Analysis Date2014-12-18 00:01:26
MD518b13e879d79cc6d23c3de2da65783f8
SHA1e2782d98b4356e42d31a2202fd2a4fe07f74d4a0

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 0b807a4e95441bdfcc61e91691930781 sha1: 8c7774f47022b5cfb39bb91d3a9e5cec05b68c87 size: 117248
Section.rdata md5: 2a5a05364afa237f78a47f7523449d8f sha1: 1e3b883aadd91b467343c2a7cf52bf2114a44655 size: 1024
Section.data md5: 5929b7c8b6db5d826b8fe63f7c384ce5 sha1: dba1d745b77001c3dc883ed59197a3bc0442d6b7 size: 79872
Section.reloc md5: d9bba2b357401e98f5895f01f46db308 sha1: 6a5ba4615a9f02ea3a2f668ae94823f7277bd322 size: 1024
Timestamp2005-09-05 14:09:09
PEhash4dcd0b92770704d94a2268471bcfa5bd5d3b9887
IMPhash052dc41c2de7f4f796ec2cdf1079c065
AV360 SafeGen:Heur.Conjar.5
AVAd-AwareGen:Heur.Conjar.5
AVAlwil (avast)Cybota [Trj]
AVArcabit (arcavir)Gen:Heur.Conjar.5
AVAuthentiumW32/Goolbot.K.gen!Eldorado
AVAvira (antivir)TR/Crypt.ZPACK.Gen
AVBullGuardGen:Heur.Conjar.5
AVCA (E-Trust Ino)Win32/Cycbot.G!generic
AVCAT (quickheal)Backdoor.Cycbot.B
AVClamAVTrojan.Gbot-449
AVDr. WebBackDoor.Gbot.73 - infected, incurable
AVEmsisoftGen:Heur.Conjar.5
AVEset (nod32)Win32/Kryptik.SXV
AVFortinetW32/Kryptik.SMY!tr.bdr
AVFrisk (f-prot)W32/Goolbot.K.gen!Eldorado
AVF-SecureRogue:W32/OpenCloud.A
AVGrisoft (avg)Win32/Cryptor
AVIkarusBackdoor.Win32.Cycbot
AVK7Backdoor ( 003210941 )
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesBackdoor.Bot
AVMcafeeBackDoor-EXI.gen.n
AVMicrosoft Security EssentialsBackdoor:Win32/Cycbot.G
AVMicroWorld (escan)Gen:Heur.Conjar.5
AVRisingBackdoor.Win32.Cycbot.a
AVSophosMal/FakeAV-IS
AVSymantecBackdoor.Cycbot!gen7
AVTrend MicroBKDR_CYCBOT.SME3
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
1
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load ➝
C:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\Application Data\75DE.FFC
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Application Data\dwm.exe%C:\Documents and Settings\Administrator\Application Data
Creates ProcessC:\Documents and Settings\Administrator\Application Data\dwm.exe
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft
Creates Mutex{4D92BB9F-9A66-458f-ACA4-66172A7016D4}
Creates Mutex{5A92A751-F926-4BB9-872E-BEC4A4CD571F}
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutex{61B98B86-5F44-42b3-BCA1-33904B067B81}
Creates Mutex{0ECE180F-6E9E-4FA6-A154-6876D9DB8906}
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates Mutex{5D92BB9F-9A66-458f-ACA4-66172A7016D4}
Creates Mutex{B16C7E24-B3B8-4962-BF5E-4B33FD2DFE78}
Creates Mutex{B37C48AF-B05C-4520-8B38-2FE181D5DC78}
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock DNSfolusho.com
Winsock DNS127.0.0.1
Winsock DNSyourmediaresources.com
Winsock DNSyourblogresources.com

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Application Data\dwm.exe%C:\Documents and Settings\Administrator\Application Data

Creates ProcessC:\Documents and Settings\Administrator\Application Data\dwm.exe

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft

Creates ProcessC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe

Process
↳ C:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe

Network Details:

DNSfolusho.com
Type: A
67.222.55.143
DNSzonedg.com
Type: A
141.8.225.80
DNSzonedg.com
Type: A
141.8.225.80
DNSyourblogresources.com
Type: A
DNSyourmediaresources.com
Type: A
HTTP GEThttp://folusho.com/wp-content/uploads/2010/09/web-20-what-is-300x251.jpg?v90=30&tq=gJ4WK%2FSUh7TFmkR8oY%2BQtMWTUj26kJH7yZJSPbqVybhqtUn5CGFATA%3D%3D
User-Agent: mozilla/2.0
HTTP POSThttp://zonedg.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfVsSvT5wug%2BtygfvO7H33Hhbj%2Fh7sbedf1sSvT8t65i9hlL9PmxqXH0bF%2FmiMWrdPd5SOeikL50gB9K5PLNq3eFGjzh%2F8DdAYdrT5WO0alxtygbpb6HvnSAOQij%2B8yvUq%2F3vleWbkY%3D
User-Agent: mozilla/2.0
HTTP POSThttp://zonedg.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfVsSvT5wug%2BtygfvO7H33Hhbj%2Fh7sbedf1sSvT8t65i9hlL9PmxqXH0bF%2FmiMWrdPd5SOeikL50gB9K5PLNq3eFGjzh%2F8DdAYdrT5WO0alxtygbpb6HvnSAOQij%2B82uYvEaSvT%2BsqxSr%2Fe%2BV5ZuRg%3D%3D
User-Agent: mozilla/2.0
Flows TCP192.168.1.1:1031 ➝ 67.222.55.143:80
Flows TCP192.168.1.1:1033 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1034 ➝ 141.8.225.80:80

Raw Pcap
0x00000000 (00000)   47455420 2f77702d 636f6e74 656e742f   GET /wp-content/
0x00000010 (00016)   75706c6f 6164732f 32303130 2f30392f   uploads/2010/09/
0x00000020 (00032)   7765622d 32302d77 6861742d 69732d33   web-20-what-is-3
0x00000030 (00048)   30307832 35312e6a 70673f76 39303d33   00x251.jpg?v90=3
0x00000040 (00064)   30267471 3d674a34 574b2532 46535568   0&tq=gJ4WK%2FSUh
0x00000050 (00080)   3754466d 6b52386f 59253242 51744d57   7TFmkR8oY%2BQtMW
0x00000060 (00096)   54556a32 366b4a48 37795a4a 53506271   TUj26kJH7yZJSPbq
0x00000070 (00112)   56796268 7174556e 35434746 41544125   VybhqtUn5CGFATA%
0x00000080 (00128)   33442533 44204854 54502f31 2e300d0a   3D%3D HTTP/1.0..
0x00000090 (00144)   436f6e6e 65637469 6f6e3a20 636c6f73   Connection: clos
0x000000a0 (00160)   650d0a48 6f73743a 20666f6c 7573686f   e..Host: folusho
0x000000b0 (00176)   2e636f6d 0d0a4163 63657074 3a202a2f   .com..Accept: */
0x000000c0 (00192)   2a0d0a55 7365722d 4167656e 743a206d   *..User-Agent: m
0x000000d0 (00208)   6f7a696c 6c612f32 2e300d0a 0d0a       ozilla/2.0....

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   56735376 54357775 67253242 74796766   VsSvT5wug%2Btygf
0x00000040 (00064)   764f3748 33334868 626a2532 46683773   vO7H33Hhbj%2Fh7s
0x00000050 (00080)   62656466 31735376 54387436 35693968   bedf1sSvT8t65i9h
0x00000060 (00096)   6c4c3950 6d787158 48306246 2532466d   lL9PmxqXH0bF%2Fm
0x00000070 (00112)   694d5772 64506435 534f6569 6b4c3530   iMWrdPd5SOeikL50
0x00000080 (00128)   6742394b 35504c4e 71336546 476a7a68   gB9K5PLNq3eFGjzh
0x00000090 (00144)   25324638 44644159 64725435 574f3061   %2F8DdAYdrT5WO0a
0x000000a0 (00160)   6c787479 67627062 3648766e 53414f51   lxtygbpb6HvnSAOQ
0x000000b0 (00176)   696a2532 42387976 55712532 4633766c   ij%2B8yvUq%2F3vl
0x000000c0 (00192)   6557626b 59253344 20485454 502f312e   eWbkY%3D HTTP/1.
0x000000d0 (00208)   310d0a48 6f73743a 207a6f6e 6564672e   1..Host: zonedg.
0x000000e0 (00224)   636f6d0d 0a557365 722d4167 656e743a   com..User-Agent:
0x000000f0 (00240)   206d6f7a 696c6c61 2f322e30 0d0a436f    mozilla/2.0..Co
0x00000100 (00256)   6e74656e 742d4c65 6e677468 3a20300d   ntent-Length: 0.
0x00000110 (00272)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x00000120 (00288)   73650d0a 0d0a                         se....

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   56735376 54357775 67253242 74796766   VsSvT5wug%2Btygf
0x00000040 (00064)   764f3748 33334868 626a2532 46683773   vO7H33Hhbj%2Fh7s
0x00000050 (00080)   62656466 31735376 54387436 35693968   bedf1sSvT8t65i9h
0x00000060 (00096)   6c4c3950 6d787158 48306246 2532466d   lL9PmxqXH0bF%2Fm
0x00000070 (00112)   694d5772 64506435 534f6569 6b4c3530   iMWrdPd5SOeikL50
0x00000080 (00128)   6742394b 35504c4e 71336546 476a7a68   gB9K5PLNq3eFGjzh
0x00000090 (00144)   25324638 44644159 64725435 574f3061   %2F8DdAYdrT5WO0a
0x000000a0 (00160)   6c787479 67627062 3648766e 53414f51   lxtygbpb6HvnSAOQ
0x000000b0 (00176)   696a2532 42383275 59764561 53765425   ij%2B82uYvEaSvT%
0x000000c0 (00192)   32427371 78537225 32466525 32425635   2BsqxSr%2Fe%2BV5
0x000000d0 (00208)   5a755267 25334425 33442048 5454502f   ZuRg%3D%3D HTTP/
0x000000e0 (00224)   312e310d 0a486f73 743a207a 6f6e6564   1.1..Host: zoned
0x000000f0 (00240)   672e636f 6d0d0a55 7365722d 4167656e   g.com..User-Agen
0x00000100 (00256)   743a206d 6f7a696c 6c612f32 2e300d0a   t: mozilla/2.0..
0x00000110 (00272)   436f6e74 656e742d 4c656e67 74683a20   Content-Length: 
0x00000120 (00288)   300d0a43 6f6e6e65 6374696f 6e3a2063   0..Connection: c
0x00000130 (00304)   6c6f7365 0d0a0d0a 20737563 68206669   lose.... such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.


Strings
@`.W..
 
..
.|
 
..
..
.
.
K8..
;
..

080904b0
1.0.0.1
1509
FileVersion
&find
&Find any        Alt+F
PrivateBuild
ProductVersion
StringFileInfo
Translation
VarFileInfo
VS_VERSION_INFO
``````
````````
``````````````````
``#_, @
^^^^^^
~~~~~~~~~
>>>>>>
>>>>-----
 `!%:	
         
_______
------
-----------
, `|'*
,,,,,,,
,,,,,,,,,,,
;;;;;;;;;;;
::::::::
!   </
??????
?????????
//((((
''''''
'''''''
""""""
((((((
(((((((((
))))))))?
[[[[[[
[[[[[[[
]]]]]]]
]]]]]]]]
]]]]]]]]]
}}}}}}}}}
@@(@ .
@@@^^^^^
$$$$$$$
$$$$$$$$
&&&&&&&&&&&$
&&&&&&&&&&&&&&&&&&&&&
%%%%%!!!!!!!!!!
%%%%%%%%%%
++++++
						
^^^^^^000
0000000000
0000000222
01<Q=2$
:"@`07	
"0.GVK
"  0K;
0lCVJ]>N
0T7Mg5
0;xF(g\
1$ @*` 
11111111
1111111111
-1.2.5j$
1(8K7M
+1jBu;
 ,1"	N
1pJpH/
+1_zX@o
%))`^2 
2222222
22222222222222
2ab`\a
2idKO;
2#_@pMh
2U		ri
}2xg$h}
;_2yUt
!	30nGP8
333333
33333333
3EC'CSD
@3k^}U
404|9c
44444------
444444444
444{{{{N
44&sG/3
<4%D6S
;5*  ,
5@7WijN
5mL#Dg;C
5X|7E:}
`@62|)
666>>>>>>>>>
666666666666''''
~<6g&$4
[6m"k_8
6QTXb\
6	#T8DY
* @%6x
______7
;7<4S 
777777
_['7dGmt
<7Lf)-
7SCIwA
888888
%%%%%%%%%%%%%%%%%%%8888OO
>8BL.X
8Jr2Bg
(8#@#L
8r^$dr
8v{L(k}
8:vO0?
\90jN^,@
**************\\\\\\\\\\\999
99999999'
9jyLn]0
9%p?& 
> `@@9%Q&
 @`9S[
@@9v|D
A.&0sY
;a7,  
a`9)1$
aaaa\\\\\
aaaaaa'''''
aaaaaaaa
AF:\K2
ah'$@`
ALP&` 
`A(`@M
Aoo,`@||
Av!|GN
@@A/w.
 azeT+r
bbbbbbbbbb
bbbbbbbbbbbb
.  -bD 
!!!!!!!BEEEEEEEE]]]]]]]]]]
 {\Bh$
b|HVom
BS{/~T
budY!u
bwL5LB
;|B$y`
~c"@@;
c'_|6h
,@@C9$
cc____________
CCCCCCCCCCC
cccccK
;C ?^E
c:iSb-
CKshYWW
ClipCursor
cn@,&.
(` Cn"
-com:a
CreatePopupMenu
 cT,``
Cw(KNB
.  d*`
d7douJ
}#D9:k
@.data
dc @`^
DDD//////////
''''DDDDbb
DDDDDDD
DDDDDDDD
DDDDDDDDDDDDDDDDD
DestroyMenu
".dex.|
&d^]&hIo
;DiNApz
}d);Q0
D TZ*K
duBwty
DuplicateHandle
.DuTAjt
)dZ0 C8
e3!m}"
,ed]Lw
EEEE~~~~
EEEEEEE1[[
eeeeeeeee
eEHscu
E:G|nD
EnumResourceNamesW
}EVIwv>Jj
!ExO/.
F1bns%
F3?80m
 `f:'CR
\\ffff
ffffff
fffffffffffff
fffffWW
FindClose
FindFirstFileA
FindResourceExA
FindWindowA
FJ7wPv
fkg^]~&
FlushInstructionCache
+F<niyJ
fOfz$@
fP(l"y
FS4c]6
F/tu7B
$f[*UW
fvXWw5
Fz$@@]
|G/|@=
G_@[\)
G%3_xV
g4DIot
gAKVZS	w
gem1u-m
GetDesktopWindow
GetModuleFileNameW
gggggg
++++++GGGGGG
ggggggg
GGGGGGGG
GGGGGGGGGGTTTTTTTTTTTTT
gggQQQQ
	=G~h4
)\*GL^
@`, @gm
$gmtHy
GP.:uM
gReb~Y'
Gv`k0,
GWtqt]
H3LEv!_2
H7Zr" 
|h?)AL	
HHHHH))
hhhhhhhVVV
HhtvPF
H)M4LKI
H)Ny;]`
>hrq'&
~hth `
HtVIx/QC
i*`@,@
?i3>lz
icBqso
IcZ:Z>
I+>[D$
 @i]DD
i'DFBS
Ie1	+6
[ifestV	rsi
@ ~Ig4
IhPAPI
IIIIII
IIIssss
Ik@7jlg
IO~OAA
iO'x$A
@@ip+p+
-%Ip=QS
iRRRRRRR}
|<iT @
J:.@ $
>,J61I
 <j7O[
J7z{|=
[?j9,|
``J9D@0
jA|a.@ 
j-B`@<
@j	cC `
jg^ib1
JHe[0g"[edHE
j><iT[
JJJJJJJJJ
jjjjjjjjjjjjjjjjj
jjjTTTT
Jn9jia
Ju0AuY"
J%U4zfw
:jV}&/
#jVA6W
(@`|k 
` K(@@$
@@@@@@@@@K
K4>6n\
)k"a.Z
%"@@kE
KERNEL32.dll
KHX$iC
kkkkkk
KKKKKKKr
KKKKKKKssssssssssssss
KLi)1.
	)kZ\A
>`!'l	
& `l'#
L~~~~~~~
&L298 `
l47o`J
L:D=,`
Ld2^x%
+L<Dg]`0@
 L	g/3
l'g(k b
 ` l-j
&&&Ljjjjrrrrrrrrrr
llllll
LLLLLLL
lllllll88888
lllllllll
lllllllll}}}}}}}}
llllllllllll
lmAsn"
LP+wDA
=lPY`U
lRtB$ 
lx1;pv
;<LxHZ
lY[B]y
l|zHOG
|||LZZZ-
&``:M_
m7c"gcf
MapViewOfFile
M[-H|-
mIM0*@`c
?mLJ(e
{[MLrM
?ML-	uS
mmmmmmmmmmmmmmmmmm
mN.4Bc
m'Oaap
Mqjz<VA
mr2=rK
*m^XC^
  mXVV
<n]6C[E
_N.A&Tc
NdrComplexArrayFree
N\-e/~W
*=niN<!D
nnnnnnnnn  
N@[pT6
Nr`>D%M8
Nr)V3(D
nsi,r"
n?~t^HH
 nwqjp
[nxuOt:OJ
( `NY&
O2`b@?
O9) try
OFtg<R
Oi6VG:
oooooooo
OOOOOOOOOOOOOOOOOO
oooooovvvvv
'OwnD[
(@@!/oX
oxd>rM
o;xz;J
`P0I`7T
	P] 3zz
`p7Dru
P8i#`f
p_8O)i
pbbb\\\\\\EEEEE
?p-bjO
pFuIeI
-P,`@h
p:H$@@L
PJ]i^W
PK1GW[R
,``P[M3-
PP" `>
pppPPPPPPP
`@Ppq'
p!+pS|
pWX,`@
(`@PZx>
q%6f]R
@Qa{oT
$qN"n`
,	Qoa7JX
.@ q]q
QQ5pEEI
qqnnnn
qqqqqq
QQQQQQQQQQ
______QQQQQQQQQQwwwww////{
r'0Vh"
R|1wsHpu
@R6dLRn!
,R70Y}
r|A{E)
`.rdata
RedrawWindow
.reloc
R:L}jP
Rm`v+Z0#
rOG\$`
RPCRT4.dll
r_r0fUl
r  <req
&&rrrrrrr&&&
rrSSSS
r_r@ve|
r.uwVO[
rvW4S\
r(VYpd*
RWY$@`
$$$$$RXXXXXXXXX
ry^iDb
 :};s @
s	4H~[[
 @ S8$
s* `BQ
SetFileShortNameW
SHELL32.dll
Shell_NotifyIconA
\ShG3@:
/sopli
@@SQc=
(((ssss
SSSSaaaaaavvvvvvvv
sssssmmmmm
ssssss
SSSSSS
SSSSSSSSSSSSSSSSSSSSS
&&&&&&&&&ssssssssst
SvXSBX
*S&W%a
SwU( `
=<SXxJI
t6Ns?v{
/TdMuM
tE79lx
Teeeee
TFr6T8
"``TGw
!This program cannot be run in DOS mode.
timeEndPeriod
^}tJyz
tLo1ZLi
Tm\4et
^@~to/G
tpH@.D
TrackPopupMenuEx
tttttt
ttttttt
ttttttttttt
ttttttttttttttttttttt
tttttttvvvv
>tUcei"m
`T@W0|
` :~tx\^
U*%2#0L
, u4z*t
U(@ 79
`*u9Gr
Ubougct
UC%t=[)
u.@ GW
u*kJGl;c4
UMpdlf
UnmapViewOfFile
up7exB.
uPvB@R#e
USER32
UuidCreate
    UUnn
"UUUUU
uuuuuuu
uuuuuuuuuuu
}UUUUUUUUUUU
^UUUUUUUUUUUUcccc
@#u@;Wi
_.v1" m
@V5'_;
VAAAAAAA
VAQ~0Z
`@Vc.@
vCceER
v{h.dll
?;vI2X
* @\VkU
,vlo"0<
v|$P~g
v,@RW.
Vut9wnL
:V$`@v
VV/25F
''------@@vvvvvv
VVVVVVV
;VVVVVVVVV
vvvvvvvvvvvvvvvvvvvvvv
VVVWWW
}W4mwx
w5^L?`
w9x</	
wb7[Dg
;wHxK8
WINMM.dll
WmF?*@
WNT;nh
^WPDer
WPp.yG
?}w~SDr
WSL{HT
wt&bu*s
WWggggr
WWWWWWW
wwwwwwwwwww
wxa+?f`
``;X&`
{| Xbq
XhSMh	8
xP\2wK
XT7 Sx}
xxxx```````
''''''XXXXXXXX
XXXXXXXXXXXX
xxxxxxxxxxxxxxxxxxxxx
Xzhl<,`
 <Y!	\
Y0 @z8V
/y|c6k0j
)`_#YIBC
Ym}_tP<
/@yN|nIjJ
Yoooooo
YP(@`X
/yr!weu
yy99@@@     
Z1h&>E6
Z5]&-~7
]Z]>aX
z</Bsqu	
zDFNUt@
ZuEAN+
ZU#SM\
]Z|!X#%
ZXr%\rr
$$$ZZZZZZ