Virus.win32.nsag.a ?????

kk'un connais t'il ce virus, mon antivirus me la detecter ce matin pas moyen de desinfecter et j'ai fait des recherche sur google pour trouver un outil de desinfection il y a rien du tout!!!

il c loger sur le dosier wininet.dll....

Si qq un a des info sur ce virus merci de m'en faire part

61 réponses

Résumé de la discussion

Une infection autour de wininet.dll est détectée par l'antivirus, rendant la désinfection difficile et confrontant l'utilisateur à des solutions potentielles sans outil clair. Des conseils évoquent de désactiver la restauration système et d'essayer de copier ou remplacer wininet.dll malgré l'erreur 'ressource utilisée', certains signalant des variantes de nom du fichier. D'autres préconisent des analyses en ligne (Kaspersky, Panda) et l'examen d'éléments suspects via des outils comme HijackThis, puis la désactivation de services indésirables et vérification des tâches. En parallèle, l'utilisation d'un CD d'installation Windows et d'outils de sauvegarde peut faciliter le démarrage en mode sans échec et l'analyse hors ligne sans impact sur le système actif.

Bobot (l’IA à votre service)
  1. bonjour tout le monde , je suis egalement infecté par ce trojan, je pense que je lai eu en me baladant sur astalavista.
    Estce que vous penser que ce soie possible de virer la dll, en connectant le disque dur en slave sur un autre ordinateur. Je pense que oui mais j'ose pas trop le faire car j'ai peur que du coup l'autre ordi soit infecté,ce qui m'embeterai bcp.
    1. salut,

      la verif que moe ma demander de faire me cause pb parce que la verif me dit que c pas le bon cd de windows ( du moins pour les fichier dans dllcache) en effet j'ai formater y a quelque temps et changer de windows ( xp familial a xp gold)....

      donc je pense serieusement au formatage je m'y prepare ce soir.

      Merci enormement de votre aide vous avez ete genial

      je recommande votre forum !!!!

      A+ Melo
      1. ok j'essai ca je te remercie

        j'ai trouver ca sur le site de kaspersky... peut etre ca peut aider ( ce n'etais pas la hier)

        Virus.Win32.Nsag.a
        Aliases
        Virus.Win32.Nsag.a (Kaspersky Lab) is also known as: Trojan.DownLoader.2636 (Doctor Web), W32/Nsag.A (H+BEDV), W32/OleADM.A (Panda), Win32/Oleloa.A (Eset) Detection added Jun 07 2005
        Behavior Virus

        Currently there is no description available for this program.

        As many viruses and worms are modifications of earlier versions, it may help you to check the descriptions of similar programs. If such descriptions are available, they will be listed at the top of the page.

        Our virus analysts work hard to ensure that descriptions of the commonest and most potentially dangerous software are available to users. The Virus Encyclopedia is updated on a regular basis.

        je doit filer donc je repasse en fin d'aprem

        merci

        a+
        1. ok
          si tu as ton cd d'xp, essaye d'utiliser la commande qui permet de vérifier l'intégrité des fichiers windows:

          désactive la restauration systeme

          Insére le CD-ROM de Windows XP dans le lecteur tout en maintenant la touche Maj appuyée afin d'éviter son exécution automatique

          Par Démarrer/Exécuter, saisir la commande sfc /scannow (faire un espace entre sfc et le /).

          je repasse se soir

          a+
          1. hier dans la journee j'ai envoyer ce post:

            < 18 > - virus.win32.nsag.a ?????
            Ajouté par melo (09/06/2005 à 16:29 GMT+2)
            je viens d'aller sur http://virusscan.jotti.org/ pour y analyser la dll infecter ( wininet.dll dans le sys32)

            les resultats:

            File: wininet.dll
            Status: INFECTED/MALWARE
            MD5 d7fadaacf1b819b477756bb2802c0e53
            Packers detected: -
            Scanner results
            AntiVir Found nothing
            ArcaVir Found nothing
            Avast Found nothing
            AVG Antivirus Found nothing
            BitDefender Found nothing
            ClamAV Found nothing
            Dr.Web Found Trojan.DownLoader.2636
            F-Prot Antivirus Found nothing
            Fortinet Found Nsag.A
            Kaspersky Anti-Virus Found Virus.Win32.Nsag.a
            NOD32 Found Win32/Oleloa.A
            Norman Virus Control Found nothing
            VBA32 Found nothing

            je suis aller sur le site de dr;web et sur celui de kaspersky ce matin et les deux on donner les mm resultats
            1. voila ca va pas mieux lol il ma changer le nom du virus: Ẵz||Ẵ{||Ã│||Ã}|Ã~||ÃΑË|r)‹|||{ǘ| alors la c le comble mdr

              a+
              1. je crois que c'est un reste de lop.com (messenger plus 3 installé avec sponsor).

                Pour melo: est ce que tu as ton cd d'xp ?
                1. Contributeur
                  non je pensais à celui là

                  O4 - HKLM\..\Run: [bend phone great ford] C:\Documents and Settings\All Users\Application Data\flapboldbendphone\mixsetup.exe

                  mai sfausse route
                  1. re salut jean et moe,

                    j'ai suprimer le service demander j'ai verifier si j'avais haxdrv.sys et non j'ai pas, voila...

                    toute vos idee sont genial et bien sur si vous en avez d'autre je suis preneuse, mais la je commence serieusement a me dire que formater serais peut etre la meilleur solutions...

                    franchement merci enormement de votre aide

                    a+
                    1. salut jean

                      de quel prog ? celui du post 47 ?

                      sinon, C:\WINDOWS\system32\pctspk.exe, je crois que c'est un outil de diagnostics pour modem.

                      a+
                      1. Contributeur
                        salut Moe,

                        dis moi ce service
                        O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

                        n'est pas en relation avec le prog que tu lui as fait supprimer plus haut??

                        amities
                        Jean
                        1. salut,

                          oui oui je suis la je fesais les manip que tu m'avais demander ( j'ai fait en sans echec) et malheureusement tjr rien .....

                          j'essai de faire la manip de moe et je reviens
                          voila le log:

                          Logfile of HijackThis v1.99.1
                          Scan saved at 12:42:03, on 14/05/2005
                          Platform: Windows XP SP1 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\ISS\BlackICE\blackd.exe
                          C:\WINDOWS\System32\mnmsrvc.exe
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\WINDOWS\System32\rundll32.exe
                          C:\WINDOWS\system32\pctspk.exe
                          C:\Program Files\ISS\BlackICE\rapapp.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\RUNDLL32.EXE
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\WINDOWS\System32\ctfmon.exe
                          C:\Program Files\MSN Messenger\msnmsgr.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\Program Files\ISS\BlackICE\blackice.exe
                          C:\Program Files\AntiViral Toolkit Pro\avpm.exe
                          C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Documents and Settings\melotoinou\Bureau\hijackthis\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
                          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_5_7_0.dll
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_5_7_0.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                          O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                          O4 - Global Startup: BlackICE Utilitaire .lnk = ?
                          O4 - Global Startup: AVP Monitor.lnk = C:\Program Files\AntiViral Toolkit Pro\avpm.exe
                          O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
                          O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
                          O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
                          O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr
                          O16 - DPF: Interface Chat Voila - http://chat9.x-echo.com/version5/Applet/vchatsign.cab
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
                          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
                          O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                          O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\blackd.exe
                          O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
                          O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\rapapp.exe
                          O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
                          1. salut melo, jean

                            on dirait les restes d'un ver...

                            tu peux carrement supprimer le service:
                            lance hijackthis > open the misc tools section > delete an NT service
                            dans la boite de dialogue, tape winmdgr et valide

                            vérifie et dis nous si ce fichier existe: haxdrv.sys

                            a+
                            1. Contributeur
                              Salut melo,

                              je viens de reprendre ton log et je trouve un truc etrange.

                              alors voilà fix dans hijack la ligne:

                              O23 - Service: Microsoft Service Manager (winmdgr) - Unknown owner - C:\WINDOWS\winsvcmgr.exe (file missing)

                              ensuite,

                              Dans le menu Demarrer>Executer >tape: Services.msc
                              recherche le service avec cette orthographe exacte:
                              Microsoft Service Manager
                              Double clic dessus (winsvcmgr.exe) et clic sur arreter puis dans type de demarrage selectionne désactivé

                              refait tes analyses

                              Jean
                              1. salut

                                ce matin j'ai essayer de fermer tout les processus actif qui utilisais la dll( en mode sans echec ) le seul qui bloque c EXPLORER.EXE, qd je veut le fermer toute les fenetre se ferme ( ce qui est normal apparemment a moins que je me trompe!!) tous ca dans le but d'effacer la dll pourri pour la remplacer par une saine!!

                                Ensuite j'ai reesayer, apres une mise a jour de mon AV, de refaire un desinsfection( tjr en mode sans echec). Donc il desinfecte la dll et me dit qui doit rebooter pour terminer la desinfection, je le fais rebouter en mode sans echec rien, le virus est tjr la, je le fait rebooter en mode normal rien non plus...

                                merci de votre aide

                                A+
                                1. a priori mon AV n'est pas activer en mode sans echec ( je suis aussi aller voir dans le gestionnaire des tache il n'y est pas) j'essai en mode normal et j'arete pour ce soir, merci bcp

                                  a+

                                  voila le log suite au manip que j'ai fait:

                                  Logfile of HijackThis v1.99.1
                                  Scan saved at 23:17:28, on 13/05/2005
                                  Platform: Windows XP SP1 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\WINDOWS\System32\RUNDLL32.EXE
                                  C:\Program Files\iTunes\iTunesHelper.exe
                                  C:\WINDOWS\System32\ctfmon.exe
                                  C:\Program Files\MSN Messenger\msnmsgr.exe
                                  C:\Program Files\ISS\BlackICE\blackice.exe
                                  C:\Program Files\AntiViral Toolkit Pro\avpm.exe
                                  C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
                                  C:\Program Files\ISS\BlackICE\blackd.exe
                                  C:\WINDOWS\System32\mnmsrvc.exe
                                  C:\WINDOWS\System32\nvsvc32.exe
                                  C:\WINDOWS\System32\rundll32.exe
                                  C:\WINDOWS\system32\pctspk.exe
                                  C:\Program Files\ISS\BlackICE\rapapp.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\iPod\bin\iPodService.exe
                                  C:\Documents and Settings\melotoinou\Bureau\hijackthis\HijackThis.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_5_7_0.dll
                                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_5_7_0.dll
                                  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                  O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\System32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0
                                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                                  O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
                                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                  O4 - Global Startup: BlackICE Utilitaire .lnk = ?
                                  O4 - Global Startup: AVP Monitor.lnk = C:\Program Files\AntiViral Toolkit Pro\avpm.exe
                                  O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
                                  O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
                                  O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
                                  O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr
                                  O16 - DPF: Interface Chat Voila - http://chat9.x-echo.com/version5/Applet/vchatsign.cab
                                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
                                  O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
                                  O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                                  O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\blackd.exe
                                  O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                  O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
                                  O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\BlackICE\rapapp.exe
                                  O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
                                  O23 - Service: Microsoft Service Manager (winmdgr) - Unknown owner - C:\WINDOWS\winsvcmgr.exe (file missing)
                                  • 1
                                  • 2
                                  • 3
                                  • 4