| | |
Bridge.dll
![]() |
•
•
Join Date: Jun 2004
Posts: 9
Reputation:
Solved Threads: 0
Hello everyone,
Bridge.dll keeps on coming out everytime I restarted my computer. I tried to search for a solution to this and I found out this forum. I already run Hijackthis and this is the log.
Logfile of HijackThis v1.98.0
Scan saved at 9:05:01 AM, on 6/30/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\FIVEAN~1\Active play.exe
C:\Program Files\Microsoft Firewall Client\ISATRAY.EXE
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\sea\client\BIN\siebel.exe
C:\sea\client\BIN\siebel.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\RODERI~1.SAT\LOCALS~1\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search200.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sykesasia.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search200.com/searchbar.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = PHCEBISA001:8080
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\roderick.satina\Application Data\Mozilla\Profiles\default\oeum7pbu.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\roderick.satina\Application Data\Mozilla\Profiles\default\oeum7pbu.slt\prefs.js)
O1 - Hosts: 64.28.155.62 ussmcc004
O1 - Hosts: 64.28.155.126 ussmcc005
O1 - Hosts: 64.28.155.60 crmsvc00.palmone.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Send Poke - {3BCF8BBF-8BBF-ED11-82F6-F513D2FF2DAE} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Chic cool - {F8A9C87E-8DA3-4000-2A20-11F49295EA00} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRONoMgrWired] c:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\system32\bridge.dll",Load
O4 - HKLM\..\Run: [boobmix] C:\PROGRA~1\FIVEAN~1\Active play.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Program Files\Microsoft Firewall Client\ISATRAY.EXE
O4 - Global Startup: palm.bat
O14 - IERESET.INF: START_PAGE_URL=http://www.sykesasia.com
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.roings.com/cabs/mp3.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = apac.sykes.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = apac.sykes.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = apac.sykes.com
I would greatly appreaciate if someone can help me with this.
Thanks.
Bridge.dll keeps on coming out everytime I restarted my computer. I tried to search for a solution to this and I found out this forum. I already run Hijackthis and this is the log.
Logfile of HijackThis v1.98.0
Scan saved at 9:05:01 AM, on 6/30/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\FIVEAN~1\Active play.exe
C:\Program Files\Microsoft Firewall Client\ISATRAY.EXE
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\sea\client\BIN\siebel.exe
C:\sea\client\BIN\siebel.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\RODERI~1.SAT\LOCALS~1\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search200.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sykesasia.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search200.com/searchbar.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = PHCEBISA001:8080
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\roderick.satina\Application Data\Mozilla\Profiles\default\oeum7pbu.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\roderick.satina\Application Data\Mozilla\Profiles\default\oeum7pbu.slt\prefs.js)
O1 - Hosts: 64.28.155.62 ussmcc004
O1 - Hosts: 64.28.155.126 ussmcc005
O1 - Hosts: 64.28.155.60 crmsvc00.palmone.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Send Poke - {3BCF8BBF-8BBF-ED11-82F6-F513D2FF2DAE} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Chic cool - {F8A9C87E-8DA3-4000-2A20-11F49295EA00} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRONoMgrWired] c:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\system32\bridge.dll",Load
O4 - HKLM\..\Run: [boobmix] C:\PROGRA~1\FIVEAN~1\Active play.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Program Files\Microsoft Firewall Client\ISATRAY.EXE
O4 - Global Startup: palm.bat
O14 - IERESET.INF: START_PAGE_URL=http://www.sykesasia.com
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.roings.com/cabs/mp3.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = apac.sykes.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = apac.sykes.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = apac.sykes.com
I would greatly appreaciate if someone can help me with this.
Thanks.
Hi. Just to let you know, there is a thread at the top of this forum dealing with bridge.dll
but as you have other problems as well, we will give you a fix
.
Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or directly on the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search200.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search200.com/searchbar.html
O2 - BHO: Send Poke - {3BCF8BBF-8BBF-ED11-82F6-F513D2FF2DAE} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O3 - Toolbar: Chic cool - {F8A9C87E-8DA3-4000-2A20-11F49295EA00} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\system32\bridge.dll",Load
O4 - HKLM\..\Run: [boobmix] C:\PROGRA~1\FIVEAN~1\Active play.exe
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.roings.com/cabs/mp3.cab
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
C:\PROGRA~1\FIVEAN~1< folder
C:\PROGRA~1\COMPWI~1< folder
Reboot normally.
Plz do the following also.
Lop.com uninstaller.
http://lop.com/new_uninstall.exe
but as you have other problems as well, we will give you a fix
.Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or directly on the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search200.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search200.com/searchbar.html
O2 - BHO: Send Poke - {3BCF8BBF-8BBF-ED11-82F6-F513D2FF2DAE} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O3 - Toolbar: Chic cool - {F8A9C87E-8DA3-4000-2A20-11F49295EA00} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\system32\bridge.dll",Load
O4 - HKLM\..\Run: [boobmix] C:\PROGRA~1\FIVEAN~1\Active play.exe
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.roings.com/cabs/mp3.cab
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
C:\PROGRA~1\FIVEAN~1< folder
C:\PROGRA~1\COMPWI~1< folder
Reboot normally.
Plz do the following also.
Lop.com uninstaller.
http://lop.com/new_uninstall.exe
•
•
Join Date: Jun 2004
Posts: 9
Reputation:
Solved Threads: 0
Thank you so much for your reply crunchie..
This is my first time actually to join in a forum that's why I'm not that familiar with the thread or something..I was having a problem creating a new thread before, it took me about 10 minutes because as I've said I'm not familiar or I'm not used to join in a forum..but anyways, thank you so much crunchie for your time..
I did what your told me to do and it works!!I also did the Lop.com uninstaller. I would like to ask, what would the lop.com uninstaller do to the computer?is it like the adaware or spybot?what does it do?
This is my first time actually to join in a forum that's why I'm not that familiar with the thread or something..I was having a problem creating a new thread before, it took me about 10 minutes because as I've said I'm not familiar or I'm not used to join in a forum..but anyways, thank you so much crunchie for your time..
I did what your told me to do and it works!!I also did the Lop.com uninstaller. I would like to ask, what would the lop.com uninstaller do to the computer?is it like the adaware or spybot?what does it do?
Lop uninstaller does just what it says. Removes any Lop installs & leftovers from your computer. As you have probably guessed, Lop is an uninvited guest. (No pun intended
)
) ![]() |
Similar Threads
- Removing Bridge.dll (Web Browsers)
- What is BRIDGE.DLL (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: hijackthis log
- Next Thread: About:Blank hijack (homeoldsp)
Views: 2347 | Replies: 4
| Thread Tools | Search this Thread |
Tag cloud for Viruses, Spyware and other Nasties
acrobat adware anti-malware anti-virussitesaccessissue antivirus apple attack avg backtoschoolspeech bar blackhat botnet botnets censorship china combofix commercial conficker control cybercrime cyberwarfare ddos education email europe exam exploit explorer facebook fake fancheckvirus firefox gtaiv halloween herss.exe hijack hosting ie8 internet iphone links logfiles malware mcafee microsoft mobile msn nazi news norton obama onlinethreats paedophile panel parents patch pc pdf policeprovirusmba-mblockedinternetaccess president privacy pro redirect redirecting report research rogueantivirus rootkit samhain sans scareware search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans symantec system teen threat translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses vista vulnerability war warning windows worm yahoo zero-day zeroday






