Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Hijackthis log - brauche Hilfe (https://www.trojaner-board.de/18639-hijackthis-log-brauche-hilfe.html)

mursain 05.06.2005 19:17

Hijackthis log - brauche Hilfe
 
IE startet nach Aufrufen einer Internetseite eine Einwählseite. Mit Hijackthis habe ich schon diesen Eintrag entfernt:
O4 - HKLM\..\Run: [Hot_Tarts_fr] C:\Program Files\Mpb\Dialers\Hot_Tarts_fr\Hot_Tarts_fr.exe /dontdial

Das scheint aber nicht ausreichend zu sein. Sieht jemand noch an anderer Stelle Probleme? Hilfe! Danke! :dummguck:

C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\svchost.exe
c:\winnt\system32\srvany.exe
C:\WINNT\System32\gearsec.exe
c:\winnt\system32\cmd.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
c:\winnt\system32\srvany.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\SUSS.EXE
C:\WINNT\RCSERV.EXE
C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\CyberArmor\casvc.exe
C:\Program Files\VRAS\Extranet_serv.exe
C:\WINNT\System32\svchost.exe
C:\Program files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
C:\PROGRA~1\Tivoli\lcf\PCREMOTE\w32-ix86\TGT\EQNRCMAI.EXE
c:\winnt\log\bin\SLEEP.EXE
C:\PROGRA~1\CYBERA~1\pcs.exe
C:\PROGRA~1\CYBERA~1\pcshelp.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\System32\qttask.exe
C:\Program Files\CyberArmor\pcshelp.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program files\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Mpb\Dialers\Hot_Tarts_fr\Hot_Tarts_fr.exe
C:\winnt\system32\smgbmfvp.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Nortel Networks\TunnelGuard\platforms\win32\TGIconApp.EXE
C:\Program Files\Network Associates\VirusScan\MCUPDATE.EXE
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINNT\System32\MDM.EXE
C:\Program Files\Network Associates\Common Framework\McScript_InUse.exe
D:\HijackThis.exe


O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINNT\System32\qttask.exe
O4 - HKLM\..\Run: [CyberArmorHelper] C:\Program Files\CyberArmor\pcshelp.exe -check
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [Mobile] "C:\Program Files\Tivoli\lcf\dat\1\Mobile\epspawn.exe" -w "C:\Program Files\Tivoli\lcf\dat\1\Mobile" "C:\Program Files\Tivoli\lcf\dat\1\Mobile\mobile.exe"
O4 - HKLM\..\Run: [DIRECTCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"

O4 - HKLM\..\Run: [lcfep] "C:\Program files\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe"
O4 - HKLM\..\Run: [BlueCard SSD] C:\WINNT\SSD.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Hot_Tarts_fr] C:\Program Files\Mpb\Dialers\Hot_Tarts_fr\Hot_Tarts_fr.exe /dontdial
O4 - HKLM\..\Run: [SMGBMFVP] c:\winnt\system32\smgbmfvp.exe /install
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: TunnelGuard Tray Monitor.lnk = C:\Program Files\Nortel Networks\TunnelGuard\platforms\win32\TGIconApp.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\System32\shdocvw.dll


O17 - HKLM\System\CCS\Services\Tcpip\..\{4CE01D05-1A9B-4B04-8D7F-9DBDD0C3BB3D}: NameServer = 130.143.180.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{6180F6CE-D6F1-447D-AD75-81F17F1E8CA7}: NameServer = 130.143.180.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{72A6A023-88B4-4859-B12D-765FC9D17CD3}: NameServer = 130.139.36.5,130.143.166.30
O17 - HKLM\System\CCS\Services\Tcpip\..\{829DBB78-DA22-4CB9-960E-EDE7DB92C0EA}: NameServer = 217.237.150.141 217.237.150.97
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0D09181-D082-4650-BA22-630A8404D3B7}: NameServer = 130.143.180.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5507202-966B-4655-8725-47A2736D31ED}: NameServer = 130.143.180.26



O18 - Filter: text/html - {7B03BAB4-6DA9-4195-99C2-691A8272C963} - C:\Documents and Settings\dep05872.HBG\Local Settings\Application Data\microsoft\internet explorer\V0.28.dat
O20 - AppInit_DLLs: cahooknt.dll
O23 - Service: McAfee Alert Manager (AlertManager) - Unknown owner - C:\Program Files\Common Files\Network Associates\Alert Manager\amgrsrvc.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe

O23 - Service: CyberArmor Run Service (CyberArmorRunService) - InfoExpress - C:\Program Files\CyberArmor\casvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\VRAS\Extranet_serv.exe
O23 - Service: FtpLog - Unknown owner - c:\winnt\system32\srvany.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT\System32\gearsec.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfeeLogger - Unknown owner - c:\winnt\system32\srvany.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\Programme\Ora81\BIN\ONRSD.EXE
O23 - Service: Tivoli Remote Control Service (TME10RC) - IBM Corporation - C:\WINNT\RCSERV.EXE
O23 - Service: Nortel Networks TunnelGuard (tunnelguardservice) - Alexandria Software Consulting - C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe

chaosman 05.06.2005 20:34

@mursain

poste bitte die systeminfos mit

ist das ein beruflich benützte Rechner?
chaosman

mursain 06.06.2005 11:45

Hallo,
ja, das ist ein Firmenrechner. Ich habe alle Einträge entfernt, die den Firmennamen enthalten, sonst darf ich es nicht posten. Mehr habe ich aber nicht herausgenommen.
Ich hoffe, das log reicht trotzdem aus?
Gruß mursain

cacatoa 06.06.2005 11:46

Nein, die Systeminfos fehlen noch (sind die ersten vier Zeilen).
cacatoa

mursain 06.06.2005 11:53

So, hier habe ich die firmendaten mit sternchen ausgefüllt:

Logfile of HijackThis v1.99.1
Scan saved at 15:39:07, on 03.06.2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\*******\Xcelera\Programs\AutoUpdateD.exe
C:\Program Files\*******\Xcelera\Programs\enconcertrms.exe
C:\WINNT\System32\svchost.exe
c:\winnt\system32\srvany.exe
C:\WINNT\System32\gearsec.exe
c:\winnt\system32\cmd.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
c:\winnt\system32\srvany.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\SUSS.EXE
C:\WINNT\RCSERV.EXE
C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\CyberArmor\casvc.exe
C:\Program Files\VRAS\Extranet_serv.exe
C:\WINNT\System32\svchost.exe
C:\Program files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
C:\PROGRA~1\Tivoli\lcf\PCREMOTE\w32-ix86\TGT\EQNRCMAI.EXE
c:\winnt\log\bin\SLEEP.EXE
C:\PROGRA~1\CYBERA~1\pcs.exe
C:\PROGRA~1\CYBERA~1\pcshelp.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\System32\qttask.exe
C:\Program Files\CyberArmor\pcshelp.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program files\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Mpb\Dialers\Hot_Tarts_fr\Hot_Tarts_fr.exe
C:\winnt\system32\smgbmfvp.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Nortel Networks\TunnelGuard\platforms\win32\TGIconApp.EXE
C:\Program Files\Network Associates\VirusScan\MCUPDATE.EXE
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINNT\System32\MDM.EXE
C:\Program Files\Network Associates\Common Framework\McScript_InUse.exe
D:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://********/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://***************/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by ****************
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://******************/proxy.pac
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINNT\System32\qttask.exe
O4 - HKLM\..\Run: [CyberArmorHelper] C:\Program Files\CyberArmor\pcshelp.exe -check
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [Mobile] "C:\Program Files\Tivoli\lcf\dat\1\Mobile\epspawn.exe" -w "C:\Program Files\Tivoli\lcf\dat\1\Mobile" "C:\Program Files\Tivoli\lcf\dat\1\Mobile\mobile.exe"
O4 - HKLM\..\Run: [DIRECTCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SwdisUsrPCN.DEPHBRSAA1NB6SL] "C:\PROGRA~1\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [lcfep] "C:\Program files\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe"
O4 - HKLM\..\Run: [BlueCard SSD] C:\WINNT\SSD.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Hot_Tarts_fr] C:\Program Files\Mpb\Dialers\Hot_Tarts_fr\Hot_Tarts_fr.exe /dontdial
O4 - HKLM\..\Run: [SMGBMFVP] c:\winnt\system32\smgbmfvp.exe /install
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: TunnelGuard Tray Monitor.lnk = C:\Program Files\Nortel Networks\TunnelGuard\platforms\win32\TGIconApp.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\System32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://pww.de.ms.philips.com/
O15 - Trusted Zone: http://*******************
O15 - Trusted Zone: http://***************** (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = **************.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{4CE01D05-1A9B-4B04-8D7F-9DBDD0C3BB3D}: NameServer = 130.143.180.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{6180F6CE-D6F1-447D-AD75-81F17F1E8CA7}: NameServer = 130.143.180.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{72A6A023-88B4-4859-B12D-765FC9D17CD3}: NameServer = 130.139.36.5,130.143.166.30
O17 - HKLM\System\CCS\Services\Tcpip\..\{829DBB78-DA22-4CB9-960E-EDE7DB92C0EA}: NameServer = 217.237.150.141 217.237.150.97
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0D09181-D082-4650-BA22-630A8404D3B7}: NameServer = 130.143.180.26
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5507202-966B-4655-8725-47A2736D31ED}: NameServer = 130.143.180.26
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = **********************************
O17 - HKLM\System\CS1\Services\Tcpip\..\{4CE01D05-1A9B-4B04-8D7F-9DBDD0C3BB3D}: NameServer = 130.143.180.26
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ************************
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = ***************************************
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = ***************************
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = **********************************************
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ************************************************
O18 - Filter: text/html - {7B03BAB4-6DA9-4195-99C2-691A8272C963} - C:\Documents and Settings\dep05872.HBG\Local Settings\Application Data\microsoft\internet explorer\V0.28.dat
O20 - AppInit_DLLs: cahooknt.dll
O23 - Service: McAfee Alert Manager (AlertManager) - Unknown owner - C:\Program Files\Common Files\Network Associates\Alert Manager\amgrsrvc.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AutoUpdateD - Unknown owner - C:\Program Files\******************\Xcelera\Programs\AutoUpdateD.exe
O23 - Service: CyberArmor Run Service (CyberArmorRunService) - InfoExpress - C:\Program Files\CyberArmor\casvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ***************************** - C:\Program Files*************\Xcelera\Programs\enconcertrms.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\VRAS\Extranet_serv.exe
O23 - Service: FtpLog - Unknown owner - c:\winnt\system32\srvany.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT\System32\gearsec.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfeeLogger - Unknown owner - c:\winnt\system32\srvany.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\Programme\Ora81\BIN\ONRSD.EXE
O23 - Service: Tivoli Remote Control Service (TME10RC) - IBM Corporation - C:\WINNT\RCSERV.EXE
O23 - Service: Nortel Networks TunnelGuard (tunnelguardservice) - Alexandria Software Consulting - C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe

cacatoa 06.06.2005 11:59

Hi,
bitte folgende Dateien erst mal bei Jotti online scannen lassen:
C:\winnt\system32\smgbmfvp.exe
C:\Program Files\Mpb\Dialers\Hot_Tarts_fr\Hot_Tarts_fr.exe
C:\WINNT\system32\SUSS.EXE
Berichte bitte das Ergebnis, dann machen wir weiter.
Außerdem, kennst Du Die IP:
130.143.180.26
Wenn du mit Philips zu tun hast, dann ist es o.k.
Internet-Explorer updaten!!
cacatoa


Alle Zeitangaben in WEZ +1. Es ist jetzt 09:01 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129