Vraag & Antwoord

Beveiliging & privacy

Backdoor.Trojan

Anoniem
None
40 antwoorden
  • Zodra ik me PC opstart krijg ik een melding van Norton Antivirus dat er een virus op mijn PC staat: [b:2fce2833e4]Backdoor.Trojan[/b:2fce2833e4]

    De file die besmet is staat in de volgende map:
    [i:2fce2833e4]C:\WINDOWS\System32\hlpbfo.dll[/i:2fce2833e4]

    Ik ben hulp gaan vragen op de website www.virushelp.nl
    Tot nu toe is 't nog niet gelukt om het virus te verwijderen.

    Ik heb het systeem herstel al uitgeschakeld. Heb al een aantal keer Norton Antivirus laten scannen ook in [i:2fce2833e4]veilige modus[/i:2fce2833e4] maar hij vindt 'm dan niet.

    Ik heb het [b:2fce2833e4]hlpbfo.dll[/b:2fce2833e4] handmatig proberen te verwijderen maar dat lukt ook niet de toegang wordt geweigerd tot het bestand!
    Dit heb ik ook al in veilige modus geprobeerd maar daar laat hij het .dll bestand niet eens zien.

    Kunnen jullie mij helpen?

    Ik gebruik WinXP Pro.
    Virusscanner is Norton Antivirus 2003

    Mvgr. Bas
  • Hallo -TeR-,

    Misschien dat we iets kunnen zien in een hijackthislog.
    Kan je er er ééntje maken en posten?

    groeten,
  • Ja natuurlijk:

    Logfile of HijackThis v1.98.0
    Scan saved at 11:41:56, on 21-7-2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\System32\drivers\CDAC11BA.EXE
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Executive Software\Diskeeper\DkService.exe
    C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
    C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton Internet Security\NISUM.EXE
    C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Norton Internet Security\ccPxySvc.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\System32\RunDll32.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Messenger Plus! 2\MsgPlus.exe
    C:\PROGRA~1\DAP\DAP.EXE
    C:\PROGRA~1\SHIMRO~1\Wipe 01 Wma.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    C:\WINDOWS\System32\rmctrl.exe
    C:\Program Files\TweakNow PowerPack\RAM_XP.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
    C:\wincmd\WinCmd32.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\macromed\flash\GetFlash.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    D:\Hijak\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = c:\searchpage.html
    R1 - HKLM\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\searchpage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = c:\searchpage.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zdnet.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://minisearch.startnow.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.zdnet.nl/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    R3 - URLSearchHook: HyperSearchHook - {3CCF13CB-A170-4E91-B4F6-FAC31534AA1A} - C:\Program Files\Common Files\Hyperbar\HyperbarSS3.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: HyperBHO - {4B2F5308-2CB0-40E2-8030-59936ED5D22C} - C:\Program Files\Common Files\Hyperbar\Hyperbar.dll
    O2 - BHO: (no name) - {5C3B8868-39D2-460D-82B5-9398406696C3} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: mess poke - {7F05B138-A9A4-11AE-8199-87CBC6AEDB57} - C:\PROGRA~1\cityvga\More Grid.dll
    O2 - BHO: PopKiller Class - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\PKExt.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [Ulead Memory Card Detector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0\Monitor.exe
    O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
    O4 - HKLM\..\Run: [QD FastAndSafe] C:\PROGRA~1\NORTON~1\NORTON~3\QDCSFS.exe /scheduler
    O4 - HKLM\..\Run: [objtray] C:\PROGRA~1\SHIMRO~1\Wipe 01 Wma.exe
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
    O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\TweakNow PowerPack\RAM_XP.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - Startup: PowerReg Scheduler.exe
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
    O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
    O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
    O12 - Plugin for ¸æå: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
    O13 - Home Prefix: c:\searchpage.html?page=
    O13 - Mosaic Prefix: c:\searchpage.html?page=
    O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://www.ea.com/downloads/rtpatch/EARTPX.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://D:\Bas\Programma's\Autodesk Architectural Desktop 3\AcDcToday.ocx
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28177.cab
    O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://D:\Bas\Programma's\Autodesk Architectural Desktop 3\InstBanr.ocx
    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
    O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://D:\Bas\Programma's\Autodesk Architectural Desktop 3\InstFred.ocx
    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
    O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://D:\Bas\Programma's\Autodesk Architectural Desktop 3\AcPreview.ocx
    O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.98.176.62/EPlugin_NL.cab
    O16 - DPF: {FE8287E9-5F43-11D3-ABCA-00105A5C1F46} (HouseCall Control) - http://www.housecall.nl/housecall/xscan4.cab
    O20 - AppInit_DLLs: C:\WINDOWS\System32\hlpbfo.dll
  • ik kijk wel even
  • Verwijder dap (download accelerator plus) in software in het configuratie scherm.
    Sluit daarna alle vensters en run hjt opnieuw fix de volgende items indien aanwezig:

    [list:a852b244b2][b:a852b244b2]
    R1 - HKCU\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = c:\searchpage.html
    R1 - HKLM\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\searchpage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = c:\searchpage.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://minisearch.startnow.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
    R3 - URLSearchHook: HyperSearchHook - {3CCF13CB-A170-4E91-B4F6-FAC31534AA1A} - C:\Program Files\Common Files\Hyperbar\HyperbarSS3.dll
    O2 - BHO: HyperBHO - {4B2F5308-2CB0-40E2-8030-59936ED5D22C} - C:\Program Files\Common Files\Hyperbar\Hyperbar.dll
    O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O13 - Home Prefix: c:\searchpage.html?page=
    O13 - Mosaic Prefix: c:\searchpage.html?page= [/b:a852b244b2][/list:u:a852b244b2]

    Reboot in safe mode en laat alle verborgen bestanden weergeven verwijder daarna de volgende items indien aanwezig:
    [list:a852b244b2][b:a852b244b2]
    c:\searchpage.html <— dit bestand
    C:\Program Files\Common Files\Hyperbar <— deze map
    C:\Program Files\DAP <— deze map[/b:a852b244b2][/list:u:a852b244b2]


    en bij onderstaande 2 heb ik twijfels:
    [list:a852b244b2][b:a852b244b2]O2 - BHO: mess poke - {7F05B138-A9A4-11AE-8199-87CBC6AEDB57} - C:\PROGRA~1\cityvga\More Grid.dll [/b:a852b244b2][/list:u:a852b244b2] kan ik namelijk niks over vinden.


    [list:a852b244b2][b:a852b244b2]
    O4 - HKLM\..\Run: [objtray] C:\PROGRA~1\SHIMRO~1\Wipe 01 Wma.exe [/b:a852b244b2][/list:u:a852b244b2] word ook niet zoveel wijzer van googlen behalve dat er kans is dat het een virus is, doe daarom een online scan

    edit: en post straks een nieuwe log
  • Ik zie dat bij de log de allerlaatste staat

    http://www.housecall.nl/housecall/xscan4.cab
    O20 - AppInit_DLLs: C:\WINDOWS\System32\hlpbfo.dll

    Dat is het filetje waar Norton Antivirus zegt dat daar die virus inzit, moet ik die ook verwijderen?
  • die file weggooien en die fixen dan ja.
  • Het weggooien lukt niet omdat het wordt geweigerd.
    En als ik fix doe en ik scan 'm opnieuw staat hij er nog steeds bij.

    Ik ga 'm nu virusscanen met de virusscanner waar je de link van gaf. :D

    moet nu ff weg, ben rond 5/6 uur weer terug.



    Logfile of HijackThis v1.98.0
    Scan saved at 15:01:39, on 22-7-2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\drivers\CDAC11BA.EXE
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Executive Software\Diskeeper\DkService.exe
    C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
    C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\System32\RunDll32.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Messenger Plus! 2\MsgPlus.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\Norton Internet Security\NISUM.EXE
    C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0\Monitor.exe
    C:\PROGRA~1\SHIMRO~1\Wipe 01 Wma.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    C:\WINDOWS\System32\rmctrl.exe
    C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    C:\Program Files\TweakNow PowerPack\RAM_XP.exe
    C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Norton Internet Security\ccPxySvc.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
    C:\wincmd\WinCmd32.exe
    D:\Hijak\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zdnet.nl/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.zdnet.nl/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: mess poke - {7F05B138-A9A4-11AE-8199-87CBC6AEDB57} - C:\PROGRA~1\cityvga\More Grid.dll
    O2 - BHO: PopKiller Class - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\PKExt.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [Ulead Memory Card Detector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0\Monitor.exe
    O4 - HKLM\..\Run: [QD FastAndSafe] C:\PROGRA~1\NORTON~1\NORTON~3\QDCSFS.exe /scheduler
    O4 - HKLM\..\Run: [objtray] C:\PROGRA~1\SHIMRO~1\Wipe 01 Wma.exe
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
    O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\TweakNow PowerPack\RAM_XP.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - Startup: PowerReg Scheduler.exe
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
    O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
    O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
    O12 - Plugin for ¸æå: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
    O13 - Home Prefix: c:\searchpage.html?page=
    O13 - Mosaic Prefix: c:\searchpage.html?page=
    O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://www.ea.com/downloads/rtpatch/EARTPX.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://D:\Bas\Programma's\Autodesk Architectural Desktop 3\AcDcToday.ocx
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28177.cab
    O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://D:\Bas\Programma's\Autodesk Architectural Desktop 3\InstBanr.ocx
    O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
    O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://D:\Bas\Programma's\Autodesk Architectural Desktop 3\InstFred.ocx
    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
    O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://D:\Bas\Programma's\Autodesk Architectural Desktop 3\AcPreview.ocx
    O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.98.176.62/EPlugin_NL.cab
    O16 - DPF: {FE8287E9-5F43-11D3-ABCA-00105A5C1F46} (HouseCall Control) - http://www.housecall.nl/housecall/xscan4.cab
    O20 - AppInit_DLLs: C:\WINDOWS\System32\hlpbfo.dll
  • en als je die file die norton aangeeft in safe mode verwijdert? of met de killbox?
  • Hallo -TeR-,

    Dit is een verborgen installer.
    Ik wil toch even dubbelchecken voor de zekerheid:
    Download het bestand Appinit.bat.
    Run het bestand niet uit de zip-map, maar unzip het naar je desktop.
    Even verschijnt er een dosbox en dan wordt er een bestandje aangemaakt dat windows.txt noemt.
    Post de inhoud van dit windows.txt bestand in je volgende bericht.

    groeten,
  • Het [b:28e95e1044]hlpbfo.dll[/b:28e95e1044] staat er in de safemode niet tussen.

    m@rc ik ga het nu even proberen.

    Ik heb me PC nu met de housecall trendmicro virus scanner en tot mijn verbazing zie ik dat er nog 3 virussen opstaan die door Norton Antivirus niet aangegeven worden:

    [img:28e95e1044]http://members.lycos.nl/tercounterstrikenl/hpbimg/virussen.gif[/img:28e95e1044]

    Wat doe ik hiermee ik heb op de knop herstellen geklikt maar er gebeurt niet echt veel. :-?
  • [quote:c54654ad37]Het hlpbfo.dll staat er in de safemode niet tussen.[/quote:c54654ad37]

    ???

    In safe mode???

    Wat staat er in de windows.txt????
  • Ik weet niet of je er wat aan heb.

    regf       iÌüÆXuaVrÎj ÝkŽ-¢ŠÒ—'2²+B½ lv -,ž\ËegŒŒtòðAo6ر±0×õ¾Ô}Œ)Zõ×^´c‘“‘”P_3ï,Åà KmF?f$œÏéÿ Y Î ºž ãíPÿŸø?u–HHœ=ŠüŽp
    2@ÍH™8J…˜ðt!Yƒ=%={ |'ö{Œ‡WÆ—Ïy‰´DŒtJ}‚ ^Kƒ“qFú$ÀÃÂàP0­›`4v€°;‰ËÕÏJ,sϯË^òëY”LºK=‰û=%lM9äª성P&æ7z6²E£:ABð,ŸsдÌ9Þá±üsyW -²iQÃ!S:ž,ýNæ9ß$rg½Ø$gIÌú 9Þ¬ ¶B©/B+ƺg0i¼{½tü»V‡„'5µ‡k)K#SÜyqPMDi >¤JSñÙL.öe5—†@+Y1/ùtJÝeózOd„žtÞ»u ô1ùð¬æðÅ)oEŸJ*ù hbin  Y›,+±íŒ>'¦i\V“%ͨÿÿÿnk, †tpæëoÄ ÿÿÿÿ ÿÿÿÿÿÿÿÿ @ x ÿÿÿÿ 0 > ?ÁãL WindowsƒÈþÿÿskH|x x         ì
         !
     €  !      #
     €  #  ?    
         ?   
        ?    
            Öí6Øÿÿÿvk > Ø   fùAppInit_DLLs֍æG¸ÿÿÿC : \ W I N D O W S \ S y s t e m 3 2 \ h l p b f o . d l l vk  ° Ðÿÿÿvk  X   ceDeviceNotSelectedTimeoutðÿÿÿ1 5 YîQÊðÿÿÿ9 0 | Xv| Ðÿÿÿvk  €'   =pGDIProcessHandleQuotau| àÿÿÿvk  È   trSpoolertðÿÿÿy e s _£ûó ° ( x ¨ ð àÿÿÿvk  €   | swapdiskÐÿÿÿvk  h   TransmissionRetryTimeoutàÿÿÿ° ( x ¨ ð  ` Ðÿÿÿvk  €'   S USERProcessHandleQuotal p !œ´Ø )Nrq/S¼' HÌOÄO@yØlÜÖ‹ œ„:%QDpQAà#KèÇ$kH¼@F¥< î*NéMb”1V‘Î$uÑ•Þ²(Ⱦ©MìÏàV°
    쫼 Œ+:¾^ ©z­~Àf°$T Á
    ÈA>§ˆOO¤+ǸŽžèRõ†h˜òÿ†œ,ârlóþ
    €Œ¨¦dèF1’D7XO8K櫓œ¤nPwÜÀ½Y·ŽOˆÄ±s(V¸„£œîX|t؁ Ö‰²Œ äåä¸êV 4`E¯‹þG>‰½ƒ=«È 8¾¢
    ¹ƒÕAaN¬>9a+C ³‹Æ^ éÒî7‚¢8 #h5°&â ð˜|R'S,¦ÔQ_€Ø¢Ž€ú«Ø€“úUnô)†84ï@7 ²ª°‹žŸ̍‰Õ–åÙ)@
    ØMäâ<‰f¾¤ÑŒ8 L½V |qȘŒ)¼_üBàd»µ/NM„0 õ!$±oøÈCx !'OðˆŒ¬‡’«T(Ç-}R„€¨]ÿ4³µèÔ!ÿ¸"Ô:2 ôó™ôȸˆ¥š
    ÌH)’0÷½åCBj&„šP8“æØ“Ð æl©”ä®Õ‘OæÙêšÝXT²x2Ɂ5 §¾AY0–X°¹ØGŽôc ¸$þ= é„xºê1ž…î_0'‰ð㐄8y ƒ— ¤V‡\7d¥ ,øyV5.!Á€Ãg²LI¨ÉQ<àS1è¡£+º±Ö&MÖ›žîÔaçªçR˜Ðû“üìIÇ ¸­Œ¤1^ª[e¼fLž#þS1ÀÖT=Óüû4©6—aô†‰û #,%Ð <Üž­Nxç´W¸ûWÄ'ŒÈPƒP‹é–Á˜a…»næœxô üؐdT‹,¢ Ú }$wÜȳTˆz“©€} G,dý
    ا™*òÕÔžÀ$ñ@Š Ò­r¤™¯Xdª… EÉ£$8Œª"Ð@ŒÀ6€Ô¼|c…Äð~…^Hã ë‰(*c èët;éÝŠ³±ì±06œN‚—ÔšæêçâE€ ©i#À¤ úOkƒ>DI#),Ž½äåe–ÀàðH`h`MdԏZIj¦yõ¬ƒpˆ1ø'²Æ.븘Tµ(íœÄJê`ฃ«$‡Øü¹K¢#Á™Ê¢“ƒ§BRÎj2¡ )®°ËÀ({/, ì*NXTÖá":rF߸"Aµì$/[S:éƒ{ ‹hà5-…= S¶wû %L²I–
    ”Å‘`í/³¨ËR<,¾+8ŒT¨Ê„¨¦TàB.Å2Ú¾‰Ä(@²¡%R O'’M1”T4M¤:É• ­)Fœ2îµhäЗ¬¢J’
    ³‘«jaîl5 fä¬_ÆÍסdHC& H„ïY–¬V)CÆÃ8”kêN ¤‰ÎÄšZrNUƒ½™"U¤~O|˨+‰¾k¯xV8"&·íµ1.„`,
    çðYhaƒÕíT>^Ü5Thà1¡±!^…âdk›;9Lji†pI<øŠÀ;%À1ãa‹QÚ=
    ¥X‚±â·¼8ò$³ƒðïžN
    ÓT !ð)€ß)ÖY‰#üb-„Àt$ÔF ۍ_>X¹Ö«pzNñc`d
    ­fî:>ՍՐ!±‡µ AâSˆ«¦(7Y\‹Æc „ÔfÀXF*Š´!µcÜ¢‘sÏzd…¬Á^áß] ~9„#ÈSy´ „ùZs ÈžU‘]µ’4:Ql #DùØ24ŸaQÌ:$Œ`X£ÿHQ‹P‹•1œQ!ì—âpŠ/ð!ÀetI(Ø_H×{.Çtdì0—j4¦×Ô£Dç M¯ pM€ƒ€_P€`<ÿ¡(åÿÿX “,—ž°Ô §,ŽD°¹l#kŒ%ªZ$h2b@à²V夔.¤z¥äY¥,DsÈà O¨,ªڝÜÈ.`°§F3ZA¨ø‡C›–.‹óÐ_*(¬ <ô2ˆ6MD“˜u±D¶(Ø&‰nBEw®õœ$ P¸¸ÀùÐQuNø€9`’›×JÈŠ±N@*Ó€AŒP{V§
    ÈÉâ ÛR %ñƒ!‡›rû!;mW8‹;ÖÚð×X( üQDøPåÖ~¬ð)`„û*üÅI´ƒî áÞÐ#Ò•ôBüÙEr¯±RÔ‡ó ã‹„âU,3!|4° C7ã‡'/¥I”ƒ2U‚©tJ«3ÆÁ¢R„l‰*œýª'ª*ˆújA´(Q*#”ëà>AÚèó&j]êÊ¿©Ü!³Gÿ;„ƒÞA„bÌj65§ ð”ij€•QžÓæpÍâ»Té&p'[ä~éq€½k•/…Ÿþ±‚ÚGHœ„Ì[O<–‘Àê N<Í ¾€ƒ”ôŒêžVyO ƒ/¡è•"¤u¯Š= ÙbQL¬XpXêÀì¸M:µ’µw¿r‹Oˆ‹ø…’…qN.x¤¶yH±s? 6SDhijj… œÁÕ^E“ã úóU™¯Š–þPœMõev8„Š2烃Tú¡ y¸ W°“øaqpÿç3ØX:jvOŒRû °ˆŽt²ºšŠ5ž€³ë¦–©s\Q!£ÆÔ"/FÂŽ¯Â!è‘|‹){Œ•†P9°|â
    ÖA(t€ žl0V…ÿfŸ™ŽA
     ªy-ú` «,dQ£rÁâ×"PQºÚZx6 >Êõ¯¶
    …,[ "t ±0yÈHñ›;0šË‰v0XX‹’ŒÑžäÚ~“&à‡pNd?U<l¡ÛSB‘.£’X‰zî@%Œ¾=t)‰è캵¤Û!P|¦ÌA6°ÌM@ñ9‰Ê°ˆ„­'ja´D­”0æŸ! NíT ¾*»æ±Ê»“ÐWTÙô‡wÞ`G.´ûÖÑæÔ)'ä …RXN«s>ÓR4ÐBÛòésŒúÊHëjÍö·Â¨wÕËÛ´@ ʇ¤Œ²ƒ'ò•¨˜°2NSPå±­â‹ÏŒç‹ô9Ù‘3PÌ~P˜è[µ *O„úšdTè ®jÔ3HÄ T€~•Dct`™6„Ÿžµê¬z\§´ÙÁã*I4Á`î2ˆÃJ˜†ƒÕŸºmšN
    l² h4ˆðröbü]é‰17F¥‹˜¡–Ô…±³ÛVÂ[HªcÁÜÖÙÉ+IÔ>ƒ84V? -€|ß$ž'¼åoŽ`¶üùŽXÈÁ€QLàAƒlä»Ü ZÃ𒠝ÜT7 Pó
    á‹%®F=RÀ‰~,“'’葁y2¨ßbUXˆ7L„E¼,qO”§†ë”
    •É¦¨Ëhot0ôÏzÒ
    ÜáTN :a%¨}‚„ühüòžû0–, F-˜l08v{òéÀ6 ÐDöB<N82јˆ&ÔʈÁ:nô p°ž5Q\©ÅäÛnÅÈbÜl=f-œÅI™¦ ‰ÑE-¸,ÐCTcRÏj3¯Ü¬^B1 ¢ÊÑr <cž¼}g+–ÈK£@eM.È×A¦ž­Ìg¼Hà+ç±qV¹ROüX¨0 Ll Æ!GÌqŒ d¬Óî͐Ôy èòŒEè“a¬" æÄ+ècȘönQd¡ÜP d&ª­âÔ+ûe"~ˆ切$0 ÄYõü‹Ö‰Ùä°ŒM–5éLØ2-!„™pìÐ…‰íÈùè£V
    ÔÙ^!À`­ÐBOHBÍUÊPhK2öBž à„h°Ù8rpà¥Ï‡äpΨ1B‡ò¬Vp¶j÷ŒñqʨR\T´6ÁKšMܨ²úÿp‚Æ ó‹¹Ì£6jJ2îÓÛ>0=Ѻù òbГþnßþ
    Xq]Êpœ>90Ý£êÝL>ì!e^KÄ1@‰Æ,9¶© äw›/ËvS+‰p<DL;ÎHcMãʁªqHt{XC•õÒ FÂg¨¾T<È…X …ڐâ‰?˜ßÿ ŽH€ b
  • C : \ W I N D O W S \ S y s t e m 3 2 \ h l p b f o . d l l

    dat bestand moet weg (zoek maar in windows.txt je ziet hem staan)
  • Download hiving.bat.
    Lees ook dit even door: Eigenaar worden van een map of bestand.
    Verbreek de connectie met het internet tot de verwijderprocedure achter de rug is.
    Dubbelklik op hiving.bat om het te starten.
    Na een reboot zou C:\WINDOWS\System32\hlpbfo.dll zichtbaar moeten zijn in je verkenner.
    Bevestig even of dit zo is en dan gaan we verder.

    Gebruik je FAT32 of NTFS?
  • Ik gebruik NTFS

    En moet ik het hlpbfo.dll bestand dan zien staan in veilige modus of gewoon, want gewoon zie ik 'm wel staan in verkenner.
  • OK. Zeker dit lezen dan: Eigenaar worden van een map of bestand. (print het desnoods uit.)
    Is het bestand nu zichtbaar via de verkenner?
  • Ben ff eten, ik zie nu opeens het bestand niet meer in verkenner staan.
  • Smakelijk -TeR-.

    Als het bestand niet zichtbaar is in je verkenner (zorg wel dat alle verborgen bestanden weergegeven worden), verwijder je windows.txt van je buroblad en run appinit.bat opnieuw. Post de inhoud van het nieuwe windows.txt bestand.
  • Thanx, ik heb bij Extra>Mapopies>weergave Beveiligde besturingsbestanden verbergen (aanbevolen) uitgevinkt en verborgen bestanden en mappen weergeven aangevinkt. Het .dll bestand staat er niet tussen, maar als ik in windows commander kijk zie ik 'm wel staan. :)
    Moet ik dat eigenaar worden van een bestand of map nog ff doen. (ik heb 't gelezen).




    regf       Pugf hbin  „h°Ù8rpà¥Ï‡äpΨ1B‡ò¨ÿÿÿnk, †tpæëoÄ ÿÿÿÿ ÿÿÿÿÿÿÿÿ @ x ÿÿÿÿ 0 > ?ÁãL WindowsƒÈþÿÿsk‰Æx x         ì
         !
     €  !      #
     €  #  ?    
         ?   
        ?    
            Qî+ Øÿÿÿvk > Ø   fùAppInit_DLLs֍æG¸ÿÿÿC : \ W I N D O W S \ S y s t e m 3 2 \ h l p b f o . d l l vk  ° Ðÿÿÿvk  X   ceDeviceNotSelectedTimeoutðÿÿÿ1 5 YîQÊðÿÿÿ9 0 | Xv| Ðÿÿÿvk  €'   =pGDIProcessHandleQuotau| àÿÿÿvk  È   trSpoolertðÿÿÿy e s _£ûó ° ( x ¨ ð àÿÿÿvk  €   | swapdiskÐÿÿÿvk  h   TransmissionRetryTimeoutàÿÿÿ° ( x ¨ ð  ` Ðÿÿÿvk  €'   S USERProcessHandleQuotal p o¯cÀ² ðpÁ)„QÀ“ H;UÞÆÀÖÍj Y_‘ ÜA:QÑBÿ>ØU)eÔ³Vf‹úB ü}ëe;ØÏÝqðPGJ".@[,A¢`ÃZ»c
    è8GcÂçËW Œª"ôôQà{>dÐ(¾gƒ³ìWX– Áѧ¨DËÔk»fèPV 7 f;ÁaAžŽ`ŠþíEt3ƒÆ9}ìrj#êoÎçÿs<XðÌô«ö_Ã)j\;ِÑB]F{…Y û{U0O;„FU—Y +Š²…(¯¯þsü³WÀ
    €x\ëf;4y‚hªÚûacÛ´ÝÉ‹>øìK†Q@LÇ~"€‹ðÁæ ð:6öcˆVR^QÙ|[F”¨);äe|FÁ-¨¶ë†[QŸ¦‚vÂÇ…ªo è^_ºÓÊ“å |£Voè.ÆJU‹LP Og¦ø¹ob¿Ù~ô 9x94+ÐaÌ"èzæA—±€#Œ9÷Ÿª>Kµþ¿ÒH$øþûÆË0ЋP àf+p“ãˆ,¸wW‚Ö0ÖÌEHÏf׫ÉÃÜüVë­hð§»Uõì.UÀ@WPúZ–mið#àáâãí»`/ñåXô´ï~±ÆÉ„ aÙ/Gnô´d={á¿Ÿc“O%U<‰„‹»ûXÜÈæ\$
    RÇþØVXˆ>N,S3c±_þÀÏ1ÒjR[€ÃA$¥¦DK…±ìÛ8ªrW@¤Fst;DW^… oÃfT·Ù÷;xs´ý­È(tAx~c'lØo()v™¥… ÿóô⚢6~U‹@ˆØTØ“ƒÜjÿ ,^ߥYÝÚòQd÷ÒöOŠÚôèún@Pë˜Vö¶N³jYWÁFàlÓ§ý=¸MQ'‚< ÜØþ,=b¶ô€}¬-Y¬Çª ^£ïÇkýÒÚ)Èèm ¶
    ùAŒ®ª»gT,VøBBFA^jÑ×Ꮣl¥è×÷C)ƒs
    Oã
    ‚ÙÑÿÉÄŠ@
    ÒuùoÌ°ƒ 1À´ÐÞ}MæÛ{H9‡Xʵ%_XÙ@€íÉ»€FW„VWE‚Ý“ÛßP1,HHo
    W6Ïšw³Z<Ï6ƒø:òÃÌ·KGnÜrÑë]ÃÞ<9# ƒm«¬WêS–eÙ¾+Ò!UÜØÔäì8èí-×+VžTƒ½Ì´†ŽæŒÛ¹âOOÐéuMÞF†®&HX¹]²–ìNê©ðSÔdQËøìZzspPWV1ãÈÇn?¹ð÷|J˜ƒè L7Ö‚úAtPZH es&Úâìê Z†9õêj¢Ÿ¶®ÿVîŸð²5òq­ŠƒÃe?Và…ˆÞu¬·Oâ¾ÀÃ·ôö’AÍЊÿô“À
    „uÈ…LR1Ùac©8ƉË—¨¸… RYÖóª¦B¦±_€±‹Œ;Š ªÙ ×ukñMIúˆÊZ_qrÁð@A惴wx™:;?#£¥ ·GMf
    Û
    • pÒæ
    ¸3ÀJÂ%ͱVä€vB
    IÓ«Æ?
    üø-A÷ÞXxŠá¯$
    ƒý`º,QZ3À¸žãa=À8üüßòH¦0ðd–ÊSÈ÷8Šˆ´ÑæÛ\ qÈÆ7:Š8Ñà'ül&ˆS°“«Æɇ̤.g¼+XŽÍZ$níÆ)URUÿ0tl‡æ%'ÁnÞ]¾<¤+øôªWYìÙ|@> ³¨³­è-”ožôY)k‹o!Ô‰{Eï «–M¦5ëØ¿ø§-¨Ÿ ŠÐÐP`9ãu¨8hV5ŽT4Ó½ÖJ´¦Á~=Ê l|–Š6Ej¼mÆŠ>û‹Ñ
    ›sÙYÅ×AŠ¯YP©cf!dasàHRôX»‰_=Sh8‹ƒ4Ø
    ß:
    ÛÁé Û¿ öu¯ë¦„ÉîZV¨€É€b jWí}—¥j
    i¹[IO…+ ‘éÙ‡wìÅT_aƾE&tåX+E 2¬¸m¹¶ÌÏÙ]3^1vçW²jP]#703ˆ´ ÍøÜú‚Teœ»:5 ƒt˜àŒðGpûa€F8²zÛ>¢«ù@ýÐá}‘±Mt{u¦*~l)`¯\G"€y4–¶ŽÜH ÕcÂe†(€ºÝ”ÜHÃ@ Îø“­4°’VZ)ʹm=\¯8ØlÜÇ‘0BÑ;Ôb ñ`7n´ÚÙ¤YËúÁÝ^P<OUœZÛ=kj.F‚N…Ö¢ƒˆ3“Ó —,ÄmÇœëD>Ü |û ÃøÄóç=½³î~ÐN:LH„“aï‰ê QÈH ɱÇ\j.^Õ&s<@1£!¶
    ã‡@L…
    ‰1Ôp]òf–“àXÕ¢âÒý(:øÔ˜ým;AœZ,9YzcÛAãÔ ¨’ŠMÿ}¶õœ-0]xJËÎ^ã$ʈÚ®´HÁð@º[Š¥UŒÂÈØ·† süµøvä×ÆŸW`
    ÿlÅxBbø\XÜ
    v¡9IÔWÐH[ oQIŠÀˆo(ÉØ×IGÒ`(N €©XK‡Õ}DõØÆòÁ8áˆðG8“é×bŠNBÃÏ9•N@;ÆØ-ZT'ì/…ƒÝ>È€ûz«;RÚ<
    ¿ìŒ~
    èŠZ$¶ƒËöŠAA<*4uÕ"ᩯ5ĤYðc¨]A6¼²PÁ£ÀÎVp‰S*x¯zvÆC¯z6ì©Ç³‚Ìæ(ÃÆ¢ÔÄ¥RO›FÙh…R"y ’ú€Z… B(¡ÒÖhù™÷®Õ–_‚VÐitņŽžÒ)¾ZíX-Þ·¿í>ՁÚÞ±eÑêÑØ-ëHÙä V2¼÷ùhƒYd ÈÔl·ŽÅA‰±ÒKHÃ…àÁno «ÛÒ+Óœ)û6P(¼Që"èI éÓG|Dì ‹Ð{½nð éƁh5Úôƒ>¬‰øObŽ¦áÃÿVÃ3L—~ô¬žÚU¸62À“;ȱM?Ùf·ÐîP_t戊5$¾\Z::sAA8f}‚)Ivp­¹_ lVhß(·N±Ãª‰ÃºŽ…ˆÇ‹Á~QчGªú‹fµ”2c)é0øbŠ½ ªl¯ÙáÆvÃõ0¯é ü_CzؚЊeôPGÙ—ŒU@SUVÓ
    v3<Bz,þÏ:d+žYŠ :P(â|`ƒò«F‰þ)Ί8¡ Ï­;ŠùÚákígËÇp
    KyÅÇ: nø³Ø!ÖrÖ0ˆA<‡£ý@SÔAôÚm¨Ð°€ÔWK§ÆþÜ‹Øv3úzüY-¤ÏϨA85`"ý %ÚþQòj=Æ¥Õ Y>¹ %ò·7¶£ÉÇŠj}¶ù@o°Û+Ç.g¸B)uH[GÐ ¡Œhð`#s+ÜWÔV§:×N
    @€ hûÅ
    ½k€cN
    Z#{bÃнԟՈËõ€é ˆÚ€: >”¹Zs p;ÝPÔ°gŒID ‹~4<±­TýB¶AH(7p–][Ò‹L•0 à?l‡ä›OûUÈ ‡Óô;B/ýÓ€Á "ÁŠÊœˆ UÌ >IÔ.¡IŽ1]dsàŽQìh %£ùRVåÓ g¥´U°‹Ñ“¥ SÿÄn6O°ø¢„h–VV8ìùÅvV°·I =Ù–ÎöhkWЫӞc0#¼WPŠ~}Õ*H×rd…·g¢×‰·ÐÁ+Â÷MmŒ¦X„[ùÃ03ªàŒÎ;ò ·Æèȉz|õ؈Átå<Y¥Yƒm çö.#?ãà@
    É+ÖÛ6½N¢@@‰‹mcl°‹
    4„: ¤ Sð +Á]©`à#<‘ßÄÛÄR[3C8í~ƒû DÔ½7Zá0š0Pî¹i;±1® f­ÃðØ£¹ˆ É-›:d{VÁÕH¾í&1ÈŽŸŠ
    ;à6Ü o à‹fŽ‡ÁñO–XøÎ%ÿXÖ© ÀßWðÅE{réÐÈd’ŽøG§àI<©
    ŸÉgØÚƒªPË}Y pX[ ¤ãÙpb r€ûòPú³ºx¦£ ¸

Beantwoord deze vraag

Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.