seems fine now…
should svchost.exe be taking 116,348ks of memory?
That does seem high,what % of cpu is it using.
Delete the copy of Combofix you have and download a fresh one from the links below,run it and post the new log.
Link 1
Link 2
okay so i ran combofix. It seems to be running on 0% CPU.
Here's Combofix log:
ComboFix 11-11-18.02 - Max 18/11/2011 19:18:52.2.4 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1252.2.1033.18.4030.1947 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-10-19 to 2011-11-19 )))))))))))))))))))))))))))))))
.
.
2011-11-19 00:30 . 2011-11-19 00:30 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-11-18 09:03 . 2011-11-18 22:09 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{42DB5E2D-65A2-4140-924D-E0BCC1CC5092}\offreg.dll
2011-11-18 09:03 . 2011-10-07 04:16 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{42DB5E2D-65A2-4140-924D-E0BCC1CC5092}\mpengine.dll
2011-11-18 05:23 . 2011-11-18 05:23 ——– d—–w- C:\_OTL
2011-11-12 21:05 . 2011-11-12 21:05 ——– d—–w- c:\windows\system32\Macromed
2011-11-11 19:44 . 2011-11-11 19:44 ——– d—–w- c:\program files (x86)\ESET
2011-11-10 22:32 . 2011-11-10 22:32 ——– d—–w- C:\Sun
2011-11-10 02:54 . 2011-11-10 02:53 66856 —-a-w- c:\windows\SysWow64\SynTPEnhPS.dll
2011-11-10 02:54 . 2011-11-10 02:53 392752 —-a-w- c:\windows\system32\drivers\SynTP.sys
2011-11-10 02:54 . 2011-11-10 02:53 226600 —-a-w- c:\windows\system32\SynTPAPI.dll
2011-11-10 02:54 . 2011-11-10 02:53 148264 —-a-w- c:\windows\system32\SynTPCo9.dll
2011-11-10 02:54 . 2011-11-10 02:53 107816 —-a-w- c:\windows\SysWow64\SynTPCOM.dll
2011-11-10 02:54 . 2011-11-10 02:53 277288 —-a-w- c:\windows\system32\SynCtrl.dll
2011-11-10 02:54 . 2011-11-10 02:53 222504 —-a-w- c:\windows\SysWow64\SynCtrl.dll
2011-11-10 02:54 . 2011-11-10 02:53 1048576 —-a-w- c:\windows\system32\syndata.bin
2011-11-10 02:54 . 2011-11-10 02:53 177448 —-a-w- c:\windows\SysWow64\SynCOM.dll
2011-11-10 00:21 . 2011-03-22 05:22 48640 —-a-w- c:\windows\system32\wwanprotdim.dll
2011-11-10 00:21 . 2011-03-22 05:22 229888 —-a-w- c:\windows\system32\wwansvc.dll
2011-11-10 00:19 . 2011-02-25 06:36 295296 —-a-w- c:\windows\system32\drivers\volsnap.sys
2011-11-09 19:02 . 2011-11-09 19:02 ——– d—–w- c:\users\Max\AppData\Roaming\SUPERAntiSpyware.com
2011-11-09 19:02 . 2011-11-09 19:02 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2011-11-09 18:40 . 2010-10-06 02:26 109240 —-a-w- c:\program files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\components\abhelperxpcom.dll
2011-11-09 18:40 . 2010-10-06 02:27 150200 —-a-w- c:\program files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\components\kavlinkfilter.dll
2011-11-09 18:38 . 2011-11-18 22:17 ——– d—–w- c:\programdata\Kaspersky Lab
2011-11-09 18:38 . 2011-11-09 18:38 ——– d—–w- c:\program files (x86)\Kaspersky Lab
2011-11-09 17:27 . 2011-11-09 17:27 ——– d—–w- c:\programdata\Kaspersky Lab Setup Files
2011-11-09 04:50 . 2011-11-09 04:50 ——– d—–w- c:\users\Max\AppData\Roaming\Malwarebytes
2011-11-09 04:50 . 2011-11-09 04:50 ——– d—–w- c:\programdata\Malwarebytes
2011-11-09 04:50 . 2011-08-31 22:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-09 04:08 . 2011-10-01 05:28 886784 —-a-w- c:\program files\Common Files\System\wab32.dll
2011-11-09 04:08 . 2011-10-01 04:43 708608 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll
2011-11-09 04:08 . 2011-09-29 16:24 1897328 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 04:08 . 2011-09-29 04:09 3141120 —-a-w- c:\windows\system32\win32k.sys
2011-11-08 21:29 . 2011-11-09 01:10 ——– d—–w- c:\users\Max\AppData\Local\VMware
2011-11-08 21:29 . 2011-11-09 01:10 ——– d—–w- c:\users\Max\AppData\Roaming\VMware
2011-11-08 21:27 . 2011-08-22 22:07 62064 —-a-w- c:\windows\system32\drivers\vmx86.sys
2011-11-08 21:26 . 2011-08-22 22:07 354416 —-a-w- c:\windows\SysWow64\vmnetdhcp.exe
2011-11-08 21:26 . 2011-08-22 22:06 432752 —-a-w- c:\windows\SysWow64\vmnat.exe
2011-11-08 21:26 . 2011-08-22 22:06 30320 —-a-w- c:\windows\system32\drivers\vmnetuserif.sys
2011-11-08 21:26 . 2011-08-22 22:07 942192 —-a-w- c:\windows\system32\vnetlib64.dll
2011-11-08 21:26 . 2011-08-22 04:11 39024 —-a-w- c:\windows\system32\drivers\hcmon.sys
2011-11-08 21:24 . 2011-11-18 22:07 ——– d—–w- c:\programdata\VMware
2011-11-08 21:24 . 2011-11-08 21:24 ——– d—–w- c:\program files (x86)\VMware
2011-11-08 21:24 . 2011-11-08 21:24 ——– d—–w- c:\program files (x86)\Common Files\VMware
2011-11-08 21:24 . 2011-11-08 21:24 ——– d—–w- c:\program files\Common Files\VMware
2011-11-07 03:58 . 2011-11-07 03:58 ——– d—–w- c:\users\Max\AppData\Roaming\Symantec
2011-11-07 03:10 . 2011-11-07 03:10 ——– d—–w- c:\programdata\Wavefunction
2011-11-07 02:07 . 2011-11-07 02:07 ——– d—–w- c:\program files (x86)\Wavefunction
2011-11-05 15:17 . 2011-11-10 00:39 ——– d—–w- C:\Fraps
2011-11-04 18:15 . 2011-11-04 18:15 ——– d—–w- c:\program files (x86)\Rockstar Games
2011-11-02 00:43 . 2011-11-02 00:43 ——– d—–w- c:\users\Max\AppData\Roaming\fltk.org
2011-11-02 00:43 . 2011-11-02 00:43 ——– d—–w- c:\programdata\fltk.org
2011-11-01 17:11 . 2011-11-01 17:11 ——– d—–w- c:\programdata\Trymedia
2011-11-01 16:39 . 2011-11-01 16:39 ——– d—–w- c:\program files (x86)\Activision
2011-10-26 18:50 . 2011-08-15 05:08 6144 —-a-w- c:\program files\Internet Explorer\iecompat.dll
2011-10-26 18:50 . 2011-08-15 04:25 6144 —-a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
2011-10-26 14:02 . 2011-10-27 14:49 ——– d—–w- c:\program files (x86)\SmartSound Software
2011-10-26 14:02 . 2011-10-27 14:49 ——– d—–w- c:\programdata\SmartSound Software Inc
2011-10-24 21:54 . 2011-10-24 21:54 ——– d—–w- c:\program files (x86)\LiveMath
2011-10-23 21:31 . 2011-11-14 03:02 ——– d—–w- C:\MC Server 1.8
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-12 21:05 . 2011-05-18 22:01 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-10 02:53 . 2011-02-04 03:56 415528 —-a-w- c:\windows\system32\SynCOM.dll
2011-10-05 16:49 . 2011-03-03 20:03 13888 —-a-w- c:\windows\system32\RTNICVer.dll
2011-10-05 16:39 . 2011-08-31 20:09 81920 —-a-w- c:\windows\system32\nusb3co2.dll
2011-10-05 16:04 . 2011-04-09 00:48 224256 —-a-w- c:\windows\system32\staco64.dll
2011-10-01 03:21 . 2011-10-12 10:16 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-10-01 02:59 . 2011-10-12 10:16 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb
2011-09-05 13:57 . 2011-09-05 13:57 366136 —-a-w- c:\windows\SysWow64\flcdlmsg.dll
2011-09-05 13:57 . 2011-09-05 13:57 476728 —-a-w- c:\windows\SysWow64\flcdlock.exe
2011-09-05 05:35 . 2011-09-05 05:35 270912 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-09-04 13:07 . 2011-09-04 13:07 2874880 —-a-w- c:\windows\system32\python32.dll
2011-08-31 20:09 . 2011-08-31 20:09 91648 —-a-w- c:\windows\system32\drivers\nusb3hub.sys
2011-08-31 20:09 . 2011-08-31 20:09 208896 —-a-w- c:\windows\system32\drivers\nusb3xhc.sys
2011-08-27 05:40 . 2011-10-12 10:15 861184 —-a-w- c:\windows\system32\oleaut32.dll
2011-08-27 05:40 . 2011-10-12 10:15 331776 —-a-w- c:\windows\system32\oleacc.dll
2011-08-27 04:43 . 2011-10-12 10:15 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll
2011-08-27 04:43 . 2011-10-12 10:15 233472 —-a-w- c:\windows\SysWow64\oleacc.dll
2011-08-24 19:30 . 2011-08-24 19:30 868688 —-a-r- c:\windows\system32\DPLic.dll
2011-08-24 19:30 . 2011-08-24 19:30 621392 —-a-r- c:\windows\SysWow64\DPLic.dll
2011-08-24 18:55 . 2011-08-24 18:55 859472 —-a-r- c:\windows\SysWow64\DPCrProv.dll
2011-08-24 18:55 . 2011-08-24 18:55 330064 —-a-r- c:\windows\system32\DPPassFilter.dll
2011-08-24 18:55 . 2011-08-24 18:55 259408 —-a-r- c:\windows\SysWow64\DPPassFilter.dll
2011-08-24 18:55 . 2011-08-24 18:55 1038672 —-a-r- c:\windows\system32\DPCrProv.dll
2011-08-24 18:55 . 2011-08-24 18:55 765776 —-a-r- c:\windows\system32\DPFPApiUI.dll
2011-08-24 18:55 . 2011-08-24 18:55 664400 —-a-r- c:\windows\SysWow64\DPFPApiUI.dll
2011-08-24 18:53 . 2011-08-24 18:53 652624 —-a-r- c:\windows\system32\DPFPApi.dll
2011-08-24 18:53 . 2011-08-24 18:53 328528 —-a-r- c:\windows\system32\DPSCEL.dll
2011-08-24 18:53 . 2011-08-24 18:53 499536 —-a-r- c:\windows\SysWow64\DPFPApi.dll
2011-08-24 18:53 . 2011-08-24 18:53 378192 —-a-r- c:\windows\system32\DPClback.dll
2011-08-24 18:53 . 2011-08-24 18:53 267088 —-a-r- c:\windows\SysWow64\DPSCEL.dll
2011-08-24 18:53 . 2011-08-24 18:53 311632 —-a-r- c:\windows\SysWow64\DPClback.dll
2011-08-23 15:10 . 2011-08-23 15:10 4406064 —-a-w- c:\windows\system32\vcsAPIShared.dll
2011-08-23 15:10 . 2011-08-23 15:10 3806512 —-a-w- c:\windows\SysWow64\vcsAPIShared.dll
2011-08-23 09:37 . 2011-08-23 09:37 3175728 —-a-w- c:\windows\system32\vcsFPService.exe
2011-08-23 09:24 . 2011-08-23 09:24 8704 —-a-w- c:\windows\system32\vcsEventMsg.dll
2011-08-23 09:23 . 2011-08-23 09:23 2774320 —-a-w- c:\windows\SysWow64\vcsFPService.exe
2011-08-23 09:12 . 2011-08-23 09:12 8704 —-a-w- c:\windows\SysWow64\vcsEventMsg.dll
2011-08-22 20:40 . 2011-08-22 20:40 252016 —-a-w- c:\windows\SysWow64\vmnc.dll
2011-08-22 20:12 . 2011-08-22 20:12 62064 —-a-w- c:\windows\system32\vmnetbridge.dll
2011-08-22 20:12 . 2011-08-22 20:12 48752 —-a-w- c:\windows\system32\vnetinst.dll
2011-08-22 20:12 . 2011-08-22 20:12 45680 —-a-w- c:\windows\system32\drivers\vmnetbridge.sys
2011-08-22 20:12 . 2011-08-22 20:12 24176 —-a-w- c:\windows\system32\drivers\vmnet.sys
2011-08-22 20:12 . 2011-08-22 20:12 20080 —-a-w- c:\windows\system32\drivers\vmnetadapter.sys
2011-08-22 19:59 . 2011-08-22 19:59 100808 —-a-w- c:\windows\system32\drivers\MfeEpeOpal.sys
2011-08-22 19:59 . 2011-08-22 19:59 13256 —-a-w- c:\windows\system32\drivers\MfeEpeHb.sys
2011-08-22 19:59 . 2011-08-22 19:59 158920 —-a-w- c:\windows\system32\drivers\MfeEpePc.sys
2011-08-22 04:01 . 2011-08-22 04:01 37680 —-a-w- c:\windows\system32\drivers\vmusb.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-10-17 283160]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-10-05 113288]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-05-23 103992]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-08-19 421736]
"HPQuickWebProxy"="c:\program files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" [2011-08-31 169528]
"QLBController"="c:\program files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2011-07-06 323128]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-15 1955208]
"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2011-11-09 365336]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
.
c:\users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Max\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2011-02-03 23:09 75360 —-a-w- c:\windows\System32\DeviceNP.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\sbhook.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R1 SASDIFSV;SASDIFSV;c:\users\Max\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]
R1 SASKUTIL;SASKUTIL;c:\users\Max\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2011-08-22 11837440]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [x]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [x]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [x]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [x]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [x]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [x]
R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x64.sys [x]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe [2011-09-05 476728]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-08-15 130976]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 RTL8192su;TRENDnet 300Mbps Wireless N USB Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [x]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 MfeEpeOpal;MfeEpeOpal; [x]
S0 MfeEpePc;MfeEpePc; [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [2011-09-01 169624]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2011-07-20 89600]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 138400]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-01-07 53920]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 2329480]
S2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-06-21 85560]
S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-09-01 227896]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 320000]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-07-06 1698360]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-17 13336]
S2 jhi_service;Intel® Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-08-22 1318912]
S2 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-01-03 2656280]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2011-08-23 3175728]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-22 846448]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [x]
S3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-05-23 1098296]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001Core.job
- c:\users\Max\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-24 05:21]
.
2011-11-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001UA.job
- c:\users\Max\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-24 05:21]
.
2011-11-18 c:\windows\Tasks\HPCeeScheduleForMax.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
2011-10-31 c:\windows\Tasks\HPCeeScheduleForMAXHP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPPowerAssistant"="c:\program files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe" [2011-01-27 13880]
"MfeEpePcMonitor"="c:\program files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe" [2011-08-22 200704]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-05-18 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-05-18 391704]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-07-20 1128448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\x64\kloehk.dll c:\progra~2\KASPER~1\KASPER~1\x64\sbhook64.dll
.
——- Supplementary Scan ——-
.
uStart Page = my.daemon-search.com
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
LSP: %SystemRoot%\system32\vsocklib.dll
TCP: DhcpNameServer = [removed] [removed]
DPF: {BAD4FE2C-503B-45CC-88CD-4B0574057D11} - hxxp://clients.futuremark.com/calico/systeminfodeploy/FMSI_v420.cab
FF - ProfilePath - c:\users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\
FF - prefs.js: browser.startup.homepage - about:home
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226} - c:\program files (x86)\InstallShield Installation Information\{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}\setup.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:6a,26,62,4b,84,a5,e3,95,14,c4,f4,ad,c5,7a,33,84,c9,84,a6,ae,6c,
e5,a5,58,03,a2,cc,11,c8,5b,f8,6e,1d,b5,8c,c3,70,40,bc,5e,dd,d8,f2,a6,e0,25,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:6a,26,62,4b,84,a5,e3,95,14,c4,f4,ad,c5,7a,33,84,c9,84,a6,ae,6c,
e5,a5,58,03,a2,cc,11,c8,5b,f8,6e,1d,b5,8c,c3,70,40,bc,5e,dd,d8,f2,a6,e0,25,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*€ *]
@="\010\01"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*â]
@="\06?"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*
R]
@="\06?"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*
]
@="?"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\;¾Q&**€*]
@="??&?\02"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-11-18 19:32:56
ComboFix-quarantined-files.txt 2011-11-19 00:32
ComboFix2.txt 2011-11-11 19:31
.
Pre-Run: 59,577,167,872 bytes free
Post-Run: 59,513,294,848 bytes free
.
- - End Of File - - 9DC74C000C569ACE91198C763DDB1566
Shall I restart?
If it is not using any cpu then it is fine.
You appear clean of infections,please do the following.
ComboFix - Cleanup
Time for some housekeeping
Click Start …select Run from the menu. Copy and paste the following into the text entry box:
Combofix /Uninstall Click the OK button. (See image below as reference.)
🖼 Click to load external image (Posted Image)
Clean up with
OTL:
Double-click OTL.exe to start the program. Close all other programs apart from OTL as this step will require a reboot On the OTL main screen, press the CLEANUP button Say Yes to the prompt and then allow the program to reboot your computer.
Download TFC to your desktop
Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean
Here are some recommendations to help you stay clean.
Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/
Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices' .
So how did I get infected in the first place.
please take a moment to read
quietman7's excellent prevention tips in post 3 here
Click >>>>
Tips to protect yourself against malware and reduce the potential for re-infection :
Preventing Infections in the Future
Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:
Avoid gaming sites , underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections , remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware . Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology .
Update Non-Microsoft Programs
It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting
Secunia Software Inspector and
Calendar of Updates.
Thats it you are good to go.Safe surfing
Thanks a lot for helping me
You're welcome,glad we could help
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.