Analysis Date2015-01-14 13:31:31
MD55d835a75511381fe17b617e675cb56cd
SHA1e16fb01552d250dd5feb81dd2365b123b1856d6d

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhashc574aee6e2074c3d8841b9ce1f350e40c696066d
IMPhash
AV360 Safeno_virus
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)VirLock-A:Win32:VirLock-A
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)Ransom.VirLock.A2
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99f1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!5D835A755113
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecW32.Ransomlock.AO!inf
AVTrend MicroPE_FINALDO.F
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\eKsEEIcA.bat
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\eKsEEIcA.bat
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Creates FilePIPE\wkssvc
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Process"C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates Filewwcg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FileoEgy.ico
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FileC:\RCX2.tmp
Creates Filecokg.ico
Creates Fileaogo.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FilewUEW.ico
Creates FileYUYu.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileC:\RCXF.tmp
Creates FileAYke.ico
Creates FileC:\RCX12.tmp
Creates FileYAoO.exe
Creates FileC:\RCX18.tmp
Creates FileKoEy.exe
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FilekwAM.exe
Creates FileEgko.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileC:\RCXC.tmp
Creates FileyAQW.exe
Creates FilewYQi.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileEwUs.ico
Creates FileC:\RCX9.tmp
Creates FileyAki.ico
Creates FilePIPE\wkssvc
Creates FileCUMW.exe
Creates FilewEoe.exe
Creates FilemEok.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FileC:\RCX1D.tmp
Creates FileuIMi.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FileegkU.exe
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileIAMS.ico
Creates FileC:\RCX17.tmp
Creates FileYIkA.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FileesIU.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FileyYMO.exe
Creates FileYQkC.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileAoUK.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FilewgQi.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FileMAwY.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileAIwy.ico
Creates FilegAUm.ico
Creates FileC:\RCX3.tmp
Creates FileC:\RCX20.tmp
Creates FileYsYm.exe
Creates FileC:\RCXB.tmp
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates FileYQom.ico
Creates FileUsgs.ico
Creates FilewAIW.ico
Creates FilegwMC.exe
Creates FileEYIY.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FileWMEI.ico
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1.tmp
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileUwMQ.ico
Creates FileAYEy.ico
Creates FileC:\RCXA.tmp
Creates FileYcUi.ico
Creates FileC:\RCX1F.tmp
Creates FileC:\RCX13.tmp
Creates FileC:\RCX11.tmp
Creates FileC:\RCX21.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileC:\RCX19.tmp
Creates FilesYsg.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileC:\RCX1C.tmp
Creates FilekswI.exe
Creates FileC:\RCX1A.tmp
Creates FileAoMW.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FileEcAc.exe
Creates FileUIQo.exe
Creates FileEkkQ.ico
Creates FileIQQC.ico
Creates FileC:\RCX8.tmp
Creates FileAQEW.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FileIocK.ico
Creates FileWEEG.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FileAsgq.exe
Creates FileWwcY.ico
Creates FilegUkW.ico
Creates FilecsoI.exe
Creates FilePIPE\DAV RPC SERVICE
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FilegYQS.exe
Creates FileC:\RCX16.tmp
Creates FileMwMs.exe
Creates FileC:\RCX4.tmp
Creates FileMIQU.ico
Creates FileEQUs.ico
Creates Fileissm.ico
Creates FilecEMQ.exe
Creates FileUscc.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates FilekUUM.exe
Creates FileYMUC.ico
Creates FileYoki.exe
Creates FileYMgm.exe
Creates FilecMoU.ico
Deletes FileAoUK.ico
Deletes Filewwcg.exe
Deletes FileoEgy.ico
Deletes FilewgQi.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FileMAwY.exe
Deletes Filecokg.ico
Deletes Fileaogo.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FileAIwy.ico
Deletes FilegAUm.ico
Deletes FilewUEW.ico
Deletes FileYUYu.exe
Deletes FileYsYm.exe
Deletes FileYQom.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileUsgs.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FileAYke.ico
Deletes FilewAIW.ico
Deletes FileEYIY.ico
Deletes FilegwMC.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FileYAoO.exe
Deletes FileWMEI.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FileUwMQ.ico
Deletes FileKoEy.exe
Deletes FileAYEy.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileYcUi.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FilekwAM.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FileEgko.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FilesYsg.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FileyAQW.exe
Deletes FilewYQi.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FileEwUs.ico
Deletes FilekswI.exe
Deletes FileyAki.ico
Deletes FileAoMW.ico
Deletes FileCUMW.exe
Deletes FilewEoe.exe
Deletes FileEcAc.exe
Deletes FileUIQo.exe
Deletes FileEkkQ.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FileIQQC.ico
Deletes FileAQEW.ico
Deletes FilemEok.exe
Deletes FileIocK.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FileWEEG.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileAsgq.exe
Deletes FileWwcY.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FilegUkW.ico
Deletes FilecsoI.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileuIMi.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FileegkU.exe
Deletes FilegYQS.exe
Deletes FileIAMS.ico
Deletes FileMwMs.exe
Deletes FileYIkA.exe
Deletes FileEQUs.ico
Deletes FileMIQU.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes Fileissm.ico
Deletes FileUscc.exe
Deletes FilecEMQ.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FilekUUM.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FileYMUC.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FileYoki.exe
Deletes FileYMgm.exe
Deletes FileesIU.exe
Deletes FilecMoU.ico
Deletes FileyYMO.exe
Deletes FileYQkC.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Network Details:

DNSgoogle.com
Type: A
173.194.125.64
DNSgoogle.com
Type: A
173.194.125.78
DNSgoogle.com
Type: A
173.194.125.73
DNSgoogle.com
Type: A
173.194.125.72
DNSgoogle.com
Type: A
173.194.125.71
DNSgoogle.com
Type: A
173.194.125.70
DNSgoogle.com
Type: A
173.194.125.69
DNSgoogle.com
Type: A
173.194.125.68
DNSgoogle.com
Type: A
173.194.125.67
DNSgoogle.com
Type: A
173.194.125.66
DNSgoogle.com
Type: A
173.194.125.65
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 173.194.125.64:80
Flows TCP192.168.1.1:1033 ➝ 173.194.125.64:80
Flows TCP192.168.1.1:1034 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .


Strings
7.7..
...
.
Q
.
.
.>.
..~
.
.
..
.
.
..
C....
.
.
..'
.
..C.
.....
k
.
.e
..
w
..]
@.
=-}""+
{)}#)*
06DM/D:
0CxP3_,
0G|]O"n
0PI>[^
0Vh2+%w
0Xe}6R
![0XfC
{153[?A
1, I*dx
1IQ{9A
1IQC:A
1IQ??G
1IQo=E
1IQS94
1IQw=E
1Kb%AZ
/1$M7L)
.1Wn;-8
211}v_
*&@~24
?27osP
2'g:Ad
2[Lsq 
2)ph?)ph
-2}PZ/	Y
;2.`re
#2Rhow
2tpk5q
:2uOsJ=n
2)<W1g
	@3d.#
3fS |ym
3H'"(L
3hn\x>
3_IeoH 
3(ioMj
3@j,c@
3Kjqq5^_
+3uHTXZd+
3#v7GN
3`>>ve
4dA8H|AF
4g$=&?y
);4-*K
]4Nhow
4Tz`pO
%>4Yh&)r
`/_..5
52P(y1~
_5)5&:L
5F;lx?
5FY@(S-d
5L9{BrvN%'a
5&mI%d"
(5p4'c
'|*5w5
^5zZ.8UmM_a
>6>jI\
6<l8I8
$:6pdN
|6P N[
}6 )}Q
&!=6rn
6tdN\~
6>vJ2W
7A4PF,f
7Dz6x.
7e+[T 
7M?1)F
7`}]O5w
7UA!<?
7YLnlqfp
8i|{\=
&8lw'Ko
8$; m\
8mv1]~
8nbe<gi
8]nopWn
-@8q7/
8u(L$J0
(8w*|N
8yh;_a
9.1D`-
92)F)&
9A8j_H
9aA)QK[W
9Ae/6M
9D&H][
9hmfUR
9kzr>w`7?
9/L#FV
9l @Pd
9Q4	d_O
9;V`@&
)>9X6.
A;>",,
a0^M&fj
%[\A21Tg
A3*boZ
a487d%
	A4V|AF
A8H|AF
,A90)F
A9D8.hF0E
AC'82h:6^}
?|aD,J
adt\z5
Ag!:/}
~^%aGr"
A&]gW^
ai8zB&	
(A l['
A"M2!c
a`n:)px
:Aoikv
aosHF[
aP~:)p
AQ}bp.
a?#QET&C
a[q"Ro
@As,D6
awgh]C
Aw@h)r
A<+YVVsg
>A/yzM#
b2Kix@x
*B'4h0v
b7>W!r
)$ba3/
~bbD;=
+`B-bX0
BCwLxA
B\c}zhJe
b{-\]d4
Bd6RpO
Bdz	gM
"B}}HW
bI"ZhN
BMZXpEq
bNj`N?.-
;)bPk;
=[b]uX
BwJ)T5,6
{b+X6H
B.y_zR{
.|C-~$
c2%*vZi
C7K_rO
c+8`1m
c9X6ly
Cas3h-
/<c+#b
cce)b]
,Ccv.FM
cErti`
Ch@X;=
ClpX}0%2
!c&\MkU
`cn?7cn
C\NbA|w
Cn,Wb&
cSuFE#
C,VGl(
 <cXw>
d4M_sd
+!d;7	
D`@[a#
d=A~A3
:Dak5%
DEeG$6
D/fBf~
Df| Mxr
d/G>@qG>
DiC:Om
diE4NK}-D@w;
D'` kL
dn5O`n
DT_|%M
Dv<4?7
%Dy VcQ
E4f`39
E7ohe03_
e98,aO
EAR9%'
\EBJm}
E=Cbs$
eE8gkN
EE.at_
e(e-F;
*ef2#Q
EF:vjG7
EF]\XG
egI#tt
eiKi[YG
ej3ekg)
$eJ-e\
E>NWn)-0
)	;E$r
Erm--n";
?>"{Ey
EY~)WB
EZ3'li
]f4{*C#
_f7_^W
F8mH059
F90(F2
F90)F90)F90)FR0)T9
$fAo[G
)Fb0)T9
Fc=BV`GF2
"!fDf|%
FdO3N5
.F}dvu
F[:Hs5
fI#o9H0
F=j9-/w
F>"=l58
[FL'!p
'FNLVD`
FoP1&F+
+fpBT!
;F-S&%h
fUZ|-(
[FV.XE
fZZ\<i
G1~	Id
_"g1/ty
G1Y+F?t!
G6Lhow
g6PFN7~
<gbKeW
GC	B;L
?g@Gw'
ghK*ph;Ws
ghK(ph;Wsm;)
ghK(ph;Wu
ghK*ph;Wu
,g@j'fB
g:j+U	[
gNNMGN
!G(p(6
gp{|rJ
GpY5Q.
]"gqA`
G|R&nC	
G+ssjPX
g%t?~c
._gXz4
Gyt7B -(EO
h1)P@:;
h1)tp:;
H.2LOB\
H]7R^98
Hbq2l6
hd0&|/
h=G>.'
#hgs.Ne
Hj+Nu8
[H):KH'_Il
Hm6cBzSB
hM"pa;
H,N?($+
hnA%Wo
h;)phE*p`;
h;)phE,po;
H;P^ku
\HSf{_K
[HTX m)q
hu)rDC
H?"wj~
<\&h.x
I0XW5"
iCOGJ_4p|
}I}CV!
I.!$"j
i.M~^i
Im-P_4
I[[N()
iN	?E'
Ip:7)xq
IqDz#H
iRR&.v
i~U8vY
IusJB	
iy4iHu">
i%?&Yx
J1|KK5x
J1|OK5x
)J5XA_
j`71Z3
&/j9-#
J-$93~*
)?JA(^
jcLQ~v
)jDd8k
?Je|ML
%j]faK 
;Jgp	Xf
{JHh$|
Jh{(oN
JJ*?b^
j[n	^[ns^[n#]Zn
jnu!?Hg
j{p:p%
jqw|j/T.`
J>!.RS|
j_'V5yVT
]:)JVSeQJ
~jy;0Lx
JyIjyhU
K4tZRN
k7(vq%
KhlJ~vL
K}&iC(
}:kIO+
:kIOFXH
kjH*X)/\s
k*J<`Mm
[)*KM:
kNdXeV
KS_Yd*
k	u1e^
.k/WoN3`
l1c80R
l2/_uu
(l3.#3
L?(5z]
l90{g70)
&lbv{[
lKQ)yz
Lkr'7@0,!
Ll~'0Y
&\&l>n
lN 'F_R
LNU@jR
.LOhS.
Lp,x7 
>lrg7&M^
luM+7J
L<Vo]J
@?%!lv|WS
LVyye[ZU'}
LW`B*\
_["><LX@
LXa#pW
!L!$Zx
lZZjl0z
(\[[m 0
M!~3H%~3Nu~
m.3PH-
<m8snF
#MAyvn 
McH;"Tl
>*	m+d
m#{DFru
m	~ErV
MFw^XTwW
]<m`@G"
mh!vN`C@
#MJTXOG
MMMMMM333333333333
,%MQ^^
MqH2)nv
M#[@shsl>
muM~'s|
M	'w|/
m*w&oK:z
mZX=mcR6
%N5hCx
N6P@M{
N6RDO7~
N6RTOt~b
n\6RvO
[n7DZn
@na5}#
nAO2BJB
nbW`aq
n? .c:
+nce*n
*NdAATJG
N%GL.1F
ngVpcR`:
)nhS^M
`nIt`nI8`n
N-;ju,
NN"wOp
(np;yrH
=nV5@`
``nWbdn
nz t[F1;
%>o&2W
O5lT&S
O6z/uY
(O{F5%
@,Oi;,c@
oKC.`(qR@Z,
oo07"D
Oo=q+$
oP7nnK
_oqkI%2
o&qUAr
~{Ov4|
::%p&?
P}|,$@
p2un2e
-P4\~;
"p*5-e
P9l+t<:[
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
P;cB:U
:)phm p
]pHS_$F
:)phY&p
(ph;Yqi;)
:)pi3a
p:~Mi,
PnNtn	
|po%eg
pp~f0F
+PrP$M
pv6Zz'$
PXR}Ckc
^pzotF
=Q.0>Pl
Q\5Vmc
Q6E';5
QC'j}?
]-qD+0
Q`:>sDk
Q%!VlU
Q=y>F 
/r2]1\
R4:NGt@
^RB5~[
rC6RbO
r:d7=M
=,R}G'j
rgqs%t
Rich!4O
^rL<^P
rnDLVz
Rq!]$Q
r!/rT+
!$/RVg
`rw`		JRm
RXb.^U
""s,"#
@'S.,8
&S9SnR-
s!@A5.
	~.Sc03
SDxQY:
S")g|h
+sgoPXu
< @\'SM>=73jz
sN_]lq
(s~&]o:
ST6Dj|
S%VUm-}
sX{ma,
T3znR%
T46&CLr
T9pC* 
TBn*j?4F>J
TD48cIB
TE[w5y
 tGkL+
#t$G~q
!This program cannot be run in DOS mode.
TkE/0X
tN\noh
~!T-WZ
/<T,-{Z
:\u46R
U)5'_B
<UanD1
U}d-c3
*ueF)(zbbV
U=f6T2!
u	gRn0T	
|uH4H5LB
u&h6vi
_%=#uHB
uIub/;
u>Jhow
Upv!w3
U?(qeMp
u[S0eY
u{tfBnJ
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
ux&Q?W
UzekNt
(-'`}v
}!v_' 
V2zm,}
v5o}|S
V>#5VM
_V6k #W4
V)~a20e
vAa;a|
vbYb1v
Vc[.6J 
Vd"Jjx
VIK!`LD
\ V/iq
VJ#oXiGL#
vl5?#bj;
VM-CAJ
v[nBwk
:)vr+]
vS_7;I
VU,.5m
`vuhFH*MdZ
?)vz++
W),"~)
W2^&_~
w6j<TL
w^8M	N
[wc8U>
wdvC/8T
Whmd8X
WhNcJ%
@(%W-KN
W`kujS4,
w@Kun>H
\.WNf?
w;Nhow
,W!n<hu
.wNl/|
w=OzYn{
wr0K~	j
[W~=:V
wwwUUU
wwwwwwUUU
 {	_x}
X)3"G)
x%eF8\
X!),Fz
xGz1Bo
X.,SYJ
x~$]uB
%X]%v-
XxMQK>
xx(Ubxq
+xYh+n
xy=/x}E_@M
X*`zKx5
y<}6D\
	Y9"65
/-YaW}
>YdtdI
!yEfeE
:)yfh.	k
<*YgG!}n
yh;Ysi;)
/Ym7=kr
y\.Nm@/
Y^ntAe
y^O\Z2
>?y|Q'
YQ=`_	
+y`r.r
%[y/Sl
Y.uiA\
YV}gKB
+y.?z1yb6H
	*">Z;
z 2ot\
Z641(y
,;Z8X^
ZacsM'
z(a!-f
([ZF0.
ZH6PrNZ
zHi818
ZM63[9=
ZM67[I<
zNr&$*
zo=),U5
ZR)cAe
ZrIREW
ZRkmu%
ZukWU{b
Zxw~dKg