Analysis Date2015-01-10 23:53:11
MD51e9d4cfd0f0902e14dc8f9d268e364fb
SHA1b89cdbedb9c78ea8fd051a2806535979f6daffdb

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhash7bfd043ac63ba2facdc9c3129ea88fe8c8472fd7
IMPhash
AV360 Safeno_virus
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)VirLock-A:Win32:VirLock-A
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)Ransom.VirLock.A2
AVClamAVWin.Trojan.Agent-833019
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99f1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!1E9D4CFD0F09
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecW32.Ransomlock.AO!inf
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\fsgsgkAk.bat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\fsgsgkAk.bat
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates Mutex_SHuassist.mtx
Creates MutexShell.CMruPidlList

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Creates FilePIPE\wkssvc
Creates Process"C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FilerEAU.ico
Creates FileC:\RCX2.tmp
Creates FileFgIg.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FilezsoQ.exe
Creates FilefEsO.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FilebMsU.exe
Creates FilebUQc.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileRsYy.exe
Creates FileC:\RCXF.tmp
Creates FileTAcw.exe
Creates FileC:\RCX12.tmp
Creates FilePIks.exe
Creates FileBgMs.ico
Creates FilefccE.ico
Creates FileC:\RCX18.tmp
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileDUkA.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileVMUI.ico
Creates FileC:\RCXC.tmp
Creates FilejgIk.exe
Creates FilefgQe.ico
Creates FileXEcW.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileC:\RCX9.tmp
Creates FileXUgK.ico
Creates FilerggE.exe
Creates FileDAwc.ico
Creates FilePIPE\wkssvc
Creates Filevgwq.ico
Creates Filezwoo.ico
Creates Filelgsw.exe
Creates FilejwYI.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FilePgQu.ico
Creates FiledIwC.ico
Creates FilerMsu.exe
Creates FileC:\RCX1D.tmp
Creates FilePogG.exe
Creates FileTYAo.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FilezkIg.exe
Creates FileTkIc.exe
Creates FilejYIA.exe
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileC:\RCX17.tmp
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FilejMgA.exe
Creates FileDwcc.ico
Creates FileRQYO.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FilePgsG.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FilenIEi.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FilenwoW.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FilerEos.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FileXssI.ico
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FilezksI.ico
Creates Filevkgi.exe
Creates FileC:\RCX3.tmp
Creates FileC:\RCX20.tmp
Creates FileC:\RCXB.tmp
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FilezYME.ico
Creates FileHIoS.exe
Creates FileHkoi.ico
Creates FilenswK.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FilexIAu.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1.tmp
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileC:\RCXA.tmp
Creates FileC:\RCX1F.tmp
Creates FileC:\RCX13.tmp
Creates FileC:\RCX11.tmp
Creates FileHEMO.ico
Creates FileC:\RCX21.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileC:\RCX19.tmp
Creates FilePskm.ico
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileC:\RCX1C.tmp
Creates FilenYUi.exe
Creates FileC:\RCX1A.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FilezEgQ.ico
Creates FileNwQE.ico
Creates FilePgEu.exe
Creates FilefggW.ico
Creates FileC:\RCX8.tmp
Creates FilezQkw.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FilevkgS.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FilePgQK.exe
Creates FilePIPE\DAV RPC SERVICE
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FileTwYc.exe
Creates FilevggC.ico
Creates FileC:\RCX16.tmp
Creates FilerIMU.ico
Creates FileXAQy.ico
Creates FileC:\RCX4.tmp
Creates FileDkEw.ico
Creates FileLUsQ.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates FilerAkU.exe
Creates FiletEYA.exe
Creates Filetkcw.exe
Creates FileDMYM.exe
Deletes FilePgsG.ico
Deletes FilenIEi.exe
Deletes FilenwoW.ico
Deletes FilerEos.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FilerEAU.ico
Deletes FileFgIg.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FileXssI.ico
Deletes FilezsoQ.exe
Deletes FilefEsO.exe
Deletes FilezksI.ico
Deletes FilebMsU.exe
Deletes Filevkgi.exe
Deletes FilebUQc.ico
Deletes FilezYME.ico
Deletes FileRsYy.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileTAcw.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FileHIoS.exe
Deletes FileHkoi.ico
Deletes FilenswK.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FilePIks.exe
Deletes FilexIAu.ico
Deletes FileBgMs.ico
Deletes FilefccE.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FileDUkA.ico
Deletes FileHEMO.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FileVMUI.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FilejgIk.exe
Deletes FilePskm.ico
Deletes FilefgQe.ico
Deletes FileXEcW.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FilenYUi.exe
Deletes FileXUgK.ico
Deletes FilerggE.exe
Deletes FileDAwc.ico
Deletes Filevgwq.ico
Deletes FilezEgQ.ico
Deletes Filezwoo.ico
Deletes FilePgEu.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FileNwQE.ico
Deletes FilefggW.ico
Deletes Filelgsw.exe
Deletes FilezQkw.exe
Deletes FilevkgS.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FilejwYI.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FilePgQu.ico
Deletes FilePgQK.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FiledIwC.ico
Deletes FilerMsu.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FilePogG.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FileTYAo.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FilevggC.ico
Deletes FileTwYc.exe
Deletes FileTkIc.exe
Deletes FilezkIg.exe
Deletes FilejYIA.exe
Deletes FilerIMU.ico
Deletes FileXAQy.ico
Deletes FilejMgA.exe
Deletes FileDkEw.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes FileDwcc.ico
Deletes FileLUsQ.exe
Deletes FilerAkU.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FiletEYA.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FileRQYO.ico
Deletes Filetkcw.exe
Deletes FileDMYM.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Network Details:

DNSgoogle.com
Type: A
173.194.125.66
DNSgoogle.com
Type: A
173.194.125.67
DNSgoogle.com
Type: A
173.194.125.68
DNSgoogle.com
Type: A
173.194.125.69
DNSgoogle.com
Type: A
173.194.125.70
DNSgoogle.com
Type: A
173.194.125.71
DNSgoogle.com
Type: A
173.194.125.72
DNSgoogle.com
Type: A
173.194.125.73
DNSgoogle.com
Type: A
173.194.125.78
DNSgoogle.com
Type: A
173.194.125.64
DNSgoogle.com
Type: A
173.194.125.65
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 173.194.125.66:80
Flows TCP192.168.1.1:1033 ➝ 173.194.125.66:80
Flows TCP192.168.1.1:1034 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .


Strings
.o
..D..
,
...6
e%
y..8
T.
..".
.
e
z
..
..
.
C
3
.
.
F
.
c
C.5(
I
.
.#d

[|-:+~/
0"3CT>
(+%06}
0G=xiB
0j+i%DNyhj'n
0/jwH/
0lej/K
|,0sjd
0 TUR;@
-?0uX.
{(0WnE
0' Wng
1#.0]z
15lo_/
<1:?AB
<1]"H1
 }]1N2
_1?-o}
-"(1<t
1&T.D29 
1#w"Vo
},22l%D
2.cc t
[$2@o>7
2r<k'ja
2tQHIf
(2>?(Z
3>C7vLb
3DP@>j
3dXXuc
3e81Drv#2?
3g>+`B4
3i%l%f0%
3iO*Vr4
3m%`0u
3m-4Zp
3m-,*j
3m%l:{
3,S[-d
~3WtQ_
3Xa*m%d2vu|
/4b5 [
4/$#c1
4(!Cu&j
4dVp45
4/|eIf
4(&G?3
4_i|z:
4j!g61
4S}%$"<
4s7Y#A3
4,S[-d
4T}Et\D
>4W%bl
5[4x8,4
=5 8/(h
5&c	7.
{.5> j
~5k+-4d
5;$>m)
_5M(!bi+
5pM>L7-+
5`pU]H
5uoQDh
"5YbrH
64|J=L
6@#9[#
6EB.a9
}6iyN5
6iZz?l
6	k+-be
#6Lbe1
6:=`$m
6'nma}
6O	\1bD
6OD:z,
6pi+ia
6 s8i%
6wNgFfq
6Xj+mn
^6Z(,K]
[=79rB
"<7DX?
7hj+i%
7)j*-m
7K1NUo
7lf	96
7{lH	"
7\ N@g
*7q1QO
7=S9	6"e
7	u1L.
81([TH
8.?#"7
8	cV}~
8[D'DZ
>`8eGv
8F^QLz$
8i%<l~
8j`HzG
^8k+m&
8m%8'}t
8m%H#u
8m%T x
~8O45M/
_>*8P>
8	p.)mb
8P#}q=
8u&n&4
$8U<oBYVz
.8W]BZ
8x	Ph+k
-91c:#B
9~9m2iM
$(#9EE
9g"SZg0
9#h^Uho
"9JN)@
9o*D82
9oWY-9
9s!jWk
9u<5Pv
>9+uH9<
9=VeW^
,9wfPC>J5)
9{wxaR"
a{','<
(<{<#A
<A2+_uM?
[.a7/#
A7ZcO.pq
 A=9]y
]"a}A"
ABz\9 
)AdK0Q
)AdK=t
aE(4-%T5
aEmzazCl{
aGjD+)
AHdHH=d
a-^hZ0nl
ai'&bi+
ai/Ke-
a!IV,l&
Amz,fAlm^n~
AnITD70f!
|AQcJ%
AqmmBmz
As8-fe
Atou7v
(aXMNGk
A*X-M$y@
aXSy	s
@<ayM)`
/b1F(E
B5'%ZaO
.>+B6}
| B@(>B
Bb5`)wx
}Bb9.N
Bc[BMR$0es
[b(gO`
b+gPEev~
BhA)0z
bLGzvB
=|`BN 
b|NLuEL
]|`bO|H
bP-/!P
bQp8-e
B,S[-d
BsG^Ffu
b,S[-t
bu!A20
b|U?[j
bWCa9mq
B'x^@-
$by D#y
\bz9:@CW
""c15y
;^c3{6
C.~+ 4e
C4=-k!
)c"5{'r
C.~+@6e
C7~Hyd
c9o,Ix
-C"AlP-
CB1$\7L
cb@,S[-d
c*-.d1
'}cDsT
\CFCLOjc`w:'
*<C"!h
C.~+h4e
C~H+V!
CiC$2,
ck04"7
C k3$~
c,KbzaW
:#"cLl
c*m%|,c
CmvUpnFm
C.~+P6e
c	p#W[
cQ2ZT4
c}s8%a
ctXjPV
#<c-u_vn
C	v)-^
)~Cv+qL
cw<	cc*i
|cYZ'@
&d(@>,!
d2-h_NB
d4EK`]
d?5Q9A
}|]d9	K
|DbcYKB
&D[bRa
'd[,DNv
d;duJ9e
_dGdIc
}dH$|O~8N
_~DJ"1o
Dk4Doy
dk*i-|2`
DKnCy&
D`$m`x
d^MztfD
dp^.QyU
d+[Q>0
dq0z"+
DQUJGe
Dq=|#Y
Dr=&1.
dupU2s
dv2|+e
dwkET]
d`(Z'9O
E6o')XE
E7+5H*s
ei+%fi+
E!&I lD
E`iZ ix;
EK(!&h+
ek/Ke!
ELKOb 
En~WMozk_
En~'Xo-
eP[9B 
EQO_jRCdLV
erDs3,4
e?S7vC
?ESS R
Et:R|b?
eUK+rgO
eut9}(
EZ|;(d;
F0(tsM
f$55-En9
FF$3-;t
fjNr}R
FN4cCSc/
Fnu40~
fpk+m%,
f@,<rN]VL
f~SOoC
F-T^_\0Z
?*F^)u
^F V^hz
{\;}G 
G_6#Zskh
 g/7]6
<g7g6}"x
:gb[82
g~b,S[-
GczXY	J
GFaUAR
Gh/yG@
G?*IVp
\Gk*!*x*
Gl/lJ~<
Gl/p|!
~gpW5d
|:GPz?r
%,gqw)
$gwT??
G@yD._
gZ^+gB
h*!*~*
H03H<S
h0l;g-
H1jW}Ct-O
HA#taAbO
h~Cej~W
h`CN!=+
 hFBmT
<HGSgk-
HhrW|,
~,h&ja
h`KG0<Oy
_hk*miYIxu
:"{Hl^
hlc1+~
HLy8vI
|h+m%d
|HmKiN
)h/Oaq
Hq8i%8/g'
H,S[-d
hTzI{@
^H|u9K
h=v7\U
hVB64X
:h/wZ7"
h-#YA?
h+yjY*
i*!*~*
*i#*4!
\+I8Wv
I9Y-&L
`I: bd
I=$/Bm
/IC_X^
IF"Bj6
IGjiKjabF[
i=-?^gP
i+%&h+
i.hFl/
`i+i-l/w
i+i-P)e
(i)|j~u 
}}I]%Kt
(I;l~H
Ilvs@Qj
i'naqrh
i/Oa=Jy|
i/OaYM_r
*i#*p#
'_:(Ir
IR`D@b
iRwHF&
`*i%TNu
iW2$JnH+
i^wMvT
I@X~za
/iYQ3'
IYU<Cq\{
j4y47i
?J@7i@~
]j+}8I
j>"8R:h
jaU+}U
JCqx{u
Jcx#"AU?
jdkLY{<
.JD\%wX
.JD<&wXR$KH
je5>m}(
j+eb}+
je=D~{
$jeEicc
j+efi+
j+-fe1
j-fZSu
jg[-r.
'|~<Jgr
%JHL'Kl
 j+i%$
^|j+i%H]m
&j<k3h
j/K}GOz
%JL,&K
j/Oa=Jpm|l
jrE7oU'?*
J<rOZd
[%/J	rPw
?j\//S3
[jsLB(>]
j*!*x*
Jxi+mm
]$j?\X<%)xnD>
JyObKg
>K&2ZK0r
k3-8N\
,Ka9Fhq
kB8,S[-d
K{B$Gh
,K}[ca
kCMi]D
Kc\rJp
,KeeKm`t
$,Ke-m}dtYS
.kEzvn
~KHATB/>
k)h+kfk
%KH~(Y[
kiAo5|
k+I|k+
Ki=SNA
Kj~;ck
k/KaEctq
Kk+Q^f
k/K)TU}
k+m%l _
k+m%p\v
k+m-`/r
k+!*R+
k,S[-d
KU_dfx
K:U*-E
k+u^f+
k($U(f
k*!*v*
k*!vt*
,K};Wz
]kYH.;
@'k+!*z*
k*!*z*
/{^\<L
L;1Jrg
=l37dJ
\^La=j
LalW&H
lcCODh
)LCC	P>i
ldt%p&
?Lh+m-
l>IH$.
+L}JQy
lKnyuy0
?#L,m[
Lm!Ro8
ls3l%`
l,S[-d
=+LT{L
^LUT!JV
-L:@w06
-L<(&X
Lx$neq
l~_+Z|[
lzp1\/
^>m&	"
m^0qw<
*m%4#ja
m)$Bad
M|`BF 
m`	] f
MFDI%O
\Mh(RS'
.mi40F
MIMlI+O
{&</mIR~
 M[i'z+}
>MK{	?
mk+-~f
MM9|)s
$m(MAF
MmF>O?
MMMMMM333333333333
+m) na
Mqv"uSXA
'@Msu+xr_W["
Ms Zc>
mTEn0qr
MVGHgd
mW	1qtr
MXYXVo
MzP@! 
>~,N^@(
n0|3=HI
>N2nsx
n&%.5.
_=n`8\
-!}n?8%
na]ezyTE>
naq>in
`nC-"4
}N]Dwr}
neE	li
ne!Slj
NfH'Pw
nFm:`z
"NgTw)
),Ngx[
nJHV$lj
N/@{	k
nK0H]lt
$+nk]NN
~_NkUWO
@Nl/@F
@"'nm9
noxxqK@
(_NQL0
$nR,9P
NS{Aex
N+Sgyo
NSsKcFR
Nvt`7ZK
%n@W~^
n}W(f&
n^-WG Q]
@n(X7.
NXtZvn
N&y.G$
n"y"q)
O2"8K$
o3]5iU+
+o:+4g
O6Y4L*
)o9B50
OaDJ"v2
`@o=B#
|ocQK2
,Oe9C`}0"nY`
o$gwT?
+OH@fc
%OHk%g
oK0ndx
,O}KXak
O~kYolTOciG
OLdhBZWb
O)\L	J
=o,lt6
oM?ROR[
omWl5e
o=`"n+
OnRUOo
OnZUOow
op#Kg 
o|TM+JA%
 o-uw+
o~WOo9r
*Oxe6xfL
Oy}y<|
p#*.0M
P^<11&<Y
(>p1y	
p2{d`D
@_P3bk
^`p3l%\
@p4s~1
p8i&xB
p8i%x#v
p!a8rX
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
PB@[hUbtc
Pb+maY
P>d].G
	:Pec#
]>.PE@U
}/p;_I
pJdw.p
P&l$1`
:[p{Lr8'b
#>Plwui
Pm3dcHv$
Ps8i%lk}
Ps8m%<
Pu^n-ar
?Pu|Qx
@?!p~v
?pvn	;
pW6(YI&
pxLM5wA
=px:pc
PZTzpj
q1yH~:
q1yH~$y
Q2\97!
q5cgi2
~Q5$.t
qA~"J9
qAmzmV
*)q\=c#
~qd_A\
~_&QhW
`.QhY7
QI3S/V
@QjADmz
qj- cP
Qj/Ka	
%)|@qmm
{Qm%My
QNy|Wf5K
Qox'do
	Qr$).
QU1jSd1
,Q/vBqsQ
qV^C}S
Q{xq8m-
#qy|,2&kW
|	R-&<
R>`=\!
r4i+i.
RcJ%)xr
rC\lO3@
r;dUgS
R[g_7\f^
rg91dbQ
Rich!4O
R}.K8.
rlL&jm
$`]~Rm
r}O"X6
\>+	rR
`rRua#nY
R/UP&H
~r\VZ+
rwpcL>3
R[Y{(J
ryrUOo
r%z&<*
%RZ+gv
s8(!62F
s9{9']
s9	&s[Sl8
s`a*m.
s~CobS
SCOZva
 ,S[-d
?,S_-d
[,S[-d
$,S[-d
+^ ,S[-d
+,S[-d
s?Fg.H
SI0;]S
S~i'n^+m
$Sj33y
S[%K3HJ
sl~LgZ6l
s)Mfe1
"<,SN>#
s{p9|*
Spz&vC
Sq^fs_
#SR@,6
S];,S[-d
;s;T1"
S[yD< e
*:sZ1ef
/;SZ@8
T+1QU&
_T2^TY
T'(ad;GD
tA-L}n
tb*i%h
_{tC>^
,tcl@ (m
\t>d|G$R
!This program cannot be run in DOS mode.
Tj+m-<
Tkma4i
T	NKBE
toeFLj
TOk*!*r*
t=| 'PZ
tqU3`R
'>trE:
TU[#]lf
>;TXdhN1
TYG`=I
~~U=\-
U0j_?U
:<uA.8
u@@}E*i
?~u;\eL
u>FG{*
Uf}oD2
uGY5@Y
u~{>h5
uiA^wt
U\`IS{
_Uj%GZ
ulJ""c
UN%rE~
_UolUW
?UqGhj
 ur0B7
$us^2-
Usc'dw
U~tAPk
UUFtyat
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
uv`5{`
u=#W)&
U&"^W[_
*UXbZ=
|U%X|T
/u"z <
uzHIbB
uZq;aj
%+V;&]"
V0k+m%
V0kMy)MIz
!,V>4( 
?v4"0#+
V8b57#X
vA"&)n.
>V#c5]XP
~vdcL3g
V;dtDu
vD.%xP
!v]~e'
Ve+~Uf
Vf3FTN
V{_]Fb`Ya
>VG|:Pt
v<=`h*
V\HcD|
v]Hs~=
VJS;C+
>VOo1b9
/VP	i5
vPrN'y
*vQ4~s
v~QU2ti6
V<,S[-d
Vtou&d
@:V<u,+
=VXN9W
vy09Yx
W11)L~
,w8=/<
w\b*me
W;c]i+}u
WcT}XD
w&?EL6
wF$J1p
}WHAhG
wH`e~I
wH|Niv
^wK|Hz
~wl=c1
}WO}_[
~WOo~WOo~WOo~WOo9r
,~WOo~WOo~WOoZUOow
^w<Qjc*
_wqLNy
w,S[-d
wwwUUU
wwwwwwUUU
<w=$Y/b
>wye],
`Wyo>i
|(_w\z
WZ0,S[-d
X,[60$
X6[!W^
x>buhr
x@dDJQ(
xdXc*S
X}F}A`
~xF!KC/y
XF#o5i{
XfP)'w
Xh+i%d@jfY
xhO6X/H
X=OR~I
:Xp.MZeH
>`xQ^*e
-x)]qu
~Xs8m%PG|3v
X,S[-d
~xS_Y3
xtAmKd
xuEVd]
}XV?gM
Xwfumn
X>yEa-SW
Xy{L\7,
>&@=-y
Y0dL,U
Y0zTR!
Yc*-IO
&yC,J<
yECm j
y~|hf5
Yk+-~f
*YkM~=x
YKvUQl
YkZ_xs
Y$MhUm
ymR;qQ@
YpSr#`7
ypTVp#w{W
(YqD=3
Y*%ri+
Y}?r}MK
YT62qQG
Y>tCny
Y|TqY`C
y`,	uFQ
YUrA4[gM
: [yvtIb
y/w>'#
YY9HEY
yzCmfm
yZ(HM;ll
z2M=*L
Z>4c6L
z/%@:#5@
Z]|9JX
za#Q6x6
z]Btbg
>Z}_m0
	}Zo0bV
zR'Apn
z~SOoB[
Z;VRY%
zW$dm"ozY@
z(wnct>
ZX@w+Ue