Beruflich Dokumente
Kultur Dokumente
Key:
BTATH_LWFLT
ImagePath: system32\DRIVERS\btath_lwflt.sys
C:\Windows\system32\DRIVERS\btath_lwflt.sys
60064 bytes
Created: 8/2/2011 2:03 PM
Modified: 8/2/2011 2:03 PM
Company: Atheros
---------Key:
BTATH_RCP
ImagePath: system32\DRIVERS\btath_rcp.sys
C:\Windows\system32\DRIVERS\btath_rcp.sys
263968 bytes
Created: 8/2/2011 2:03 PM
Modified: 8/2/2011 2:03 PM
Company: Atheros
---------Key:
BtFilter
ImagePath: system32\DRIVERS\btfilter.sys
C:\ndows\system32\DRIVERS\btfilter.sys
436896 bytes
Created: 8/2/2011 2:04 PM
Modified: 8/2/2011 2:04 PM
Company: Atheros
---------Key:
BthEnum
ImagePath: \SystemRoot\system32\drivers\BthEnum.sys
C:\Windows\system32\drivers\BthEnum.sys
34816 bytes
Created: 7/14/2009 6:51 AM
Modified: 7/14/2009 6:51 AM
Company: Microsoft Corporation
---------Key:
BTHPORT
ImagePath: \SystemRoot\System32\Drivers\BTHport.sys
C:\Windows\System32\Drivers\BTHport.sys
393728 bytes
Created: 10/3/2011 10:34 AM
Modified: 4/28/2011 10:15 AM
Company: Microsoft Corporation
---------Key:
BTHUSB
ImagePath: \SystemRoot\System32\Drivers\BTHUSB.sys
C:\Windows\System32\Drivers\BTHUSB.sys
60416 bytes
Created: 10/3/2011 10:34 AM
Modified: 4/28/2011 10:15 AM
Company: Microsoft Corporation
---------Key:
clr_optimization_v4.0.30319_32
ImagePath: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
130384 bytes
Created: 3/18/2010 1:16 PM
Modified: 3/18/2010 1:16 PM
Company: Microsoft Corporation
---------Key:
clwvd
ImagePath: system32\DRIVERS\clwvd.sys
C:\Windows\system32\DRIVERS\clwvd.sys
27632 bytes
---------Key:
IconMan_R
ImagePath: "C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe
1755136 bytes
Created: 9/30/2011 11:04 AM
Modified: 3/7/2011 10:45 PM
Company: Realsil Microelectronics Inc.
---------Key:
igfx
ImagePath: system32\DRIVERS\igdkmd32.sys
C:\Windows\system32\DRIVERS\igdkmd32.sys
10855424 bytes
Created: 8/31/2011 12:48 PM
Modified: 8/31/2011 12:48 PM
Company: Intel Corporation
---------Key:
IntcDAud
ImagePath: system32\DRIVERS\IntcDAud.sys
C:\Windows\system32\DRIVERS\IntcDAud.sys
269824 bytes
Created: 10/15/2010 1:27 AM
Modified: 10/15/2010 1:27 AM
Company: Intel(R) Corporation
---------Key:
kbdclass
ImagePath: \SystemRoot\system32\drivers\kbdclass.sys
C:\Windows\system32\drivers\kbdclass.sys
42576 bytes
Created: 7/14/2009 6:11 AM
Modified: 7/14/2009 8:20 AM
Company: Microsoft Corporation
---------Key:
kbdhid
ImagePath: \SystemRoot\system32\drivers\kbdhid.sys
C:\Windows\system32\drivers\kbdhid.sys
28160 bytes
Created: 10/3/2011 10:49 AM
Modified: 11/20/2010 4:50 PM
Company: Microsoft Corporation
---------Key:
LMS
ImagePath: C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.
exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
325912 bytes
Created: 9/30/2011 11:04 AM
Modified: 8/8/2011 5:39 PM
Company: Intel Corporation
---------Key:
MEI
ImagePath: system32\DRIVERS\HECI.sys
C:\Windows\system32\DRIVERS\HECI.sys
41088 bytes
Created: 9/30/2011 11:04 AM
Modified: 10/19/2010 4:33 PM
Company: Intel Corporation
---------Key:
Microsoft SharePoint Workspace Audit Service
ImagePath: "C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" /auditservice
Key:
NisDrv
ImagePath: system32\DRIVERS\NisDrvWFP.sys
C:\Windows\system32\DRIVERS\NisDrvWFP.sys
65024 bytes
Created: 4/27/2011 3:25 PM
Modified: 4/27/2011 3:25 PM
Company: Microsoft Corporation
--------Key:
NisSrv
ImagePath: "c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
208944 bytes
Created: 4/27/2011 3:39 PM
Modified: 4/27/2011 3:39 PM
Company: Microsoft Corporation
---------Key:
osppsvc
ImagePath: "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtect
ionPlatform\OSPPSVC.EXE"
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\
OSPPSVC.EXE
4640000 bytes
Created: 1/9/2010 9:37 PM
Modified: 1/9/2010 9:37 PM
Company: Microsoft Corporation
---------Key:
RSPCIESTOR
ImagePath: system32\DRIVERS\RtsPStor.sys
C:\Windows\system32\DRIVERS\RtsPStor.sys
253544 bytes
Created: 9/30/2011 11:04 AM
Modified: 5/4/2011 10:44 PM
Company: Realtek Semiconductor Corp.
---------Key:
RTL8167
ImagePath: system32\DRIVERS\Rt86win7.sys
C:\Windows\system32\DRIVERS\Rt86win7.sys
414824 bytes
Created: 8/23/2011 9:57 PM
Modified: 8/23/2011 9:57 PM
Company: Realtek
---------Key:
Serenum
ImagePath: \SystemRoot\system32\DRIVERS\serenum.sys
C:\Windows\system32\DRIVERS\serenum.sys
17920 bytes
Created: 7/14/2009 6:45 AM
Modified: 7/14/2009 6:45 AM
Company: Microsoft Corporation
---------Key:
Serial
ImagePath: \SystemRoot\system32\DRIVERS\serial.sys
C:\Windows\system32\DRIVERS\serial.sys
83456 bytes
Created: 7/14/2009 6:45 AM
Modified: 7/14/2009 6:45 AM
Company: Microsoft Corporation
---------Key:
SHDSERV
ImagePath: C:\Program Files\Shield\shdserv.exe
C:\Program Files\Shield\shdserv.exe
221184 bytes
Created: 11/3/2011 1:31 PM
Modified: 11/4/2010 10:28 AM
Company:
---------Key:
ShieldClientService
ImagePath: C:\Program Files\Shield\shieldclnt.exe
C:\Program Files\Shield\shieldclnt.exe
45056 bytes
Created: 11/3/2011 1:31 PM
Modified: 11/4/2010 10:24 AM
Company: [no info]
---------Key:
SkypeUpdate
ImagePath: "C:\Program Files\Skype\Updater\Updater.exe"
C:\Program Files\Skype\Updater\Updater.exe
-R- 158856 bytes
Created: 2/29/2012 8:50 AM
Modified: 2/29/2012 8:50 AM
Company: Skype Technologies
---------Key:
swenum
ImagePath: \SystemRoot\system32\drivers\swenum.sys
C:\Windows\system32\drivers\swenum.sys
12240 bytes
Created: 7/14/2009 6:45 AM
Modified: 7/14/2009 8:19 AM
Company: Microsoft Corporation
---------Key:
SynTP
ImagePath: system32\DRIVERS\SynTP.sys
C:\Windows\system32\DRIVERS\SynTP.sys
1350704 bytes
Created: 6/9/2011 6:19 PM
Modified: 6/9/2011 6:19 PM
Company: Synaptics Incorporated
---------Key:
TermDD
ImagePath: \SystemRoot\system32\drivers\termdd.sys
C:\Windows\system32\drivers\termdd.sys
53120 bytes
Created: 10/3/2011 10:49 AM
Modified: 11/20/2010 7:30 PM
Company: Microsoft Corporation
---------Key:
TsUsbFlt
ImagePath: System32\drivers\tsusbflt.sys
C:\Windows\System32\drivers\tsusbflt.sys
52224 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 5:24 PM
Company: Microsoft Corporation
---------Key:
UNS
ImagePath: "C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS
.exe"
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
2656536 bytes
Created: 9/30/2011 11:04 AM
Key: Atheros
CLSID: {B8952421-0E55-400B-94A6-FA858FC0A39F}
Path: C:\Program Files\Bluetooth Suite\BtvAppExt.dll
C:\Program Files\Bluetooth Suite\BtvAppExt.dll
145568 bytes
Created: 8/2/2011 1:58 PM
Modified: 8/2/2011 1:58 PM
Company: Atheros Commnucations
---------Key: Cover Designer
CLSID: {73FCA462-9BD5-4065-A73F-A8E5F6904EF7}
Path: C:\Program Files\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll
C:\Program Files\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll
2250024 bytes
Created: 9/24/2009 5:07 PM
Modified: 9/24/2009 5:07 PM
Company: Nero AG
---------Key: Eazshell
CLSID: {CB0877AB-7E94-4073-8194-6F992D27EFAA}
Path: C:\Program Files\Shield\shieldshell.dll
C:\Program Files\Shield\shieldshell.dll
36864 bytes
Created: 11/3/2011 1:31 PM
Modified: 11/4/2010 10:27 AM
Company:
---------Key: EPP
CLSID: {09A47860-11B0-4DA5-AFA5-26D86198A780}
Path: c:\PROGRA~1\MI8079~1\shellext.dll
c:\PROGRA~1\MI8079~1\shellext.dll
301128 bytes
Created: 6/15/2011 3:16 PM
Modified: 6/15/2011 3:16 PM
Company: Microsoft Corporation
---------Key: Shell Extension for Malware scanning
CLSID: {45AC2688-0253-4ED8-97DE-B5370FA7D48A}
Path: C:\Program Files\Avira\AntiVir Desktop\shlext.dll
C:\Program Files\Avira\AntiVir Desktop\shlext.dll
150480 bytes
Created: 4/14/2012 9:32 PM
Modified: 1/31/2012 8:57 AM
Company: Avira Operations GmbH & Co. KG
---------Key: XXX Groove GFS Context Menu Handler XXX
CLSID: {6C467336-8281-4E60-8204-430CED96822D}
Path: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
4221328 bytes
Created: 6/12/2011 11:15 AM
Modified: 6/12/2011 11:15 AM
Company: icrosoft Corporation
---------************************************************************
10:46:57 PM: Scanning ----- FOLDER\COLUMNHANDLERS ----No Folder\ColumnHandler entries found to scan
************************************************************
Taskname:
{E5F53081-305B-4CDF-84A0-F1B730B6C3E6}
File:
c:\program files\mozilla firefox\firefox.exe
c:\program files\mozilla firefox\firefox.exe
924600 bytes
Created: 9/30/2011 11:19 AM
Modified: 4/8/2012 8:50 PM
Company: Mozilla Corporation
Parameters:
http://www.skype.com/go/downloading?source=lightinstaller&ver=5.8
.0.158.259&LastError=12002
Schedule:
At task creation/modification
Next Run Time:
Status:
Ready
Creator:
SkypeSetupLight
Comments:
---------Taskname:
MirageAgent
File:
C:\Program Files\CyberLink\YouCam\YCMMirage.exe
C:\Program Files\CyberLink\YouCam\YCMMirage.exe
136488 bytes
Created: 7/6/2011 8:13 PM
Modified: 7/6/2011 8:13 PM
Company: CyberLink
Schedule:
At logon
Next Run Time:
Status:
Running
Creator:
CyberLink
Comments:
---------************************************************************
10:47:01 PM: Scanning ----- SHELLICONOVERLAYIDENTIFIERS ----Key: Groove Explorer Icon Overlay 1 (GFS Unread Stub)
CLSID: {99FD978C-D287-4F50-827F-B2C658EDA8E7}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: Groove Explorer Icon Overlay 2 (GFS Stub)
CLSID: {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)
CLSID: {920E6DB1-9907-4370-B3A0-BAFC03D81399}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: Groove Explorer Icon Overlay 3 (GFS Folder)
CLSID: {16F3DD56-1AF5-4347-846D-7C10C4192619}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: Groove Explorer Icon Overlay 4 (GFS Unread Mark)
CLSID: {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
File: C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
---------Key: SharingPrivate
CLSID: {08244EE6-92F0-47f2-9FC9-929BAA2E7235}
File: %SystemRoot%\system32\ntshrui.dll
C:\Windows\system32\ntshrui.dll
442880 bytes
Created: 3/19/2012 8:34 PM
Modified: 1/4/2012 3:58 PM
Company: Microsoft Corporation
----------
************************************************************
10:47:02 PM: Scanning ----- DEVICE DRIVER ENTRIES ----Value: msacm.l3fhg
File: mp3fhg.acm
C:\Windows\system32\mp3fhg.acm
232448 bytes
Created: 9/30/2011 10:30 AM
Modified: 10/19/2006 1:05 AM
Company: Fraunhofer Institut Integrierte Schaltungen IIS
---------Value: VIDC.YV12
File: yv12vfw.dll
C:\Windows\syem32\yv12vfw.dll
237568 bytes
Created: 9/30/2011 10:30 AM
Modified: 11/4/2010 1:08 AM
Company: www.helixcommunity.org
---------Value: msacm.ac3acm
File: ac3acm.acm
C:\Windows\system32\ac3acm.acm
151552 bytes
Created: 9/30/2011 10:30 AM
Modified: 3/20/2011 2:00 AM
Company: fccHandler
---------Value: VIDC.FFDS
File: ff_vfw.dll
C:\Windows\system32\ff_vfw.dll
80896 bytes
Created: 9/30/2011 10:30 AM
Modified: 3/29/2011 3:00 PM
Company: [no info]
---------************************************************************
10:47:03 PM: ----- ADDITIONAL CHECKS ----Winlogon registry rootkit checks completed
---------Heuristic checks for hidden files/drivers completed
---------Layered Service Provider entries checks completed
---------Windows Explorer Policies checks completed
---------Desktop Wallpaper: C:\Users\USER\AppData\Roaming\Microsoft\Windows\Themes\Transc
odedWallpaper.jpg
C:\Users\USER\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
729698 bytes
Created: 10/6/2011 3:46 PM
Modified: 4/14/2012 10:30 PM
Company: [no info]
---------Web Desktop Wallper entry is blank
---------Checks for rogue DNS NameServers completed
---------A Proxy Serr is enabled for Internet Explorer
Proxy Server: [10.10.1.12:8080]
C:\Windows\System32\spoolsv.exe
317440 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Program Files\Bonjour\mDNSResponder.exe
349472 bytes
Created: 4/6/2011 4:20 PM
Modified: 4/6/2011 4:20 PM
Company: Apple Inc.
-------------------C:\Program Files\Common Files\LightScribe\LSSrvc.exe
73728 bytes
Created: 8/20/2009 1:34 PM
Modified: 8/20/2009 1:34 PM
Company: Hewlett-Packard Company
-------------------C:\Windows\system32\SearchIndexer.exe
427520 bytes
Created: 9/30/2011 11:57 AM
Modified: 5/4/2011 11:28 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\wbem\wmiprvse.exe
257536 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Program Files\Windows Media Player\wmpnetwk.exe
1121792 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
80336 bytes
Created: 4/14/2012 9:32 PM
Modified: 1/31/2012 8:57 AM
Company: Avira Operations GmbH & Co. KG
-------------------C:\Windows\system32\winlogon.exe
286720 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Windows\system32\Dwm.exe
92672 bytes
Created: 7/14/2009 6:24 AM
Modified: 7/14/2009 8:14 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\taskhost.exe
49152 bytes
Created: 10/3/2011 10:49 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
--------------------
C:\Windows\system32\taskeng.exe
192000 bytes
Created: 10/3/2011 10:50 AM
Modified: 11/20/2010 7:17 PM
Company: Microsoft Corporation
-------------------C:\Program Files\Mozilla Firefox\plugin-container.exe
16824 bytes
Created: 9/30/2011 11:19 AM
Modified: 4/8/2012 8:50 PM
Company: Mozilla Corporation
-------------------C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
149352 bytes
Created: 1/9/2010 9:18 PM
Modified: 1/9/2010 9:18 PM
Company: Microsoft Corporation
-------------------C:\Windows\system32\SearchProtocolHost.exe
164352 bytes
Created: 9/30/2011 11:57 AM
Modified: 5/4/2011 11:28 AM
Company: Microsoft Corporation
-------------------C:\Windows\system32\SearchFilterHost.exe
86528 bytes
Created: 9/30/2011 11:57 AM
Modified: 5/4/2011 11:28 AM
Company: Microsoft Corporation
-------------------C:\Program Files\Trojan Remover\Rmvtrjan.exe
FileSize:
4738296
[This is a Trojan Remover component]
--------------------------------------************************************************************
10:47:08 PM: Checking HOSTS file
No malicious entries were found in the HOSTS file
************************************************************
------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS -----HKLM\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Microsoft\Internet Explorer\Main\"Local ge":
C:\Windows\System32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://.microsoft.com/fwlink/?LinkId=54896
HKCU\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://go.microsoft.com/fwlink/?LinkId=69157
HKCU\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\Windows\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://go.microsoft.com/fwlink/?LinkId=54896
************************************************************
P RSHAjS`M HA3f <3e <3 < H @A H @A dQAI H @A
HA =HAt
=HAuHAjS33_^[ ]U SVW } u
|$$ C | 34
D$(P u C
b
$_@ @ @k@ @ %@j@@@q @ @#@ @#@ |$
$$ Pht $$ $$ $$ $$ $$ $$ 6<
$$
$$ w<
$@ I
Rb
$,
$$ 3
$$
t3
5 L@AT$
>L@A t
L@A L@AX |$
[ O |$ D $$Rt$. |$ # $3 $$ .u&3 $% \u $&
HA
t
3t02
HA$$
3\t
HA
HA
3HA
$$
3t&3
HA
|$
3$%
:u
$$3
$$$|$
U $
L$
QhQjzjhAA
$h Y u3D$ D$P $R L$QjhAAt$$1t$
3S5@@A $PhAA $Rs $Q tC $Pjet$
$%
$ $
jC$ $ $ u
R $,
$Qut$
& $$
$$
$$0
$
$$Y
$$ |$
D$D$D$D$ $ $$0 $3 $ "ue $$0 $B =At $A" $" P
t $ $$@ :t $$@ $ $ $ $ $$` :t
$$` $$0 8 $ $Q; tAA
uuC B ;u }t- E t#h RVY EG ^[ ]SVW dUA $ t$t!3 t
%AA dUA <3<3F "u S V3J3 "u3 "u @ <u3 t3 L /u u
$@ VAA
$@
hX\
_<$
^[
(tTh
Q
D
3TjjhBAh
uDD$ L$Q
u
4$6
@[A
@ASHA
@A @hAS|3P5A
@A [
R
T T
0 @A
jd
V hD$@A
Pjh
L$QR
: 3 $ d SV 0@A 8u
jSh @A D$
Pjh 4^[
S @Bvu3[;vd[kd3[ SVWUQ t ?u
3 3 % "uP3 W "u u;u G3 ,t tG"FO $ t3 G"L :$u(3 ,u uG3
EPh@GAjjhPGA
V UR
QPW EP R }
tju
MQ PD }t
u UR
Q, K3 t R MQ P$ URhpGA MQ |;h Rjujj j Q EP
QYZ^[
SV H& =8@Au; =<@Au2h@Aw th@AVr8@A =8@A <@A =8@At BjP T$RS t$
\u3 J \u
\@ "3
\u3 J nu
@
B @ :u U E Pu
R
3 ]
SePj>
N =HA [
$ /@
UE
30
PjeS^h
h`R
jQ7j hpjfS
PP
R
Qj
@Pjhj2
Rj
@Qjhv
UXQA
XQA
PR
R zPh@A
QPV @R MQ^
PR
j2
PQjjStV PuF
p ,P
Rh@A
Pj
@Rjhj2
Qj
@Pjhj
RQ nPh@A
PR
PQjkSh Pt
=TQAtE
pTQA P
pRh
jfS
]Vh@A
HAj;
SF
jj
M[jS]
7
U_
j
3
EPt3O_^[]
t#j
EZvPh
=\QA
jUh5HA
WjeS3
S
=PA
WEjfS*
]u Rh
U@Kf
5HA
UfPS
hft
@A=HA
5Auf@t#05\QA
E tPA
jPj
8t8EP
u
RV
Pj$ U uuu
uP]
U 3 U ]
U SVQ E
^[]
Ph@5HAh@A5A
3
SVWP PHu
p]A
/u43
j3HA
T st
3Su$
p]A lT]At=HA
3 u =HA
uuX@A H@A
\@A3@X
u E
}uhhdQA
Ej
E
hdQA
0h=D@A
AAtjVPA
AjdSL
3=T@A
dYAj~e5
H@A 5dYAkhYA tP\ = Au =HAt A HA5 A3^[ ]SHA HA t}PjS3
U SVW } ]
u u
@ ]GA E# u 7 ] GA E u V h ]GA E u F H ]`GA E u V
3[]
U 3]
U 3]
U SVW }U
u ] G3 M U R wE33 C U SM K
F U
U @ ]
U E ]
U @ ]U @ ]U ]$S D$PR SRh0GAjj L$Q C tMThGAP |>S L
$R
Q D$Ph GA SR
| D$P R L$Q P[
Q
$Q PZ[
S C u3[P R C[
33 H33 P3 H
P@"
@ ME
SVKPVj
t
j URV@
{t PtSj
Y^[
C tPU
SS
3jVVW
P{ U+UR
ujZ
M+M
CQu
CjV E@Ph@jhBAj { tj
PhGAV |j K
tP R3 K
C t SR
Q3
RQ 33C^
C[
V ptSVW 3 $3 T$ H+='wKjjjj D$Pn t$jjj T$R L$Q D$PTV R
|+ D$P R |W L$Q P D$P R $_^[ SVWU P $
3 D$jjjjhLBA W
R
Q, $ = D$4$u lm Uj@ D$
t$
wD$ D$P |$,u T$( s3 L$dBA |$t%kBA x D$BA _ $ C3 td
|$u
BA
FF
|$
uT$_ L$Qjl
t$ |$
t|
l G t]USjVjj V D$jjURjSjh uD$ P |$t
tT$
Y G L$Q P]_^[ SVW @ $ <$u3Y X 4$: t$3
u;4$t
3 V t FGW3 t*3 &u!33
SVWU + @
#$3 L$
e D$
2 3|3 D *u,3 T *u!@EA E] u \$$ P3 D Ru93 T au.MEA E& u $
F $RP
$3
F u
F $
N F33 G t| \uY ; n t 0 "t :t4 rt t"( \" "
t
3 tGB
u
B ;~ w V
U SV W
rt
JtZEA
U y u U m tH s
"u ^[C t
uC3
t ;u3^[
@PjSu
_^[[]Ul
SVW
=hEAuU
$ujTh
u D$LEA
T$hEA t]A
_=hEA
*
ut]A3 t
SVQ
G
d
$3 $ PVSiPEZ^[ U 0t
t& A SE A Q M]SVW T t3Z \$3 T$L$$ L$
U SVW U E } t
EP u
QtS Y^[
SV t
tP tS
Y ^[
SV Q f u
^[SVW ;u3
t V
u!3nV
u3Q
3
3
H S
EA
_^[
tEA
U SVW
u 0 t3/S + u3PF
@
I
8
'
E" u:
lP
l
p
x
|
x
g T
t f _^[ ]
SVWU 3 /%n t k =AtA H F u t = ?t63 G@ t(
C^[K }f >tF t F ^[ SVW $ 33 t%3 S .u3 K .u3 Co t {C ;u
. ^[SV t C S
t3^[
\t
/t3 :
3 }_ +H~
M 7_^[SVWUQ
$ 3 =AtA;
D$ CT$ SL$ K CH C EAS @;Cr {v tC fD$ T$R L$Q $+D$C [S V f f D$f Sf T
f Kf L$f C
;J
u H;Ju H;Ju@;Bt3
H H - H ? H H
3 t +=} ?uD$
t $ f <r u |$
t
$f <q\t
$9 +
$L$T$ |$
];t
_^[
T$ `U Q
SVW
^M[SV
U q
}t E t
8 t
fu;t3
S M}tVE
8 ^[
u3u
MFA}t E8|]A
u3|]A
RPM
Ml
Pf P
rfu
3v
3Bf
P D$<P
uX+ VS ~
V e u3
>t e3R P 3kw
U > e3R
R P P ~ P D$W X ^[S VW K 3 $ u3z ^ <$to S D$b T$ L
AU s s^[ SV t t tS Y ^[ ;P~ +P P S VWS S C;}< y ;} s
AEU s_^[
SVW "o FA
hO~
{
@> > 0
z
o
d K
H
=
2
f'
eue e
e
3 e
33 Se
3
e` e e
ef i
e e
e e
e t>
e_^[
e @>SQ
$e
e
$
e u&x
l>3
QP
e
eS
D$ r L$ T$ p 3; D$3 0 R t} et? ~; }6 ~1+D$3 RuR3
>3
e e
D$R 3P
v gq
e L$
eue
$>
L$ e
o
D$
ef;
>t)|
R > 0
<
8u3 whtS%~Y]_^[
SVWU 3!E u ;p>u $ W t t {t p>{u3
; ev~3 ` k t3P D$0X u4h U u i ANjj
n $ T$
e
e;T$u;$w
AvM3P D$05XV |>uu D$,s5 |>su >t D$,r > D$,r > e e
e
e
rD$,}r
V! D$,
VrD$,qr
V" D$,
VrD$,1r
V$ D$,
VrD$,Yr
F t V(
V D$,
D$,Mr
r V,
V D$,q
D$, 3 V, V( ~u
3 FF,
F(3 3RP F
3$T$
f ~"s
~" T$H D$, qD<H T$H F0 w / ~z ~
F"+ F
t 0
D$,
Jq(FA F0Uw
tO
$HcF D$HFv@N"+Q
0Qh T$T
$TFFf 0uf f
D$,vp
VT33
3
F
' T$
D$,o J
K $\
$`
T$
\ L$+L$
|$
|$
|$
o+FA
ff
F0f
u ee
A
f;>ts
G~F0
zu PhP UR
> t T$
e
|>
e; eu
>%=
>w >u3
> r^t t
>
<5w
>3
>
K
/3
K
uvp K
/t
CP
u\u
h
S\%k
=A
tD$
A
D$
y
3S
F u
;uKB$
f f /tf \uf\ f 8u_^[ SVWP
$
Knf KtQ
L$
T$ L$
K3RP V3
K D$3Z
t; KtO
KPq P S_
S t :m3 3 3 K C[
S f3
B
$ $ Pj
B t+
U S VW s0 Mnk=s
B | |aAA |[
t3 M E _^[ ] U S VW
E
e
[X
D
u3
ECU
P3
JE
NT S UTu
4f
Eyp }
>utI SR
P
e
f Ejj 3 Q t
e<
}t
U p>tu* [
e
e+
K
.G
E
1E
J H JHR
E U M H U PM H
EM }
D$a3339$3 ,$ \
0 D$3 T
hA T$
0B D$3 T
hA T$
0B D$3 T
hA T$
0B D$
jA D$
0D$ |$t1;T$3 \ |
hA0T
3 T
hA0T
hA0T 3 T
hA0T
B;T$}3 \ |
| \
@ |BA;T$} | uF3;T$}
~
i ,]_^[ SVW $ 33 $3 z <> A > A 2zR <> A > A22 T A |@ | T
| _^[
SVW P T$ $ $ T$
C D$ \$ @
3C
\$
@ >~A D$
@ > A D$8 B@ > A D$< D$0 \$4 3 \$83 \$<3 \$, A D$@ B >zA D$D B@ >~A D$H3 B
D$T B
>zA D$X B@ >~A D$\ B@ > A D$`3 B > A D$d D$X \$\ 3 \$`3 \$d3 \$T D$
D$
3p
3 t$h3 t$l3 Z r A > A |$p z >zA > A >~A |$t 3 t$p3 t$t3 r Zzv A> A |$x
v A
$ $ $ $
$
$
$ 3 $
3C
$ C
3
iA B
@
iA A B@
iA A B@
iA A B
iA A3 B
iA A B
@
B
iA A B@
iA A B
iA AB@
iA A 3 B
iA A
@
iA A B
iA A
BB@
@
iA A
AR
iA A $ $ $
$ $ $
$ 3
$
$ P
$ 3Q P
$
$ J $ 3 HJ $ $
$ 3B
_^[
SVW 3
L3
AvA
@rA
?nA
>jA t L3
@vA
?rA
>nA
tRP$
t$ttAttttttt
VL t t$Pt
$tttP
$ 3tttu
D$
tD$
tttAtt$x
) @A
ttt(
tAAAA
D$i
^[
$ <$ t<$
SVW<$t
Hu tthth tt
ttt
ttt
[[[[
[
fff
t5[
WWty$
tttttjt$ytt$tt'SSSSS
tttt@tttAtHu
t$ ^[
ttttZtHu
t| [tthttttt$ftttttttttf ;
Y $$$
$$AYYYYYYYYYY3 <YYYYYY>Y$
|Y YYYY
YY
YxYYYYY
YYY YYY
4YYYY>Y3
$YYYYYTYYYYYY T
Y YYYY YYYYYYYYYY T Y YYYYYYYY Y YYYYYY YYY <YYYYYY
ltYYYYYYY
YYYYYYYYYYYYlYYY Y
YYY |
0YYt'YY Y YYYYYYYU
Y|
YY4<Y YYY
YYY
YYt |YYYYTYTYYYYY
YYYYYYYYY tYYY#t
Y
T
YY
4 T tYY
$
YYY4
t
YY
Y$
YYY
YYY
YY
YY
Y$
LLLL YYYYtSLY^[
SYD h L $YYY Y Y YY<YUt 4, FY Y { } {YYYrYYtS SKJYYYYY
t {
YYY uY
0 s N
0 t
o@ C V
$$
0$$$$$$$$$t
$$$$$$
$$$$$X$
$$ rF$$t
($$$$
$$$$ $$$$hhhhhhhhhhhh
$$$$$ H {t ($
$$$$
$$$$$$rhhhb $$$$$$$V$$$X
$$$$ #
$$$$P$
$ $$$$
$$$$$$t$
$$$$$ V0
$${$$$$$$$$ $$999999999 $$$$$$ $$~$$$t .$$$$$$$$ V0
F
$t33 u $ $$$$T$$t@@$$$ ($$ $ $ H$$$T$$P$$ $$$$$$$$ |$|$|{t $$
$Z
p
/
p$}-.
{{{{{{{{t
}
$2
$ 2$$2$
$4 {3-$ {t$$$$ $ 3 8 {{{{{{{{ $$8$$$$$$$$$t$$$$$$t F,%