Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > HijackThis Log Help (Inactive)
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


 
 
LinkBack Thread Tools
Old 11-28-2006, 11:15 AM   #21 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,029
OS: WinXP and Vista


Ack--so sorry, I forgot you still have Ewido. Ewido has been purchased by Grisoft, makers of AVG Antivirus, and the program is now known as AVG Anti-Spyware. Ewido currently can still be updated to the newest definitions, but this support will likely not last forever. I recommend you uninstall Ewido, restart your system, then download and install AVG Anti-Spyware. Update it's definitions as directed below, and run a scan where I have it placed in this fix.

Download AVG Anti Spyware

Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows"

  • Install AVG Anti Spyware
  • Double-click the icon on Desktop to launch AVG
  • On the top of the main screen click Shield
  • Click the word active to change it to inactive
  • On the top of the main screen click Update.
  • Then click on Start Update. The update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
When you have finished updating, EXIT AVG Anti Spyware.

You would run the scan the same as you did with Ewido. Let's see if the updated version finds anything else.

**Before you download the newest version and run another scan, please do the following for me:
  • Please download Autoruns and AutoCmd.
  • Extract the contents of Autoruns into a new folder.
  • Now extract the contents of AutoCmd into the same folder as Autoruns. This is important!
  • Double-click on AutoCmd.cmd & select option '1'
  • It will produce a log called autoruns_X_Y.txt (where X and Y are the date and time respectively). Please attach the log in your next reply.

I can be going over that report while you download AVG A-S and run that scan--post the AVG A-S results when ready.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 11-28-2006, 11:36 AM   #22 (permalink)
Registered User
 
Join Date: Nov 2006
Location: London, England
Posts: 68
OS: Windows XP


The CMD scan has been on the same screen for a while now, is this normal? Its saying a "report will be produced, please wait until this window closes". Should I just be patient or has it stalled?
champster2k6 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-28-2006, 12:27 PM   #23 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,029
OS: WinXP and Vista


Sorry, but I have to ask... Did you extract the contents of AutoCmd into the same folder as Autoruns?
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-28-2006, 12:38 PM   #24 (permalink)
Registered User
 
Join Date: Nov 2006
Location: London, England
Posts: 68
OS: Windows XP


Its a relevant question, I did get confused. I'm not so good with this extracting and zip file malarky

If I delete the programs I downloaded, could you talk me through how to do it please? I use WinRar.
champster2k6 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-28-2006, 12:45 PM   #25 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,029
OS: WinXP and Vista


No apologies necessary...I did the same thing myself when testing it.

First, find where the Autoruns folder is unzipped to. Write down, or note the full path of where the folder is located.

When unzipping the Autocmd--Winrar will automatically fill in the 'unzip to' field for you--you don't want that path. Select 'Browse' and browse to the location that the Autoruns folder is in. Double click it and that path should now show in the 'unzip to' field.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-28-2006, 03:09 PM   #26 (permalink)
Registered User
 
Join Date: Nov 2006
Location: London, England
Posts: 68
OS: Windows XP


Right, firstly here's the AVG report.

AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 21:59:03 28/11/2006

+ Scan result:



:mozilla.27:C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\9dx75rxh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.28:C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\9dx75rxh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.29:C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\9dx75rxh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.79:C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\9dx75rxh.default\cookies.txt -> TrackingCookie.Sitestat : No action taken.
C:\System Volume Information\_restore{B191484F-6940-4C0A-B094-69318FF0F599}\RP468\A0117420.exe -> Trojan.DNSChanger.gp : No action taken.

:Report end

I didn't know if you wanted me to apply all actions so I thought it best I did. The tracking cookies I deleted and the Trjoan.DNS I quarantined. Hope I did the right thing.

Now, despite my best efforts the Auto stuff refused to work and got me rather angry

I do however have the whole report, I hope its not too tough to assess. If it is I apologise and with some more advice I'll try to get the report.

Here it is:

Lee - 28/11/2006@20:12:19.68
running from C:\Documents and Settings\Lee\Desktop\Autoruns\

Other users of this machine:
* Everyone else

----------------------------------------------------------------------------------

HKLM\System\CurrentControlSet\Services
ANISERVICE
Airgo Networks NIC Service
(Not verified) Airgo Networks, Inc.
c:\windows\system32\aniserv.exe
Automatic LiveUpdate Scheduler
Manages the scheduling of Automatic LiveUpdate sessions
(Verified) Symantec Corporation
c:\program files\symantec\liveupdate\aluschedulersvc.exe
ccEvtMgr
Event propagation and logging service
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\ccevtmgr.exe
ccProxy
Symantec Proxy Service
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\ccproxy.exe
ccSetMgr
Settings storage and management service
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\ccsetmgr.exe
CFSvcs
Service of ConfigFree.
(Not verified) TOSHIBA CORPORATION
c:\program files\toshiba\configfree\cfsvcs.exe
ewido anti-spyware 4.0 guard
ewido anti-spyware guard
(Not verified) Anti-Malware Development a.s.
c:\program files\ewido anti-spyware 4.0\guard.exe
navapsvc
Handles Norton AntiVirus Auto-Protect events.
(Verified) Symantec Corporation
c:\program files\norton internet security\norton antivirus\navapsvc.exe
Pml Driver HPZ12
PML Driver
(Not verified) HP
c:\windows\system32\hpzipm12.exe
SiteAdvisor Service
Provides low-level support for McAfee SiteAdvisor
(Verified) McAfee, Inc.
c:\program files\siteadvisor\4608\saservice.exe
SNDSrvc
Symantec Network Drivers Service
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\sndsrvc.exe
SPBBCSvc
Symantec SPBBC
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\spbbc\spbbcsvc.exe
Symantec Core LC
Symantec Core LC
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe
UserAccess7
c:\windows\system32\uaservice7.exe

HKLM\System\CurrentControlSet\Services
eeCtrl
Symantec Eraser Control Driver
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\eengine\eectrl.sys
EraserUtilRebootDrv
Symantec Eraser Utility Driver
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\eengine\eraserutilrebootdrv.sys
ewido anti-spyware 4.0 driver
c:\program files\ewido anti-spyware 4.0\guard.sys
GEARAspiWDM
CDRom Class Filter Driver
(Verified) GEAR Software Inc.
c:\windows\system32\drivers\gearaspiwdm.sys
NAVENG
AV Engine
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\virusdefs\20061128.018\naveng.sys
NAVEX15
AV Engine
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\virusdefs\20061128.018\navex15.sys
Netdevio
TOSHIBA Network Device Usermode I/O Protocol
(Not verified) TOSHIBA Corporation.
c:\windows\system32\drivers\netdevio.sys
SAVRT
AutoProtect
(Verified) Symantec Corporation
c:\program files\norton internet security\norton antivirus\savrt.sys
SAVRTPEL
SAVRTPEL
(Verified) Symantec Corporation
c:\program files\norton internet security\norton antivirus\savrtpel.sys
Secdrv
SafeDisc driver
(Not verified) Macrovision Europe Ltd
c:\windows\system32\drivers\secdrv.sys
SPBBCDrv
SPBBC Driver
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\spbbc\spbbcdrv.sys
SYMDNS
DNS Filter Driver
(Verified) Symantec Corporation
c:\windows\system32\drivers\symdns.sys
SymEvent
Symantec Event Library
(Verified) Symantec Corporation
c:\program files\symantec\symevent.sys
SYMFW
Firewall Filter Driver
(Verified) Symantec Corporation
c:\windows\system32\drivers\symfw.sys
SYMIDS
IDS Filter Driver
(Verified) Symantec Corporation
c:\windows\system32\drivers\symids.sys
SYMIDSCO
IDS Core Driver
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\symcdata\idsdefs\20061113.031\symidsco.sys
symlcbrd
Symantec Core Component
(Verified) Symantec Corporation
c:\windows\system32\drivers\symlcbrd.sys
SYMNDIS
NDIS Filter Driver
(Verified) Symantec Corporation
c:\windows\system32\drivers\symndis.sys
SYMREDRV
Redirector Filter Driver
(Verified) Symantec Corporation
c:\windows\system32\drivers\symredrv.sys
SYMTDI
Network Dispatch Driver
(Verified) Symantec Corporation
c:\windows\system32\drivers\symtdi.sys
TVALD
Toshiba Notebook PC SMI Driver
(Not verified) Toshiba Corporation
c:\windows\system32\drivers\nbsmi.sys
WNIPROT5
Airgo Networks Ndis 5.0 Protocol driver
(Not verified) Airgo Networks, Inc.
c:\windows\system32\wniprot5.sys

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
HP Standard TCP/IP Port
Standard TCP/IP Port Monitor DLL
(Not verified) Hewlett Packard
c:\windows\system32\hptcpmon.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls
interceptor.dll
API Interceptor
(Not verified) Tenebril Inc.
c:\windows\system32\interceptor.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
TPSMain
(Not verified) TOSHIBA Corporation
c:\windows\system32\tpsmain.exe
THotkey
(Not verified) TOSHIBA
c:\program files\toshiba\toshiba applet\thotkey.exe
TFncKy
TFncKy
(Not verified) TOSHIBA Corporation
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
AGRSMMSG
SoftModem Messaging Applet
(Not verified) Agere Systems
c:\windows\agrsmmsg.exe
HydraVisionDesktopManager
HydraDM
(Not verified) ATI Technologies Inc.
c:\program files\ati technologies\ati hydravision\hydradm.exe
Startup Manager Scanner
c:\program files\startup mechanic\startupmonitor.exe
ccApp
Symantec User Session
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\ccapp.exe
SiteAdvisor
SiteAdvisor
(Verified) McAfee, Inc.
c:\program files\siteadvisor\4608\siteadv.exe

HKLM\SOFTWARE\Classes\Protocols\Filter
application/octet-stream
Microsoft .NET Runtime Execution Engine
(Not verified) Microsoft Corporation
c:\windows\system32\mscoree.dll
application/x-complus
Microsoft .NET Runtime Execution Engine
(Not verified) Microsoft Corporation
c:\windows\system32\mscoree.dll
application/x-msdownload
Microsoft .NET Runtime Execution Engine
(Not verified) Microsoft Corporation
c:\windows\system32\mscoree.dll

HKLM\SOFTWARE\Classes\Protocols\Handler
msnim
MSN Messenger Protocol Handler
(Not verified) Microsoft Corporation
c:\program files\msn messenger\msgrapp.dll
siteadvisor
SiteAdvisor
(Verified) McAfee, Inc.
c:\program files\siteadvisor\4608\siteadv.dll

HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components
0
File not found: About:Home

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
n/a
Microsoft .NET IE SECURITY REGISTRATION
(Not verified) Microsoft Corporation
c:\windows\system32\mscories.dll

C:\Documents and Settings\Lee\Start Menu\Programs\Startup
Scheduler.lnk
Scheduler daemon
(Not verified) Tenebril Incorporated
c:\program files\spycatcher 2006\scheduler daemon.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD
CD/DVD Drive Acoustic Silencer
(Not verified) TOSHIBA
c:\program files\toshiba\toscdspd\toscdspd.exe
msnmsgr
MSN Messenger
(Not verified) Microsoft Corporation
c:\program files\msn messenger\msnmsgr.exe
iIWiper
iISystem Wiper
(Not verified) iISoftware
c:\program files\iisystem wiper\systemwiper.exe

Task Scheduler
AppleSoftwareUpdate.job
Software Application
(Verified) Apple Computer, Inc.
c:\program files\apple software update\softwareupdate.exe
Norton AntiVirus - Run Full System Scan - Lee.job
Norton AntiVirus Scanner Module
(Verified) Symantec Corporation
c:\program files\norton internet security\norton antivirus\navw32.exe
Symantec NetDetect.job
File not found: C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
AcroIEHlprObj Class
Adobe Acrobat IE Helper Version 6.0 for ActivieX
(Verified) Adobe Systems, Incorporated
c:\program files\adobe\acrobat 6.0\reader\activex\acroiehelper.dll
{089FD14D-132B-48FC-8861-0048AE113215}
SiteAdvisor
(Verified) McAfee, Inc.
c:\program files\siteadvisor\4608\siteadv.dll
SpywareBlock Class
Spyware blocking module
(Not verified) Tenebril Inc.
c:\program files\spycatcher 2006\scactiveblock.dll
PCTools Site Guard
Site Guard
(Not verified) PC Tools
c:\program files\spyware doctor\tools\iesdsg.dll
SSVHelper Class
Java(TM) 2 Platform Standard Edition binary
(Not verified) Sun Microsystems, Inc.
c:\program files\java\jre1.5.0_09\bin\ssv.dll
CNisExtBho Class
NIS Shell Extension
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\adblocking\nisshext.dll
CNavExtBho Class
Norton AntiVirus Shell Extension Module
(Verified) Symantec Corporation
c:\program files\norton internet security\norton antivirus\navshext.dll
PCTools Browser Monitor
iesdpb.dll
(Not verified) GuideWorks Pty. Ltd.
c:\program files\spyware doctor\tools\iesdpb.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
ewido anti-spyware 4.0
ewido anti-spyware guard
(Not verified) Anti-Malware Development a.s.
c:\program files\ewido anti-spyware 4.0\shellexecutehook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Display Panning CPL Extension
File not found: deskpan.dll
Fusion Cache
Microsoft .NET Runtime Execution Engine
(Not verified) Microsoft Corporation
c:\windows\system32\mscoree.dll
Shell Extensions for RealOne Player
RealPlayer Shell Extensions
(Not verified) RealNetworks, Inc.
c:\program files\real\realplayer\rpshell.dll
iTunes
iTunes Mini Player DLL
(Not verified) Apple Computer, Inc.
c:\program files\itunes\itunesminiplayer.dll
WinRAR shell extension
c:\program files\winrar\rarext.dll
OpenOffice.org Column Handler
(Not verified) Sun Microsystems, Inc.
c:\program files\openoffice.org 2.0\program\shlxthdl.dll
OpenOffice.org Infotip Handler
(Not verified) Sun Microsystems, Inc.
c:\program files\openoffice.org 2.0\program\shlxthdl.dll
OpenOffice.org Property Sheet Handler
(Not verified) Sun Microsystems, Inc.
c:\program files\openoffice.org 2.0\program\shlxthdl.dll
OpenOffice.org Thumbnail Viewer
(Not verified) Sun Microsystems, Inc.
c:\program files\openoffice.org 2.0\program\shlxthdl.dll
Crypteze Shell extension
Crypteze Shell Extensions 1.0
(Not verified) kcSystems Inc.
c:\program files\kcsystems\crypteze\cryptezeshl.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}
(Not verified) Sun Microsystems, Inc.
c:\program files\openoffice.org 2.0\program\shlxthdl.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar
Norton Internet Security 2006
NIS Shell Extension
(Verified) Symantec Corporation
c:\program files\common files\symantec shared\adblocking\nisshext.dll
Norton AntiVirus
Norton AntiVirus Shell Extension Module
(Verified) Symantec Corporation
c:\program files\norton internet security\norton antivirus\navshext.dll
McAfee SiteAdvisor
SiteAdvisor
(Verified) McAfee, Inc.
c:\program files\siteadvisor\4608\siteadv.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions
PartyPoker.com
RunApp MFC Application
c:\program files\partygaming\partypoker\runapp.exe

If it's easier for you I've attached a document in notepad with the above report in it.
Attached Files
File Type: txt autoruns1_28-11-2006_20-12.txt (11.6 KB, 2 views)
champster2k6 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-28-2006, 05:52 PM   #27 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,029
OS: WinXP and Vista


Hi,

Everything appears in order there as well. Let's have a look at Windows Event Viewer. It might give us a clue as to what is causing these issues

Go to Start > Run - type in eventvwr <Press Enter>

You will see Application, Security & System listed in the left pane.
  1. In the left pane click on Application.
  2. Click the gray title “Type” at the top of the source name column in the right pane to sort by type name.
  3. Look for “Error” & double-click on the most recent 5, and evaluate the event description for any indication of the cause of the problem.
  4. Make note of the Description, EventID and Source of these Event Properties.
  5. From the right pane, doubleclick on the line where it says error.
  6. In the upper right corner, you should see 2 arrows. One is pointing up & the other, pointing down--there is another button below the 2 arrows. Click once on it. (this will copy some information to clipboard)
  7. Open notepad & paste the info in there. This will copy the event information to the clipboard. Paste the information for each event here
Repeat steps 1-7 for System
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-28-2006, 09:43 PM   #28 (permalink)
Registered User
 
Join Date: Nov 2006
Location: London, England
Posts: 68
OS: Windows XP


Hello Ried, couldn't get back to sleep - doesn't bode well for my lectures today

I've attached the Notebook document with the relevant information.
Attached Files
File Type: txt System.txt (6.8 KB, 1 views)
champster2k6 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-28-2006, 10:15 PM   #29 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,029
OS: WinXP and Vista


Hi Lee,

Those are definitely OS related issues and you would be better served discusssing this with the Windows XP experts.

Give them a description of your remaining issues as well as the Event Viewer info and let them know you've been cleared by the HijackThis section.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-28-2006, 10:24 PM   #30 (permalink)
Registered User
 
Join Date: Nov 2006
Location: London, England
Posts: 68
OS: Windows XP


Righto, cheers for all your help Ried - let's hope they can sort the remaining issues out.
champster2k6 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 08:15 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85