Analysis Date2015-01-14 12:01:57
MD53c56680f66fb8526e7343ccde7cad99a
SHA17a77711021fe1ee79da85ff5b480c6645298514f

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhashf65f4db6a3bab47b53458baa9d826156d437d9f1
IMPhash
AV360 Safeno_virus
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)VirLock-A:Win32:VirLock-A
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)Ransom.VirLock.A2
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99f1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!3C56680F66FB
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecW32.Ransomlock.AO!inf
AVTrend MicroPE_FINALDO.F
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\BwIIMkEA.bat
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\BwIIMkEA.bat
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Creates FilePIPE\wkssvc
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Process"C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates Mutex_SHuassist.mtx
Creates MutexShell.CMruPidlList

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FilemwMG.ico
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FileC:\RCX2.tmp
Creates FileCcQk.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FileQAAe.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FileCQYA.exe
Creates FileGAwm.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileC:\RCXF.tmp
Creates FileC:\RCX12.tmp
Creates FileOoUs.ico
Creates FileQkQy.ico
Creates FileyEwW.exe
Creates FileYwwO.exe
Creates FilekcIA.ico
Creates FileCgYo.exe
Creates FileC:\RCX18.tmp
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileyIEq.ico
Creates FilemEoq.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileSgMc.ico
Creates Filemgse.ico
Creates FileC:\RCXC.tmp
Creates FileqgUA.exe
Creates FilewAUW.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileeEkW.exe
Creates FileC:\RCX9.tmp
Creates FileiwcQ.ico
Creates FilePIPE\wkssvc
Creates FilecwoM.ico
Creates FileiMMk.ico
Creates FileugQu.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FileyoMG.ico
Creates FileC:\RCX1D.tmp
Creates FileawsA.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FileiQgI.exe
Creates FileeYwK.exe
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileyYkE.exe
Creates FilegggQ.ico
Creates FileC:\RCX17.tmp
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FilemkIa.ico
Creates FileiIog.exe
Creates FilewkUS.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FilegYIy.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FileqMYy.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FileyYYw.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FileKsMA.ico
Creates FileKYso.ico
Creates FileWMIu.exe
Creates FileisIM.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\RCX3.tmp
Creates FileC:\RCX20.tmp
Creates Fileaksk.exe
Creates FileC:\RCXB.tmp
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FileSkoo.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileYQsG.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FileucsC.ico
Creates FileCAcU.exe
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates FileScEs.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1.tmp
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileKcok.exe
Creates FileIIcM.ico
Creates FileC:\RCXA.tmp
Creates FileeYwO.ico
Creates FileGEQW.ico
Creates FileC:\RCX1F.tmp
Creates FilekwYw.ico
Creates FileC:\RCX13.tmp
Creates FileC:\RCX11.tmp
Creates FileC:\RCX21.tmp
Creates FileCQUc.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileC:\RCX19.tmp
Creates FileugwK.ico
Creates FileKEwQ.exe
Creates FileWcIe.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileC:\RCX1C.tmp
Creates FilekccA.exe
Creates FileKMgw.exe
Creates FileqQoQ.exe
Creates FileC:\RCX1A.tmp
Creates FileQYgG.ico
Creates FilesMkw.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FilemkYy.ico
Creates FileC:\RCX8.tmp
Creates FileiMgI.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FileysIM.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FileMkcU.ico
Creates FilePIPE\DAV RPC SERVICE
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FileGsIW.exe
Creates FileSEcc.ico
Creates FileC:\RCX16.tmp
Creates FileyUQE.exe
Creates FilemgwW.exe
Creates FileC:\RCX4.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Deletes FileqMYy.exe
Deletes FilemwMG.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FileyYYw.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileWMIu.exe
Deletes FileCcQk.exe
Deletes FileKYso.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FileKsMA.ico
Deletes FileisIM.exe
Deletes FileQAAe.exe
Deletes FileCQYA.exe
Deletes FileGAwm.ico
Deletes Fileaksk.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FileSkoo.exe
Deletes FileOoUs.ico
Deletes FileQkQy.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FileYQsG.exe
Deletes FileucsC.ico
Deletes FileyEwW.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FileCAcU.exe
Deletes FileYwwO.exe
Deletes FilekcIA.ico
Deletes FileCgYo.exe
Deletes FileScEs.exe
Deletes FileKcok.exe
Deletes FileIIcM.ico
Deletes FileeYwO.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FileGEQW.ico
Deletes FilekwYw.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileyIEq.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FilemEoq.exe
Deletes FileCQUc.ico
Deletes FileSgMc.ico
Deletes Filemgse.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FileKEwQ.exe
Deletes FileugwK.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FileqgUA.exe
Deletes FileWcIe.exe
Deletes FilewAUW.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FileeEkW.exe
Deletes FilekccA.exe
Deletes FileKMgw.exe
Deletes FileqQoQ.exe
Deletes FileiwcQ.ico
Deletes FileQYgG.ico
Deletes FilesMkw.ico
Deletes FilecwoM.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FilemkYy.ico
Deletes FileiMgI.ico
Deletes FileiMMk.ico
Deletes FileugQu.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FileysIM.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FileyoMG.ico
Deletes FileMkcU.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FileawsA.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FileiQgI.exe
Deletes FileGsIW.exe
Deletes FileeYwK.exe
Deletes FileSEcc.ico
Deletes FileyYkE.exe
Deletes FileyUQE.exe
Deletes FilegggQ.ico
Deletes FilemgwW.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes FilemkIa.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FileiIog.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FilewkUS.ico
Deletes FilegYIy.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Network Details:

DNSgoogle.com
Type: A
173.194.125.70
DNSgoogle.com
Type: A
173.194.125.69
DNSgoogle.com
Type: A
173.194.125.68
DNSgoogle.com
Type: A
173.194.125.67
DNSgoogle.com
Type: A
173.194.125.66
DNSgoogle.com
Type: A
173.194.125.65
DNSgoogle.com
Type: A
173.194.125.64
DNSgoogle.com
Type: A
173.194.125.78
DNSgoogle.com
Type: A
173.194.125.73
DNSgoogle.com
Type: A
173.194.125.72
DNSgoogle.com
Type: A
173.194.125.71
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 173.194.125.70:80
Flows TCP192.168.1.1:1033 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1034 ➝ 173.194.125.70:80
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .


Strings
.
.k.
.
.
[MMMM]MMMMMMM]MMMMMMMMMM]MMMMMMMMMmM]MMM.
.
c
q.
.
.
@;M

=0?"3%B
*#~?0HH,
0(^jWL*
0^`'R#0
0;RLiAb|
0)*=TK
0X*\D)
0xpOzo
1'-8P:
~1cq|n/
1]Y@4U
2]4Ny/
2}4Ny/
2AM$:[
2G0<.S8
2g~@?G[K
!2h++KsU
2lgGb&
2m:SRf
2]~nobF
|2n'z2
]2*O>3
2r[K=P
^2rT.%Y
2S04~S
(??2-T
_2&X*{
32pr{i'i
\]3].3
=$3	}*h
)3	}/h
	3	}/h
:3hu3@
)3i{h'@
3ky/h:
)_3M':I
3!o(~~
3-~R]`W
3^s{R0l
3VZ(Me
#&~3Yv/h:
#&>3Yv/h
#&>3Yv/h:
3Yv/h:
4}2qvoWR
4e(+g,]
4G8*tar
4GOyXH
|4H;,u
4K;._:
4NVG1\
+4o[er
4&;x|e
 5|5NG
5,97F25
5g5vzG
5h:}r>h
5L6xV<
[&}_6*
:65d(r
6:5+V<
66p#9uf
_6AAT0
6E&6;Hz2.
6i1.)&	
6MYn~!
<6pbzM l
6prai{
#6u*_	
6?yk0+
?%7BWE
7ix0\y|z
7jCsgv
~7jLZ3
7l&#"b
-7m(rR0pR
!7PpME
7pR#i~
7P;Tp{M0
`7PW)e!
'7~q>h'
}8_1fN$
8+9|FT0#:
^&*8av6&
8<{b1i
8EFq#i%8
8HB_h}7
8+Ju^Y
$8:LDi
-8Mj&n
8U<'54
/8unm7Y@KU
<8x5&i
8|$y2~
 "8Zo]
93	}R>
9#3U	{
/94[YpB
9~9dsA
9jH5(jh
 9[MEH
9s5pr6
-9;sTV
9v7O|6
;9?}Z~3
?a*CEy
aEd%AG
_afjy D
:A~i?%
aiI' =
A=K}*\
a#~#q&
|aq>1{
AuLZm*{
A#vO4?
b2_<k+
B~2taX
(<B4s.
bc4[voh
;BdiWf
Bf^?\.=
bg]Sd]y
`)*BHN
bi3+y*h
biHAxG
b!K+}m
bkVW M
<b{/l:z
!=`|?*B#n
B%~(Nn
bohO1q
bOJt%l0J
?.,BP$
:bQ?1N
b(Ut+L
BV =BxhC
bW\*w*
bx3+y*h
B&Y?6j-
B&Y8e^!
Bzw\05
c4*K:?j
C9N+}y
'C%ax 
CdG*L:3Ds\
cDP!13
Ckx{t=
)cLgk+	
C!+!=S
c~T5y(
Cx51/P7
CZ<DCW
%#d3({
D*3DSW
d91]In
D9c+%e
dA P7{
daSY\Hhl
DB~K.@
Dj3DCT
DJkx'I+m$
=D<.l6
DP~r%j
D`qr4N
D<%T=[
\DXkxU
DyB?CN
D<yDLBRT
];^dz2
*\D)z<u]:\t
d<zxP1
e3v$u	
e4_gIp
(} EbN
EFyfIp
EGAc38
,E?j(6Xk
e'JCN3
E. Lv,
{eNP{6
e-n\U*
en\U%"
\ewVUop
%EY3\$
F3P1i'_k
f3r-!A
fA8d3	}*h
f`!a];z65
FCN0E	
FdX$Xz
fe6+uh
*/FF.jo
}f*hzr
fiO],Z
;f[j.w,
FK6*J1
fl[IN|
^fl,Qf
fM -SN$
fo&*#B
f%Re>7/j
FS"0"9
:FslnVY
FS_Xz2^
[Ft_-;+}
FURY.L=7
Fwi|"z
$FX{PL
F&yH(&}P
^fz2^rz2
fzgwD:
FZn$9 
#{('_g'
g"00 7
g|)0~s
G*<}!5
[G^7T 
GB\[vF
-GDg3O
gg:L:3
 #%gh/6#]
Gj3D#_
~gjCj3
@@|G(L
^:GLJ}
G,$NBC
;g[=P6
	Gq9T"Q
g(rR4p
|G];:U
@G\U3-
gVJ#iu
gVn.r]tB
GVXjJT
_gXzZYx
{H0fq'
h&0w,0?
`h|A6}
~hA9~f
haG+Id
hgp-s%
&<&hH\f
[HI1F])
hl,0+N,
Hl"lDV
<|;HNg
.hP:hh
hQ361A
H}RT X
hu3M7"
`*/H&X5 
-!HyK{AO
i0-?r	
I=2\L,
i3	}/h
I3	}/h
`I:=4*
[}I8vR>(
i:.9oU
i<bqRTAhz'
	I_bW;d
/i;cA:
~IEfEg
i.eHhC
iep2>:z2
iGNA`(
;I @IaGW:
#&I\j?
`I^JgL
ijSC	*X
ik3}x;
IN}cQz
iqK:KV
iT^'H,
iu5u@{
\Iv5;5
ixvji8v
J{<40c6
.J4&4Uc
;}$^J"7U
J'a,*C
Jc`Ozq
j=EA:=
jF O#B
J]G_{\V
,jhB*	)
J<Hi1Q
-Jh(r	.
~jIfhvj
jInGDe
jK3Q+|WP
JK4+k@
jL>3o0bw
JNGi|]
j_nN v8/
j_OW'nZ
=J/qWb
)J`"`*R
,j(r"5p
Js.yES~
j`V	T\	
J=W(Z\$
JXEj"Lm]{\%)
	JXgEgS
J%`+\y
JYF}8B
j>y|wk
jz2Nrz2
Jz2Nrz2
`]jZ4?Wy
k-%[[=&
\=?=K]]
|/*k0sc
K0U![850
K2nRQvp{>
k(2s5p
"k(2x>pR
k3;u7@
,k("47pr
k8dIZ]
=K_96<
K\ERj+
kh0yvM
KHC?T7h
k;j,m>
).	KLL
K]NA~ba
`Kqj5tI
=kQ"|P
kR73vJ
krB>q+
?k(R|?p
K:sDC\
K:sDcY
K>sm(rr2p
K}t|#A
`K.]`U
"kU}03
/kU439s
kUQ0~M
-	>&KW
kwV939
kxzg:C~3
*L%)6TS
L_8v|\
l9iowW
l|a; bv	
:LDiN_
lD+j8'
\l)/%eu
lf\9Lg
`lg?<N#
L%:~iq
(l"$N}h
L`q!bx
l?(rOr
;:LU8H
/	LUW?
>lv<EN
<lXvql
l#ZVH:"
M"1x3S
=#<"m7w
M7!yTv
'<;md,
m/dee	+
M'%DI-
M;.Dz2
:ME*N.
\MGwo>fi
?`m>H3
Mh<{^s2z
>=`m>HT
Mi1mrj
/M-l{c
M{LN\=
.m{Lwlu
).m{Lwlu
m|.m{Lwlu
MMMMMM333333333333
.@MmnvEc	
Mm=+Oi
`\mnaq
MQlJ'7kn
MRjM:3
.mr>k[@
"Ms0hW
ms8:g%=
msh_^Ym
MSs	DO
M|!tBRLq
MUbiB#
MUepFZ
Mwox;3
m)xbmh
&mxe^!8F&yH
MY'AKT
<m|>Yq
"n5u&Llt
/'~,Na
N$?A{2
-'nck%
nD<JoP
%ndkm/
"neJ*LV
"ne> L
"ne{'L6
-Nh]vb
niefEG
NI@#WvP
nj6Pad_k
n^*+kfH
"n%)#Lr
-nlZ%P`
N_{mh$
N``"mSy
n}P*\E
}nqV+[
 n\S%}Z
"nuK$L
"nuK$L	
"nu(*L]
"nU+'L
[%n\U$n\U%n\U%n\U%6?_
NU{p3,
|Nv{L 
=$n&xh
NyHp9%
O1"IYyj
O:3DcW
O3nbkdcoft
o7:M*3
}@(,oA
_o`c|*
oDN;1!
~oe	jA
#&~oFy
Oh"8>p
(OHG-j3K
oK[A^yD
<oOaYW 
*,,OPL
O\q4_(
or\pI&M
o(rR?pr
>O{}T7
ouFNz2
Ox^K/<
>,*<@p
\p<1nvK
`p2E{ 
p2Y|tr
:P>4)#j-FK3
p;=?,5
p7*iZ3
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
pb?ngfw
pEgjSo
{PHPA9%
PjvQ_CK	.
P(jXd9
p"+~lk
p](ME/{
pMg1]@^
pM*=VK
pnY>Gi
/PpF:b0
PQ@f{u
p?SS(w&}
pSw'W\5C
+P+U6fQ
~pu .m
px*=TI
)^!p	Z
<pz#$h
pz!+L(
q?"1d6V
q'%2IJ
q3Yv/h
Q6sDQvs
#Q=,Ag
q!c0%-
qfyi[;s
qJFl+Br
;!QJK7
\Qj/q8z
qL5=`F
q$ l%Q
qNt6AF;
^qp@Uw
|qS"ru
qtAoNV
Q:Vl*<
q]vpX8U
Qw1_EZ7
r2su,;
r&.8}"
`R9EJG]
R<$9_p
RA|Sv[
(r^dZX
R>/G*`AD
R	Gb[M
_;#Ri-
^^R^.I
Rich!4O
!R~J}smk
rl1 O,
r(L+BS9{:
	rO\Ex
)RrZ^(
RUWo~ 
R\XU.K
+!rZ3 
s8@^H4G
s#8szP
S){A%j
S[B$;]B
@sBZ:O
s]DW#3
SEf\U%
)S)E~R
]SEylC
"SFh9gE
Shb5-OI2?
};sicF
..sjdB
SmpjpT
s@<MTB
\*/S]N
=sn(r"7prt
S|O@%Q
sq"')3v
={^srx
\-~s^-^s^
{'ss2BzL
:s/t7/S
sT	aP'
StVUSoQ
 sTZ).
"s-u~Y
s^ V+	'
S}WQcK
swzy=c
<sx.|R
sZEw3Y
};sZSFZ
T12$|}
t">|`2
'T:2K6
t3&WoQ
}T+;8sL
TCaubU
[TCwSV
_t@Fa?
%^tf!SoQ
'TfX#C
TgA/r9
,T([}$H*
!This program cannot be run in DOS mode.
:Thz2^
|t:;MV
):}T*nh!I?	P
;To=r4
+tR7ZI
ttpmT!
twJzq3_
@U3(S)
u3+y*h
U5 @_Ax
u7WGus
U!&f9%
$U)FyX
UjVvE(5
[Uk15B
u%k6j2
ulq!HzX
|"Ul(r
u}Mcui
\uM;-u
\uM~,U
uMWd&;
&uoOv5i
u	`q$/
UrLw8*l
(Usi&E
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
uw5Yug5
Uxgn|/
;./U<Zmd9kH%
V/1AN<f
VE9kEy
V}HX2 {
vJ&NZX
V`?.@P
v]pp3g
v^`q:/Z,
vsr*\{!
`Vt~U_o
VVh	fg
>`&vXu'h
-(% vy`
\#W"2?v6
"W3Yv/h
"w4Nso)
W4Q'0&
W"5QCj
Wcx2S5l
:)W.EA*I
Wen\U%
:W'^?G\
WG6<p	
W'k(BO5prt[p
WmR8lmS!
/WpF:b7
$WrSoa
W`TS(Q
Wv590	{
wwwUUU
wwwwwwUUU
=>|W;YS
X2ym j
x/"4[_
X4my>p8n
< X5WW
X6%\!B6
xbjKq,jE
xBXhe0
XehD	%
X*\f#vA
xG*Gz3
xi#sY(
$x}J]:
=Xk{W[`
[XMwHw*
xO3	}*h
x?qS%dL=
X/v=z<u]
xy^'H1[
^|:y2.
Y30NTS>ys
)Y4|2x
y82vAU
#)yAh(C
y|AhqN
`Y.b[+
Y!*Cm>
,y=e-H
`$	yeP
=yHzQ#
yJeRGGaQq
?;(,Yk
 YK $d
ynBtQv9
YQJ/qJ
~y*s2~Jz2
'y~\U!
~YUp2.*z2
-y..vIM
,yvKx"
:'Y-z'
z2>bz2
z2Nbz2
z2Nrz2
:z2Nrz2
z2^rlu
za!3/U
	Za!vf
#@(ZDgN
:/z~Ec}
z<e	k(F
+Z!F"d.I
zfxb43*
zg	;<e
ZIYIjV_
zjgobp#
z?Ll(Y
zlu]N\$
Zmd9k($
Zp+8#g
zr8U}pWw
zv4PvnZ
Z(XN:WZ
zx?U<H
zYv!e6
+$Z"/$z