Analysis Date2015-01-16 10:56:38
MD5dba3cdee2f8454249525e016dc083b9a
SHA1b4013c3ae1534ab5640040087849edaf091a6c31

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhash7bfd043ac63ba2facdc9c3129ea88fe8c8472fd7
IMPhash
AV360 Safeno_virus
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)VirLock-A:Win32:VirLock-A
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)Ransom.VirLock.A2
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99f1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeW32/VirRansom
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecW32.Ransomlock.AO!inf
AVTrend MicroPE_FINALDO.F
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.zip
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\LAQwcMMI.bat
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\LAQwcMMI.bat
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.zip
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.zip

Creates FilePIPE\wkssvc
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.zip

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FileHcoU.ico
Creates FileXkgs.ico
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FilezYkm.exe
Creates FileTEAa.ico
Creates FileC:\RCX2.tmp
Creates FileLEoe.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FileFoEm.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileC:\RCXF.tmp
Creates FileC:\RCX12.tmp
Creates FileHYMg.ico
Creates FilePcso.exe
Creates FileLMsS.exe
Creates FileC:\RCX18.tmp
Creates FileREEk.exe
Creates FilebQEy.ico
Creates FileC:\RCXE.tmp
Creates FilefEYE.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FilevooM.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileC:\RCXC.tmp
Creates FilevwAU.exe
Creates Filedwsq.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileC:\RCX9.tmp
Creates FilejoQS.ico
Creates FilePIPE\wkssvc
Creates FilevAYg.ico
Creates FilerYgi.ico
Creates FileLYUe.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileLoAC.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FileC:\RCX1D.tmp
Creates FilefoMU.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FilezMQO.ico
Creates FiledsUi.exe
Creates FilefsQs.ico
Creates FileBAwg.ico
Creates FilebYsG.ico
Creates FilehQUG.ico
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileLQcO.exe
Creates FileXosw.exe
Creates FilefUIM.exe
Creates FileC:\RCX17.tmp
Creates FilefcMk.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FilejYAS.ico
Creates FileHgMQ.exe
Creates FiletcUO.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FilexgYY.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileHsAk.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates Filefcgc.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FileRUgg.exe
Creates FileTAIy.ico
Creates FileHoAI.ico
Creates FileLgwm.ico
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FilePQkA.exe
Creates FileC:\RCX3.tmp
Creates FileC:\RCX20.tmp
Creates FileC:\RCXB.tmp
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FilefkYw.exe
Creates FilebQgu.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1.tmp
Creates FileHIAo.exe
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileC:\RCXA.tmp
Creates FileC:\RCX1F.tmp
Creates FileXwQg.ico
Creates FileC:\RCX13.tmp
Creates Filedgcy.exe
Creates FileC:\RCX11.tmp
Creates FileC:\RCX21.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileXwsg.exe
Creates FileC:\RCX19.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileC:\RCX1C.tmp
Creates FileC:\RCX1A.tmp
Creates FilefowE.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FilePQgQ.ico
Creates FilevsoA.exe
Creates FileC:\RCX8.tmp
Creates FileLEcC.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FilebQsq.exe
Creates FileLEkG.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FilejYQm.exe
Creates FilePIPE\DAV RPC SERVICE
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FileTEoq.ico
Creates FileXAgw.ico
Creates FileC:\RCX16.tmp
Creates FileTEEK.ico
Creates FileC:\RCX4.tmp
Creates FilefoIA.exe
Creates FilexMco.exe
Creates FileTIcK.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates FilerEUC.ico
Creates FilezQsQ.exe
Creates FileXMYg.ico
Creates FilezEYC.ico
Creates FileDAkW.ico
Deletes FileHcoU.ico
Deletes FileXkgs.ico
Deletes FileHsAk.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes Filefcgc.ico
Deletes FilezYkm.exe
Deletes FileTEAa.ico
Deletes FileRUgg.exe
Deletes FileTAIy.ico
Deletes FileLEoe.exe
Deletes FileHoAI.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FileLgwm.ico
Deletes FilePQkA.exe
Deletes FileFoEm.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FilefkYw.exe
Deletes FilebQgu.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FileHYMg.ico
Deletes FilePcso.exe
Deletes FileLMsS.exe
Deletes FileHIAo.exe
Deletes FileREEk.exe
Deletes FilebQEy.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FilefEYE.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FileXwQg.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes Filedgcy.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FilevooM.exe
Deletes FileXwsg.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FilevwAU.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes Filedwsq.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FilefowE.exe
Deletes FilejoQS.ico
Deletes FilePQgQ.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FilevAYg.ico
Deletes FilevsoA.exe
Deletes FilerYgi.ico
Deletes FileLYUe.exe
Deletes FileLEcC.ico
Deletes FileLEkG.ico
Deletes FilebQsq.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FileLoAC.exe
Deletes FilejYQm.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FilefoMU.ico
Deletes FileTEoq.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FilezMQO.ico
Deletes FiledsUi.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FileXAgw.ico
Deletes FilefsQs.ico
Deletes FileBAwg.ico
Deletes FilebYsG.ico
Deletes FilehQUG.ico
Deletes FileLQcO.exe
Deletes FileXosw.exe
Deletes FilefUIM.exe
Deletes FileTEEK.ico
Deletes FilefcMk.exe
Deletes FilefoIA.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes FilexMco.exe
Deletes FilejYAS.ico
Deletes FileHgMQ.exe
Deletes FileTIcK.exe
Deletes FiletcUO.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FilerEUC.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FilezQsQ.exe
Deletes FileXMYg.ico
Deletes FilezEYC.ico
Deletes FilexgYY.ico
Deletes FileDAkW.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.zip

Network Details:

DNSgoogle.com
Type: A
216.58.219.110
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 216.58.219.110:80
Flows TCP192.168.1.1:1033 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1034 ➝ 216.58.219.110:80
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .


Strings
.....
.v
v'..d-..
..8.c.M
3..
.7..
.Z..
.
.......
..Y|..y...
AGham
.
.
.
..
.
w
..
>
w.c
.S..
..hh.
-.
C
:.
|'
5....
.
&!=)<;
0+`.0..x
01d3'9
0?!1fW
0+3:&x
0f!{Zz
;0@G_=4AZX[
>0i%PAgw
0j+4{J
0Pd\r5\D
(0*PE|
0X4	L%
0XE{YOt
^+1(>$
1EKig>
1GCYMS
^1G"Z>
1MxDyM
1o$B!2
]1oq=,
)/1t%2
1UCIPK
1]	w%+
`1W\D.
<1X99J
23-_	2/
>&>,	25
2.AEyc"
!2!(AZ
>2E$^F
_`\*2o
2$SVRd
;2xdj]5
	3/;'6a
38!'	<!'	<!'	<
3G <*9.S
3>+}H[
3i<&[b/
3IO1CTb
>3jkzH}
.3.LQ3V
\3 L?!t
3[M@QA
(3P'QL
,-|3qQp5
3RPm&hWk$
,_3;|U
4%$44%
|4DFvf
4h1)+>
4-,/. \o
.4 p,v
 |4=tu7a
4}y%JSzm
5(b1y'
<5BKy4E
|5BKy4E
|5BKyt
+-5H"S
/5JA<Ej
+5pk8m
/`5 qt
?,	5U/
+5!&U#'g
,5WWeI
5Ys|k*
%"64"S3
6~AgWUd
6~AgWUi
%6cqq*Mq&
6!d0GN
>6D^	N
6!g	<(
	6;Hh7=Vhw
6`k'+z(]\
6=~O#"
6,\OIv
	6|vh7
6VZG3VZ
6VZxT}
#[@6y'
6Y`0yC
&6z^{'$
6z_1zV
!7	<!'
7[#@`(`||
|7!/0%
75I]'y\
}79N"t
7~AgWU
7eAAuXF
7j+4{D
7+O-2{kI
8?;+|?
8;bGIvYw
8(+f'}
8$$fEN
$8,k0U
=*8K&T*
8lBIh(
8nO0nlvw
8*Qx'#
8R}f*Y,{U"v
8s(>83k|x!
8s(>~a
	8;Wf<
<!>8xiy6<
8xY&;Udlv
^968{)<X
9[-BMI
9hO![S-p
9(i<B7
_+}9!J
9O2"_2
9 U92o
9>VL3.
9+W[TzttJ
9xc=#x
9(.xX"
a?3+xku
a5wWJY*
a6C(GyFEH
a>8;,>>
aaroRP[
A"d9aS
A|D}x|Q6
A_/.DY
 %a;EU
AE	+x7
AgerTW
$ahwY&
>AiYg3`i(q6
AiYi3`x(q6
a]l%]9H
a-L;S&
A	<p,E
(Aqn/<c
;|ar<,
av}Kt+oR
awGtCW
!A),Z~
B>]!^[
&B1>4G
B}\9GM|:
Ba\9GY\
B {Bdv
}BD`}9
B]/^G^/
B.I6b!r
\&;;bIIv
	=b{Lv
+bn^0HP
B?o_3.
bP\LRD
b<;q	_
bQ_Ue0:
B|'RHtlm
&B~SpIv
|(B{Sxbj
buJ	&q
BvY<B|
by\Qm20
*({!^C
\|c2)-
-Ca_- aY
(cbnXl
C[DCQl
(cE1&=+
_cF#?3Z
(CFgVf
/&C$)IF
COE9n~
Cs"CsqD
|CswM:
Cu1B7_
*cVFC+6C
{c]W^;"(B
Cx5fZ5
cx~F:(
CxyA*]-\R
{C"y?$Z5g
D}$'0&
d5>aC'_
D8E	Xl
DaGbz>
d*aMK'H
;DC3sZ
D{C~S7
d	'cU[
dh79gFw
dh79YFw
dI$*E2a"
DSRh@7
DT=p>$Ba
}dT;RX
DW KXd
*DXUyZ)
dz-49fX
e{73E-
e'C<=h
Eg".Ce
E!%{GCv
E!%{GEvp/
\e`gHw
ek|]M#
.~E$kv
#em-"#
EMe0:H
eo`T*RC
Ep}vI"y
eR#>Izp
e.Rvq5
E';u4w
eU6do\
!~evd4
^F\1r.
 F.3.V
@@F4G^
:F5Jo$t
F8Ci)YQ
=?/f&c
ff	2k@
\(FFAmh
_f^(fs
FG9.fvR67
-]FHuC
FiT(;Q>#
f&i=Zx
F\,KR[.
FKX>db
 @f(ln
&F	N>?
Fn).vQ
Fn	{"X
&f+OGp
%f_^Rh
f<[rRW
[fVV/F
@fwC2XQ@
FZ=6VZ
FZFZJk
 g.^*;
_+%{G_
,^G_/^
]/^G\/
*^G_/^
G08u$?
g2Hn?r
,G'2s:
^g)9BR
gap=`s
gb	I|z	B8
gDxQ&Q
GG^'6V
|?ggea
GG<v?.
,Gi7> 
GJTtSp
gM"?VF
GmVZaU
_Gn3.V:P?o:P?l
)GSUGq
.GtI/<
'GW&]{
G;"wV6;
Gy<-hG~
GYVZ+V
{GZUzn
H1qo8.o
H/5V;W
h6q!Vy
h$6{:T
h7<k!(
H\>B7M
H\dbww
$:HDUU
HgPHgp
$ hI.c(
H(~IgS{
hM:4?QkF
%H}M(g
^,^HMJ
H\n)%M
Hn-nOn
HoDyEn
h$(Ou`
H>Ra[h3
Hrv\8-,
hwc'pw
_hwM<Zt]4
@hwO]`w
h<w\U3
hWv@'U
}Hx?;5<
#|hY4z
_]]HyEV|
H\ylM09
/H~YLR
:HYm)e
h=+z//K
i4#juHM&
I6=!-s5S\
@i`Fg.
ih+~:^
;IHG,)
i"H	tr,
iI556r0
iIljzP
#I	litS
i.LQ3.
:IMh)6
i@m{%(T#*
I'na}gK?
i|@o4=D
I^oORS
	iowvd6
iqA]#1
Ivzj0T]8
*I~XQMo
I=XTU}
j0,.jU
J1=}tV
j+4{WJ:
j5$%X{x
j/	a2H
j)c:t8G
J#dA	"T
 j&|DS_;
_J?,fh
JGLcZ1
JGL;Z>
jH6{kx
JI@U~D\'
jJspi7
J=K`=]
=j=~k:f\(
;JM_U~
j%O>Zb
Jq,fbe
&_JT]yP
 ~JWdmW
]J}xOK
JY.gMJp{
jZ0k$Uf
k~3T}?T
k7#eM'
k.A]1o 
Ka7I<#'
	kIf:f
;K ;Jxwh
klyBYn/
kmGpOnga
Kn0yje
kNA^/K
@KnHRK
kOAK:]
|*Kp1U
"KQ_eO
'kS;mS
Kwa1+N
kX%W{+{
KY~a&,
L%0h*%
L)={1+9g
-+*l2R
$L.!4<\
^#l9oM
LAG\3J
LB(!G&z
l[E33[
LgWUb28
L\J}JSy0U$j
l+k*CJ1tz|
lMP#1rJ
l<o{M/
L`oUvdoUvdoUvdoXv$
LuiV@VWI
lvirqz
L.V@sMGs'
/=l%x{
LXGJ0J
LYdN D
l!Z.6LIJ&
Lzr]g/
LzW23XT
M^4Din
m|4h7g
m9dvh}
MC\eNA
++McvK
MDgty.vi
MDtIvM
<|me6K
[	Mf6s
{/m)KHc
mKWa=F
Mm!b\m'!
MmG3&2
:m,MQG
MnHRRz
MOx8t@
m_#p$a
[+}\M(S
MsD-|B
MuugY)
}"mVl8
MW2#sWG
("M^x`
m]{YJ1
$^N01%*
n3.V^3
n4]GLE
N6 ;.b
NF;0 D
n#I@Z<
nNA]nKG
nN';rg
nOld*-
npN/!@3
nq_EA\>
NQTx8F
n\`rn\
n=Rz:+c
Nt[kj;
n<W4AD
nwsj'!
Nx"<Gr
NxVZw{
*^NZ(^I
O^+1!e
O2h>kbd
O2\WOM@
\O4?\c
o4S%6V
O)9_)Dl
OaK10R
oa:Q2U
O\AZ7m
OB)Kc)
'OBqx <
OC@*=$)P
"O-doi"U
o Iku`
![O:Ja
:OjKp9
*|oKt2
o~n8 n(
&Oo&K2
OoNA_b
O,OQ_.
o!o!Ux
op]afRP
opk^FmzJW$[
O/Q?B6
o>qe h
Oqx2w6
-OR_nH
#OrX\B
oVJ}r2
~+oW0mn
=oX~j_
O(x==w
$>"?p\
]P0e'i`Ky:S
?P1}4	^
p^2ph=
p3<FEh
p3YJ@nh
P8B	(7
 ~=PA:
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
pEGh1R
Pf00'f
;/pGj]
PgJ)HK/
pIpOp}tI
P;jix[
pky8;+
+PNMY[
\!PT,{g
pwJl@0
;Q^<0Rwf
&q.1o2`
Q<|4'{
,Q6Mwp
q6S[,b|$
'	|q,}a
q&~a!'	<2'
QBeT?;
q@C,Ni
q+hY>t
QJ%U;&
q{+m8&U
QNeNBB*
q@n NOG"w
q_PIxa
/-qrB8p
Q[w3.V.Q'Vc3
QxC\W(
q"x=fX.a'D
QyL-VA
+;Q-Yv'y
qZ8jaSS
,QZ~Lv
>	#R?#
R@bbjn
R |G/0
}R{GpQ
Rich!4O
Rjg^A,.
rjpr}e
Rllh%>
Rn3.Vn3.Vn3.VL3.
Ro8)>:
R! &P)
r{P$P8,
"r-pVg
RPY+J`
r=?)"t
r%U1/	
>r@XGsb
@RyRx_~
{s\>0T
S<1'	<|D
s+1}!(s
{s5[??
s,/[5[
s52Y	i)&
(s.6D-
S~=+b[n
S(bTS:
S.("cH
SEd5Sy*?QZ
%SEg^&9
SEysTvh
S=+(g9
sI~))>
Sicf@B
]sIvYSV
@sjEW`
[Sj:.wc;
S`k( g
s>;ME>
)-sMv<
,_@s}o
s&>OG{.
S}+qRk
S>=tY$
s}u	#2D
S	u,wXH
s}X	#2D
[?SyZ%I
t"1;#0
T1+Q,H
:t]6(-??
T 6|Hl
t6\uq8]
ta@1..
'!ta3d
ta/6`BT
>T^BZ*
)t_D<3@
TE~(M$
tG:H/&V
tGKWdG
tH.\ir
!This program cannot be run in DOS mode.
tI{q}+.]~
%@)^tj
tJog.ee
tk)J|grGvN#
TLGVUB
+-tM`*|*9'_0AkC
t	N6MZ
TNS)2U
tN?=s5
tpE:KY+
t(,q8F
Tq\__zr
,Trk.T
`tSG\H
ttA0KO
tTUFwF
:={<tX
tZ]9'%
u"5M y
u*65}:
~U9a(b6
"U'A<t
{uB0[c
uBz=iwi
Udkk%W
ud+S,3
U(,"F"
Ufdo^v$
U[G%Q~
ujh	yC
UMe0:H
^um]oB
U<mvKC
u^%q+/
uq4Ka7
U.Q.V~i;
UR%z`Be
Uss248]F
)Ut<4f
utm5kyK
uTX{uTm
Uvdo+;
UV)^@Pg
!--U	-X_
UXB@J`
u<y7pJb
`UYFC&
|^V\|&
V01Axpp
v0t*/8
v18'	<aE
.V4Q?n.!
v6;Qol
v7)ui;
(V?a{#8
v	C=Dyz
V|ir??
vIR06W
vIsTR>#
VL3.Vlu
v{L/Yv
vM|:	]
Vpqzxp~
.VQsMGB
VrDjdz
~vR	h~rpX
vS2OulRb
vSe_w(
V	/x|j]
vxm3C#
VYsLG~i=
,vZ-6L
[VZ7{n
VZ`k;:
w+.@):
@W1%;R9
Wa0eAE:9
W)DCnh*
wgWE70d
	WH{/gD
wJGVfh
&WjQ:<
>w+pZ8,
W%^qI[
WSQ6VZ
WTXO[ 81zW
WuYM~|Y
{WZtGz
[#x05Ezbya
X$23Rbu}
x79Fb7y
x)9WIw
xbVcFR
<XCD:N
#x}CQv
=[XE^F
X*EID&^
X`<*f'
:X`FB:
X\G$Kf
Xj_&<R`\
XJROUT
xkBMZW
XkE=-z
Xl~@;A
Xn3.Vo3
Xn)!5]d
=XnwM"
>XOY:\/3
xpr9<@
	<XTK<
x}TQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeTQBeT\B%7
XU<L%b
]X{uTP
xwM|Sk^
:XZz1Q
Y3wv7M(
$Y6gu)
ya3	/y
yaCU,>N
(yBKBHq
YB}LMh
?YcwE\
|y|c=#x
y?dg~O
;yDQ_ 
YI8YS_
yL7mqML
!yO&b^
	yoojCH![=
YOvvF\
|<yq1,
y]rb1<
<-+Ys3
yt76{}"
$~Y)Tg
_!Yuuj
YwhwY:
[yXa3T
y&Y7dc
Yz{	^_.
Yzuy7;+
Yzvy"{
Z`#5%,!
Z*6LnJ&
Z?B)}_N
Z:CTZ`
z d`{6
zeIa%/
Z}E+Mn
(Ze]xd 
ZjEFfb.
ZjEzfb
:	%Zl@
%z;M$|
"ZnPcN
ZRV_Wz?
 z_<}t
.z.t1z
zt)kC1
*zuTXStT]m
z+vPCa
z,Xpzo/[
zZDE&@