I GOT INFECTED!!!

  • Scott

    I clicked on a file from aim and got this trojan. Then, I ran adaware, then I ran a virus checker. The virus checker found them but said they could not do anything then i got this Hijack this from a friend and ran it and this is my log file.

    I need to know which ones need to be fixed….

    Logfile of HijackThis v1.99.1

    Scan saved at 12:19:44 PM, on 10/25/2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\System32\ibmpmsvc.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\System32\S24EvMon.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\WINDOWS\System32\hkcmd.exe

    C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

    C:\WINDOWS\system32\TpShocks.exe

    C:\Program Files\Symantec AntiVirus\DefWatch.exe

    C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe

    C:\PROGRA~1\SYMANT~1\VPTray.exe

    C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\IBMTOOLS\UTILS\ibmprc.exe

    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

    C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe

    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe

    C:\WINDOWS\system32\16gkhe62.exe

    C:\WINDOWS\system32\btpanui0.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\System32\QCONSVC.EXE

    C:\WINDOWS\System32\RegSrvc.exe

    C:\Program Files\Symantec AntiVirus\SavRoam.exe

    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    C:\Program Files\Common Files\Windows\services32.exe

    C:\WINDOWS\system32\TpKmpSVC.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\Program Files\AIM\aim.exe

    C:\WINDOWS\explorer.exe

    C:\Program Files\MSN Messenger\msnmsgr.exe

    C:\Program Files\Ares\Ares.exe

    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

    C:\DOCUMENTS AND SETTINGS\SBALDAUF\DESKTOP\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.seektheglobe.com/sp2.php

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\Searchx.htm

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.seektheglobe.com/sp2.php

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.acs.nmu.edu/home.php

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.acs.nmu.edu/home.php

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 68.213.34.54:80

    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll

    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL

    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll

    O4 - HKLM\..\Run: C:\Program Files\SurfSideKick 3\Ssk.exe

    O4 - HKLM\..\Run: c:\nmutools\backup_reminder.exe

    O4 - HKLM\..\Run: C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    O4 - HKCU\..\Run: C:\Program Files\SurfSideKick 3\Ssk.exe

    O4 - Global Startup: Image Transfer.lnk = ?

    O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE

    O4 - Global Startup: TurnWirelessOff.lnk = C:\nmutools\turnwirelessoff.vbs

    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb02948US_ZZ

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O20 - AppInit_DLLs: repairs302972949.dll

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll

    O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

    O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe

    O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe

    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe

    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)

    O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE

    O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe

    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe

    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

    I really dont know too much about computers so I kinda need lots of help

    Thanks Scott

  • Erik

    Post your log here: http://forums.spywareinfo.com/index.php?showforum=18

    I think it will bettter for you to have a forum in English :?

  • Peter

    Or download and run the programs from the link below and post another HijckThis logfile:

    http://www.virushelp.nl/partners/hijackthis/hijackthislog.htm

    I think the English language won't be that much of a problem for most of the visitors here ;-).

  • Scott

    i heard there was really good help here from a friend so i posted it herePeter schreef:

  • Scott

    I did aware and it failed the fail the spybot i got some error like–> you need to install the decection updates first by using the integrated update or the manial updater, i could not find the updates

    then i ran cws and got this

    CWShredder v1.59.1 scan only report

    Please understand that a CWShredder ‘Scan only’ report

    might not be sufficient to troubleshoot an infected system.

    You can use HijackThis for that:

    http://www.merijn.org/files/hijackthis.zip

    http://www.spywareinfo.com/~merijn/files/hijackthis.zip

    Windows XP (5.01.2600 SP2)

    Windows dir: C:\WINDOWS

    Windows system dir: C:\WINDOWS\system32

    AppData folder: C:\Documents and Settings\sbaldauf\Application Data

    Username: sbaldauf

    Found Hosts file: C:\WINDOWS\system32\drivers\etc\hosts (734 bytes, A)

    CWS.Msconfig Registry value: HKLM\..\Run C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    Shell Registry value: HKLM\..\WinLogon Explorer.exe

    UserInit Registry value: HKLM\..\WinLogon C:\WINDOWS\System32\userinit.exe,

    Found Win.ini file: C:\WINDOWS\win.ini (949 bytes, A)

    Found System.ini file: C:\WINDOWS\system.ini (246 bytes, A)

    then ran hijackthis again and got

    Logfile of HijackThis v1.99.1

    Scan saved at 1:05:33 PM, on 10/25/2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\System32\ibmpmsvc.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\System32\S24EvMon.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\WINDOWS\System32\hkcmd.exe

    C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

    C:\WINDOWS\system32\TpShocks.exe

    C:\Program Files\Symantec AntiVirus\DefWatch.exe

    C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe

    C:\PROGRA~1\SYMANT~1\VPTray.exe

    C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\IBMTOOLS\UTILS\ibmprc.exe

    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

    C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe

    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe

    C:\WINDOWS\system32\16gkhe62.exe

    C:\WINDOWS\system32\btpanui0.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\System32\QCONSVC.EXE

    C:\WINDOWS\System32\RegSrvc.exe

    C:\Program Files\Symantec AntiVirus\SavRoam.exe

    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    C:\Program Files\Common Files\Windows\services32.exe

    C:\WINDOWS\system32\TpKmpSVC.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\explorer.exe

    C:\Program Files\MSN Messenger\msnmsgr.exe

    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

    C:\Documents and Settings\sbaldauf\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.seektheglobe.com/sp2.php

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\Searchx.htm

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.seektheglobe.com/sp2.php

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.acs.nmu.edu/home.php

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.acs.nmu.edu/home.php

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 68.213.34.54:80

    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll

    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL

    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll

    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll

    O4 - HKLM\..\Run: C:\Program Files\SurfSideKick 3\Ssk.exe

    O4 - HKLM\..\Run: c:\nmutools\backup_reminder.exe

    O4 - HKLM\..\Run: C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    O4 - HKCU\..\Run: C:\Program Files\SurfSideKick 3\Ssk.exe

    O4 - Global Startup: Image Transfer.lnk = ?

    O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE

    O4 - Global Startup: TurnWirelessOff.lnk = C:\nmutools\turnwirelessoff.vbs

    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb02948US_ZZ

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O20 - AppInit_DLLs: repairs302972949.dll

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll

    O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

    O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe

    O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe

    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe

    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)

    O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE

    O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe

    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe

    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

  • Erik

    Only start Hijackthis, check the following lines:

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = www.seektheglobe.com/sp2.php

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\Searchx.htm

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.seektheglobe.com/sp2.php

    R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll

    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL

    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL

    O4 - HKLM\..\Run: C:\Program Files\SurfSideKick 3\Ssk.exe

    O4 - HKCU\..\Run: C:\Program Files\SurfSideKick 3\Ssk

    O8 - Extra context menu item: &Search - bar.mywebsearch.com/menusearch.html?p=ZSzeb02948US_ZZ

    Close all other browser windows, Click fix checked

    Reboot in safe mode by tapping the F8 key just before windows loads.

    Remove the following Folders:

    C:\Program Files\MyWebSearch

    C:\Program Files\SurfSideKick 3

    Reboot into normal mode.

    Perform an online scan at TrendMicro: http://uk.trendmicro-europe.com/consumer/housecall/housecall_launch.php

    Save the logfile

    You most likely have this Backdoor Trojan: http://www.sophos.com/virusinfo/analyses/w32rbotmb.html so change all your passwords.

    Please post the Trend log aswell as a new HJT log.

  • Erik

    Also remove these files when in safe mode:

    C:\WINDOWS\system32\16gkhe62.exe <== File

    C:\WINDOWS\system32\btpanui0.exe <== File

  • Erik

    I stated this a bit premature : You most likely have this Backdoor Trojan

    But you do have a Trojan on your system :-)

  • Scott

    ok ill try it now thanks

  • Scott

    it would not let me delete the sursidekick3 file it gave me a error and said it was being used and can not be delete….