![]() |
| ||
| bridge.dll i am having problems with an error message "rundll," and need help with fixing it through hijackthis program, here is the log: Logfile of HijackThis v1.98.2 Scan saved at 3:52:21 PM, on 9/23/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe C:\WINDOWS\system32\msCMTSrvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\WinTools\WToolsS.exe C:\WINDOWS\Explorer.EXE C:\windows\system\hpsysdrv.exe C:\Program Files\VERITAS Software\Update Manager\sgtray.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE C:\WINDOWS\rspcxdyj.exe C:\WINDOWS\System32\jlycle.exe C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE C:\Compaq\EAKDRV\EAUSBKBD.EXE C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe C:\Program Files\NaviSearch\bin\nls.exe C:\Program Files\BullsEye Network\bin\bargains.exe C:\WINDOWS\dhbrwsr.exe C:\Program Files\Common Files\WinTools\WToolsA.exe C:\PROGRA~1\Toolbar\TBPS.exe C:\PROGRA~1\ezula\mmod.exe C:\PROGRA~1\Web Offer\wo.exe C:\PROGRA~1\Toolbar\PIB.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe C:\Program Files\Common Files\WinTools\WSup.exe C:\Program Files\Web_Rebates\WebRebates1.exe C:\Program Files\Web_Rebates\WebRebates0.exe C:\PROGRA~1\MOZILLA.ORG\MOZILLA\MOZILLA.EXE C:\Documents and Settings\Angela\Desktop\HijackThis.exe C:\WINDOWS\system32\NOTEPAD.EXE R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.search-exe.com/nph-sea...=sbar1_srchbtn R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/re...c=2c02&lc=0409 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50168 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.search-exe.com/nph-sea...=sbar1_srchbtn R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=2839 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O2 - BHO: (no name) - SOFTWARE - (no file) O2 - BHO: CSIECore Class - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll O2 - BHO: twaintecObj Class - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll O2 - BHO: (no name) - {00041A26-7033-432C-94C7-6371DE343822} - (no file) O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dll O2 - BHO: Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} - C:\Program Files\Recommended Hotfix - 421701D\v15\RH.DLL O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINDOWS\SYSTEM32\winb2s32.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - (no file) O2 - BHO: CATLEvents Object - {60112085-E1CE-4e0e-823A-EBB1AD98804C} - C:\DOCUME~1\Angela\LOCALS~1\Temp\nibten.dat O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\Angela\LOCALS~1\Temp\nibten.dat O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem302.dll O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll O2 - BHO: (no name) - {ACB3E0B7-7D0C-40B7-99B3-3EEACDF86BFB} - C:\WINDOWS\mslagent\4b_1,0,1,1_mslagent.dll O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll O2 - BHO: (no name) - {BF2AAD80-E0F8-D4C1-C1D6-E77118634662} - C:\WINDOWS\Gijazgzc.dll O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll O2 - BHO: Band Class - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C:\WINDOWS\dealhlpr.dll O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Angela\Local Settings\Temp\7Yxm.dll O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINDOWS\SYSTEM32\winb2s32.dll O3 - Toolbar: Search - {223613D2-2B0C-505F-36CC-7E0A7FA166EC} - C:\WINDOWS\Gijazgzc.dll O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe" O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE O4 - HKLM\..\Run: [kfmbafjf] C:\WINDOWS\rspcxdyj.exe O4 - HKLM\..\Run: [ISAK] C:\WINDOWS\ISAK.exe O4 - HKLM\..\Run: [AKXFP] C:\WINDOWS\AKXFP.exe O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load O4 - HKLM\..\Run: [HR5b6rDI] C:\documents and settings\angela\local settings\temp\HR5b6rDI.exe O4 - HKLM\..\Run: [4S2NSLA3QS#366] C:\WINDOWS\System32\Zubxk.exe O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe" O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain O4 - HKLM\..\Run: [9I8t] C:\documents and settings\angela\local settings\temp\9I8t.exe O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe" O4 - HKLM\..\Run: [ursatbct] C:\WINDOWS\System32\rgyvjaki.exe O4 - HKLM\..\Run: [vmirduiyau] C:\WINDOWS\System32\jlycle.exe O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun O4 - HKLM\..\Run: [ClrSchLoader] C:\PROGRA~1\Lycos\IEagent\Loader.exe O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe O4 - HKLM\..\Run: [Search-Exe] "C:\Program Files\se\v11\se.EXE" /H O4 - HKLM\..\Run: [DealHelperUpdate] C:\WINDOWS\DHUpdt.exe O4 - HKLM\..\Run: [DealHelperBrwsr] C:\WINDOWS\dhbrwsr.exe O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE O4 - HKCU\..\Run: [ClockSync] "C:\Program Files\ClockSync\Sync.exe" /q O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe O4 - HKCU\..\Run: [MyDailyHoroscope] C:\PROGRA~1\MYDAIL~1\MYDAIL~1.EXE O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409 O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} - http://akamai.downloadv3.com/binarie...ia32_EN_XP.cab O16 - DPF: {FB2961FD-DD24-4F8A-8A92-6F9325FF6F11} - http://www.supaseek.com/toolbar/toolbar.cab O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll anyhelp would be great |
| ||
| Re: bridge.dll Download Spybot: Search & Destroy, http://www.majorgeek.com/esselbachfp...a089e94b7b6b55 and get a hold of Norton SystemWorks 2004 and run Norton Windoctor Good Luck |
| ||
| Re: bridge.dll SpyBot alone isn't going to do the trick for that mess... :eek: 1. I don't see any indication in your log that you're currently running any anti-virus software at all. Get your hands on a good anti-virus program which also detects adware and spyware components. Both Norton (Symantec) and McAffe make such products. 2. Download Ad Aware and Spybot Search & Destroy; the download links are in my sig below. 3. Open Ad Aware and click the "Check for updates now" option on the main startup page; follow the prompts to install the most current reference file. 4. Open SpyBot and get the latest updates for it by clicking the "Search for updates" option. Once it finishes updating, close the program. 5. Delete the contents of all Cookies, Temporary Internet Files, and Temp folders, and empty your Recycle Bin. 6. Reboot into Safe Mode. You do this by hitting the F8 key as the computer is booting. 7. Run SpyBot; have it fix everything it finds. 8. Reboot into safe mode again. 9. Run Ad Aware. Once it finishes its scan, select all of the items it finds and have Ad Aware delete them. 10. Reboot normally, run HJT again, and post a fresh log. |
| ||
| Re: bridge.dll BLECH! I'm not normally one to suggest this, but you might just want to go ahead and go for the jugular: consider backing up your data, reformatting your drive, and reinstalling Windows. Even after doing all of DMR's suggestions, you still might not end up with a "clean" system. What are you doing with that machine, anyways? |
| ||
| Re: bridge.dll Quote:
Not exactly the most technical of assessments, but I couldn't have put it any better myself. In all seriousness though- while the log does indicate heavy infestation, it is most likely fixable without a total reinstall if you don't to take the "shotgun" approach. |
| ||
| my new log i still havent got around to an anti-virus program yet, but very very soon. this is my new log after following DMR's suggestions. Logfile of HijackThis v1.97.7 Scan saved at 12:54:02 PM, on 9/29/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\windows\system\hpsysdrv.exe C:\Program Files\VERITAS Software\Update Manager\sgtray.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE C:\WINDOWS\System32\RUNDLL32.exe C:\Program Files\VVSN\VVSN.exe C:\Program Files\WildTangent\Apps\GameChannel.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe C:\WINDOWS\system32\msCMTSrvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE C:\Compaq\EAKDRV\EAUSBKBD.EXE C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe C:\Program Files\mozilla.org\Mozilla\mozilla.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Julia\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/googlesidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/googlesidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/re...c=2c02&lc=0409 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://image73.eguard.com/lowermybil...nt23491-0.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file) N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Julia\Application Data\Mozilla\Profiles\default\d8cv7sr5.slt\prefs.js) O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O2 - BHO: (no name) - SOFTWARE - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - (no file) O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file) O2 - BHO: (no name) - {BF2AAD80-E0F8-D4C1-C1D6-E77118634662} - C:\WINDOWS\Gijazgzc.dll O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll (file missing) O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file) O3 - Toolbar: Search - {223613D2-2B0C-505F-36CC-7E0A7FA166EC} - C:\WINDOWS\Gijazgzc.dll O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe" O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE O4 - HKLM\..\Run: [kfmbafjf] C:\WINDOWS\rspcxdyj.exe O4 - HKLM\..\Run: [HR5b6rDI] C:\documents and settings\angela\local settings\temp\HR5b6rDI.exe O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain O4 - HKLM\..\Run: [9I8t] C:\documents and settings\angela\local settings\temp\9I8t.exe O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe -z O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O9 - Extra button: AIM (HKLM) O9 - Extra button: MoneySide (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409 O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} - http://akamai.downloadv3.com/binarie...ia32_EN_XP.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {FB2961FD-DD24-4F8A-8A92-6F9325FF6F11} - http://www.supaseek.com/toolbar/toolbar.cab thank you very much for all the help |
| ||
| Re: bridge.dll I missed a couple of things in my last post- take care of these before we proceed: 1. You are running an older version of HijackThis. Please download the latest version (1.98.2) and use that instead, as it does a more thorough job of detecting and reporting than previous versions. Post a new log from that version. 2. You are running HijackThis directly from your Desktop folder, which is not advised. Please create a separate, distinct folder for HijackThis and run it from there. The folder should not be created within any Temp or Temporary folders; something like C:\HijackThis or C:\downloads\HijackThis will do. |
| ||
| ver. 1.98.2 log ok here is the new log: Logfile of HijackThis v1.98.2 Scan saved at 3:07:42 PM, on 9/29/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE C:\WINDOWS\System32\RUNDLL32.exe C:\Program Files\VVSN\VVSN.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe C:\WINDOWS\system32\msCMTSrvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE C:\Compaq\EAKDRV\EAUSBKBD.EXE C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe C:\Program Files\mozilla.org\Mozilla\Mozilla.exe C:\Hijackthis\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/googlesidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/googlesidesearch.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/re...c=2c02&lc=0409 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://image73.eguard.com/lowermybil...nt23491-0.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file) N2 - Netscape 6: user_pref("browser.startup.homepage", "www.msn.com"); (C:\Documents and Settings\Julia\Application Data\Mozilla\Profiles\default\d8cv7sr5.slt\prefs.js) N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Julia\Application Data\Mozilla\Profiles\default\d8cv7sr5.slt\prefs.js) O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O2 - BHO: (no name) - SOFTWARE - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - (no file) O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file) O2 - BHO: (no name) - {BF2AAD80-E0F8-D4C1-C1D6-E77118634662} - C:\WINDOWS\Gijazgzc.dll O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll (file missing) O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file) O3 - Toolbar: Search - {223613D2-2B0C-505F-36CC-7E0A7FA166EC} - C:\WINDOWS\Gijazgzc.dll O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe" O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE O4 - HKLM\..\Run: [kfmbafjf] C:\WINDOWS\rspcxdyj.exe O4 - HKLM\..\Run: [HR5b6rDI] C:\documents and settings\angela\local settings\temp\HR5b6rDI.exe O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain O4 - HKLM\..\Run: [9I8t] C:\documents and settings\angela\local settings\temp\9I8t.exe O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe -z O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409 O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} - http://akamai.downloadv3.com/binarie...ia32_EN_XP.cab O16 - DPF: {FB2961FD-DD24-4F8A-8A92-6F9325FF6F11} - http://www.supaseek.com/toolbar/toolbar.cab |
| ||
| Re: bridge.dll OK, this will take a bit due to the number of problems you have, but: 1. Close/quit all open programs. 2. Run HJT again and have it fix the following: R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/googlesidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/googlesidesearch.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/r...&c=2c02&lc=0409 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://image73.eguard.com/lowermybi...ent23491-0.html R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file) O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O2 - BHO: (no name) - SOFTWARE - (no file) O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - (no file) O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file) O2 - BHO: (no name) - {BF2AAD80-E0F8-D4C1-C1D6-E77118634662} - C:\WINDOWS\Gijazgzc.dll O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll (file missing) O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file) O3 - Toolbar: Search - {223613D2-2B0C-505F-36CC-7E0A7FA166EC} - C:\WINDOWS\Gijazgzc.dll O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file) O4 - HKLM\..\Run: [kfmbafjf] C:\WINDOWS\rspcxdyj.exe O4 - HKLM\..\Run: [HR5b6rDI] C:\documents and settings\angela\local settings\temp\HR5b6rDI.exe O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain O4 - HKLM\..\Run: [9I8t] C:\documents and settings\angela\local settings\temp\9I8t.exe O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} - http://akamai.downloadv3.com/binari...tia32_EN_XP.cab O16 - DPF: {FB2961FD-DD24-4F8A-8A92-6F9325FF6F11} - http://www.supaseek.com/toolbar/toolbar.cab Today 01:19 PM 3: Reboot into safe mode and: - Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files". - For every user account listed under C:\Documents and Settings, delete everything inside the following folders (don't delete the folders themselves though): 1. Local Settings\Temp 2. Cookies 3. History 4. Local Settings\Temporary Internet Files\Content.IE5 - Delete the entire content of your C:\Windows\Temp folder. (If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll be automatically regenerated by Windows if needed.) - Delete these folders entirely: C:\Program Files\Toolbar C:\Program Files\WildTangent C:\Program Files\NaviSearch C:\Program Files\VVSN - Search your system for all of the .exe and .dll files mentioned in the HJT entries I listed above. If you find any of those files still on your sytem, delete them. - Empty your Recycle Bin. - Reboot normally. 4. If you haven't been able to install an anti-virus program yet, get a free online virus scan: http://housecall.trendmicro.com/ http://www.pandasoftware.com/activescan/ 5. Run HJT again and post a fresh log. |
| ||
| Re: bridge.dll Help protect your system, download, install, and update SpywareBlaster from here: http://www.javacoolsoftware.com/spywareblaster.html Have it enable all protection. Get an antivirus program installed ASAP. Make sure your firewall is enabled (instructions here): http://www.javacoolsoftware.com/spywareblaster.html |
| All times are GMT -4. The time now is 10:46 am. |
Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC