Analysis Date2015-01-14 13:09:12
MD5faa321de7c6e14206e82907d5159f2f1
SHA18c0abb5d187bbd5919ce1b85e42104d68416521c

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhashaab9656cbf6e533c3f3c178eb34cec7bdb9681e7
IMPhash
AV360 Safeno_virus
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)VirLock-A:Win32:VirLock-A
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)Ransom.VirLock.A2
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99f1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!FAA321DE7C6E
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecW32.Ransomlock.AO!inf
AVTrend MicroPE_FINALDO.F
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\FWYoUIEI.bat
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\FWYoUIEI.bat
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Creates FilePIPE\wkssvc
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Process"C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FiledsoG.exe
Creates FileLMci.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FileNcUA.exe
Creates FilelQwo.exe
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FileC:\RCX2.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FileNQsm.ico
Creates FileVAAU.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FiletkQO.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileVAAs.exe
Creates FileC:\RCXF.tmp
Creates FileC:\RCX12.tmp
Creates FileZAAK.ico
Creates FileBIMW.ico
Creates FileC:\RCX18.tmp
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FiledUIo.exe
Creates FilenwAA.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FilehskG.exe
Creates FileRUsG.exe
Creates FileC:\RCXC.tmp
Creates FileRwUe.exe
Creates FileNAsU.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileC:\RCX9.tmp
Creates FilehIYe.exe
Creates FileJEwW.ico
Creates FilePIPE\wkssvc
Creates FilepAIC.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FiledUoc.ico
Creates FileC:\RCX1D.tmp
Creates FileVwEA.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FiletYQM.exe
Creates FilezEYu.exe
Creates FilelcAU.ico
Creates FileNcsk.exe
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileC:\RCX17.tmp
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FilehsMG.ico
Creates FilepAQq.exe
Creates FileJoMm.ico
Creates FileVsoA.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FileVMgw.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FilepYYS.ico
Creates FileBMka.ico
Creates FileVQoY.ico
Creates FilepMwO.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileZwsI.ico
Creates FileHgYs.ico
Creates FileC:\RCX3.tmp
Creates FilexQIO.ico
Creates FilepAsO.exe
Creates FileC:\RCX20.tmp
Creates FiletYMY.ico
Creates FileC:\RCXB.tmp
Creates Filehgwq.ico
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FilezcEs.ico
Creates FileZwkG.exe
Creates FileJAUe.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileFIUA.ico
Creates FileJYgW.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FileFQgs.ico
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1.tmp
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileC:\RCXA.tmp
Creates FileC:\RCX1F.tmp
Creates FileC:\RCX13.tmp
Creates FileC:\RCX11.tmp
Creates FileC:\RCX21.tmp
Creates FiledEgk.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileZYAC.exe
Creates FileC:\RCX19.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FiletYEk.ico
Creates FileC:\RCX1C.tmp
Creates FiledwUo.ico
Creates FileZwgm.exe
Creates FileNQsc.ico
Creates FileC:\RCX1A.tmp
Creates FilevQgY.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FileVgkM.exe
Creates FiletYcs.ico
Creates FileC:\RCX8.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FileLIIS.ico
Creates FileFYcY.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FileVkIE.exe
Creates FilePIPE\DAV RPC SERVICE
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FilevoQs.ico
Creates FilejMMm.ico
Creates FileJcQu.ico
Creates FileC:\RCX16.tmp
Creates FilefQAc.ico
Creates Filehkci.exe
Creates FileC:\RCX4.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates FilexMoK.ico
Creates FiletsMg.exe
Creates FilepIky.ico
Deletes FiledsoG.exe
Deletes FileLMci.ico
Deletes FileNcUA.exe
Deletes FilelQwo.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FileVMgw.exe
Deletes FilepYYS.ico
Deletes FileBMka.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FileNQsm.ico
Deletes FilepMwO.exe
Deletes FileVAAU.exe
Deletes FileVQoY.ico
Deletes FileZwsI.ico
Deletes FileHgYs.ico
Deletes FilexQIO.ico
Deletes FilepAsO.exe
Deletes FiletYMY.ico
Deletes FiletkQO.exe
Deletes Filehgwq.ico
Deletes FileVAAs.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FilezcEs.ico
Deletes FileJAUe.exe
Deletes FileZwkG.exe
Deletes FileFIUA.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FileJYgW.exe
Deletes FileZAAK.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FileFQgs.ico
Deletes FileBIMW.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FiledUIo.exe
Deletes FilenwAA.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FiledEgk.exe
Deletes FilehskG.exe
Deletes FileZYAC.exe
Deletes FileRUsG.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FileRwUe.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FiletYEk.ico
Deletes FileNAsU.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FiledwUo.ico
Deletes FilehIYe.exe
Deletes FileZwgm.exe
Deletes FileNQsc.ico
Deletes FileJEwW.ico
Deletes FilevQgY.ico
Deletes FileVgkM.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FiletYcs.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FilepAIC.exe
Deletes FileLIIS.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FileFYcY.exe
Deletes FiledUoc.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileVkIE.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileVwEA.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FilevoQs.ico
Deletes FiletYQM.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FilejMMm.ico
Deletes FileJcQu.ico
Deletes FilezEYu.exe
Deletes FileNcsk.exe
Deletes FilelcAU.ico
Deletes FilefQAc.ico
Deletes FilehsMG.ico
Deletes Filehkci.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes FilepAQq.exe
Deletes FileJoMm.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FilexMoK.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FiletsMg.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FileVsoA.exe
Deletes FilepIky.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Network Details:

DNSgoogle.com
Type: A
173.194.125.70
DNSgoogle.com
Type: A
173.194.125.71
DNSgoogle.com
Type: A
173.194.125.72
DNSgoogle.com
Type: A
173.194.125.73
DNSgoogle.com
Type: A
173.194.125.78
DNSgoogle.com
Type: A
173.194.125.64
DNSgoogle.com
Type: A
173.194.125.65
DNSgoogle.com
Type: A
173.194.125.66
DNSgoogle.com
Type: A
173.194.125.67
DNSgoogle.com
Type: A
173.194.125.68
DNSgoogle.com
Type: A
173.194.125.69
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 173.194.125.70:80
Flows TCP192.168.1.1:1033 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1034 ➝ 173.194.125.70:80
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .


Strings
E..
B...........................................................K...97w...w9O.
..^.
V.....;....W.IO...............%...9......9......R.;3l;H.H.....\O.\.d.3....;...IL.H.3.
..h:.M..m1.f.....w.....p.=w....YBY.H................t;....
\.JO....................................O..O..............MO
..8
.......BI
...........E.O[3.:
.....E...3O...sz.3.
....O.s..9OO..;s.}L.
<!l
..3[[P.....3...Tr.G3.IG[.I..OL>.1.I
 ...........\[Y
....;.i&...
.........Ik...
.....;R....OX..V
....\1EI
..M`2U..."S........\.G.
C..
..3..........1._i..O
.3.
i
.C......I....[1
......3Y,
.
.c~
.
.l
07anxHg
0)Ay6,
0hJA\C
;>0 LMX
*+,0M8o
]0)n9W
0om Gt
0\WO4+G
0y*hMjJ
\-%1:+
12f(Tg
}143}|4
$170F*
;1iF+*t
$1jmY"
1Ju|RK
}\1=OE~
+1Q-;[j
1"]TI[N
1	veEXu
2!5<r+-
2}-7/|9"9
2{B@9A
^	2dXT
2+EuM@
2'hz}e
"2&Lv2
2n629lZ5
['2)nA
3)2i5n
` 37.6
3b]ng=#
3d;aN#p
3	MK$?
3r'Boo5
|3V,KCYi
3zIk	F
4'1.=<X
46J/eF
47S5;=1
@4?B&:
4ccD>=
4fknlZ
4hnL91c
/]4m[:
[4O`8\
4OT!9=
4!U^|i4{D
5Am%M0
5e\V/#
5F-}5FT
5(FA!mq
5Hu:8=1
|}5i%'
.5kM8;
}5m%61^{
}5m%61\{EO*!}5e%
5;T\9=
~}{5V??
;%}5,V?o
5w<V?n1
)6)@13Ih
65N0XsZ
 -69mgm
'/6CZ{I
6EjkxG
6:`l2b
#/#6{O
6O*\~{
6$R	cP
6X\@A?
\,7${*
(,723X
?%75s5n0
,{%76MrP
$7,7 _D]$_,
7A}+:i{BF
_#7B],=%
*)7D_,]$5,
|7EW,;
7<la,h!e6t;,Kt
_,7$O,7$_,7$_,7$_,
7u_mrp?
7Xk:q+:
^7-Y]z
{$7$Z,
88&6#~;
'\8A#cX
8a:zR Rn
8Ec;}*
;8ncR8?-K=PW;8 R
~8pF"b
8=[VM~
9=5YgB<s_
9)6%=HH}aIXD
(9!?aJ
9AOV8y
9eNb{e
?\`9Gt
 $9jQw
9m9q)m
9,n)T"2
9owS9y
9>|p:~
#9t8|A>
9=Tpfz
9u 6g{
9<U<Lv
9V9n[+
9W$LBR 
9]wU@9 L
9x]2G-
9=YdpxO
9yjQ}n
9yOe9y
^9yRaI
>[@9ys
9ywS-,
9<Y=	xO
<_?[a	
A-28|QyMoP
|A2V?o
A(3ayK
a3$LG2x;w
A4	AT;<1
A51Bb>
a,6p?*.ks"
A7R3$Ed
a7z@aRz8
a8t|dx
`a8zRa
AH).g^.
AIl6!x'h
+A]L@}	Y
ao*8dG
aR{8EZ
aRz9k6z
aUn",yT
a:z8aRz<
a"z@a=zTa7zJa
]a<zqa7zLa<zJa&z]a
a:zR Rn
*	b<%;
~[>B {
||@>!B\
#>B1Q 	v
b5@l\Y
b7cP9%B
bA}dTf
bAulX`)'[
B._-B$7g
bBo"PxU
BC7#'Im
bD*=DC
B[%dX4
bhnS\/
bH(q"&o%F~
BHr`wb
|bKK.i
]BM	|}`
bnQZx;Ixu:`rv7~Kw+k~H
 "bQ4b
B	QLNt
bs<QRY
B"(V_,
}B/V<o
c7/*`K
|c[9;E
CAUDy'g
C}cM?l
.$>CE 
[*cGn]
>;cGN+Q
CH+V9o3
-cKeV	m
 c)mv|)
C'O=bBM
;	CRbq
crDY`	
c&R)Vm|l6
CThV9o
CU0NWc
)[CVSJe
/{Cvw7Z
C\xV9os
${CY[$.
"cY.(84 
C!"Y% D\
;CzP;=
d[0k}pq
d!595k4+
D~|)7N
D82G<M
DAN`J)
dbi&Opf
D.cGu1
D#e7XM
D'IM[04
Dj 6T~1IS
D*`Lr)
dM0+e]
\dPD*;m
DP}MEV
|DrV<n
DZ,g"C
e0.#:K
E"3ix9
=;e4o_
	eA1qtl
%eB@6}
%eB@g0
EC\0vu
=efCf	)
eFKNPTCNP
}E\Gy]
}eHsyOH
%ehwO*)
Ei0umU
Ej#"?:
	E=.JE
%'`e?kSt
e-kwA=
>}enDO
,e$;N.z
<Eo#N'
Eo~R(<
%eQ7(	
EQZwtB
E,R`|p
-=EsTE5
	%eWxE6
"eX\iY
%eX:k9
@;~eY"'z
.eZz4?LlN\
<[F$~?!|
[}f3Ex
F63{>	
F7"S.|
f9yIf9
f9yMeB
fA5m\AD7
Fam4Qj
FbDs}O
!f|CIx0L
'fC$&X)
|Fes'r
.fEx#h
FG503CJ8
F=H[X,
FjpQ^{
f[k#?k
f#'l,)
fNDTQV
FNtM S
|foV1n1
FP"mgh
FPOtW'
 Ft$aF
'(FT>Q8a
fV3-pb
f[vWg"
FxIbg6p_
FYG)::
g4T19eV
G;8#R<
g%!bbo
( GGp:
-G#h<0
g;J.J.[
G|JxW:
)G:<m	3
G.^pag1<
"GRyY.
gT3	\O$g.
 GtBm1
GtX$ax
G_)vmc
gX6E7-
_H7$_,
h7DptU
H8;y]H@U
"*{hAK
HBJQz}
hC>`gw
h-;dIEl
@HEUB"
H%FAuP
hHdJD|k}
hH`y;pj
hj%8\hxp
	>" %_HL
HLT)<^
\>H:M@
^Hn{-rz
)hO{s;P
hO.XEV"
H*$pwv
hq|mpM
,#hs[y~
hT;dGt
HtH#nL
|h=V:o3
i5!LzW
i7{wrc
[I#8;zq=P
)ia%%a)
)ic'%f)
)ic$%f)
)id %a)
(id %f)
)id!%f)
)id&%f)
(ie!%`)
IEX|?C79
(i|>%f)
(i}<%f)
)i}<%f)
(i}?%g)
I;HA2R
iIOt's 
)il)%a)
{iM@Nt
imu*s6
)io+%a)
I(O:;m
iOMPq\
/ IPNW
$?}iUf=m4~
I~WngO
iyldUP
?j[%-+
	J2v!hoE
j&.5w{/+
j6|"xGL
.j8_[9
_j8bZ3#
'/\J{9
J@AGX?
jbrWy=
=;JdCG\"
j&fC1	)
jfKT6rX"
?j=-*k
jmjjs?
/j;[p5k:sV
jP6"zA
jRPyZ>
jS?roy
j?tsj#qw
 J|W[;?8[R
J:(Z2{
K1S~+O
<[?K{3
k3\G-DD
k4[t^"
K5(4y~8x`a
kA,@y$R
KD8N?a
KeBVlN/
KFG}fQ q
kFs$nU
kFUIZ;
|KgHtqV
kh:/<T`
Kj<qOj?tCj#qG
Kn:Qxc:#c
kpz:+* 
K~QT9G
ku*9M"
kV}{22
L5NC#>
\l6]c{
l7D_,Vd
l9(8#-
%		lCzH
l^D'OG
[L	eB%
lEyR[R`}
_L{GG1
L]g!z^
^)\Li:
ljD;4s
Ljq	p-^W
/L?$+LW'
Lmxgwa!vLlp?
lN?H[x
l	NuU'J
.L#P@/
|L!u<<X
L}v82m
lvx?Yu
LWF\5v
lW|'}r.
LXNEOW
L+%Y1B
L+$Y1N`
l|:YR<
$L_Z7$_
M0`?[A
M1-k	n0
'M3/he
Ma efV
{Mb=3K	
mE@^	1
>mg=I=1
mGY:FW
 M:<lM
MMMMMM333333333333
%m_Qg	6
mr02n>>]
/mrA02
&mrl4F?
M~>=RX|
:ms7|CIR9
Mu\m]E
mUVI[a
)m&`Uz)
|M]V8?
M+$Y1B
/mYH\\
_(M+,z
N5C|`"
(n~8%f)
+n~8%f)
n[>9ym@|2
)nb!%a)
)nb %f)
ncnE_ 
&n*CQZ
)nd&%a)
)nd#%a)
/nEA-;m
*ne%*i(
.n|?%f)
)n~>%f)
/n~>%g)
nGaN5`
)nh,%f)
&nIC67#
)niR%f)
)nj)%a)
)nk/%f)
)nk.%f)
-nMfvQ
!Nm;|O
(nn*%f)
)nn*%f)
/np8%g)
)np>%g)
N}pYR9
+nq8%f)
+nq?%f)
+nq>%g)
.ns8%g)
.ns9%g)
.ns;%f)
/ns:%g)
.nt:%f)
.nv4%g)
.nw4%f)
.nw5%f)
.nw:%f)
(nx<%f)
''n%Yh
^nz$c|
-nzG?")
o;/6dzeA
o.c=01
+od %a)
*od#%f)
oDVtv*
ofM|^fV8n1
~Og9yq
*og"%a)
+og#%a)
+og"%f)
]oGvPI`u
|-oIGFgg
=O?iZ|
o;J.J.c
O+l*JwE
-oR7c2fC
[OR{zXQ
;owS9y
=oY39yO
	O<=yc
OyxRat
(~p96k
P9ypd|
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
p#b	jR0
PB-o:#
.PC@&[
=PD4L)
pd|-og
[P[dU.N
pE2}N=
>|PG<a
PgAZH$
;"P^gw
PhyW'|
Pi=jb(
P=nq;`Y
PO0DN<
.P%o9<[
Pq&^sy
ps7n[CA
PS>E@w5
PSzHW}
|PTl?=
pU[h2S
;{Pwfc
PW}n3}
p@|X8Fm
\q00[*
q1L">@y}:6H&HLA`
q3F?;m
Q9TP(\^
_:qbh_@
Q| \FjC
~}qgC)-@
Q|<_ge
q&;M^h
qR&d&em
	#qS5~
QuF=:qF
? QUW9
<}Q.V;o
q'v*q{
[Q|~W^
=R	~^@
{/r17D
r&	4-K
R|9,Y==YY
R.AD(+
rail:Z
RaR":cR
r[$Ds\fV
ReL] T
Rich!4O
`Riv18#
Rjg$Y_
R:@*Ln
RlOXE1
*=&rnr
rPoI;m
rsgN;=X
RXG6LEZ
ryc		x
[:-`~s}
s7M"l,
s}8e3!
s8L8DYk
sA}yw\
&sBV-SC
s>dKu$
seaTN\
sEQ)eK]
.!Sgh9
Sgva}w
s>$Ku$
s>LT/7
 s]#NN5t
so)/3g
[SOGtX~o
S`qg4TaY
SS68|)
]Su[J;
'sVUzPkD\.
S@WCLk
s&"wU9
(s?Xmt
SZ4SJ5Cs
t00XfA5
t:{-'1X
T<`/1[$Yp
t<[2<z
t5{w7P+
t6MF~<
tC;/(w
T!D@i6
`Te6{/
@;t_h$i"
!This program cannot be run in DOS mode.
&T{i[h
`tj4co=
t<JF4C
T~N;O%
tp67(>
trb%#(
^TrW<R
ttn	LM
)tv^u|^
tw@$E	
'Tww E
TYQdg5
t\[Z9Z
u4Bc`L)
UbY}4:Z
Udx*6Tv
U`E}l4
uEQth81
U:FC@wj
ufI6hlY
!UH7$_,
U"mOn{
uMqB])
u}o'Rty
Ut0}=X
uTu?wb
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
{];uvc
 }UY!>
V0sG#3UC1"
V	3mS2
v5~iRY
.<}V9n
[V9y_{
vA2l2w
'vc:5\g
|'vFSc
:vG."N5
v=/[Hk
VI,~B=A=
vjICwI#Zqf^
VM4hV0
==[Vox
`V:o[Z
}~<%}VQh
}Vt~?VV
;VTw&9w
?V=?[V
w@0aKy4
W0kACR~
w_]1J=
w*!}5e%
W9{CWQ
WAYPQP
wBcKx<r
]wCq~l
wDejEPI$
(|wIW8
w}KgDs
W]mGt1
wmtq5[;
WN_,7N_F
WN/:U>
WP{C@P
WP{CvP
w$*qjyn)
WsFy`U
WSV2!{
WTJo~k
/$W{tL
. !wVO
W`@w4A
w^)w9e5
w<wQ(J
wwwUUU
wwwwwwUUU
wz\aRz8
wzx>](
=[x0}G
)|X1g/d
~|@x6r
X^7%])
X/A(M70x
XeR{oa
xgt*`l/
XI}eYR?
XJyb[b}
XoAP2/
&xOe9y{
XRf@I|e9mp
XR<o"`1
->X%t]
.X<V9o[
%XxB[	
)XxYjf
x}=YR=
|xZw:Q
{?y0(@L
~y0s9<
$Y1NX0T
+%Y1NX0V
Y3(o(Z)
y44;dmi.
Y[6Z3.
y7'|N?
Y@9D'e
Y9mW;m
~y9V9o3
yaRj8aRz8aRz8aRz8T
<Yb-Py
Y,EmJt
~yES*S
[yFNm	
:YH0_r[
Yi3qxd
<Y`I|O
Y&Jd&b
<Y'j|O
~yJU9=[
Y[n=@o
[ynrPE
=[/>yO
yOE+x<
=YoIzOf9y
<YO(zO
~yPG9<[
 YPP<s
YQQg'w
~yS{9<
.YuCvBV
|Y~V8?
YVM5WtUBNx
ywi~XJz
%((<Yx6
<Y;X~O
y?yCk#_
y/?YL=
yz*hgc+#rXt-5
Yz*hgt:
yZXB|4
Z1-<Ko
|Z6V8o3
_z7$j,
z|bOV>o[y
zC2G}X
ZC3l*pe]
zCTQ?$b
zCTQ<$B
zCTQ<#B
zCUQ?6b
zCVQ:I
zCVQ;/j
zD@75]
zJa7zQa"z@a=zTa7zJa7z
@)ZM}c
znaRO8
zN[S;;
ZO^[>l
Z(O}Q^b
zpOKM_
Zs6PdT
|Z}.-T
ZU'G=BMDb}T
ZXFb2[W
zyFbX|m5@