Sida Loo Falanqeynayo Hijack This Logs

Tarjumaada Xogta Macluumaadka Si aad uga caawiso in ay ka noqoto Afduubayaasha iyo Browser Afduubayaasha

HijackThis waa qalab bilaash ah oo ka socda Trend Micro. Waxaa asal ahaan asaasay Merijn Bellekom, oo arday ah oo Nederland ah. Barnaamijka ka saarista Spyware sida Adaware ama Spybot S & D waxay qabtaan shaqo wanaagsan oo lagu ogaanayo lagana saarayo barnaamijyada casuumaadaha, laakiin qaar ka mid ah afduubayaashii iyo afduubayaashii ayaa aad ugu daacad u ah xitaa kuwan faa'iidooyinka ka horjeeda anti-spyware.

HijackThis si gaar ah loogu qoro si loo ogaado oo looga saaro barta shabakadaha shabakada, ama software ee qaadata barta shabakadaada, waxay bedeshaa boggaaga caadiga ah ee gurigaaga iyo mashiinka raadinta iyo waxyaabo kale oo xaasidnimo ah. Si ka duwan sida caadiga ah software anti-spyware, HijackThis ma isticmaali saxiixyo ama bartilmaameed barnaamijyada gaarka ah ama URL si ay u ogaadaan oo block. Taas, HijackThis waxay eegayaan xirfadaha iyo hababka loo isticmaalo nacnaca si ay u waxyeeleeyaan nidaamkaaga iyo dib u habeeyso biraawsarkaaga.

Ma aha wax kasta oo ka muuqda qoraalka HijackThis waa waxyaabo xun, waana in aan la wada saarin. Dhab ahaantii, waa mid soo horjeeda. Waxaa la hubaa in qaar ka mid ah waxyaabaha ku qoran HijackThis ay noqon doonaan software sharci ah oo ka saara waxyaabahani waxay saamayn xun ku yeelan karaan nidaamkaaga ama aad si buuxda u shaqeyn kartaa. Isticmaalka HijackThis waa wax badan sida aad u sameysato Nidaamka Diiwaanka Windows . Maaha cilmi baaris, laakiin waa inaadan hubin iyada oo aan hage khibrad khabiir ah la socon haddii aadan ogeyn waxaad samaynayso.

Marka aad rakibto HijackThis oo aad u maamusho si aad u abuurto faylka log, waxaa jira dhowr nooc oo kala duwan oo ah goobo iyo goobo aad halkaas ugu diri karto ama aad u gudbin karto xogtaada. Khubarada aqoonta u leh inay raadiyaan waxay kaa caawin karaan falanqaynta xogta qoraalka ah waxayna kugula talinayaan waxyaabaha ay tahay in laga saaro iyo kuwa kaligood tago.

Si aad u soo daabacdo version HijackThis, waxaad booqan kartaa goobta rasmiga ah ee Trend Micro.

Halkan waxaa ku qoran qoraalka guud ee HijackThis log kuwaas oo aad isticmaali karto si aad u booddo macluumaadka aad raadineyso:

R0, R1, R2, R3 - bogagga Start iyo Raadinta IE

Waxay u egtahay:
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, La bilow Bogga = http://www.google.com/
R1 - HKLM \ Software \ Microsoft \ InternetExplorer \ Main, Default_Page_URL = http://www.google.com/
R2 - (noocan oo kale ah ma isticmaalo HijackThis weli)
R3 - Default URLSearchHook waa la waayay

Waxa la qabanayo:
Haddii aad aqoonsatid URL dhamaadka ah sida boggaaga ama mashiinka raadinta, waa caadi. Haddii aadan sameynin, hubi oo hijackThis u hagaajin. Sheyga R3, had iyo jeer hagaajiso ilaa ay ka hadlayso barnaamijka aad aqoonsatid, sida Copernic.

F0, F1, F2, F3 - Barnaamijka autoloading laga soo qaado faylasha INI

Waxay u egtahay:
F0 - system.ini: Shell = Explorer.exe Openme.exe
F1 - win.ini: run = hpfsched

Waxa la qabanayo:
Waxyaabaha F0 marwalba way xun yihiin, markaa adigaa hagaajiya. Waxyaabaha F1 badanaa waa barnaamijyo da 'weyn oo ammaan ah, markaa waa inaad ka heshaa faahfaahin dheeraad ah oo ku saabsan feylka si aad u aragto inay fiicantahay ama xun tahay. Qorshaha Bilowga Pacman wuxuu kaa caawin karaa aqoonsashada shayga.

N1, N2, N3, N4 - Netscape / Mozilla Start & amp; Raadi bogga

Waxay u egtahay:
N1 - Netscape 4: user_pref "browser.startup.homepage", "www.google.com"); (C: \ Program Files \ Netscape \ Users \ default \ prefs.js)
N2 - Netscape 6: user_pref ("browser.startup.homepage", "http://www.google.com"); (C: \ Dukumiintiyada iyo Qalabka Isticmaalka C User / Macluumaadka Codsi \ Mozilla \ Profiles \ defaulto9t1tfl.slt \ prefs.js)
N2 - Netscape 6: user_pref ("browser.search.defaultengine", "engine: // C%3A%5CProgram%20Files%5CNetscape%206%5Csearchplugins%5CSBWeb_02.src"); (C: \ Dukumiintiyada iyo Qalabka Isticmaalka C User / Macluumaadka Codsi \ Mozilla \ Profiles \ defaulto9t1tfl.slt \ prefs.js)

Waxa la qabanayo:
Badanaa bogga Netscape iyo Mozilla iyo bogga raadinta waa ammaan. Marar dhif ah ayay afduubaan, kaliya Lop.com ayaa loo yaqaan in ay sidan sameeyaan. Haddii aad aragto URL aanad aqoonsanin sida boggaaga ama bogga raadinta, HijackThis u hagaajin.

O1 - Dib-u-soo-celinta furaha

Waxay u egtahay:
O1 - Mucaaradka: 216.177.73.139 auto.search.msn.com
O1 - Mucaaradka: 216.177.73.139 search.netscape.com
O1 - Mucaaradka: 216.177.73.139 ieautosearch
O1 - Faylasha dalxiisku wuxuu ku yaalaa C: \ Windows \ Help \ hosts

Waxa la qabanayo:
Afduubkan ayaa cinwaanka u rogi doona cinwaanka IP-ga dhinaca bidixda. Haddii IP-du aan ka tirsaneyn cinwaanka, waxaa laguu wareejin doonaa goob khalad ah markasta oo aad gashid cinwaanka. Waxaad mar walba haysan kartaa HijackThis waxay ku hagaajinayaan kuwaan, haddii aad si ogaan ah u geliso khadadka ku jira faylashaada Hosts.

Sheyga ugu dambeeyaa wuxuu mararka qaarkood ku dhacaa Windows 2000 / XP oo leh qaboojiye Coolwebsearch. Had iyo jeer hagaaji shayga, ama CWShredder si toos ah u dayactir.

O2 - Waxyaalaha Helper Browser

Waxay u egtahay:
O2 - BHO: Yahoo! Saaxiibka BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C: \ BILAABYADA HALISTA \ YAHOO! \ COMPANION \ YCOMP5_0_2_4.DLL
O2 - BHO: (magac lahayn) - {1A214F62-47A7-4CA3-9D00-95A3965A8B4A} - C: \ DIIWAANKA PROGRAM \ POPUP ELIMINATOR \ AUTODISPLAY401.DLL (faylka maqan)
O2 - BHO: MediaLoads Horumariyey - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C: \ DIIWAANGELINTA BARNAAMIJYADA \ MEDIALOADS ENHANCED \ ME1.DLL

Waxa la qabanayo:
Haddii aadan si toos ah u aqoonsanin magaca Nidaamka Caawiyaha Browser, waxaad isticmaali kartaa TonyK's BHO iyo Toolbar List si aad u ogaato shahaadada fasalka (CLSID, lambarka u dhexeeya qulqulaha ciriiriga ah) oo arag haddii ay fiicantahay ama xun tahay. Liiska BHO, 'X' macnaheedu waa spyware iyo 'L' micnaheedu waa ammaan.

O3 - qalabyada IE

Waxay u egtahay:
O3 - Toolbar: & Yahoo! Isu-qabsashada - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C: \ FILES PROGRAM \ YAHOO! \ COMPANION \ YCOMP5_0_2_4.DLL
O3 - Toolbar: Dareemaha Popup - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C: \ FILES PROGRAM \ POPUP ELIMINATOR \ PETOOLBAR401.DLL (faylka maqan)
O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C: \ WINDOWS \ APPLICATION DATA \ CKSTPRLLNQUL.DLL

Waxa la qabanayo:
Haddii aadan si toos ah u aqoonsanin magaca barta, waxaad isticmaashaa TonyK's BHO iyo Toolbar List si aad u ogaatid aqoonsiga fasalka (CLSID, lambarka u dhexeeya qulqulatooyinka ciriiriga ah) oo fiiri haddii ay fiicantahay ama xun tahay. Liiska Qalabka Qalabka, 'X' waxaa loola jeedaa casuumaadda iyo 'L' macneheedu waa ammaan. Haddii aysan ku jirin liiska isla markaana magaciisu u muuqdo xaraf jilicsan oo xarfaha ah iyo feylku wuxuu ku qoran yahay 'Faylka Codsiga' (sida midka ugu dambeeya ee tusaalooyinka kor ku xusan), waxaa laga yaabaa Lop.com, aadna hubaal tahay inaad hijackThis fix it.

O4 - Barnaamijka tirtirka barnaamijyada diiwaangelinta ee diiwaangelinta ama bilaabida kooxda

Waxay u egtahay:
O4 - HKLM \ .. \ Run: [ScanRegistry] C: \ WINDOWS \ scanregw.exe / autorun
O4 - HKLM \ .. \ Run: [SystemTray] SysTray.Exe
O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe"
O4 - Bilowga: Microsoft Office.lnk = C: \ Faylasha \ Microsoft Office \ Office \ OSA9.EXE
O4 - Guud ahaan Global: winlogon.exe

Waxa la qabanayo:
Isticmaal Hantida Bilawga ee PacMan si aad u hesho soo galida oo aad u aragto in ay fiicantahay ama xun tahay.

Haddii shayga uu muujiyo barnaamijka fadhiya kooxda bilaabida (sida sheyga ugu sarreeya), HijackThis ma hagaajin karo sheyga haddii barnaamijkani wali xasuusnaado. Isticmaal Maamulaha Howlaha ee Windows (TASKMGR.EXE) si loo xiro geeddi-socodka ka hor inta aan la qaban.

O5 - Fursadaha IE aan la arki Karin Gudiga Xakamaynta

Waxay u egtahay:
O5 - control.ini: inetcpl.cpl = maya

Waxa la qabanayo:
Haddii adiga ama maamulahaaga nidaamku uusan ogeyn icon-ka Control Panel, HijackThis waxay ku hagaajineysaa.

O6 - Fursadaha fursadaha IE ayaa xadidaya maamulaha

Waxay u egtahay:
O6 - HKCU \ Software \ Policies \ Microsoft \ Internet Explorer \ xaddidaad

Waxa la qabanayo:
Haddii aanad haysan Spybot S & D dooriyaha 'Lock up homepage from changes' fir fircoon, ama maamulahaaga nidaamkan meel geliyay, HijackThis ayaa arrintaas ku hagaajineysa.

O7 - Regedit gelitaanka xayiray maamulka

Waxay u egtahay:
O7 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System, DisableRegedit = 1

Waxa la qabanayo:
Had iyo jeer hijackThis arrimahan soo hagaajin, haddii maamulahaaga maamuluhu uu xaddidaadkan meel dhigay.

O8 - Qalabka dheeraadka ah ee IE-riix right-click

Waxay u egtahay:
O8 - Qalabka menu item dheeraad ah: & Raadinta Google - c: \ C: \ WINDOWS \ DOWNLOADED MACLUUMAADKA BARNAAMIJKA \ GOOGLETOOLBAR_EN_1.1.68-DELEON.DLL / cmsearch.html
O8 - Qalabka menu item dheeraad ah: Yahoo! Raadi - feyl: /// C: \ Barnaamijyada / Yahoo! \ Common / ycsrch.htm
O8 - Muuqaal Muuqaal Muuqaal Muuqaal dheeraad ah: Ku Dhow & Ku - C: \ WINDOWS \ WEB \ zoomin.htm
O8 - Muuqaal Muuqaal Muuqaal Muuqaal dheeraad ah: Muuji Meelaha & C - C: \ WINDOWS \ WEB \ zoomout.htm

Waxa la qabanayo:
Haddii aadan aqoonsaneynin magaca sheyga ee ku yaala menu-guji midka IE, hijackThis u hagaajin.

O9 - Afafyada dheeraadka ah ee ku yaal qalabka ugu muhiimsan ee IE, ama waxyaabaha dheeraadka ah ee IE & # 39; Tools & # 39; menu

Waxay u egtahay:
O9 - badhanka dheeraadka ah: Rasuulka (HKLM)
O9 - Qalabaha 'dheeraad ah': Rasuulka (HKLM)
O9 - badhanka dheeriga ah: AIM (HKLM)

Waxa la qabanayo:
Haddii aadan garaneynin magaca bamka ama menu item, HijackThis way ku hagaajisaa.

O10 - Afduubka Winsock

Waxay u egtahay:
O10 - Helitaanka internetka oo la afduubo New.Net
O10 - Helitaanka internetka oo jaban sababta oo ah bixiyaha LSP 'c: \ progra ~ 1 \ common ~ 2 \ toolbar \ cnmib.dll' maqan
O10 - Fayl aan la garaneynin ee Winsock LSP: C: \ faylasha barnaamijka \ newton yaqaan \ vmain.dll

Waxa la qabanayo:
Waxaa ugu fiican in la isticmaalo LSPFix isticmaalka Cexx.org, ama Spybot S & D oo ka socota Kolla.de.

Ogsoonow in faylasha 'aan la garaneyn' ee ku yaala LSP yaan lagu xallin doonin HijackThis, arrimaha amaanka.

O11 - Koox dheeraad ah oo ku jirta IE & # 39; Options Advanced & # 39; daaqada

Waxay u egtahay:
O11 - Kooxda xulashada: [CommonName] CommonName

Waxa la qabanayo:
Kaliya afduubka kaliya ee hadda ku daraya xulashadiisa u gaar ah daaqada Advanced Advanced IE ayaa ah CommonName. Sidaas darteed waxaad mar walba haysan kartaa HijackThis tan arrimahan hagaajisa.

O12 - Fejignaanta IE

Waxay u egtahay:
O12 - Plugin for .spop: C: \ Barnaamij Files \ Internet Explorer \ Plugins \ NPDocBox.dll
O12 - Plugin for .PDF: C: \ Faylasha \ Internet Explorer \ PLUGINS \ nppdf32.dll

Waxa la qabanayo:
Waqtiga intiisa badani waa ammaan. OnFlow oo kaliya ayaa ku daraya fiilo aanad rabin (.ofb).

O13 - IE DefaultPrefix afduubka

Waxay u egtahay:
O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=
O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?
O13 - WWW. Horudhac: http://ehttp.cc/?

Waxa la qabanayo:
Kuwani mar walba waa xun yihiin. HijackThis iyaga u hagaajin.

O14 - & # 39; Dib u Bedelida Websaytka & # 39; afduubka

Waxay u egtahay:
O14 - IERESET.INF: START_PAGE_URL = http: //www.searchalot.com

Waxa la qabanayo:
Haddii URL uusan aheyn bixiyaha kumbiyuutarkaaga ama ISP, HijackThis waxay ku hagaajineysaa.

O15 - Meelo aan la rabin oo ku yaal Aagga Aaminsan

Waxay u egtahay:
O15 - Zone Trusted: http://free.aol.com
O15 - Zone Trusted: * .coolwebsearch.com
O15 - Zone Trusted: * .msn.com

Waxa la qabanayo:
Inta badan wakhtiga kaliya ee AOL iyo Coolwebsearch si aamusnaan leh ugu daraan goobaha loo yaqaan "Trusted Zone". Haddii aadan adigu ku darin liiska ku qoran Nooca Trusted Naftaada, HijackThis way ku hagaajisaa.

O16 - Qalabka ActiveX (Barnaamijyada Barnaamijka ee la soo dejiyey)

Waxay u egtahay:
O16 - DPF: Yahoo! Wada hadal - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Waxa la qabanayo:
Haddii aadan aqoonsaneyn magaca shayga, ama URLka laga soo dejiyey, HijackThis way ku hagaajisaa. Haddii magaca ama URL uu ku jiro ereyo sida 'dialer', 'casino', 'free_plugin' iwm, si dhab ah u hagaajin. Javacool's SpywareBlaster wuxuu leeyahay macluumaad badan oo ku saabsan waxyaabo xaddidan oo ActiveX ah oo loo isticmaali karo in la eego CLSID. (Right-click u liiska si aad u isticmaasho Fun Find.)

O17 - Lopeshka domain ee xirxiray

Waxay u egtahay:
O17 - HKLM \ System \ CCS \ Adeegyada \ VxD \ MSTCP: Domain = aoldsl.net
O17 - HKLM \ System \ CCS \ Adeegyada \ Tcpip \ Parameters: Domain = W21944.find-quick.com
O17 - HKLM \ Software \. \ Telefoon: DomainName = W21944.find-quick.com
O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ {D196AB38-4D1F-45C1-9108-46D367F19F7E}: Domain = W21944.find-quick.com
O17 - HKLM \ System \ CS1 \ Services \ Tcpip \ Parameters: SearchList = gla.ac.uk
O17 - HKLM \ System \ CS1 \ Services \ VxD \ MSTCP: NameServer = 69.57.146.14,69.57.147.175

Waxa la qabanayo:
Haddii domain uusan ka jirin ISP ama shabakada shirkadda, HijackThis waxay ku hagaajineysaa. Isla sidaas oo kale waxa loo yaqaan 'SearchList'. Wixii Nidaamyada 'NameServer' ( DNS servers ), Google ee IP-yada ama IP-yada wayna u sahlanaan doontaa inay arkaan haddii ay fiicanyihiin ama xun yihiin.

O18 - Afduubyada dheeraadka ah iyo afduubayaasha qandaraaska

Waxay u egtahay:
O18 - Xeerka udhaxeeya: xidhiidhooyinka la xiriira - {5AB65DD4-01FB-44D5-9537-3767AB80F790} - C: \ PROGRA ~ 1 \ COMMON ~ 1 \ MSIETS \ msielink.dll
O18 - Protocol: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82}
O18 - Afduubka xuduudaha: http - {66993893-61B8-47DC-B10D-21E0C86DD9C8}

Waxa la qabanayo:
Kaliya afduubayaashu waxay halkan ka muuqdaan. Bannaanka la yaqaan waa 'cn' (CommonName), 'ayb' (Lop.com) iyo 'xidhiidhada' (Huntbar), waa inaad HijackThis ku hagaajisaa kuwa. Waxyaabaha kale ee soo muuqda waa mid aan la xaqiijin amaba ammaan, ama la afduubay (ie CLSID ayaa la bedelay) by spyware. Kiiskii ugu dambeeyay, HijackThis ayaa soo hagaajiya.

O19 - Afduubka hababka bogga

Waxay u egtahay:
O19 - Foomka style user: c: \ WINDOWS \ Java \ my.css

Waxa la qabanayo:
Marka ay dhacdo hoos u dhac gaabnaanta iyo soo noqnoqoshada soo noqnoqota, HijackThis waxay hagaajineysaa sheygan haddii ay ka muuqato qoraalka. Si kastaba ha ahaatee, maaddaama kaliya Coolwebsearch kaliya tani ay tahay, waxaa wanaagsan in la isticmaalo CWShredder si loo saxo.

O20 - AppInit_DLLs Qalabka diiwaangelinta ee autorun

Waxay u egtahay:
O20 - AppInit_DLLs: msconfd.dll

Waxa la qabanayo:
Qiimaha Diiwaangelinta ee ku yaal HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Windows wuxuu xusuustaa DLL marka uu isticmaalayo, ka dibna wuxuu xusuustaa xasuusta illaa inta kaadida. Barnaamijyo sharci ah oo yar ayaa u isticmaala (Norton CleanSweep waxay isticmaalaan APITRAP.DLL), inta badan waxaa isticmaala trojans ama afduubayaasha shabakada.

Haddii ay dhacdo 'DLL' oo qarsoodi ah 'DLL' oo ka yimid qiimaha Diiwaangelinta (kaliya oo la arki karo marka la isticmaalayo 'Isticmaalka Diiwaanka Binary' ee Regedit) magaca dll waxaa lagu hor dhigi karaa tuubbo '|' si aad uga dhigto muuqaalka log.

O21 - ShellServiceObjectDelayLoad

Waxay u egtahay:
O21 - SSODL - AUHOOK - {11566B38-955B-4549-930F-7B7482668782} - C: \ WINDOWS \ system \ auhook.dll

Waxa la qabanayo:
Kani waa habka autorun aan sharciyeysnayn, oo sida caadiga ah loo isticmaalo qaybaha nidaamka Windows. Waxyaabaha ku qoran HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ ShellServiceObjectDelayLoad waxaa lagu rakibayaa Explorer marka Windows bilaabanto. HijackThis wuxuu adeegsadaa naqshadeeyaha walxaha SSODL oo aad u badan, sidaas darteed mar kasta oo sheyga lagu soo bandhigo qoraalka aan la garanayn oo laga yaabo inuu yahay mid xaasidnimo leh. Ku daawee xannaanada aadka u daran.

O22 - La wadaagayTaskScheduler

Waxay u egtahay:
O22 - La wadaagayTaskScheduler: (magac lahayn) - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} - c: \ windows \ system32 \ mtwirl32.dll

Waxa la qabanayo:
Tani waa qoris aan sharci aheyn oo loogu talagalay Windows NT / 2000 / XP kaliya, oo loo isticmaalo si aad u dhif ah. Ilaa hadda kaliya CWS.Smartfinder ayaa isticmaala. La daawee daryeelka.

O23 - Adeegyada NT

Waxay u egtahay:
O23 - Adeegga: Kerio Gaari Shakhsi ahaaneed (PersFw) - Kerio Technologies - C: \ Faylasha Barnaamijka \ Kerio \ Personal Firewall \ persfw.exe

Waxa la qabanayo:
Tani waa liiska adeegyada non-Microsoft. Liisku waa inuu la mid yahay kii aad ka aragtay adeegga Msconfig ee Windows XP. Qaar ka mid ah afduubayaashii Trojan waxay isticmaalaan adeega guri-guri ee ku-meel-gaadhka ah marka loo eego kuwa kale ee bilaabay si ay dib ugu noqdaan. Magaca buuxa badanaa waa mid muhiim ah, sida 'Adeegyada Badbaadada Adeegyada', 'Workstation Logon Service' ama 'Procedure Call Caller Service', laakiin magaca gudaha (udhaxeeya) waa nooc qashin ah, sida 'Ort'. Qaybta labaad ee xariiqa waa mulkiilaha feylka dhammaadka, sida lagu arkay guryaha feylka.

Ogsoonow in la sameeyo qalabka O23 kaliya joojin doono adeegga oo wuu joojin doonaa. Adeeggu wuxuu u baahan yahay in laga tirtiro diiwaanka gacanta ama qalab kale. HijackThis 1.99.1 ama ka sarreeya, badhanka 'Delete NT Service' ee Qeybta Hawlaha Qalabka waxaa loo isticmaali karaa tan.