1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Highjack Log

Discussion in 'Security and Privacy' started by luke74, 2004/05/14.

Thread Status:
Not open for further replies.
  1. 2004/05/14
    luke74

    luke74 Inactive Thread Starter

    Joined:
    2004/05/14
    Messages:
    5
    Likes Received:
    0
    Can someone in the know check my highjack this log to see if there is any unusual entries please?

    Logfile of HijackThis v1.97.7
    Scan saved at 20.39.41, on 14/05/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
    C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Programmi\Logitech\iTouch\iTouch.exe
    C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    C:\WINDOWS\System32\GSICON.EXE
    C:\WINDOWS\System32\dslagent.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Programmi\TechniSat DVB\bin\Server4PC.exe
    C:\WINDOWS\System32\f0r0r\dirote.exe
    C:\Programmi\Logitech\iTouch\kbdtray.exe
    C:\WINDOWS\System32\f0r0r\ppi.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
    C:\WINDOWS\System32\E_S00RP2.EXE
    C:\Programmi\Norton SystemWorks\Norton Antivirus\navapsvc.exe
    C:\PROGRA~1\NORTON~3\NORTON~2\NPROTECT.EXE
    C:\Programmi\Norton SystemWorks\Norton Antivirus\SAVScan.exe
    C:\PROGRA~1\NORTON~3\NORTON~2\SPEEDD~1\NOPDB.EXE
    C:\WINDOWS\System32\svchost.exe
    E:\Shared\Software\Antivirus\HijackThis.exe
    C:\Programmi\Internet Explorer\iexplore.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.it/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {00041A26-7033-432C-94C7-6371DE343822} - (no file)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmi\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [AtiPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programmi\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
    O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [EPSON Stylus C62 Series (Copia 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC 2.EXE /P33 "EPSON Stylus C62 Series (Copia 1)" /O6 "USB001" /M "Stylus C62 "
    O4 - HKLM\..\Run: [rn4d] C:\WINDOWS\System32\f0r0r\kolder.exe C:\WINDOWS\System32\f0r0r\dirote.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Programmi\Microsoft Money\System\mnyexpr.exe "
    O4 - Global Startup: Server4PC.lnk = C:\Programmi\TechniSat DVB\bin\Server4PC.exe
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Ricerche (HKLM)
    O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downl...0367/wmavax.CAB
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/...director/sw.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downl...922/wmv9VCM.CAB
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeu...ontent/opuc.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.c...8080.0415162037
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/...ash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A1C14150-1DA9-490A-AB40-A30F5901C9FB}: NameServer = 81.74.225.227 151.99.125.1
     
  2. 2004/05/14
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Thanks! Scan again and place a check next to these entries. Close all other windows and fix.

    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {00041A26-7033-432C-94C7-6371DE343822} - (no file)
    O4 - HKLM\..\Run: [rn4d] C:\WINDOWS\System32\f0r0r\kolder.exe C:\WINDOWS\System32\f0r0r\dirote.exe


    End task on these processes.

    dirote.exe
    ppi.exe
    And kolder.exe if there. Then navigate to C:\WINDOWS\System32 and delete the folder f0r0r. It is probably hidden so you will need to show hidden and system files. If necessary, delete from safe mode. Disable system restore. Empty ALL temp folders (C:\Windows\Temp, C:\Documents and Settings\(all)usernames\local settings\temp & temporary internet files). Open C:\Windows\Prefetch, select all and delete. Finally, empty the recycle bin and reboot.

    Suggest you scan with RAV and Housecall.

    Then post another log.
     

  3. to hide this advert.

  4. 2004/05/15
    luke74

    luke74 Inactive Thread Starter

    Joined:
    2004/05/14
    Messages:
    5
    Likes Received:
    0
    Thanks for the reply!
    I didn't find the folder f0r0r.

    Logfile of HijackThis v1.97.7
    Scan saved at 10.06.22, on 15/05/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmi\File comuni\Symantec Shared\ccSetMgr.exe
    C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Programmi\Logitech\iTouch\iTouch.exe
    C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    C:\WINDOWS\System32\GSICON.EXE
    C:\WINDOWS\System32\dslagent.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\Programmi\Logitech\iTouch\kbdtray.exe
    C:\Programmi\File comuni\EPSON\EBAPI\SAgent2.exe
    C:\Programmi\TechniSat DVB\bin\Server4PC.exe
    C:\WINDOWS\System32\E_S00RP2.EXE
    C:\Programmi\Norton SystemWorks\Norton Antivirus\navapsvc.exe
    C:\PROGRA~1\NORTON~3\NORTON~2\NPROTECT.EXE
    C:\Programmi\Norton SystemWorks\Norton Antivirus\SAVScan.exe
    C:\PROGRA~1\NORTON~3\NORTON~2\SPEEDD~1\NOPDB.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    E:\Shared\Software\Antivirus\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.it/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmi\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [AtiPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programmi\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
    O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [EPSON Stylus C62 Series (Copia 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P33 "EPSON Stylus C62 Series (Copia 1)" /O6 "USB001" /M "Stylus C62 "
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Programmi\Microsoft Money\System\mnyexpr.exe "
    O4 - Global Startup: Server4PC.lnk = C:\Programmi\TechniSat DVB\bin\Server4PC.exe
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Ricerche (HKLM)
    O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB
    O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...apple.com/sikes/it/win/QuickTimeInstaller.exe
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38080.0415162037
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
     
  5. 2004/05/15
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Looks good, but I would like to do more since you are unable to find the folder. Please install Process Explorer, reboot and do some normal activities....surfing, word processing, listen to music, whatever. Then open Process Explorer, click file>save. Open the saved text file and copy/paste it here.

    I see you Scanned with Housecall.....please scan with RAV too.
     
  6. 2004/05/15
    luke74

    luke74 Inactive Thread Starter

    Joined:
    2004/05/14
    Messages:
    5
    Likes Received:
    0
    I've found Worm.bagle.gen-1 with House call.

    Then I've saved process explorer's report:

    Process PID CPU Description Company Name
    System Idle Process 0 97
    Interrupts n/a Hardware Interrupts
    DPCs n/a Deferred Procedure Calls
    System 4
    smss.exe 792 Windows NT Session Manager Microsoft Corporation
    csrss.exe 912 Client Server Runtime Process Microsoft Corporation
    winlogon.exe 944 Applicazione Accesso a Windows NT Microsoft Corporation
    services.exe 988 Applicazione Servizi e Controller Microsoft Corporation
    svchost.exe 1168 Generic Host Process for Win32 Services Microsoft Corporation
    msmsgs.exe 3476 Messenger Microsoft Corporation
    svchost.exe 1320 Generic Host Process for Win32 Services Microsoft Corporation
    svchost.exe 1488 Generic Host Process for Win32 Services Microsoft Corporation
    svchost.exe 1564 Generic Host Process for Win32 Services Microsoft Corporation
    ccSetMgr.exe 1936 Common Client Settings Manager Service Symantec Corporation
    ccEvtMgr.exe 1996 Common Client Event Manager Service Symantec Corporation
    spoolsv.exe 216 Spooler SubSystem App Microsoft Corporation
    alg.exe 1280 Application Layer Gateway Service Microsoft Corporation
    ati2evxx.exe 1296
    SAgent2.exe 1476 EPSON Printer Status Agent SEIKO EPSON CORPORATION
    E_S00RP2.EXE 1536 EPSON Status Monitor 3 SEIKO EPSON CORPORATION
    NAVAPSVC.EXE 420 Norton AntiVirus Auto-Protect Service Symantec Corporation
    NPROTECT.EXE 712 Norton Protection Status Symantec Corporation
    SAVSCAN.EXE 1648 Symantec AntiVirus Scanner Symantec Corporation
    NOPDB.exe 1980 NOPDB Symantec Corporation
    svchost.exe 488 Generic Host Process for Win32 Services Microsoft Corporation
    lsass.exe 1000 LSA Shell (Export Version) Microsoft Corporation
    explorer.exe 3968 Esplora risorse Microsoft Corporation
    atiptaxx.exe 508 ATI Desktop Control Panel ATI Technologies, Inc.
    iTouch.exe 516 iTouch Application Logitech Inc.
    KbdTray.exe 616
    EM_EXEC.EXE 524 Control Center Logitech Inc.
    gsicon.exe 532 DSL Modem Monitor GlobeSpan, Inc.
    dslagent.exe 540
    SOUNDMAN.EXE 548 Realtek Sound Manager Realtek Semiconductor Corp.
    ccApp.exe 588 Symantec Common Client User Session Symantec Corporation
    Server4PC.exe 664 Server4PC B2C2, Inc.
    procexp.exe 1640 3 Sysinternals Process Explorer Sysinternals
    iexplore.exe 3332 Internet Explorer Microsoft Corporation

    Process: Procexp Pid: -2

    Type Name
     
  7. 2004/05/15
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Good to hear! Were you able to clean it? I'm still concerned about that f0r0r folder. I was hoping to see an odd process running that might be keeping it hidden. Not the case PE log looks good. We need to find that folder! It is infected. Try this.

    Run this registry script, which forces Windows to show so called "superhidden" files:
    Copy the contents of the Quote box to Notepad, and save in a location of your choice as Unhide.reg (make sure to save as type: "All Files ")

    Doubleclick Unhide.reg, and answer 'yes' when prompted to add its contents to the Registry, then restart your computer.
    Then look for that folder again.
     
  8. 2004/05/16
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Dave - based on several responses from another thread in this section, you pretty well need to stop dirote.exe in order to see those folders.
     
    Newt,
    #7
  9. 2004/05/16
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yeah, I've seen that much from other posters. Notice earlier on that the dirote.exe process was killed with HJT, and did not return in subsequent log or in Process Explorer log, yet luke74 still reports the f0r0r folder cannot be seen. I'm assuming that the machine has since been rebooted, and a search done at that time too. Next step if this didn't help was Agent Ransack, as you and I have both suggested in the other thread.

    What I'd really like to know, is WHERE this thing is coming from. Exploiting another vulnerability? Email? Hoping one or more of the submittals will provide an answer, or something common amongst all the infected parties.
     
  10. 2004/05/16
    luke74

    luke74 Inactive Thread Starter

    Joined:
    2004/05/14
    Messages:
    5
    Likes Received:
    0
    I don't look that folder...
    With Rav I've received this report

    Scan started at 16/05/2004 9.48.58

    Scanning memory...
    Scanning boot sectors...
    Scanning files...
    C:\Programmi\EppiQuizScript\code\tb - IRC/Generic* -> Suspicious
    C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Temporary Internet Files\Content.IE5\O9MFKHAR\WksPatch[1].exe - Win32/HLLW.Nachi.B.dam#2 -> Infected
    E:\Email\abs_model\Mail\Inbox->(part0030:pASS.doc.pif) - Win32/Sircam@mm -> Infected

    Scanned
    ============================
    Objects: 58018
    Directories: 4459
    Archives: 4300
    Size(Kb): 1331369
    Infected files: 2

    Found
    ============================
    Viruses found: 2
    Suspicious files: 1
    Disinfected files: 0
    Mail files: 1584

    How can I remove them? I've used Norton FixWelch but it doesn't find any worms...
     
  11. 2004/05/16
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    For this one, C:\WINDOWS\system32\config\systemprofile\Impostazi oni locali\Temporary Internet Files\Content.IE5\O9MFKHAR\WksPatch[1].exe - Win32/HLLW.Nachi.B.dam#2 -> Infected, empty your temporary internet files.

    For this one, E:\Email\abs_model\Mail\Inbox->(part0030:pASS.doc.pif) - Win32/Sircam@mm -> Infected, double click My Compter>E:>Email>abs_model>Mail>Inbox, locate and delete this file part0030:pASS.doc.pif.

    This one, C:\Programmi\EppiQuizScript\code\tb - IRC/Generic* -> Suspicious, may or may not be a problem. Do you know what it is? If you don't, let me know and I will send you a PM with my email address so you can send it to me for examination.

    Empty the recycle bin after deleting both files. Reboot. Open task manager to processes tab and make sure dirote.exe and ppi.exe are not running. If they are, end task. Go back to RAV, click the scan a folder button, click the + next to C: then Windows and check the box next to system32. Then scan. Note the results. Then scan the E: drive and note the results.


    **Note to forum** I can't get on my XP machine right now. The path to the TIFs doesn't look right to me. Shouldn't it be in Docs. and settings\User\Local settings? Is that entire config folder in system32 suspicious looking?
     
  12. 2004/05/17
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    I have the folder C:\Windows\System32\Config\SystemProfile\Local Settings\Temporary Internet Files. This is on a newly installed XP SP1, one user.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.