Analysis Date2015-01-11 20:13:34
MD500980e9f61f78e9a015fb706041cc88f
SHA161e909d30dca528cd2e15ba19cd2b0fce632e2f9

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhash7bfd043ac63ba2facdc9c3129ea88fe8c8472fd7
IMPhash
AV360 Safeno_virus
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)VirLock-A:Win32:VirLock-A
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)Ransom.VirLock.A2
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99f1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!00980E9F61F7
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecW32.Ransomlock.AO!inf
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.zip
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\bScsoMMc.bat
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\bScsoMMc.bat
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.zip
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.zip

Creates FilePIPE\wkssvc
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.zip

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FileQQwc.ico
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FileoUUo.ico
Creates FileQAAU.exe
Creates Filecckm.ico
Creates FileC:\RCX2.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FilekcgW.exe
Creates FileC:\RCX5.tmp
Creates FilekMcc.ico
Creates FileggEs.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileC:\RCXF.tmp
Creates FilegkIo.exe
Creates FileC:\RCX12.tmp
Creates FileIcUs.exe
Creates FileC:\RCX18.tmp
Creates FileaoUQ.ico
Creates FileUsQU.exe
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileqsMq.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileC:\RCXC.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileC:\RCX9.tmp
Creates FileusQK.ico
Creates FileooMQ.ico
Creates FileoEoY.ico
Creates FilePIPE\wkssvc
Creates FileIEgY.exe
Creates FileIsAU.ico
Creates FileogUY.ico
Creates FileaEMg.ico
Creates FileYEoI.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FileYQgA.ico
Creates FileC:\RCX1D.tmp
Creates FileGEkO.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileoYEo.ico
Creates FilekcAW.ico
Creates FileC:\RCX17.tmp
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FileksEO.exe
Creates FileggQw.exe
Creates FileccMS.exe
Creates FilessoO.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FileQwkU.ico
Creates FileioAg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FilessYi.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileSgMo.ico
Creates FileC:\RCX3.tmp
Creates FileMEkG.exe
Creates FilecQQq.exe
Creates FileysEk.exe
Creates FileC:\RCXB.tmp
Creates FilekQIS.ico
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FilegEgG.ico
Creates FilemEAe.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates FileUkoi.ico
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1.tmp
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileC:\RCXA.tmp
Creates FileC:\RCX1F.tmp
Creates FileQcMI.ico
Creates FileQMQQ.exe
Creates FileC:\RCX13.tmp
Creates FilecYkO.exe
Creates FileC:\RCX11.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileC:\RCX19.tmp
Creates FilemQke.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileMcMO.ico
Creates FileC:\RCX1C.tmp
Creates Fileowgw.ico
Creates FilewYYc.exe
Creates FileC:\RCX1A.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FilegsYU.ico
Creates FilecIoi.exe
Creates FileC:\RCX8.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates Filekswe.exe
Creates Filegksi.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FileIQQU.exe
Creates FilesUoO.ico
Creates FilekAQK.exe
Creates FileYwQo.ico
Creates FilePIPE\DAV RPC SERVICE
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FileAccQ.ico
Creates FileC:\RCX16.tmp
Creates FileGQsu.exe
Creates FileQcMU.exe
Creates FileoIAk.exe
Creates Filesksi.exe
Creates FileC:\RCX4.tmp
Creates FileQQQS.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates Filemgoq.exe
Creates FilekQsi.ico
Deletes FilessYi.exe
Deletes FileQQwc.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FileoUUo.ico
Deletes FileQAAU.exe
Deletes Filecckm.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FilekcgW.exe
Deletes FileSgMo.ico
Deletes FileMEkG.exe
Deletes FilecQQq.exe
Deletes FilekMcc.ico
Deletes FileggEs.ico
Deletes FilekQIS.ico
Deletes FileysEk.exe
Deletes FilegEgG.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FilegkIo.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FilemEAe.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FileIcUs.exe
Deletes FileUkoi.ico
Deletes FileaoUQ.ico
Deletes FileUsQU.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FileQMQQ.exe
Deletes FileQcMI.ico
Deletes FileqsMq.exe
Deletes FilecYkO.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FilemQke.exe
Deletes FileMcMO.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FileooMQ.ico
Deletes FileoEoY.ico
Deletes FileusQK.ico
Deletes Fileowgw.ico
Deletes FilewYYc.exe
Deletes FileIEgY.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FilegsYU.ico
Deletes FilecIoi.exe
Deletes FileIsAU.ico
Deletes Filekswe.exe
Deletes FileogUY.ico
Deletes Filegksi.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FileaEMg.ico
Deletes FileYEoI.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FilesUoO.ico
Deletes FileIQQU.exe
Deletes FileYQgA.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FilekAQK.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileGEkO.exe
Deletes FileYwQo.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FileAccQ.ico
Deletes FileGQsu.exe
Deletes FileQcMU.exe
Deletes FileoYEo.ico
Deletes FilekcAW.ico
Deletes FileoIAk.exe
Deletes Filesksi.exe
Deletes FileksEO.exe
Deletes FileggQw.exe
Deletes FileQQQS.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes Filemgoq.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FilessoO.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FileccMS.exe
Deletes FilekQsi.ico
Deletes FileQwkU.ico
Deletes FileioAg.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates Processtaskkill /FI "USERNAME eq Administrator" /F /IM VyAMAMkQ.exe
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.zip

Process
↳ taskkill /FI "USERNAME eq Administrator" /F /IM VyAMAMkQ.exe

Creates FilePIPE\lsarpc

Network Details:

DNSgoogle.com
Type: A
173.194.46.66
DNSgoogle.com
Type: A
173.194.46.65
DNSgoogle.com
Type: A
173.194.46.64
DNSgoogle.com
Type: A
173.194.46.78
DNSgoogle.com
Type: A
173.194.46.73
DNSgoogle.com
Type: A
173.194.46.72
DNSgoogle.com
Type: A
173.194.46.71
DNSgoogle.com
Type: A
173.194.46.70
DNSgoogle.com
Type: A
173.194.46.69
DNSgoogle.com
Type: A
173.194.46.68
DNSgoogle.com
Type: A
173.194.46.67
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 173.194.46.66:80
Flows TCP192.168.1.1:1033 ➝ 173.194.46.66:80
Flows TCP192.168.1.1:1034 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1039 ➝ 173.194.46.66:80
Flows TCP192.168.1.1:1040 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....


Strings
.
.
..v
W
...
(

055H'o
0(^b~f
0cko/7[
0Cq@r#
0dbU_c
0D[JB@V
[%0H<^
0H?(IvJ
0j0JDB]0
0lH<_l
0o2fC2}
`<:[0v
0XD"<A#S
|[:1f8
:1Q0_m
1syk9L
1T8/ pR
1TtocR
1u	lp7
1>+x9C
{$1zT_
}~;2:!
20bfo/#I
2bp:mv
2@.kPl
";2L d
2m:4k3
2n@=968
2$PC0:=
#2;UR]
2vy<^S;j
,=2>W'
2*xe44
3"1}	(
32,6qD
35T`S7
3#B^1&
~3g_r$
3iPvO6
3#ke`^:
3K+F3H
`,.>3L
3wY#70
:3Y73#
3Z	k~B#^
3Z"{M[?
-@!{@45
[.466X
&4!?Yxa$
4	Zg&K
4^`[zk
$50ww/
5g(CpJp
<5+i>L
5(lYL7
$"5vij
6h|1~j6
6k,NUw O
"6~&RW
6_X,Q	h
6ytc	u
	7B;/-
7?'=B?'=B?'=B
7=Bv$@
7%C[y.
7dJe\:w
7LUTw]
7N$laBr
?7s3fW:
7/<x-\
86~F~X
8,6Nik
(88S%?
$8d4r}
=8^!I:N
8Na/!4i
93%lM6UJ
9::7fB
^9|92.
9%d?F^
9E#/wS
{9i"&V
9Ja*^"
9k9[b}
	'9lsj
9mU(u"N-
9,O.&0
9oAX<I
9R{/6i
!9t'0l
9T8/ pR
"&9Ybu
9	Ye=4
A7_('B
a7VyZL
A9L0HS
A?}/,AT.
%A>BOH
AC.xxU2
aHZ$NQ@
aLeTWD
an_%N*
AT9c^wZT
A?%-VV
AwKI+sZ
a@@X,-&
a."x2Cx
aXYRjg
\azc^gzTbHwf
.?*/B;
B%5G!{
B=a`hf
bDLRGW
b~D^oj
B;e *f
bhNT&WF
bjfx(:
bJJ}be7bE
BlgQ2bfI
B\MPJP
boHWx!y
="b[_Q)
bRI.)?Z
B{t\{K
Bxx-,3
|bZ(':
"|BZ.X$`
C&0<Y>
c3[R"-
c6)4t]7
C	+)7ez\
c}7mOS7]v
{Ca"2=
`?'=C='	B
C;#bz+
ce<` W)
; CF-<I=l
(Cl,Mos
clO:h6N
clvm/	
c\m`HZ
Cn QbofZ
"#CQ&[
CQ9}ff
C$V5'&
>Cwm&)B
.CWSqVM
C&?<Y>
c",Y8+
Cym.eq
[cY<YN
|D02v)!
!^d55o
D5kw]h
d81poh[
D{a-#s
_Day!p
^DgBe-
)dGSmZ
dkAF@2
d' \Kz
|(`DLi
~ Dn"?
Dn\,^!
Do/ME2(aG
(doY-=~
'(Dq }
DQbdj&/
:dR~>*
DS,{iL
$D~Wtb
dZc`k`z
)E;_0#
e~	?08
[e 3 a</I
EDe*~J
E!fVNSC
E;g%9N
(Eik]%D-
E|l2[wb
(/E~`ll
eOH-nO
EP2bf2
EpgRmvd
	Es,71)J
E_SF5T
E|/tOAz@9
Et,r)f
euL/%2f
?:e!w&
eX%$e2>
 e-XI`
f	1xWb
F^4%IH
F4TA[.
F5g	Qw
F*&6>.
{F?6Zdu
f9Wi\Hi
Fa~9tEO
f^Ah~_
fB5VKs=
fBne}x~Iw
F|Ede9
FGf</.
f}^k* 
FOmgs&
,fpvob
.FQxs\b
;F]Sdr
Ft^G?:N
(=f]Vg
FW>l $
Fytu{D
fz7(dc_!
*F]zC?Y
g3eK_?
+{g5e%TPS
g:~aD\
gd7Q47AV
`g-.e-
'GE@td
g[!gx-
g$J1w~
glvd6B
GNs	?5+
#Goj#%m
G_PXeSBF
G`*#q5o
G!rEVs
g\s-=q
gt<nPl	
gu<s+r
guT95B
?@gV*\
+g#{`W
G{/)w=o
/<Gy5T
G'*<Y7
gZlYwO
=`h++@
!=H9G[
(hBe''
h!D]3*c
Hi(3W0
	~]h;j
hjOlDs
,h$K]b
 hKiP5%
h$lf|k
H_S,.X
H;&*T6
,H+TfR
Ht$I*.i
hU<.mT
hwk\mW
]Hye-<
H ]#zu
Hzy38TbZ{"w
-i&*)1P	
iAA_R^
i&%@dr
IJ&#8aK\
.IKA[#
i<l2MU
,IMr$v
I{N]*I
In)J&X
|[i}pg
>IR7*G
IrWk#N=U
is6*(~B
\<I=t$
I*tX/x
I<U,4X@
IXnRVc
`IZoQ1
j0?UXfe
j?)_2%
(J=2oj
j6t+(~J(`D
!,j7*ch
JAG-L\
\j^/a<Iy(
JHwIxbI
JHxC~%
J)IGk'
!jJ.aOL
?JK?2/
j:L8*_
J!MN2Jq
&jpsy	
Jsv<@@
^JVmkt5
JYch=w
jytb6<
)j,z25
]JzhPX 
jZNHlMjr
K&|^]>
^k-0ga
K6:Pd%
<k7Q)u
Kc9o,f
KCUb,pr:
KEF)l0{;+
KEop`f*
% kgnD	
kGU~^{M
/#_k>J
kK.hk0
.kKyc&
<?koBT
~Kp.80Xe%W_|
KPbGew"+(k
KQym'h
KRQ(8K/
k-_s0<l
+?#KuHH
kVI1+7<
Kw.~bw
L|3<]q
l55	y 
+l6<[VM
lGHQ%*
LG;Qc5
/l[jGg
 L~~lA
lNha'u3
lOd.N+
lOU3s4
?`{lQtV^
"LtYWf
l:!W`a
lWb:@)
LXHJJ8
"$:M"<*
m+0)N+
m3gu;t
M3S-SA
M6nE__
MAF+#G
&%mF$\
.MFHoFM7~]
mg	mGos
#&mjBG
M"l&nd
`m$qc	i
m,q\tQ
m"r*c+
m)Rh>iC=
MsO:or
MUfVlA.
mxZrYy
m#=YcFml
\^~~MZ:\4
},^+}:N
n%"0dG
+"n2cl
?N5f$'q
>n998m
'N	9&EF
?N?'=B
_nD:Ee
n" <E6,
N'HL/nXe
NHMQxm
NijDM$i&
#'njBG
#&njBG
#'njCG
#'nj|G
njkhRE_
"<N)LS>
n[ ::N
-N	p1^
npJp`a
n%;=$[Q
-ns^|	
(N_sbJ
,N;TX}
#nVI+LU
N*Xgq`	
n"YRV"
O6:FE(i
oBfw|	
OBxU%%y
	Oc$=9
odA8:N
/;O^iD/
o?Iu)K _
#'ojCG
#'oj|G
o/KEqi
;O+ko$
omeJrW^
ooOb,l
%O^&:P
~,op`f
~,op`f/
 %OQ:?
oSdn2tE
Ow#R^+
oX`-145k
p1#5\E
P1OhzR
p2mv.$->
p40A~1(t@O
p5zj3e
p6=q36
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
+pCyCU
p&\H U
P(+hXC")U
pIc+MTuSv.<
'PJU9f
pl.;~Q
pp!y.$
PS]KTH
<p|v"$2
{PV6fyB=-
*<PwLJ%
pXejj	
pxjCi*
Pz>5An
-PZicT
Q*/&2ql#@ 
+ Q4OP
|=Q67/Z
Qb0e_oyo
q CP%#
Q^E)7B
q"e:JCa
Qfk,'d
<qLtYh
}-QO]x
^qX@iT
QX{LoV
qY.%Nh
r0cdC_rl
#r62U'g
r#6Qoj
R7Iu;(
Ra4	,7l
Rb0bBs
]RD0O-~
r/FEucQ:
]r]Ft=3X
%(r}g+
RHYkDH
Rich!4O
?Rk;C;.
`rkoy?
R*l3OT
RL+^dO
RlV.MQG8
RqOlmG20
R#?~v?1rC&?
r:v>oi
rWpj)^
RX36-KT
rXZ va
(]r"}Y
:RYp=j
rzt'Xh
RZZ[#=
s&0AuB
S4[$BXh
s|4:NY
Sf*Inc%D
sG]#?mcs
}+S#Ivs
sJ3ubO{
s =lD7cX
SLkz+'9D
sN\NE[#?
[sR>k]
#)#sT;E#
sv%DD%J
t2WXkU
!t4<Rk
T}6}S-
+TC>&g
#Tcy'e
tf2.Wd
Tf:<t0
"TGuCT
!This program cannot be run in DOS mode.
.=TNkXd
tNo/ED
TUA>UC
tU,uIP
t	V	|T
t#]	vu
tyo.+D
T?z]4aE
{&U@42?
:u6Oo;
>_]ucB
U'du*&
ufo/yr
ufS[h7	
U$-]G,
U;j_F	N@
{u`>LP'
UOi<^9_
UoR\+f(
=U~#WM
uxBW	8
UY? di
'U}Y,r
<U+z$1
,	V1*{
V""2 h
v|{3^;*
V7c;\-
V7=M%X
v@9{*u:
Vbg4|;
V;hLK9q8
vHui4j
=V)#!K
VKj;VYh6VVn
<,V`"M
v^NV7G
,	voeN
Vrxk5I
 [ vs~
vspD~t
VU$1_tt
v/!]wV
VX.D.{
V%yOxf
w1> O`
w7|.Odje !F
W);?9iQ
=w?'}B
W CiU`
W<Do]FH
WeEg<>
 &" wf
*w)fZ8G
W	H"RE
WhY7~9
WkgSya
WKi?;N
WL4 <E
W$l`B@
wmOQY/
 WN@9$(t
W[NIw(
wnl=mz
`wOf6w
/!	woM
WR?{^]
WrHuHKw
wr^"::N
|WSLaw
%	wu&7
_WVah[
WV>tXQ
w#)&<y
Wz J{1
X0c~ &
X_3U#~]T9
x5@PAs
X8!qQw_
xcG	m=
xfDnT#
xh.TX+
<`XK~=|1
_xn],]
xnFOU	
Xp:gXM
}$xpTZ
/x<{\R4	
X\szt"
x+WnZi
xWr|I9
Y1f07hQ
[&!<Y3
Y6Qz}c
y8;:e7y
$Yb?RIb
&<Ycy_
Y	F4	=
*~yH'1v
&yI7WE
:"yjnzs*
)Y kqx
,y@RA_K
YRp~B6
Y(& <T
+y$X8^.
Z3\7DB
Z4bU")
z}!<ab>,
ZCdf|\f
zCXM!#
+Z$`<H
ZId.z^	w
zI~\U1
ZJdg<\
Z	j-o`S]
Zl9V	|Ge
z-N}mZ
ZqI>y*
z`&,SW
z^T1:N
zT7ix:=
|\ZXJJ!/4L
ZYU(%]0^
zY`WY?;V