Analysis Date2014-08-16 13:57:17
MD51c87f3704911d94d89fcf4f4c05c1897
SHA110769b065e9da81aeb03baec96148c51b6c35ce4

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: c2d67a1de51739c3aee85bf0e3d9ae15 sha1: e5e08de2492b906b4b13cd7047c17da0d2368218 size: 25600
Section.rdata md5: 7f8d553a7f82735880f470d85238702f sha1: 280e596e60fb5c7ec878e043d123992909765e85 size: 7680
Section.data md5: 96549a697f7d93bc7ba7de851245f44b sha1: ac617e9fb94f82ed9b9d368cbeb2a07ad6df23d8 size: 173568
Section.rsrc md5: 4f190e280c1dd75229a590b69fb86f6f sha1: b66f560f2350e294c34a008da5268f36ff1aa6ef size: 49152
Section.reloc md5: 129e8e3ca2801e44c3dd5009aa74aaf1 sha1: e02ba5b732574ca6e6dcdf883ec1e3774b1f4918 size: 4096
Timestamp2014-08-08 11:48:08
PackerMicrosoft Visual C++ ?.?
PEhash96a279923afdb2ec937487073c15cf0f7a531eae
IMPhash0284f4483cfa39f6f8c08ac867e47162
AV360 Safeno_virus
AVAd-Awareno_virus
AVAlwil (avast)no_virus
AVArcabit (arcavir)no_virus
AVAuthentiumno_virus
AVAvira (antivir)no_virus
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftTrojan.Generic.11609214
AVEset (nod32)Win32/Korplug.A
AVFortinetW32/Korplug.A!tr
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Generic.11609214
AVGrisoft (avg)Agent4.CALB
AVIkarusTrojan.Win32.Agent
AVK7Trojan ( 003c36381 )
AVKasperskyTrojan.Win32.Agent.ahhfs
AVMalwareBytesno_virus
AVMcafeeno_virus
AVMicrosoft Security EssentialsBackdoor:Win32/Plugx.A
AVMicroWorld (escan)no_virus
AVNormanno_virus
AVRisingno_virus
AVSophosno_virus
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus
AVYara APTno_virus
AVZillya!no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_LOCAL_MACHINE\Software\CLASSES\FAST\CLSID ➝
NULL
Creates FileC:\Documents and Settings\All Users\SxS\NvSmart.exe
Creates FileC:\Documents and Settings\All Users\SxS\NvSmartMax.dll
Creates FileC:\Documents and Settings\All Users\SxS\xxx.xxx
Creates FilePIPE\lsarpc
Creates MutexZA-MUTEX

Process
↳ C:\Documents and Settings\All Users\SxS\NvSmart.exe

Network Details:


Raw Pcap

Strings
.CC
 
.
3
.
.8
.J,z
.
.
]
..o..
3G(

1.0 
(&A) ...
Copyright (C) 2012
(&F)
                                 H
         (((((                  H
(&H)
         h((((                  H
KERNEL32.DLL
mscoree.dll
MS Shell Dlg
Shell3
 Shell3
SHELL3
(&X)
                          
;~"}%+
0$0,040<0D0L0T0\0d0l0t0|0
0!090\0l0s0~0
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
$020y0~0
;$;(;,;0;4;8;<;@;
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
0A@@Ju
0c5wcK
_0d^#w(
0h7"a=n
0O1X1^1
0SSSSS
0Vwh0F
0WWWWW
0Y-+Lz
1*101;1G1\1c1w1~1
1&1:1]1i1u2
1%121Y1q1
1+181D1N1V1a1
1b=-a t2Q5
1(,kpT
<#1q>?
1UQYSY-a
1_UX<8
-1:ZC6!
2#2/2>2D2M2Y2g2m2y2
2-2:2D2z2
2&2q2|2
2$2T2u2
2	3^3h3
24383@3D3`3|3
2dA(b[
2]F>saw$
2x%6Zu
31D1~1
3$3*383A3P3U3_3m3
363v3|3
:3:D:J:[:
^3=Gs)e
3H4X4h4x4
(&	3k[{
3@K,~p
3M6T6Z6
3Ovt	V
"^~3r7y`T
3.rkI\o
"`3VME
3x$gP}
3z4*5_5x5
'3Z:%BGW/
404L4P4p4
445@5S5e5
475>5Y5^5f5l5s5y5
4c<Q:yE|
4)f`R\
4%:h=D
4,Ky#!
`4_{R!
4VrY~G
505P5p5
5D'^}F
:5:<:U:i:o:x:
63[4]5mm]5\]m]mm5\mm5555555\\\5\\\5m\55\\5ed:
6!6&61666C6Q6W6d6
6"6*6:6O6
6 6$6n6t6x6|6
6/6X6i6{6
^6cwa 
6|hXL_
>6L+&g@
6P"(K-
6p-VWb'
6	%<xL
[<6yw?~
7 7A7k7
7/888D8
7A6psf
7b7<8D8\8t8
7d0w^N"v
7K*AgN~
7tS*f6
]]'7Xjj
[;7/zG
8`&	3G
8#8.8R8[8b8k8
8"959M9_9
,89#R8U^
)8.c<e
+8f2ex
_8Lqw<1
8q8w8}8
8t,sf5
8+ZC\t9
8'zw:wg'
]}931Y
96:<:U:[:
9&989K9V9\9b9g9p9
9!9)919=9a9i9u9
9"9'979<9B9H9^9e9x9
9yg=z@
A6W9XL
AAFFf;
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
aGPL`#t
A}jmzc
:amqCg gu
An application has made an attempt to load the C runtime library incorrectly.
ApG|@<
A&,+SC
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
),auCsnm
August
aXXXC]
AXXX.:E
b0$.mi
B2K%1}
[b?2oXj
	bAhkH
BeginPaint
BjV%W*
~b=l[R
bQf-\'0
BqmSAE
B.tJx<
c05O9MEP
C	`0kC
.C2m>Wf
c$3n/9
/ca\d=
c]@KrR|
CorExitProcess
cOXY/P.Z0.0.QR00/ZPP0000000/0PPZR.BI@/DE0,
)c+qVa7
CreateWindowExW
- CRT not initialized
#'C<y4
@.data
d!AY'Z
dddd, MMMM dd, yyyy
:D;d;t;
December
DecodePointer
DefWindowProcW
DeleteCriticalSection
-*DE>R
DestroyWindow
DialogBoxParamW
DispatchMessageW
DJ$*j)
DmK=G{7
>d<mNe$
DOMAIN error
doU#?{970
-~D/OX
^,dQrx
dT!5_F)>=
D~tn\qyvj
>*>e>~>
e9#>;v=
|e<'CeW
e"-e7wN
;|(Ejc!
>e/`#M
en3q%'
EncodePointer
EndDialog
EndPaint
EnterCriticalSection
/,e|"q`q@L
ExitProcess
eXXXC]
EXXXEE(<
e|y_Al
EyhH-4
faXhG*`T
fBeLS-
FD88ZE]
February
fGpykv
)~/FIW
- floating point support not loaded
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
f_?mLZ 
f:&ohm:_G6
FreeEnvironmentStringsW
Friday
Ft#aQE
fW)DH?
g	(1k-HT
^G6KW@f
}<G8-<
G`ar7L}\y
@]GB\I
GBM]}2
G]cB4z
GcQrh}ew
Ge"FS8
GetACP
GetActiveWindow
GetCommandLineW
GetCPInfo
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileType
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetMessageW
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessWindowStation
GetStartupInfoA
GetStartupInfoW
GetStdHandle
GetStringTypeA
GetStringTypeW
GetSystemTime
GetSystemTimeAsFileTime
GetTickCount
GetUserObjectInformationA
;ggIcu
gGzC<4
GT6R-S
gu|78yh;P
G-Y3Xgs
H1L1P1T1
)}H4rY
H~64=Nj
HeapAlloc
HeapCreate
HeapFree
HeapReAlloc
HeapSize
)*hF<+?
HH:mm:ss
HjktP*BKKe!
hl1DK>
!`@hoj
H}Vk$$
HwQSeaMG
i1?vky
I3')+*+)))*))()*+++,6J!54 CBA
i*/a]$
'id6!c
IjoPmI
i+k2a>"b
InitializeCriticalSectionAndSpinCount
InterlockedDecrement
InterlockedIncrement
ipt0IF
?iq'K3
IsDebuggerPresent
IsValidCodePage
i%V1eU
i_@}Wt
I$*Zq1
iZx/k)
\J6\pZ~
JanFebMarAprMayJunJulAugSepOctNovDec
January
JEEEEEEEEEEFC
JEEEEEEEEEEFD
JEFEEEEEEEEEB
 jel!Q
JHHGGGGGGGGHI
JJIIIIJIIIIJJ
j@j ^V
Jk{\L#
)jKu6<
}J%V4}
Jv(Z0C+
J%};Wu
JWW^i`
j(~xEW
j[	X.eX
jYPQTVTSkllZTTXRTUiHceWda/
  JZ&Uw
KERNEL32.dll
K-J|d4}
Kj+#vj
]	_K]L'
kL9^RC
K')LzF
kO-,]%
"k'qS~
>Kzj#R
L[*1pq
LAW4%tX
LCMapStringA
LCMapStringW
LeaveCriticalSection
lGV`#y,
Lj,_d(
L-M:X9b2Ni
LoadAcceleratorsW
LoadCursorW
LoadIconW
LoadLibraryA
LoadStringW
#L=oMs
}LoZ_\
l+&Pt}
{*M8@+
#M8p3Hh>R"
?/?M?a?g?
MD&h )
.!-me=
MessageBoxA
m@]F0o
<`{m%H"
Microsoft Visual C++ Runtime Library
miI7WE
M]K0nZ4
-ML%bT
mL%KreM
MM/dd/yy
mmXS0x
m"Na >V$X
Monday
(mujO2
MultiByteToWideChar
'M}-XTyG
N.:6#g>
n*8^~O
nCB|TR
nd,Wi5
N\I~}k
=+nIz7j=
#N-kcEn
nmk>Qk7
\NNmjE
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
N%RBjS
NRiW?z
N@T%ZL
nUT]5#"
nwYbxpo
Nw~ytMMMMMMUbbrrrrrxxxxxxxxrriUMMMMMMMMMUuzt
|n?yJNV;
nYXXX[
nZ % 4
)O6530./21+*-,4#4PPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPP
O(@>=77A779?<8;$O' 
=o]b?-l
 O.`CI
October
o;d/Q:
o?G#	_
O^HIPY
O}I|F@a
O%JEEEEEEEEEFFB
o\mA@@0
.Om>nI
O!pagh
,or_*+,
O~VJ}%
]~;p*:
@:P6Ocp
?P	j$\
pjc+l:rg2@
Please contact the application's support team for more information.
pO1~$`B
PostQuitMessage
PPPPPPPP
PPPPPPPPPPPPPPPPPKMNNNNNNNNNNOLO
p}&qyP
Program: 
<program name unknown>
P,UQr2
- pure virtual function call
pwwwwwwww
pwwwwwwwwwwwwwwwp
pxDDDDDDDDD@
pxDDDDDDDDDDDDDDpx
pxDDDDDDDDDH
pxDDDDDDpx
pXuXeZ=
pxwwwwwwpxDDD
pxwwwwwwwwwwwwwxpx
`q8i$8
&qE?ke9
+qfs<\
^QkU?b
,$qokc
}>qooggggggg1`_fhsnHK
QQSVWh
QueryPerformanceCounter
qXXX.:E
Qz;Z1&?f
r0u>ou
r5&Ftq
raDI/F/d
`.rdata
RegisterClassExW
@.reloc
R h4Z]-
rHOc6y
RJUIRA
~R.KO)
.RLL*;
R),`q,?
R/_(rL
Rr'zher/(
RS/m&hR
RtlUnwind
runtime error 
Runtime Error!
_r>Zt<
s8em!d
Saturday
September
SetHandleCount
SetLastError
SetUnhandledExceptionFilter
ShowWindow
SING error
sk<zr}
sLi9j@
[]@snc
Sunday
SunMonTueWedThuFriSat
+swe1~
sX;9xV
Tc3j*b
TerminateProcess
?Th$ c
This application has requested the Runtime to terminate it in an unusual way.
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
!This program cannot be run in DOS mode.
t'hKI0e
Thursday
TLOSS error
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
Tn9ew[
TranslateAcceleratorW
TranslateMessage
t"SS9]
Tua/UD
Tuesday
;t$,v-
=tv"p)&
TW$Bik
t+WWVPV
@tY=c/
t<Zj%#
U3N<KV
U85|zD
u9x`kl
uad2@#"2F
=U=b=A>P>
uF,`b{`
u/J/wP
- unable to initialize heap
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
UnhandledExceptionFilter
UpdateWindow
UQPXY]Y[
URPQQh
u{%\rS
USER32.dll
USER32.DLL
u.xgDj
UXXX:=
uXXX+>>YX
U~Y1)Z?
u]_y7t
V9h<'Y
%:V%D=
;vF|kt
VirtualAlloc
VirtualFree
v	N+D$
VVVVPPh
V#+xPyc
w4aYJ-
[w]8F4j=
Wednesday
W|>	F(
wfN0NZ
w !`GjjU
WideCharToMultiByte
WkV21TSav^8{
WLdqH>
WriteFile
"}(Wt[
Wu?'[;
'W.+UdI
wvVE/wK
wwwwwwwpx
wwwwwwwwwwwwwwwpx
w]+Y+JJ
<wZFk1A
X0	CYX
|}x1>>
!X<51	Q
 x9tCj
 Xb#E;
;X<b<o<
XCGa  
$xc{}t!
xfG)/t
}xI)$&
("XI~(
xi~X={-
X~<%q^+
XQK;{q
]XXX-`Cc
XXXEYX
XXXG-=E?
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Xy>3tm!n
xy*AX"
XzhRiyu!u
~%Y0#r
y1?~s	
~Y@1Xs
Y6x|S+i
&/y9.8
y..G.`
#~=yHK
Y!l=u)
~Y/N)P
y:RTPu
>=Yt1j
Y vf\_
Y<vPN(
{|yvrrwsqpon
YY-`CH
YY?t_-`Cf
YYYY-4
:z;'=9=K=m=
zAGV*aM
zbJa&{@
 ZtCjg
}zy|yx~