Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: das böse qvo6

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 07.05.2013, 09:10   #1
feeluck
 
das böse qvo6 - Standard

das böse qvo6



hallo!
leider konnte ich in einem anderen thread keine antwort erstellen,
habe das gleiche problem wie hier:
http://www.trojaner-board.de/134387-qvo6-problem.html

einen zoek scan habe ich auch schon gemacht:

Code:
ATTFilter
Zoek.exe Version 4.0.0.2 Updated 06-May-2013
Tool run by Feeluck on 07.05.2013 at 10:01:10,11.
Microsoft Windows 7 Professional  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected

==== Older Logs ======================

C:\zoek-results07.05.2013-1000.log	325 bytes

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2159210148-4085374171-1169642832-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\qtypesvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\qtypesvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\qtypesvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\qtypesvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\eSafeSvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eSafeSvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\eSafeSvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\eSafeSvc deleted successfully

==== Deleting Files \ Folders ======================

"C:\END" deleted
"C:\Program Files (x86)\Common Files\DVDVideoSoft\TB" deleted
"C:\Program Files (x86)\QType" deleted
"C:\Program Files (x86)\Desk 365" deleted
"C:\Program Files (x86)\Conduit" deleted
"C:\Users\Feeluck\AppData\Roaming\Desk 365" deleted
"C:\Users\Feeluck\AppData\Roaming\eIntaller" deleted
"C:\Users\Feeluck\AppData\Roaming\OpenCandy" deleted
"C:\ProgramData\eSafe" deleted
"C:\Users\Feeluck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QType" deleted
"C:\Users\Feeluck\AppData\Local\Conduit" deleted
"C:\Users\Feeluck\AppData\LocalLow\Conduit" deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====
2013-04-22 06:43:04	F042EE4C8D66248D9B86DCF52ABAE416	256000	----a-w-	C:\Windows\PEV.exe
2013-04-22 06:43:04	9E05A9C264C8A908A8E79450FCBFF047	80412	----a-w-	C:\Windows\grep.exe
2013-04-22 06:43:04	5E832F4FAF5F481F2EAF3B3A48F603B8	68096	----a-w-	C:\Windows\zip.exe
2013-04-22 06:43:04	0297C72529807322B152F517FDB0A9FC	406528	----a-w-	C:\Windows\SWSC.exe
2013-04-22 06:43:04	0277C027A26428DB64EF4F64F52BB4FD	208896	----a-w-	C:\Windows\MBR.exe
====== C:\Users\Feeluck\AppData\Local\Temp ====
====== C:\Windows\SysWOW64 =====
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
====== C:\Windows\Sysnative\drivers =====
2013-04-24 06:14:48	B98F8C6E31CD07B2E6F71F7F648E38C0	1656680	----a-w-	C:\Windows\Sysnative\drivers\ntfs.sys
2013-04-10 10:26:54	8F6322049018354F45F05A2FD2D4E5E0	223752	----a-w-	C:\Windows\Sysnative\drivers\fvevol.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2013-04-22 05:40:19	--------	d-----w-	C:\Program Files\Enigma Software Group
======= C:\Program Files (x86) =====
2013-04-22 05:32:02	--------	d-----w-	C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-04-22 00:43:08	--------	d-----w-	C:\Program Files (x86)\Sinvise Systems
======= C: =====
2013-04-22 05:43:26	D41D8CD98F00B204E9800998ECF8427E	0	----a-w-	C:\autoexec.bat
====== C:\Users\Feeluck\AppData\Roaming ======
2013-04-22 06:48:11	--------	d-----w-	C:\users\Public\AppData\Local\temp
2013-04-22 06:48:11	--------	d-----w-	C:\users\Default\AppData\Local\temp
2013-04-22 06:48:11	--------	d-----w-	C:\users\Default User\AppData\Local\temp
2013-04-22 00:43:08	--------	d-----w-	C:\users\Feeluck\AppData\Roaming\Sinvise Systems
====== C:\Users\Feeluck ======
2013-04-22 06:48:11	--------	d-----w-	C:\Users\Public\AppData
2013-04-22 00:43:09	--------	d-----w-	C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sinvise Systems
2013-04-14 23:48:52	--------	d-----w-	C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grinding Gear Games

====== C: exe-files ==
2013-05-04 06:58:30	C26BB2535C1B20DEAFAEB12634BF4DC9	781592	----a-w-	C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdateSetup.exe
2013-05-04 06:58:30	8F11F0321ED84B1533FC1384AC71AC8D	59784	----atw-	C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdateBroker.exe
2013-05-04 06:58:30	00F714CA28A01FACB709486D6DA306A8	59784	----atw-	C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdateOnDemand.exe
2013-05-04 06:58:26	76B35CB0F3A4E69D6DFF27F542B9F856	216968	----atw-	C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
2013-05-04 06:58:26	506708142BC63DABA64F2D3AD1DCD5BF	116648	----atw-	C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdate.exe
2013-05-04 06:58:26	4E252E85E5DC31BD645E809222AFAF27	287624	----atw-	C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
2013-05-04 06:58:25	C26BB2535C1B20DEAFAEB12634BF4DC9	781592	----a-w-	C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.145\GoogleUpdateSetup.exe
2013-04-30 08:28:30	133ABFCAA6EEBE48CAD58E1EB077E550	22995304	----a-w-	C:\Riot Games\League of Legends\RADS\projects\lol_game_client\releases\0.0.0.162\deploy\League of Legends.exe
=== C: other files ==
2013-05-03 15:42:25	EA2D1947560B00165E669C29D19E726B	30159	----a-w-	C:\Users\Feeluck\AppData\Local\Temp\lol_beta_riotgames_comCrash_050313_174225.zip

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
icmlaeflemplmjndnaapfdbbnpncnbda - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[07.03.2013 01:29]

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
nikpibnbobmbdbheedjfogjlikpgpnhp - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx[12.12.2012 19:51]

YouTube - Feeluck - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Last updated at time on date - Feeluck - Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Google Search - Feeluck - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
AdBlock - Feeluck - Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Stealthy - Feeluck - Default\Extensions\ieaebnkibonmpbhdaanjkmedikadnoje
Gmail - Feeluck - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Google Drive - Feeluck - Sicherungsstandard\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Feeluck - Sicherungsstandard\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Last updated at time on date - Feeluck - Sicherungsstandard\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Google Search - Feeluck - Sicherungsstandard\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
AdBlock - Feeluck - Sicherungsstandard\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Stealthy - Feeluck - Sicherungsstandard\Extensions\ieaebnkibonmpbhdaanjkmedikadnoje
Gmail - Feeluck - Sicherungsstandard\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.qvo6.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD20EURS-63S48Y0_WD-WCAZAA98094880948&ts=1367838677"
"Default_Page_URL"="hxxp://www.qvo6.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD20EURS-63S48Y0_WD-WCAZAA98094880948&ts=1367838677"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="hxxp://www.qvo6.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD20EURS-63S48Y0_WD-WCAZAA98094880948&ts=1367838677"
"Start Page"="hxxp://www.qvo6.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD20EURS-63S48Y0_WD-WCAZAA98094880948&ts=1367838677"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="hxxp://www.qvo6.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD20EURS-63S48Y0_WD-WCAZAA98094880948&ts=1367838677"
"Start Page"="hxxp://www.qvo6.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD20EURS-63S48Y0_WD-WCAZAA98094880948&ts=1367838677"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{04B4D22D-9745-486d-8A91-D9EF43FDC614} Yahoo  Url="hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH"
{1C93BC1D-D7B7-4ca1-BF21-67DB376CA421} Google  Url="hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== shortcuts on Users Desktops ======================

C:\Users\Feeluck\Desktop\miranda32 - Verknüpfung.lnk -  
C:\Users\Feeluck\Desktop\Shutdown Timer.lnk - C:\Windows\Installer\{0B1BBEE3-C10D-44BE-A6BE-EEC867315F87}\Shutdown_Timer.exe_1679CE734515425E8E8CCB32956A82D7.exe 

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe 
C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe 
C:\Users\Public\Desktop\Path of Exile.lnk - D:\Path of Exile\Client.exe 

==== shortcuts in Users Start Menu ======================

C:\Users\Feeluck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=wld&from=wld&uid=WDCXWD20EURS-63S48Y0_WD-WCAZAA98094880948&ts=1366591343

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast Free Antivirus.lnk -  
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=wld&from=wld&uid=WDCXWD20EURS-63S48Y0_WD-WCAZAA98094880948&ts=1366591343
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grinding Gear Games\Path of Exile.lnk - D:\Path of Exile\Client.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sinvise Systems\Shutdown Timer\Check for Updates.lnk - C:\Windows\Installer\{0B1BBEE3-C10D-44BE-A6BE-EEC867315F87}\Updater.exe_E20B2B5FC4F041B78CF7696254CCF80B.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sinvise Systems\Shutdown Timer\Shutdown Timer.lnk - C:\Windows\Installer\{0B1BBEE3-C10D-44BE-A6BE-EEC867315F87}\Shutdown_Timer.exe_1679CE734515425E8E8CCB32956A82D7.exe 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sinvise Systems\Shutdown Timer\Uninstall Shutdown Timer.lnk - C:\Windows\SysWOW64\msiexec.exe /x {0B1BBEE3-C10D-44BE-A6BE-EEC867315F87}

==== shortcuts in Quick Launch ======================

C:\Users\Feeluck\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
C:\Users\Feeluck\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD20EURS-63S48Y0_WD-WCAZAA98094880948&ts=1367838677
C:\Users\Feeluck\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Miranda IM.lnk - D:\Zeug\miranda\miranda32.exe 
C:\Users\Feeluck\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Shutdown Timer.lnk - C:\Windows\Installer\{0B1BBEE3-C10D-44BE-A6BE-EEC867315F87}\Shutdown_Timer.exe_1679CE734515425E8E8CCB32956A82D7.exe 

==== shortcuts After Repair ======================

C:\Users\Feeluck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
C:\Users\Feeluck\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Feeluck\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Feeluck\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Feeluck\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Feeluck\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\users\Feeluck\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\users\Feeluck\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Cache emptied successfully
C:\users\Feeluck\AppData\Local\Google\Chrome\User Data\Sicherungsstandard\Application Cache\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

After Reboot

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Feeluck\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Feeluck\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
         
schonmal danke for all help incoming!

 

Themen zu das böse qvo6
appdata, avast, check, download, enigma, explorer, firefox, free, google, iexplore.exe, installation, internet, internet explorer, java, launch, league of legends, malwarebytes, msiexec.exe, problem, recycle.bin, registry, scan, shutdown, software, start, system, system32, temp, windows, yahoo




Ähnliche Themen: das böse qvo6


  1. Der Böse V9-Virus ist weg
    Lob, Kritik und Wünsche - 02.09.2015 (0)
  2. Seitenladefehler / böse Trojanen
    Log-Analyse und Auswertung - 05.12.2008 (0)
  3. Der böse Trojaner TR/Vundo.Gen
    Mülltonne - 17.07.2008 (2)
  4. www. EDIT: böse Seite .com
    Überwachung, Datenschutz und Spam - 09.03.2008 (5)
  5. böse seiten
    Mülltonne - 23.07.2007 (1)
  6. Logfile - böse :@
    Log-Analyse und Auswertung - 05.06.2007 (14)
  7. Böse oder nicht Böse?!
    Plagegeister aller Art und deren Bekämpfung - 25.05.2007 (1)
  8. alg32.exe ... böse?
    Log-Analyse und Auswertung - 20.02.2007 (14)
  9. Böse Sache
    Log-Analyse und Auswertung - 29.11.2006 (3)
  10. 5 böse Prozesse
    Log-Analyse und Auswertung - 03.10.2006 (4)
  11. JavaScript - gut oder böse?
    Diskussionsforum - 15.09.2006 (3)
  12. Böse Kekse?
    Diskussionsforum - 01.09.2006 (1)
  13. event. böse?
    Log-Analyse und Auswertung - 11.02.2006 (4)
  14. Eventuell Böse ????
    Log-Analyse und Auswertung - 09.06.2005 (3)
  15. Böse fallen?
    Log-Analyse und Auswertung - 17.04.2005 (2)
  16. böse sachen
    Log-Analyse und Auswertung - 01.04.2005 (19)

Zum Thema das böse qvo6 - hallo! leider konnte ich in einem anderen thread keine antwort erstellen, habe das gleiche problem wie hier: http://www.trojaner-board.de/134387-qvo6-problem.html einen zoek scan habe ich auch schon gemacht: Code: Alles auswählen Aufklappen - das böse qvo6...
Archiv
Du betrachtest: das böse qvo6 auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.