Joang ho Hlahloba Lits'oaelo tsa HijackThis

Ho hlalosetsa Ditaba tsa Lefapha ho thusa Tlosa Spyware le Bahlaseli ba Sebapali

HijackTo ke sesebelisoa sa mahala sa Trend Micro. E qalile ho etsoa ke Merijn Bellekom, seithuti sa The Netherlands. Spyware ho tlosa software e kang Adaware kapa Spybot S & D e etsa mosebetsi o motle oa ho lemoha le ho tlosa mananeo a mangata a li-spyware, empa lisebelisoa tse ling tsa spyware le libapali tsa sebapali li na le bolotsana haholo bakeng sa lits'ebeletso tsena tse ngata tse khahlanong le spyware.

HijackThisse e ngotsoe ka ho khetheha ho lemoha le ho tlosa li-hijacks tsa sebadi, kapa software e nkang mochini oa hau oa marang-rang, e fetola leqephe la hau la lehae la lehae le mochine oa ho batla le lintho tse ling tse kotsi. Ho fapana le mananeo a tloaelehileng a khahlanong le li-spyware, HijackThis ha e sebelise lipontšo kapa e lebisa mananeo a itseng kapa URL ea ho e bona le ho e thibela. Ho e-na le hoo, HijackThis e sheba maqheka le mekhoa e sebelisoang ke malware bakeng sa ho tšoaetsa tsamaiso ea hau le ho tsamaisa sebapali sa hau.

Hase ntho e 'ngoe le e' ngoe e hlahang ho HijackTo lifate ke lintho tse mpe 'me ha lia lokela ho tlosoa kaofela. Ha e le hantle, ho fapana le hoo. Ho batla ho tiiselitsoe hore tse ling tsa lits'ebeletso tsa HijackLo lifate tsena e tla ba software e amohelehang 'me ho tlosa lintho tsena ho ka senya tsamaiso ea hau kapa ho etsa hore e se ke ea sebetsoa ka ho feletseng. Ho sebelisa HijackTo ho tšoana le ho fetola Registry ea Windows u le mong. Hase setseete sa rocket, empa ha ho hlokahale hore u se etse ntle le tataiso ea litsebi ntle leha u tseba hantle seo u se etsang.

Hang ha o kenya HijackThis ebe oe qeta ho hlahisa fensetere ea log, ho na le liforomo tse ngata le libaka tseo u ka li romellang kapa ho li romella dintlha tsa hau. Litsebi tse tsebang hore na u li batle li ka u thusa ho hlahloba lintlha tsa boitsebiso le ho u eletsa hore na ke lintho life tse lokelang ho tlosoa le hore na ke life tse lokelang ho tloha u le mong.

Ho lata phetolelo ea hona joale ea HijackThis, o ka etela sebaka sa molao se Trend Micro.

Mona tlhaloso e kholo ea HijackTlhaloso ena ea lintlha eo u ka e sebelisang ho phunya tlhahisoleseding eo u e batlang:

R0, R1, R2, R3 - IE Qala le ho Batla maqephe

Seo se shebahalang ka sona:
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Ntlha e kholo, Qala ho = http://www.google.com/
R1 - HKLM \ Software \ Microsoft \ InternetExplorer \ Main, Default_Page_URL = http://www.google.com/
R2 - (mofuta ona ha o sebelisoe ke HijackThis leha ho le joalo)
R3 - Default URLSearchHook e haelloa

Se o lokelang ho se etsa:
Haeba u hlokomela URL qetellong e le leqephe la hau la lehae kapa enjene ea ho batla, ho lokile. Haeba u sa e hlahlobe, e hlahlobe 'me u be le HijackTo e lokisa. Bakeng sa lintho tse R3, kamehla li lokisa ntle leha li bua ka lenaneo leo u le tsebang, joaloka Copernic.

F0, F1, F2, F3 - Ho jarisa liforomo ho tloha ho lifaele tsa INI

Seo se shebahalang ka sona:
F0 - system.ini: Shell = Explorer.exe Openme.exe
F1 - win.ini: run = hpfsched

Se o lokelang ho se etsa:
Lintho tse F0 li lula li le mpe, kahoo li lokisa. Lintho tse F1 hangata li mananeo a khale a sireletsehile, ka hona o lokela ho fumana lintlha tse eketsehileng ho filename ho bona hore na li ntle kapa tse mpe. Lethathamo la ho qala ho Pacman le ka thusa ka ho khetholla ntho.

N1, N2, N3, N4 - Netscape / Mozilla Qala & amp; Leqephe la ho batla

Seo se shebahalang ka sona:
N1 - Netscape 4: user_pref "browser.startup.homepage", "www.google.com"); (C: \ Program Files \ Netscape \ Users \ default \ prefs.js)
N2 - Netscape 6: user_pref ("browser.startup.homepage", "http://www.google.com"); (C: \ Documents le Melao-hloko \ Motlatsi \ Application Data \ Mozilla \ Profiles \ defaulto9t1tfl.slt \ prefs.js)
N2 - Netscape 6: user_pref ("browser.search.defaultengine", "engine: //C%3A%5CProgram%20Files%5CNetscape%206%5Csearchplugins%5CSBWeb_02.src"); (C: \ Documents le Melao-hloko \ Motlatsi \ Application Data \ Mozilla \ Profiles \ defaulto9t1tfl.slt \ prefs.js)

Se o lokelang ho se etsa:
Hangata homepage ea Netscape le Mozilla le leqephe la patlisiso li sireletsehile. Ka seoelo ba fumanoa liphofu, Lop.com feela e tsejoa ho etsa sena. Ha o lokela ho bona URL eo u sa e tsebeng e le leqephe la hau la maqephe kapa leqephe la ho batla, etsa HijackTo e lokisa.

O1 - Hostsfile ho khutlisetsoa morao

Seo se shebahalang ka sona:
O1 - Mabotho: 216.177.73.139 auto.search.msn.com
O1 - Mabotho: 216.177.73.139 search.netscape.com
O1 - Baeti: 216.177.73.139 ke baetapele
Fora ea O1 - Hosts e fumanehile ho C: \ Windows \ Help \ ea mabotho

Se o lokelang ho se etsa:
Ts'ebetso ena e tla khutlisa aterese ho ea ka tokelo ea aterese ea IP ka ho le letšehali. Haeba IP e se ea aterese, o tla khutlisetsoa sebakeng se fosahetseng nako le nako ha u kena atereseng. U ka lula u e-na le HijackThis ho lokisa tsena, ntle le haeba u tseba ho kenya melaetsa ea hau ho Hosting ea hau.

Ntho ea ho qetela ka linako tse ling e etsahala ka Windows 2000 / XP ka tšoaetso ea Coolwebsearch. Kamehla lokisa ntho ena, kapa u na le CWShredder e e lokisa ka kotloloho.

O2 - Lintho tsa Mothusi oa Mohanyetsi

Seo se shebahalang ka sona:
O2 - BHO: Yahoo! Metsoalle BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C: \ LITABA TSA MOLAO \ YAHOO! \ COMPANION \ YCOMP5_0_2_4.DLL
O2 - BHO: (ha ho lebitso) - {1A214F62-47A7-4CA3-9D00-95A3965A8B4A} - C: \ LILETSO TSA LIPOTSO TSA POPUP E MOLEMO \ AUTODISPLAY401.DLL (faele ha e lahlehe)
O2 - BHO: MediaLoads e Ntlafetse - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C: \ LITABA TSA LITABA TSA LITŠOANTŠISO TSE LOKELANG \ ME1.DLL

Se o lokelang ho se etsa:
Haeba u sa tsebise ka ho toba lebitso la Moemeli oa Mohlokomeli, sebelisa lebokose la BHO le Toolbar ea TonyK ho e fumana ka sehlopha sa boitsebiso (CLSID, nomoro pakeng tsa li-brackets) le ho bona hore na e ntle kapa e mpe. Ho Lethathamo la BHO, 'X' e bolela spyware le 'L' e bolelang bolokehileng.

Li-toolbar tsa O3-IE

Seo se shebahalang ka sona:
O3 - Toolbar: & Yahoo! Metsoalle - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C: \ LI FILETSO TSA \ YAHOO! \ COMPANION \ YCOMP5_0_2_4.DLL
O3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C: \ LI FILE LILETSO \ POPUP E MOLEMO \ PETOOLBAR401.DLL (faele ha ho hlokahale)
O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C: \ WINDOWS \ APPLICATION DATA \ CKSTPRLLNQUL.DLL

Se o lokelang ho se etsa:
Haeba u sa hlokomele ka ho toba lebitso la libetsa, sebelisa lebokose la BHO le Toolbar la TonyK ho le fumana ka sehlopha sa boitsebiso (CLSID, nomoro pakeng tsa li-brackets) le ho bona hore na e ntle kapa e mpe. Lethathamong la Toolbar, 'X' e bolela spyware le 'L' e bolelang bolokehileng. Haeba e se lethathamong mme lebitso le bonahala e le mohala o sa tloaelehang oa litlhaku 'me faele e fumaneha fensetereng ea' Data Data '(joaloka ea ho qetela mehlala e ka holimo), mohlomong Lop.com,' me u tlameha ho ba le HijackThokisa e.

O4 - Ho laola mananeo a tsoang ho Registry kapa sehlopha sa ho qala

Seo se shebahalang ka sona:
O4 - HKLM \ .. \ Matla: [ScanRegistry] C: \ WINDOWS \ scanregw.exe / autorun
O4 - HKLM \ .. \ Matla: [SystemTray] SysTray.Exe
O4 - HKLM \ .. \ Matla: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe"
O4 - Ho qala: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office \ OSA9.EXE
O4 - Ho qala ha Global: winlogon.exe

Se o lokelang ho se etsa:
Sebelisa Lethathamo la ho Qala la PacMan ho fumana lenane le ho bona hore na le molemo kapa le lebe.

Haeba ntho e bonts'a lenaneo le lutseng sehlopheng sa ho qala (joaloka ntho ea ho qetela e ka holimo), HijackThis e ke ke ea lokisa ntho eo haeba lenane lena le ntse le hopola. Sebelisa Mookameli oa Tsamaiso ea Windows (TASKMGR.EXE) ho koala ts'ebetso pele o lokisa.

O5 - IE Options ha e bonahale ho Control Panel

Seo se shebahalang ka sona:
O5 - control.ini: inetcpl.cpl = che

Se o lokelang ho se etsa:
Ntle le ha uena kapa mookameli oa hau a tseba ho pata letšoao ho tswa ho Control Panel, e-ba le HijackTo ho e lokisa.

O6 - IE Options ea ho kena e thibetsoe ke Mookameli

Seo se shebahalang ka sona:
O6 - HKCU \ Software \ Policies \ Microsoft \ Internet Explorer \ lithibelo li teng

Se o lokelang ho se etsa:
Ntle le hore u na le khetho ea S & D ea Spybot 'Lock homepage ho tloha liphetoho' e sebetsang, kapa tsamaiso ea hau ea tsamaiso e beha sena sebakeng sena, e-na le HijackThis lokisa sena.

O7 - Puso ea Regedit e thibetsoe ke Mookameli

Seo se shebahalang ka sona:
O7 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System, DisableRegedit = 1

Se o lokelang ho se etsa:
Kamehla u na le HijackThis lokisa sena, ntle le haeba tsamaiso ea hau ea tsamaiso e behile thibelo ena sebakeng sa eona.

O8 - Lintho tse eketsehileng ho IE-tobetsa konopo

Seo se shebahalang ka sona:
O8 - Ntho e eketsehileng ea menyako ea moemeli: & Google Search - res: // C: \ WINDOWS \ DOWNLOADED PROGRAM FILES \ GOOGLETOOLBAR_EN_1.1.68-DELEON.DLL / cmsearch.html
O8 - Ntho e eketsehileng ea mohlooho oa menu: Yahoo! Batla - faele: /// C: \ Program Files \ Yahoo! \ Tloaelehileng / ycsrch.htm
O8 - Ntho e eketsehileng ea menyetla ea menyetla ea ho etsa lintho: Tlanya & In-C: \ WINDOWS \ WEB \ zoomin.htm
O8 - Ntho e eketsehileng ea menyetla ea menyetla ea ho etsa lintho: Tlosa O & ut - C: \ WINDOWS \ WEB \ zoomout.htm

Se o lokelang ho se etsa:
Haeba u sa hlokomele lebitso la ntho eo ka har'a tokelo ea ho tobetsa ka ho le letona ho IE, e-ba le HijackTo e lokisa.

O9 - Li-buttons tse eketsehileng ka toolbar e kholo ea IE, kapa lisebelisoa tse ling ho IE & # 39; Lisebelisoa & # 39; menu

Seo se shebahalang ka sona:
O9 - Ntho e eketsehileng: Messenger (HKLM)
Mokhoa oa boitsebiso oa O9-Extra 'Tools': Moemeli (HKLM)
O9 - Tlhahlobo e eketsehileng: AIM (HKLM)

Se o lokelang ho se etsa:
Haeba u sa tsebe lebitso la konopo kapa ntho ea menu, etsa HijackThis ho e lokisa.

O10 - Bahlaseli ba Winsock

Seo se shebahalang ka sona:
O10 - Ho nkeloa marang-rang ea Inthanete ke New.Net
O10 - Internet access Broken ka lebaka la LSP provider 'c: \ progra ~ 1 \ common ~ 2 \ toolbar \ cnmib.dll' ho hlokahale
O10 - Faele e sa tsejoeng ho Winsock LSP: c: \ program files \ newton e tseba \ vmain.dll

Se o lokelang ho se etsa:
Ho molemo ho lokisa tsena ho sebelisa LSPFix ho Cexx.org, kapa Spybot S & D ho tloha Kolla.de.

Hlokomela hore lifaele tsa 'tse sa tsejoeng' ka lebokoseng la LSP li ke ke tsa rarolloa ke Tlhōlisano, bakeng sa litaba tsa polokeho.

O11 - Sehlopha se eketsehileng ho IE & # 39; Litsela tse tsoetseng pele & # 39; fensetere

Seo se shebahalang ka sona:
O11 - Lihlopha tsa khetho: [CommonName] CommonName

Se o lokelang ho se etsa:
Ke feela motlatlapi oa hona joale o kenyang sehlopha sa khetho ho sehlopha sa IE Advanced Options window ke CommonName. Kahoo u ka lula u e-na le HijackThis ho lokisa sena.

Ma-plugins a O12-IE

Seo se shebahalang ka sona:
O12 - Plugin bakeng sa .spop: C: \ Program Files \ Internet Explorer \ Plugins \ NPDocBox.dll
O12 - Plugin bakeng sa .PDF: C: \ Program Files \ Internet Explorer \ PLUGINS \ nppdf32.dll

Se o lokelang ho se etsa:
Boholo ba nako tsena li sireletsehile. Feela OnFlow e eketsa plugin mona eo u sa e rateng (.ofb).

O13 - IE DefaultPrefix hijack

Seo se shebahalang ka sona:
O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=
O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?
O13 - WWW. Seqeto: http://ehttp.cc/?

Se o lokelang ho se etsa:
Tsena li mpe kamehla. E-ba le HijackThis e ba lokisa.

O14 - & # 39; Hlahisa Lisebelisoa tsa Web & # 39; ho senya

Seo se shebahalang ka sona:
O14 - IERESET.INF: START_PAGE_URL = http: //www.searchalot.com

Se o lokelang ho se etsa:
Haeba URL e se mofani oa khomphuta ea hau kapa ISP ea hao, e-na le HijackTo e lokisa.

O15 - Liwebsaete tse sa batleheng sebakeng sa Tšepo

Seo se shebahalang ka sona:
O15 - Tšebeletso e Tšepahalang: http://free.aol.com
O15 - Tšebeletso e Tšepahalang: * .coolwebsearch.com
O15 - Tšebeletso e Tšepahalang: * .msn.com

Se o lokelang ho se etsa:
Boholo ba nako feela AOL le Coolwebsearch feela ba kenya marang-rang ho Zone e Tšepahalang. Haeba o sa ka oa eketsa sebaka se thathamisitsoeng sebakeng sa hau sa Trusted Zone, e-ba le HijackThis ho e lokisa.

O16 - ActiveX Objects (aka e fetisitsoeng Lenaneong la Files)

Seo se shebahalang ka sona:
O16 - DPF: Yahoo! Puisano - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Se o lokelang ho se etsa:
Haeba u sa tsebe lebitso la ntho, kapa URL e lokolloa ho eona, e-na le HijackThis e lokisa eona. Haeba lebitso kapa URL e na le mantsoe a kang 'dialer', 'casino', 'free_plugin' joalo-joalo, ka sebele e lokisa. SpywareBlaster ea Javacool e na le database e kholo ea lintho tse kotsi tsa ActiveX tse ka sebelisoang ho sheba litlhoko tsa CLSID. (Tlanya ka ho le letona lethathamong ho sebelisa mosebetsi oa Find.)

O17-domain Lop.com e hijacks

Seo se shebahalang ka sona:
O17 - HKLM \ System \ CCS \ Services \ VxD \ MSTCP: Domain = aoldsl.net
O17 - HKLM \ System \ CCS \ Services \ Tcpip \ Parameters: Domain = W21944.find-quick.com
O17 - HKLM \ Software \ .. \ Telephony: DomainName = W21944.find-quick.com
O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ {D196AB38-4D1F-45C1-9108-46D367F19F7E}: Domain = W21944.find-quick.com
O17 - HKLM \ System \ CS1 \ Litšebeletso \ Tcpip \ Parameters: SearchList = gla.ac.uk
O17 - HKLM \ System \ CS1 \ Litšebeletso \ VxD \ MSTCP: NameServer = 69.57.146.14,69.57.147.175

Se o lokelang ho se etsa:
Haeba domain ena e sa tsoa ho ISP ea hau kapa inthanete ea khampani, e-ba le HijackThis e lokisa eona. E tšoanang le eona e ea ho kena ka 'SearchList'. Bakeng sa 'NameServer' ( DNS server ) ho kenya, Google bakeng sa IP kapa IPs 'me ho tla ba bonolo ho bona hore na li ntle kapa tse mpe.

O18 - Litsamaiso tse eketsehileng tsa bapalami ba lits'ebetso

Seo se shebahalang ka sona:
O18 - Prothaneteng: relatedlinks - {5AB65DD4-01FB-44D5-9537-3767AB80F790} - C: \ PROGRA ~ 1 \ COMMON ~ 1 \ MSIETS \ msielink.dll
O18 - Prothaneteng: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82}
O18 - Pokello ea Protokoto: http - {66993893-61B8-47DC-B10D-21E0C86DD9C8}

Se o lokelang ho se etsa:
Ke baphonyohi ba 'maloa feela ba bonang mona. Baddies tse tsejoang ke 'cn' (CommonName), 'ayb' (Lop.com) le 'relatedlinks' (Huntbar), o lokela ho ba le HijackThis lokisa tsena. Lintho tse ling tse hlahang ha lia netefatsoa leha ho le joalo, kapa li nkoa ka mahahapa (ke hore CLSID e fetotsoe) ke spyware. Ketsahalong ea ho qetela, e-na le HijackThis ho e lokisa.

O19 - Phofu ea mosebetsing oa lesela

Seo se shebahalang ka sona:
O19 - Letlapa la mokhoa oa basebelisi: c: \ WINDOWS \ Java \ my.css

Se o lokelang ho se etsa:
Tabeng ea ho fokotseha ha sebapali le popups khafetsa, e-na le HijackThis e lokisa ntho ena haeba e bonts'a lebokoseng. Leha ho le joalo, kaha feela Coolwebsearch e etsa sena, ho molemo ho sebelisa CWShredder ho e lokisa.

O20 - AppInit_DLLs Registry value authoriun

Seo se shebahalang ka sona:
O20 - AppInit_DLLs: msconfd.dll

Se o lokelang ho se etsa:
Tekanyo ena ea Registry e fumanehang ho HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Windows e jara DLL mohopolong ha motho a se a kena, ka mor'a moo e lula e le moemori ho fihlela logoff. Mananeo a seng makae a utloahalang a a sebelisa (Norton CleanSweep e sebelisa APITRAP.DLL), hangata e sebelisoa ke batho ba trojans kapa bahlaseluoa ba bohale ba sebapali.

Haeba ho na le DLL e 'patiloeng' e tsoang ho tswa ho 'Ona ea boitsebiso (e bonahalang feela ha u sebelisa' Hlahisa Binary Data 'kgetho ka Regedit) lebitso la dll le ka' na la etsoa pele ka pipe '|' ho e etsa hore e bonahale ka lebokoseng.

O21 - ShellServiceObjectDelayLoad

Seo se shebahalang ka sona:
O21 - SSODL - AUHOOK - {11566B38-955B-4549-930F-7B7482668782} - C: \ WINDOWS \ System \ auhook.dll

Se o lokelang ho se etsa:
Ena ke mokhoa o se nang litokomane oa autorun, oo ka tloaelo o sebelisitsoeng ke mekhoa e seng mekae ea Windows ea lisebelisoa. Lintho tse thathamisitsoeng ho HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ ShellServiceObjectDelayLoad li laetsoe ke Explorer ha Windows e qala. TlhōlisanoTšebeliso ena e sebelisa sehlabelo sa lintho tse ngata tse tloaelehileng tsa SSODL, kahoo neng kapa neng ha ntho e bonts'oa ka lebokoseng e sa tsejoe ebile e ka 'na ea e-ba kotsi. Tšoara ka tlhokomelo e feteletseng.

O22 - SharedTaskScheduler

Seo se shebahalang ka sona:
O22 - SharedTaskScheduler: (ha ho lebitso) - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} - c: \ windows \ system32 \ mtwirl32.dll

Se o lokelang ho se etsa:
Ena ke autorun e sa ngolisoang ka molao ea Windows NT / 2000 / XP feela, e sebelisoang haholo ka seoelo. Ho fihlela joale CWS.Smartfinder feela e e sebelisa. Tšoara ka tlhokomelo.

Litšebeletso tsa O23 - NT

Seo se shebahalang ka sona:
O23 - Tšebeletso: Kerio Personal Firewall (PersFw) - Kerio Technologies - C: \ Program Files \ Kerio \ Personal Firewall \ persfw.exe

Se o lokelang ho se etsa:
Ena ke lenane la litšebeletso tse seng tsa Microsoft. Lethathamo le lokela ho tšoana le seo u se bonang ts'ebetsong ea Msconfig ea Windows XP. Bahlaseluoa ba bangata ba li-trojan ba sebelisa tšebeletso ea maiketsetso ka tumello ho lihlopha tse ling tsa ho qala ho ipeha bocha. Lebitso le lengata le atisa ho lekana-ho lla, joaloka 'Network Security Service', 'Workstation Logon Service' kapa 'Call Remote Call Helper', empa lebitso la kahare (pakeng tsa li-brackets) ke mohala oa litšila, joaloka 'Ort'. Karolo ea bobeli ea mohala ke mong'a fisi qetellong, joalokaha ho bonahala liphatsong tsa faele.

Hlokomela hore ho lokisa ntho ea O23 ho tla emisa tšebeletso feela ebe e e thibela. Tšebeletso e lokela ho tlosoa ho Registry ka letsoho kapa ka sesebelisoa se seng. Ketsong ena 1.99.1 kapa holimo, konopo 'Delete NT Service' karolong ea Misc Tools e ka sebelisoa bakeng sa sena.