I have several issues that I need help on
1. Hijackers – I have tried for three days now (10 hours just today) looking at posts, trying all sorts of things to rid myself of these pests. I have downloaded and run the following programs before, during and after Safe Mode only to have the hijackers return. I have manually edited the registry to delete any occurrences of these things only to have them return. I also have an external hard drive that these programs have been run on.
Norton Antivirus – nothing detected
Spy Bot – cleaned and fixed issues
Ad-Aware 6.0 – fixed issues
Ad-Watch3.0 – blocked attempted registry edits
PC Bug Doctor – fixed issues
CW Shredder – nothing detected
WinsockxpFix – fixed issues
Spyware Blaster – currently running – nothing detected
Trojan Guard Gold Version – active and useless!
HijackThis – see log below
FindIt – see log below
I have already downloaded KillBox and am awaiting your advice!
2. Rundll error messages. On reboot I receive different rundll error messages that change only in the last segment; i.e. C:\WINDOWS\system32\?????.dll. Where ???? appears, I have had the following appear after “system32\”: rputils, MEXEX, pcapi, uziplat and czpbk32 appear.
3. Coincidentally, my Palm M100 is inoperable. Is this related?
4. If your website is correct, then I am also infected with variant Apropos (no pun intended!) and will attempt the fix while I await your response to this!
5. I am unable to open FireFox web browser only Explorer. Is it possible one of these hijackers have locked this shut?
Thank you sooooooo much for your assistance – I am just about ready to do a clean re-install. Do you think that would do it?
HIJACKTHIS LOG FILE:
Find.bat is running from: C:\Documents and Settings\Renee\Desktop\Find It NT-2K-XP
Logfile of HijackThis v1.99.0
Scan saved at 8:10:33 PM, on 01/02/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPHipm11.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\kykipf.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Renee\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qt: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: ppctlcab - http://ppupdates.ca....er/ppctlcab.cab
O16 - DPF: Yahoo! Chat - http://cs6.chat.sc5....m/c381/chat.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell....iler/SysPro.CAB
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://cs6.chat.sc5....v43/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn...eUC/MsnUpld.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.communitie...UC/MsnPUpld.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...ta/SymAData.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://f1.pg.photos....plorer1_9us.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg...ntrol_v1-32.cab
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Launcher - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Retrospect WD Service - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
FIXIT Log File:
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
------- System Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is C0FE-4CCB
Directory of C:\WINDOWS\System32
01/02/2005 05:23 PM 223,870 nudll.dll
01/02/2005 05:19 PM 223,870 o6nslg5716.dll
01/02/2005 05:17 PM 223,553 enl6l13s1.dll
01/02/2005 04:56 PM 223,870 jtjo0713e.dll
01/02/2005 04:54 PM 223,777 g4220efoeh2c0.dll
01/02/2005 04:44 PM 223,730 jtpm0771e.dll
01/02/2005 01:29 PM 224,302 uxbui.dll
01/02/2005 01:05 PM 223,046 vqrcodec.dll
01/02/2005 10:09 AM 223,803 jtns0757e.dll
01/02/2005 10:02 AM 223,046 cmmpatui.dll
01/02/2005 10:00 AM 223,046 j4p0le7m1h.dll
01/02/2005 09:36 AM 223,046 enn0l15m1.dll
01/02/2005 09:29 AM 223,046 m4rm0e91eh.dll
01/02/2005 12:08 AM 223,046 f8l0li3m18.dll
01/01/2005 10:35 PM <DIR> DLLCACHE
01/01/2005 10:15 PM 224,636 q0rqla951d.dll
01/01/2005 09:12 PM 223,047 p8p6li7s18.dll
12/30/2004 09:04 AM 225,291 lnpcd12n.dll
12/30/2004 09:04 AM 225,712 dn2401fqe.dll
12/30/2004 08:46 AM 225,302 t4r80e9ueh.dll
12/30/2004 08:30 AM 225,959 ennql1551.dll
12/29/2004 08:28 PM 225,677 mv62l9jo1.dll
12/29/2004 07:37 PM 223,232 wyauserv.dll
09/23/2002 01:44 PM <DIR> Microsoft
01/05/2002 03:40 AM 487,424 msvcp70.dll
23 File(s) 5,415,331 bytes
2 Dir(s) 8,943,292,416 bytes free
------- Hidden Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is C0FE-4CCB
Directory of C:\WINDOWS\System32
01/01/2005 10:35 PM <DIR> DLLCACHE
08/31/2001 10:48 AM 488 logonui.exe.manifest
08/31/2001 10:48 AM 488 WindowsLogon.manifest
08/31/2001 10:48 AM 749 nwc.cpl.manifest
08/31/2001 10:48 AM 749 sapi.cpl.manifest
08/31/2001 10:48 AM 749 ncpa.cpl.manifest
08/31/2001 10:48 AM 749 wuaucpl.cpl.manifest
08/31/2001 10:48 AM 749 cdplayer.exe.manifest
7 File(s) 4,721 bytes
1 Dir(s) 8,943,226,880 bytes free
---------- Files Named "Guard" -------------
Volume in drive C has no label.
Volume Serial Number is C0FE-4CCB
Directory of C:\WINDOWS\System32
--------- Temp Files in System32 Directory --------
Volume in drive C has no label.
Volume Serial Number is C0FE-4CCB
Directory of C:\WINDOWS\System32
08/12/2004 09:40 PM 0 _r_a_p_.tmp
08/11/2004 12:45 AM 5,550,080 setb5.tmp
08/29/2002 05:41 AM 221,696 _000046_.tmp
02/01/2002 04:00 PM 45,056 qdc6EDF.tmp
02/01/2002 04:00 PM 15,449 csh4D18.tmp
5 File(s) 5,832,281 bytes
0 Dir(s) 8,943,091,712 bytes free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{10800918-E1C0-4BDB-AE85-A5F9CCCCB850}"=""
------------ Keys Under Notify ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OemStartMenuData]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\jtjo0713e.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM32\
cmmpatui.dll Sun Jan 2 2005 10:02:46a ..S.R 223,046 217.82 K
dn2401~1.dll Thu Dec 30 2004 9:04:08a ..S.R 225,712 220.42 K
enl6l1~1.dll Sun Jan 2 2005 5:17:42p ..S.R 223,553 218.31 K
enn0l1~1.dll Sun Jan 2 2005 9:36:04a ..S.R 223,046 217.82 K
ennql1~1.dll Thu Dec 30 2004 8:30:38a ..S.R 225,959 220.66 K
f8l0li~1.dll Sun Jan 2 2005 12:08:06a ..S.R 223,046 217.82 K
g4220e~1.dll Sun Jan 2 2005 4:54:04p ..S.R 223,777 218.53 K
j4p0le~1.dll Sun Jan 2 2005 10:00:44a ..S.R 223,046 217.82 K
jtjo07~1.dll Sun Jan 2 2005 4:56:40p ..S.R 223,870 218.62 K
jtns07~1.dll Sun Jan 2 2005 10:09:22a ..S.R 223,803 218.55 K
jtpm07~1.dll Sun Jan 2 2005 4:44:16p ..S.R 223,730 218.48 K
lnpcd12n.dll Thu Dec 30 2004 9:04:08a ..S.R 225,291 220.01 K
m4rm0e~1.dll Sun Jan 2 2005 9:29:28a ..S.R 223,046 217.82 K
mv62l9~1.dll Wed Dec 29 2004 8:28:56p ..S.R 225,677 220.39 K
nudll.dll Sun Jan 2 2005 5:23:14p ..S.R 223,870 218.62 K
o6nslg~1.dll Sun Jan 2 2005 5:19:50p ..S.R 223,870 218.62 K
p8p6li~1.dll Sat Jan 1 2005 9:12:24p ..S.R 223,047 217.82 K
q0rqla~1.dll Sat Jan 1 2005 10:15:06p ..S.R 224,636 219.37 K
t4r80e~1.dll Thu Dec 30 2004 8:46:48a ..S.R 225,302 220.02 K
uxbui.dll Sun Jan 2 2005 1:29:32p ..S.R 224,302 219.04 K
vqrcodec.dll Sun Jan 2 2005 1:05:08p ..S.R 223,046 217.82 K
wyauserv.dll Wed Dec 29 2004 7:37:34p ..S.R 223,232 218.00 K
22 items found: 22 files, 0 directories.
Total of file sizes: 4,927,907 bytes 4.70 M
------------ Strings.exe Qoologic Results ------------
C:\WINDOWS\SYSTEM32\izinus.dll: updates.qoologic.com
C:\WINDOWS\SYSTEM32\lglqzi.dll: updates.qoologic.com
C:\WINDOWS\SYSTEM32\lplamx.exe: updates.qoologic.com
-------------- Strings.exe Aspack Results -------------
C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack
C:\WINDOWS\SYSTEM32\vyvgoq.exe: .aspack
C:\WINDOWS\SYSTEM32\wqwkyg.dat: .aspack
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\kykipf.exe: .aspack
----------------- HKLM Run Key ------------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"Narrator"="C:\\WINDOWS\\system32\\vyvgoq.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
************************
Log for VX2.BetterInternet File Finder (ALL)
Files Found---
Additional Files---
Keys Under Notify---
crypt32chain
cryptnet
cscdll
MCD
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
wlballoon
Guardian Key--- is called:
Guardian Key--- :
User Agent String---
{10800918-E1C0-4BDB-AE85-A5F9CCCCB850}