Analysis Date2015-01-14 13:10:01
MD54d6eedae0a5d8c4b60db415f88296e44
SHA1e6565bccb9660465a8643d14f2f9a6493b18bd01

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
PEhash5c10ad2610789c2fdd0d04195e27cb620a3bf975
IMPhash
AV360 Safeno_virus
AVAd-AwareTrojan.Obfus.3.Gen
AVAlwil (avast)VirLock-A:Win32:VirLock-A
AVArcabit (arcavir)Trojan.Obfus.3.Gen
AVAuthentiumW32/S-43a675a7!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen7
AVBullGuardTrojan.Obfus.3.Gen
AVCA (E-Trust Ino)Win32/Nabucur.A
AVCAT (quickheal)Ransom.VirLock.A2
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Obfus.3.Gen
AVEset (nod32)Win32/Virlock.G virus
AVFortinetW32/Agent.NCA
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Obfus.3.Gen
AVGrisoft (avg)Win32/Cryptor
AVIkarusVirus-Ransom.FileLocker
AVK7Virus ( 0040f99f1 )
AVKasperskyVirus.Win32.PolyRansom.a
AVMalwareBytesTrojan.Agent.RND1Gen
AVMcafeeTrojan-FFGO!4D6EEDAE0A5D
AVMicrosoft Security EssentialsVirus:Win32/Nabucur.A
AVMicroWorld (escan)Trojan.Obfus.3.Gen
AVRisingno_virus
AVSophosW32/VirRnsm-A
AVSymantecW32.Ransomlock.AO!inf
AVTrend MicroPE_FINALDO.F
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\ekEoEUoA.bat
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\ekEoEUoA.bat
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
Creates Processreg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
Creates ProcessC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates ProcessC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates Processreg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA ➝
NULL

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Creates FilePIPE\wkssvc
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\123.rar
Creates Process"C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt ➝
1

Process
↳ reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden ➝
2

Process
↳ C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\VyAMAMkQ.exe ➝
C:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
Creates FileC:\RCX15.tmp
Creates FileC:\RCX14.tmp
Creates FileC:\RCX2.tmp
Creates FileOwca.ico
Creates FileeAke.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
Creates FileOEQC.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
Creates FileC:\RCX5.tmp
Creates FileOowu.ico
Creates FileaUYI.exe
Creates FileSsQU.exe
Creates FileGowq.ico
Creates FileWgQq.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ.inf
Creates FileGgcq.exe
Creates FileekUe.exe
Creates FileC:\RCXF.tmp
Creates FileEwwy.exe
Creates FileCMgA.exe
Creates FileC:\RCX12.tmp
Creates FilemwYa.ico
Creates FileWEoq.exe
Creates FileCcog.exe
Creates FileucYy.exe
Creates FileSwQY.exe
Creates FileWkkq.exe
Creates FileSgAE.exe
Creates FileC:\RCX18.tmp
Creates FileKwIU.ico
Creates FileC:\RCXE.tmp
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates FileicQQ.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
Creates FileqEYU.ico
Creates FileC:\RCXC.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp.exe
Creates FileC:\RCX9.tmp
Creates FileqUoY.ico
Creates FileOAwK.exe
Creates FilePIPE\wkssvc
Creates FileeUoy.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
Creates FileCggA.exe
Creates FileyEQc.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
Creates FileC:\RCX1D.tmp
Creates FileGccG.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
Creates FileqYMA.exe
Creates FileaocE.ico
Creates FileC:\RCX1B.tmp
Creates FileC:\RCX7.tmp
Creates FileC:\RCX17.tmp
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
Creates FileWwsC.ico
Creates FilemAES.ico
Creates FileysUU.ico
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
Creates FileusEW.exe
Creates FileWwsS.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
Creates FilemUgK.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
Creates FileOsEi.ico
Creates FilewQYq.ico
Creates FileqAQG.ico
Creates FileeUwm.ico
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\RCX3.tmp
Creates FileuQIC.ico
Creates FileC:\RCX20.tmp
Creates FileCEUc.exe
Creates FileC:\RCXB.tmp
Creates FileC:\RCX10.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
Creates Filemscu.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
Creates FileysEU.ico
Creates FileykEs.exe
Creates FileC:\RCXD.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
Creates FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\RCX1.tmp
Creates FileC:\RCX1E.tmp
Creates FileC:\RCX6.tmp
Creates FileCsYY.exe
Creates FileC:\RCXA.tmp
Creates FileuQQa.ico
Creates FileC:\RCX1F.tmp
Creates FileC:\RCX13.tmp
Creates FileC:\RCX11.tmp
Creates FileC:\RCX21.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
Creates FileC:\RCX19.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
Creates FileawkI.exe
Creates FileC:\RCX1C.tmp
Creates FileYIEy.exe
Creates FileWYEO.exe
Creates FileC:\RCX1A.tmp
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
Creates FileqsoQ.ico
Creates FileegAK.exe
Creates FileuUkq.ico
Creates FileCEIY.exe
Creates FileC:\RCX8.tmp
Creates FileSMUs.exe
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
Creates FileuUAK.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
Creates FileGwIC.ico
Creates FilePIPE\DAV RPC SERVICE
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
Creates FileyogM.exe
Creates FileKkYQ.exe
Creates FileaMYg.ico
Creates FilemgUK.exe
Creates FileC:\RCX16.tmp
Creates Fileikga.exe
Creates FileyYcY.exe
Creates FileC:\RCX4.tmp
Creates FilemAIG.ico
Creates FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
Creates FileyEsg.exe
Creates FileWkgS.ico
Deletes FilemUgK.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp
Deletes FileOsEi.ico
Deletes FilewQYq.ico
Deletes FileOwca.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg
Deletes FileeAke.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp
Deletes FileqAQG.ico
Deletes FileeUwm.ico
Deletes FileOEQC.exe
Deletes FileOowu.ico
Deletes FileuQIC.ico
Deletes FileaUYI.exe
Deletes FileSsQU.exe
Deletes FileGowq.ico
Deletes FileWgQq.ico
Deletes FileCEUc.exe
Deletes Filemscu.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp
Deletes FileGgcq.exe
Deletes FileekUe.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp
Deletes FileEwwy.exe
Deletes FileCMgA.exe
Deletes FilemwYa.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma
Deletes FileysEU.ico
Deletes FileWEoq.exe
Deletes FileCcog.exe
Deletes FileucYy.exe
Deletes FileSwQY.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp
Deletes FileykEs.exe
Deletes FileWkkq.exe
Deletes FileSgAE.exe
Deletes FileCsYY.exe
Deletes FileKwIU.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp
Deletes FileuQQa.ico
Deletes FileicQQ.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp
Deletes FileqEYU.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\install.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp
Deletes FileawkI.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp
Deletes FileYIEy.exe
Deletes FileqUoY.ico
Deletes FileWYEO.exe
Deletes FileOAwK.exe
Deletes FileeUoy.exe
Deletes FileqsoQ.ico
Deletes FileegAK.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp
Deletes FileuUkq.ico
Deletes FileCEIY.exe
Deletes FileSMUs.exe
Deletes FileC:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma
Deletes FileCggA.exe
Deletes FileuUAK.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp
Deletes FileyEQc.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg
Deletes FileGwIC.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp
Deletes FileyogM.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp
Deletes FileGccG.ico
Deletes FileKkYQ.exe
Deletes FileaMYg.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp
Deletes FileqYMA.exe
Deletes FileaocE.ico
Deletes FilemgUK.exe
Deletes Fileikga.exe
Deletes FileyYcY.exe
Deletes FileWwsC.ico
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg
Deletes FilemAIG.ico
Deletes FilemAES.ico
Deletes FileyEsg.exe
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp
Deletes FileC:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp
Deletes FileysUU.ico
Deletes FileWkgS.ico
Deletes FileusEW.exe
Deletes FileWwsS.ico
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp
Deletes FileC:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe

RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\QWcQAwoI.exe ➝
C:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.exe
Creates FileC:\Documents and Settings\Administrator\qwEYAYUE\VyAMAMkQ
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\hEkAgEII\QWcQAwoI.inf
Creates MutexvWcsggUA
Creates MutexScUMMMcQ

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Process
↳ "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\shell32.dll,OpenAs_RunDLL C:\Documents and Settings\Administrator\Local Settings\Temp\123.rar

Network Details:

DNSgoogle.com
Type: A
173.194.125.69
DNSgoogle.com
Type: A
173.194.125.68
DNSgoogle.com
Type: A
173.194.125.67
DNSgoogle.com
Type: A
173.194.125.66
DNSgoogle.com
Type: A
173.194.125.65
DNSgoogle.com
Type: A
173.194.125.64
DNSgoogle.com
Type: A
173.194.125.78
DNSgoogle.com
Type: A
173.194.125.73
DNSgoogle.com
Type: A
173.194.125.72
DNSgoogle.com
Type: A
173.194.125.71
DNSgoogle.com
Type: A
173.194.125.70
HTTP GEThttp://google.com/
User-Agent:
HTTP GEThttp://google.com/
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1031 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1032 ➝ 173.194.125.69:80
Flows TCP192.168.1.1:1033 ➝ 200.87.164.69:9999
Flows TCP192.168.1.1:1034 ➝ 173.194.125.69:80
Flows TCP192.168.1.1:1035 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1036 ➝ 200.119.204.12:9999
Flows TCP192.168.1.1:1037 ➝ 190.186.45.170:9999
Flows TCP192.168.1.1:1038 ➝ 190.186.45.170:9999

Raw Pcap
0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   94                                    .

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   486f7374 3a20676f 6f676c65 2e636f6d   Host: google.com
0x00000020 (00032)   0d0a0d0a                              ....

0x00000000 (00000)   94                                    .


Strings
.n..
3#
.C
.da
.%0eT+
0Nq"p.:Q
+0"TOM
0^TTk^TTk^TTk
0Um+Zd
%0vv4e
1/3M};
1`	5q{
1C}4[i
1k:IX	
1`:`rfT
1;R{,Ne
1++zI}
\21F_{
2$8P/4
|2&(cR
#2evS2
2FQ6#h
2HA[OFI'~G
2{HhH0F
2Jmg:5
2/Kxwp6U
2l<L|8
2LSSY+
2=x/oJ
``=2	x%.Q
+?)+]3
3&)._	d
3f),_	d
3hez_	$s
3j^?w?
3k('HJ
3L+.(b
3OC@_a
3#o-]E
3uPdA[
3Y%-_	$
3Zs]?q
4;^c4a
}4CiXW
$4${	D+@
4dEMD+F
4dLCD+]bpk]
4EcxJc
4[GQDT
4GT	b(
"4L^A8EA
4nj0J9
4njp5'
4njpp4
4]>r<K
4[UFDT
[54|mvpv
~58%'M
5[B"bL
$5_Cwxw
%-\_5k
5L86,Z
^5MY^5
@/5Q=&
5+)T>n
^;5;TO
6;!!_	
.62Mkq
#&6`3&6l
6:&4[lLD
6b^TTk<
6b^TTk<I
6Ew]<	
6MV>K(
6-|nRT
6-<nUT
6-|nUT
6-|nVT
^6o9L,
6p$6MR/El
6q^sl+
6^T.~$
6ty{x%&
6yMC _
6z\g7!?
+6ZnUk^
71I-uq
7}{AlU
7A#*Xa
7E]0TTk
7E]FzT+^
7:hnpU^
7j^TTk~e
"7MyUP
7ohS_d
7OUS]2
%7OxCz'
7oZhlH
7	>p,~
7q	nv1
7'V:KX
	7Y5bd
8\09N#
82NX @G
8^3n	e
8g\VmhZ%lH
;8.$^K
8_K(JD
8KRXhv?
8PcX30
 8+>Q^O
8r@*f@
8u{^.aY
8U+Gc?
8[?xgH
8x`h,;
94PyAX
9PdH`B
9X3w92
A0='@m
a`=1-]l^`
/a7RjY
a?AX&2
a~D_a0
?Ad-AU
#a~@D@E
AH7G5h
)aHr(2
AIeNG	f
A]ivRe
aODTqWED
ao~nGZ
	ApTTk
_AQGa{
aQI1T9<
~a.Qk^
A,}sle
aT)At1
>AUa[c
aXE,`C
aZ"]AkcEP[Z
B0npzxK
B6pj%7
;B`_7@
[B#,)a
@Bb^|/
bd&8G}
b`dh4rN
Bj\/zX
)b}L	}
bmS#Y	
bN@	wNT
bODTqYED
|_BPzJq
;	"-bv
b*>_`X
?BX?aSi
]<*+BYG
-b~Y.S
:!&b@\Zy
c1]AHP-
C+4$;@D+/
C6|:IK
=c.\+6u
c9CNq(
ccb0BO
'	CE'IRcP_
CH+@CV
CPDTQFWT
CPN3CTT
CqC.{<(
[cQdf1
c"R0rg
CtjJuJ
c&tWuJ$
/C=viB4v
CVn;^T
CVn?^T
CVn/^T
CVn'^T
CVn#^T
CwL~62
c)ZI8;
c;<zRn
D41JiS
>[[d5;
D% 7$k
Dc3	e-
DDn/3V
DE%	BUr^r
	DE'	LEW
DE;^TTk^
"`d*EZ
@DfMTl5
%*.Dgu
D+HWvk]u
di]JI~
dkQWTT
dnNYe.
dnOY$.K]dX
 D[Oh`khf
d.OY$.
d.OY$.H_$_
d.OZfl'
d.OZfle
dpnkRn
dP+^TTk^TTk^TTk
Dq5'f^
Dqmz~.
DSYD+02l
dTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk>
dTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TT+^TTk^TTk^TTk^TTk^
D+^TT+
d(^TTk
d*^TTk
d*^TTk^
^D+^TTk<
d)^TTk^TTk^TTk^TTk
^D+^TT+|M]
dT+^TTk^
dU+dPT
DU}oDI
dU+^TTk
dU+^TTk^TTk^TTk^TTk^TTk
dU+^TTk^TTk^TTk^TTk^TTk^TTk^TTk^
dV+^TTk
dV+^TTk^TTk
dV+^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk
dW+NTT+^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk
,e0-AD
~\e`31<Z
;E:}5@
e	.6Zv=
E7m/ #B`
e9psRx
 EA]h~
EbTTkpP
ED+^	#C
eDj^TTkoDV
ED+^TT+
EEd_EYW
+EfTT+
e_<h%F
Ehj\wFL%
ehS2Jw
ehS2UY
. EHTT
e,ig-e
>eIlRi5R
>Ej+^T
eKYL/h"
E=L}'X
ENJ}T>n
enO^gn
e`Nur:(
eNw:Vl5
`.e&)O
=Eo?!I
eP*:g^T
Epl!^)A
<eqaAfi
eQ&DVPK
eQ^*zQ^T
eTQ~TT
e+^TTk
e+^TTk=E
e^TTkN
:EtVT+>n
E-v2K(
evS2JY
%EV^TTk>
%EW^TTk
.-ExTT
eY#2e6
eY#2ev
eY#2%vSr
)f2H6o
	(f2K.
&F"<#3g9
f63M6o
f'}aZq
~=fd&L
fdLNI@
f?, f'
-f>hkbC
fks!cA
f_=L	s
FnlvB_
'fnQgE
fO/GYMm{/v
(frK/6v
F^TT3=q>
ftx[rt
@F"~xK2
 !FZ @
+FZ8ff^3
fZB&>Am`
fZx_`8	8
G67"/hy=
';g9}X_^
<*G~bGz
Gcz'h7
gehF#&B
g<E+	K
g|	FGe.
~gF_pj2#/
g%^'i*
g|ICFl	
Gjj6ub{
g$J}/xj#
Gkj:-3?V3DJ
G;=kzB
glOXdnO
gM|RJ(
>g,o?	I
g-p`J:
@G|$Q{
GQZm>%
-g;S-g;S-g;Sm
g(}T+>
gT9Yy,
GTH+VTXk^
GUT+>n
g|	(v1
g)Viw3
Gw?+Z%
"gzX:?
]`)h8/
HB2q;5
*HcSjnA7
H+CTTkG
H*(e[p
:H+EPTT+
h?eTk^tZk]u{
HEYSGE
HfC2\>
HH7siK\
+hI([g
;!hj*ZL
hK.D[bO]9
*Hl/u.j`
hMYT+K
Hn2	?]6:
h;N8vi
h$oB,ji
HODT1LED
Hp+70.
HpXt#m
H&R<qnKj
h^TNo]TT
Hv{n .<
"hxu>6D
HY	*@R]^rLlA
i3{Fu2OT
ib$-a`
~}i$C|Pd
Id+-/.
?/IDA;
>i+duT+
IG]Vr=UT
&igzkR
Ijq/UZ
ikn[^T
,Imbht'
Imc"m'
Imc$o'
IoA\{U!
i-oj]!
+Io!y3
	ipTTk
&+>I~r`}
iR6o:K/
iR6o:K/vz
iR'v6Mmu
I%ton^T
I%to{_T
iTQjTT
ITsB&}8X}{
:_iu#5M$2
Ivn-;]
.<ivp 
I,vr	}
I@w9\D/i
ixjT/8Z
i^@ZZ,
^=j~5@T
]j;b4C
JbFr$uEv
jeC+iv
j*EzTTk
jFPmRE
jGjzTZ
JH6<Se@
jLwHt=
%#JLZ&)3
Jm+;)Y
j%npj,g
jp3L=T
.j)pa}q
JPjU)6
(JQ}@@]
jQgTT+
jQKTTk
js0w~?
'JSST*
&{>jT*^TIg
JUP\:I
J Ziy?G87
K0kE>R
K(1q	=
K2$zT+
}K3${E
k8nw@~+K
{-KA^sK
Kawl3j
^k+^B;b
|<kb/g
K!Fu1^
K)J51Y
kJYm(a
`KkdFTk
:Klj+n
k?{>MN
?~knr)
$K`NU?R7
K`	qkD
/kQvTT+
KR".(.i
[k^T_k^
[k^T[k^
k^TNgTTT
k^TNo]TT
&^k$tTk
^k^TTkK
k^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk>
_Kz%`]
l66	iv
L9SSEz
L9T"K-
l(aRNh
@lb{9R
_l!CY'
LDT+_T
Le`bXi8'
l?f@^)[;%|
L+frH6
LG[0/E
LGei	>
/LI*2hrdq
l?IcB?
LIEevAG
liZHP8
l:/jzV
L#kCi9
l`KR/d
l?	]n?
lNe*{?
Lp:'O5
lq%C)2
ls -T\k3e
LTG+OTT+^
L-v6I,
L}x-	S
ly#G@3	
m2lEUE*
m9<)g=
MAu_!+1I8
m_b1V)
^M@>bq
`meG[\
M}FF[/
|m:fPL
M:iOgI
mjBz<\
m"kKZ!
M}#]Lrc
MMMMMM333333333333
!m^N/f
{MqEmA1
|Mq-Lye
M(#R~1
MTg^TTk
M-v2K(
/m'Vh]r
Mv#]Lwc
#{Mw^5
'-MXd-
n20CT+
N``=4b
n>6qO~H
["+nAN
[]narQ
N+.A^T
Na$Wj%#
n'dnT+
N<)In%
njDPQ+
NJq\CD+
n?'m4Y
n-N9}r<p
NNesd}
n;#O1,
no^TTk^TTk^TTk^TTk<
N!`pg;`j
:nrgrl
nTT+0_\
NTTk^T
NTT+>n
nv1L6/:
nw$zT+
nxDH(x3L
N=zr<p
O2!	UE
,O4;E;
\OBBcl
{,+Odp*
ODTk^TTq
"o_}@E6
Oh0G(-
oI'4n{
O_	K4u	
#}okEV{
~;O^m3
~{O^m3
[ON$~1
Op'A],
OR:h{,
oRY@	LU
oSDT+^TTs
Os`Owm0(
oUGS#y{O
OVH|DV
&o|WFO
"oWG}_
O{X#~)
.OX$nO
o\.xS^
%.OZfl!
P1|*i"
p2K/6a
p2K/6aH
p2K/vv
P3.P1~
P@](8:a
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
p^anM,
P!Cf{hq
pEzHUd
&#Pi=BN,Pn1
p:K/ve@
pL#e\v^	
ptPS)%d
pT. ^T
=pTtP:
PUG6F9
;pWuT{{
*)pxWs
p}YNa=
qcij;+R
QcTTkd
qd\qn.
QE^TTk
`~<qId
QJJu|~
/QK.Sq67pE
qk+zI}
Q~LAV2
Qm?	]n?
.#QnTT
Q>O`}B;0
)+QoTT
QpTT+>n
QPW|dAA
QPW|uOA
Q-qMEk
qq' sq'`}
qq' sq0 s
Q`TTkp9
Q<Vs%h
Q<Vs%h+|^Z
{qw'>	
Qx's&m+
Qx(x 21
Q yBJT
^*!\^r_
r)4d.r
}r61}b7
)R6o8Lm
R6o:K/
^*ra`n
rBhls,
R}B`wa|
r(c@W{"
rEhRjTX
RF9S7,
R&(hPr9
Rich!4O
:rJDGzf
rkHK]cNi
)Rl2Aa6Q
rM^4C+~-0%
Ro3ohs4(n
Rp`1!R
r*"(S]
rTHlYfLzw
R{ug.)
rUMN,"
R'v6Mmu
R]vdC&
-ryc4-!
:[`<*S
S,3@P_MPYe
S5EH<0d-
s7O?bw
s9?osCcF
s/dG~H@
sdoY+/MOh
SEY3"YY
sg)6V}
SHctZyFRY
.SH]E/
S'&^I:
sJCg`~"
"s	<jLb
sl?fsl
{:SL:J
sLWDs*
;:SN7e
SqvZD+
S:~s'B
S=}&tt
S_ujDmf
{sVD5C
swm?Ic
sx+,3(
!SX^C6
sxm?IcB?
s$X[p#
>Sy}i\
T0	E;u\
t0qYE?t
[T0uT+
t6Z]wE\
t8&Dx2/G=
TahwUm0
TBqL~&T
`tdf}Vf
|T',DR
TFN)k^
tgqL]#
!This program cannot be run in DOS mode.
\T:ITD
^T|k^PDk^
Tk^TTk^
t:NCio
'Tne3<
TnzP]ze.B['D
<"To>9
toi/Ek
"tOYa(
tPXAYOv
TSTT+^
^TT+<-
@+^TT~
~TT+drT+^
^;^TTk
^TTk<-
~TTk>*
}TTk04c
^TTk~e
^TTk_T
^TTk^TT+
^TTk^TTk>
_TTk^TTk^
^TTk^TTk^T
^TTk^TTk^TTk^
^TTk^TTk^TTkK
^TTk^TTk^TTk^T
^TTk^TTk^TTk^TTk
^TTk^TTk^TTk^TTk^
[^TTk^TTk^TTk^TTk^TTk
^TTk^TTk^TTk^TTk^TTk^TTk
^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk>
\TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^
TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk
^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTkV\\cV\\cV\\c^TTk^TTk^TTk^TTk^TTk^TTk^TTk]
TTk=u>
TTk=u8
,-tTn!^T
^TTQTTT
T^TTk$
T^TTk<E
T^TTk=u
T^TTk/u
tTTk..y
&TWJgi8
\T	y$7
&_&Ty`hb_XS
	TzA1L39 
/&& U$
~u1K6o
?u]1{r<
u2HlqvX-
U"4Df-
u9S".-
U	'		a
uFFan4u
UF"q0t
U@G|oB
u!O.Ui@
~uqK6o
uTT+>j
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
uv*.I^T
u-X(N4K
}|u_y<
u=Yxn)
v18kPCH5
.v3+x"
V5JIWs
v ;&6l"ZP
v8+B8m
+vc.OU
}V+dyT+
VE^TTk<-
VFIgT\
v^.j2*D0k
VK^8r"
vL=\K}
vl:Tk^
V&mA7J
^Vm&	G
V]m:N$
V|NTno
vo1VED
Vo*LEk
vop#s1
vP~oA*^
~vQ2 .
vqM/vsX
vQ"PFTd
\:vQw_
V+^T^k^
VTT+NTTkVTT
VT"Xy}Il
[/vvMmu
>vyTs&
`W}@`.
W6^"#Q
W74[kWD
%wCgGz
WCmR-&
W#cx^S
W|D;7b4
]wJ'N^$
WJ	TTkd
WL*Q~TTk>*
w$LR<bGO
wl(sQCK=
WN>CTT
wPrwu2c&
WqRB+p
"wQRL1
W+_s+dMTk
WTTkWTT+ITT
wwwUUU
wwwwwwUUU
-}	Wy;
WZc<S2
^x0^(7B#
,?xACbh	
XdoOY%.
Xd.OYd.
Xd.OZf
x	Dv(M
XE4IHW'
XenOY$
XE;^TTk^
x(/,G=
XgnTMn
(xkdpT+
;XMMW.
XOAOqK
XODT1PED
.XQETTk
x#s[=&
XTTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^TTk^
=<XU>4;
xu49>BiqDT
x!uY_;
x%YNyB
([Y ;!
y_.=6X9
$yC'ea
(yce%k
yd`rOK
yE-N:X
yG(H4Y
``=,yi
yIDThhp
. ~y.+iE
)Yj_/<
}^.Yk^
Y%K^D/R
-%YR'^=
\y!(t3
Y?*>T96
yTT+>n
YX(Od?#
yyDqC"
Z4Qx=r
z5"	3}
&Z5\4:
z;9\Up
z/>*a"
z``C(|YE
zdnCf4)
ZE49h9
ZGA5U&U
=ZHu_{<
%ziTTk^:
'Z`KDF
Z,M}Q|
[zNTnM
_zNTnZ
ZNWTk^
ZOjT+^
ZOk%)^
ZO(T+^
Zq~CNR
zQJTTk
Z>sZ`s
%z`TTk
%z&TTk
Z#^TTk^TTk
ZTTk^TTk^TTk^TTk
ZTTk^TTk^TTk^TTk^TTk^TTk^TTk^
z;U;`D
zWRe~P
zySoc(
ZYSZ*\