"DW8
A54~S\
&%aA"=
^_AcM)
acrXC1w
Ahe@7E
ahhH7S>
anqM"saqdR
aO"f#?8	
A[OmeG
au+3e)
aUS!nU
&Avq){
awkPf,
b1'We/
B4V/G2
b6p_PE
b?%%<B4}|
~"%&bGo
B;| IW
BlEq73
Bl)sAh
)b?Mks
{bMxIL
-_`?bp
B<-Ra(MZp
bs$h[F
B/SJ7"z
b`:~:T
BT&7xSv$n
B]U-a@o
BX1P4.
B!&XB8
&b~yF9
bz~MjZL3
B'(zUr
C*3\WM
C7`)St
CA6Ih_u
,	Cdh	n
ce$!<:
[cF4Z@
	%)cI-
cOq)V+]q
c	P5c}
cPIuO,
CTx+{&
CW4;FS
_c^)Yi
,D0F'C
%D0fwS4
@+D0vo@0
-D0vrF
)D1V*d4
D3#2B3
_D4Bm~
,D4F"D
 D4F'Do,
-D4VrD
%D6F2[
 _D6s qy
D9"#V%
|-D?al
Dam{h\NilU
%@dCaD
)}dC!D
=*DCIb
#DCib%4
 $DCQr0
)D$.*D2
%DdCaD
%DdCaEl
)DdC!D
?-DeBE
DEyw>4
-/D>fR
=+D:Fw
;Dh)0x
_dJ}+i
djU);D
+DLI7hO
|d#oE?
+d	Or#
DTb''4
DVG4-a
*)dWNl'P
Dw~QzJ
)	|e/?
&%:E=,:
 )$e|58
E6ffI8o@
:e@9RfQ
ea84yF
E	c*T0WK
)EdC!D
]%Ed-s
":eD'T
%e\F.`
.(_ek/
Ek -**
;ePoK2z\
}E-R@yJ
eT= tz>YPv
$ev./0fl
$ev.We
e-Wrc'
EYjf_a
f4szBY
f7MWe}
Fd="k9
fILQN}
FIQZ:&oy
f|+iXAW"-RV
f?@JI%
fk2s)Xhj
	F_N:C
Fn=l{8l
fQu-!4i
Fr:p{8
$F=#?t&
FtnH,F
!.fU`[0
<fvIbK
f>_VU/
f+x~9:
%*~g,*_
G8K5\/
g~!aJz
~gBcY"
gdRn}`[D
%geq`.
Giq,@x
GKeaUaa
<~GKiE
GloQ|f
:$;gnO+
go{$);
G?Us +
&G|zy 
H:{=	$
H1waZu,
H{4Gor"
H4V"D)
h[A_81{r
hA8Frp
HB?43r
H"D4F"D
heI!3a
heI!3a9
hf-906
hHGY|u,
hhyLDR
Hk8N\$
h {[n1l
'Hn	e'c%-a
HO&*7`
hq#l\BN
hRi(%%
.@hrV44
_HsfO8
.H+t$@'@h
}HXG Fd
HXV&~9
i^0VWF5
I2]}MV
i@4v/D4
i@4V/Dk
i54F'Dl
"i.5DG%
i8Fz#^i@
iA{;uY
iBsFOM}
icW uUJ}tK
iDdC!D
iE$!&J
IEr:DlX
IG>j`W
I	@h9Q
iH Ey$
IHzF+B
II{F~Y
i{o\Kko
)-iSN8
it9@0N
itsCfL;
ivdyw(|
IWe?[~
[IY3DT$
iY5#v6"
,{(j>[
#J0Sn|
&J-2k)
j[7	#~
j8$K-O
J8o:4B]7
J9h=Dn
jbJ 'z7
:Jc/?NQ
J".*D1
jGs^5|H
j*Hz	+
jhzO{z
jhzO{z;_{
jivmTQ
$*j+j)e5
jj,+~oG
JKO7|$
JK,y:f
j:LU'>VI=w+I
jN[y{.
J@?o37
#JOx:L`
#JWNl|
/+jy/KM
:j<ZK:m
|<K=;!
k0oyDx2
%k:1a} 
k21 -k
K6<OGI	
)k7I"l
^{k]=:8
k??8/,
<^KA>^KA>
(KEj_/
k<jIoKz
k;/jjx^K
k}jz+Y
	k|+&l
&@kM2l
K<M=T![
k_Pq#H
K] rb}
K':RZ,
kSi.P3
KsWx_~
\	K_T-BRj
kTQ3,H
^{ky/KMk?
k;=z:{
;/Kzx_
(%l/>+`
l(@0v_@4
{l+1c}
l"46Z>
L4]c^X[
_.l%8wK
L=;9< g"3
lA;e]@
LE.;rN
LhJ	eW
L-HZ6=x
lI :85J
'lifkbO
liv./0
,l|J5qY
l.L9`n
L;m]?5
lm:z}+
ln&f:1
lNM9`n
%LnNp>
#<LO 	
lqRV1[4'KV
.%lr3X
l|Rffyy"Fz
lSr*Iv
lS/VBVZ
lu`"#=
L~uFJ]e
;LU)oxd
+L,Y*b
L?#zZy
/M0vGd
-M0vWm
m,0|ZI
M&2a	V
M3	#uDS
m")BxP
%MdCaD
$MddL>
{_M?@E
m|=En_i
mFh_h3
m-iL=q
;m|kk?
;m<kK~
:m|{kNxh
MMMMMM333333333333
M]n|qA
|=mP	1D
m/Q*oK
~&MSF!
<-@mSF8R
mt2WUQ
>MV;0L
!M` W{\f
MxDv	E
m=z;k>
m=z:k>
n'*?0~
N?,2<^j^
N3s673
	n{!5i
_n 6![
N+6r!D0w
n7CuR=C#Dj
n]~,/7qSn
n&D3C7
n&DCJ2
n&DCS2
n&DSUr
n	JMbw
/n%lW)
]N[nt~
N}(qG;
ntUj);D
NwND<-U
nX0vrf
N)xlY:
O|0FwA
o&27xg
o5:wN(v
/o}!8l
OaUsUaU
.ob^w(
OCkooAn
OCkooAN
?*o'DQ
\oEP+^@
o(fCy$
O[fF[6
OGkR<?
o+?Go]
\/@OL}
	\/@OL}
OpJaV 
&O\wv!(
|P0-jE+
P0=j	{-q
p3M-0ih
P5<j!*
p6;_fG
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
PB?43r
P}C4vwC
Pczu}c"R;~>
PD,3-WL
P#HuNF
pI	!OW
@^PjuD
`pluwvC
 @pQD=
P\%\rl0
Pr*Uf=
/PSuEy
PuE9fhf R
p[X+7rB
&}pxy/
=_.q] 
<=Q9rrY
Q#BIZG
qc4F'D
Qf~cQH~
=qF&id
:Qf(ll
+=Qg.:
|<Q^gh
QHd(f~
@Q[__kF\
\qpZ|0
QQ'G@tu
(qRr\c
Qs}6v	
Q>,!"T
Qvba2g
<qwj2{bB
#Q+!"wV^}.
q~.x|H^
Qy*m;O&0
r4v	NJ
R@~6\S6
r/:-&8
]r92:A
r+hns&X
Rich!4O
Rm0MiEs/?
Rr?N~h
rtehHp
'rUpRj
*Rva"+h
RvE)pJ
"rwS|J
#'"	s\
S4VEUNr
|scnX+
sDDCZ`b
]=sD#g
\Se'<'
\SE7<'
\SE7<'}*)
\SE7<'r*)va
\SE7<',x/
\Se'<'b*YfA
"SgVP&
S	&J=/
S;%@jo
S{jo\,
`S`kD.
sK=-iL=
]"&skR
=Sp3FW
Ss*{DO
St9b!-
\Su7<'
s,Vqlcb
s{VZ}CJ
\S%w<'
\S%w<'<
S#w	FY >
=Sy9}t9b;
sz>bw-
'&SZ=L
#T06<S?
$t31/Bg
.;t6%A
[:T'Aap
*tb^%'
T(C;AM
_T{cO0
tdSLeN8L\
)(T=Fr
TH^#Bx
)ThC!t
!This program cannot be run in DOS mode.
	tI/GN&
&(:t*K
]Tkp\}d
<T$*rD]
(trnma
TR"'w<
T?sys?R
| TtS%
Tu!y.p
TvQP?rI
tYLsCJ0]~
&}-u2O
|UAm%lx
u}BJSb
-UCo	9
`UCxKU
Ud	5e"
UD\px6
^uf&4.
uHE0'K=|
UJs*>W
*UK 5zD
UMF-\/
U-'	@mxy
UN?*yz0
UPaL%K
u%R0&:g7
u&T066B3
U<t\if
uts1}n
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
uUVKc[
U-X&je
UxY#\A
uyT5__&T
u~	Z6C
[;v'04
V+	1`pDX.
V2]Wds
v37=E)!
V64V"DjT
?VB_}&
Vc#$kh
V[;D1l+
&Ve$a\
vN,@pcRP
v^o#t^
^vp7(^3
VqOeDQ;
VsqYp$@
V|VH.g<
vvL2'W
w5kyCR
w7XeRZ
 W8onAq|
w>8]uy
waJD8+E:)p
+(w{c	
=wC8+'W[
W#c<U~+j
@wD2X2n
}W".*D6
}W".*D7
Wd)7D;
.wDNm.~y
wdQ)T`
{-wl-ck+
Wlwxb}
W<'lxl
$W&m4C7
-wPp>4
w}[pX3
WQ0&vo?
)WS?tq
~"W&WV
wwwUUU
wwwwwwUUU
W_Zt}a
x>8'0z::
XA2{9-B7
?/XAGe
;X{~Cn
x' E0)
X*G0"]
`xGQ*r
x$h	E?
:xHE\+
~xj	>J
*${'?x`N&0s
X)N9#MNs#{
X"t4V"D
xt<#"hR
'X#Y|u
X-z8^J
]=::y_
)Y		{_
Y31yA<
y5!Q!VWhK
YBc`"6j
y'Dt>-
/!ydX9
>yF4;!
YG4v'D
yG*nmUe%}qn
yJUs?PU
{ykg-9PVz
y/KMk?
y/KMzO
Y<Ub[`
y!%u+wE
y%>WeK
	YwPL#
)Yx*;/kj
+YX{;/kj
+YX{;/kjI>
+YX{;/kjy.
Y(y&e,
z0V"G~Z
Z0vMb=
Z4F1DD
,z4#[J
Z4VoDR
z){*,6
z6`<_BI
<Z9x/;
]=Z9yN
z%=]a{
z#B"Ko
zE7<'}*)
zE7<'M:)
:}Zeyy
zIk)SAT-w1
zj>jk(
@Zj]rC%
%z-^Kp
[?z*mL[9
ZRhiaI
z'uP-uE
z>USh,8
z_X{+~
z/X{z_
"zyL5b
[?z*]=Z9
ZZU-	%