After the computer completes start-up, I get the following error message:

"RUNDLL: (Error loading C:\windows\system 32\bridge.dll. The specified module could not be found.)"

I'm not sure, but I believe the problem may have started after installing and running the latest versions of "Ad-aware 6.0" and few similar like that then deleting the problem items that were found.

Any help removing this problem from my computer would be greatly appreciated.

I thank you in advance...

Dani AI

Generated

Brief expert summary and a safe, practical cleanup checklist.

As suggested, that kind of startup error is normally a leftover startup reference left after spyware or an ActiveX/toolbar file was removed. Removing the broken startup reference is the immediate fix, then confirming the system is clean prevents reappearance. The HijackThis log posted by shows this is often part of a larger cleanup (toolbars, fake “update” items), so treat the system holistically rather than deleting a single key and assuming the job is done.

Safe cleanup checklist

  1. Backup first — export the registry keys you will edit and copy any important files to external media. Note: Windows 2000 does not have an XP-style System Restore, so a manual backup is critical.
  2. Reboot to Safe Mode (F8) to reduce running processes.
  3. Inspect startup items with a trusted tool (msconfig or Sysinternals Autoruns). Look under logon/startup for entries that reference missing files and disable/remove those entries.
  4. If editing the registry, only remove entries from the standard Run keys (export them first): HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Do not delete other keys.
  5. Check the platform’s Downloaded Program Files folder and system folders for remnants and remove only the files you can positively identify as the removed component.
  6. Run a full scan with an up-to-date antivirus plus a current anti-malware scanner to find any other traces. Repeat scans after reboot.
  7. If the error persists, produce a current HijackThis or Autoruns log and post it in its own forum thread (do not piggyback). That will allow targeted advice without risking removal of legitimate entries.

Cautions: always export registry keys before change, avoid guessing at unfamiliar entries, and prefer disabling entries first so they can be restored if needed.

Recommended Answers

All 6 Replies

Hi drajpatel, welcome to DaniWeb :)

I believe the problem may have started after installing and running the latest versions of "Ad-aware 6.0" and few similar like that then deleting the problem items that were found.

Good call- that's exactly right. "bridge.dll" is a spyware component, and while AdAware, etc. have removed the actual bridge.dll file, there is still a reference to the file in your Windows Registry.
You may also have other "loose ends" remaining on your system; please do the following so that we determine if that's true or not:

Download the free utility:

Once downloaded, follow these instructions to install and run the program:

Create a folder for HJT outside of any Temp/Temporary folders and move HijackThis.exe to that folder now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.

Run HijackThis, but do not have HJT fix anything yet; only have it scan your system! Once the scan is complete, the "Scan" button will turn into an option to "Save log...".
Save the log in the folder you created for HijackThis; the saved file will be named "hijackthis.log". Open the log file with Windows Notepad, and cut-n-paste the entire contents of the Notepad file here.

The log contents will tell us a lot about what "nasties" have crept into your system, and once we analyse the log we can tell you what to do from there. We can also tell you how to use HijackThis to fix the "bridge.dll" error.

Logfile of HijackThis v1.99.1
Scan saved at 1:49:44 PM, on 12/17/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Common Files\Real\Update_OB\rndal.exe
F:\ipod\itunes\iTunesHelper.exe
U:\program files\quicktime\qttask.exe
F:\ipod\bin\iPodService.exe
U:\program files\logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
U:\program files\logitech\SetPoint\KEM.exe
U:\program files\logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Aim\aim.exe
C:\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINNT\system32/left.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xmradio.com/xstream/service/account/index.jsp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [CrazyTalk Serve] rundll32.exe C:\WINNT\System32\crazytalk.dll,DllServeMediaFile
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [RunWindowsUpdate] C:\WINNT\uptodate.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\Downloaded Program Files\bridge.dll",Load
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "F:\ipod\itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "U:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKCU\..\Run: [LDM] U:\program files\logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - Global Startup: InterVideo WinCinema Manager.lnk = InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = U:\program files\logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = U:\program files\logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &iSearch The Web - res://C:\WINNT\system32\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\Aim\aim.exe
O16 - DPF: Yahoo! Pool 2 -
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - http://toolbar.isearch.com/general/drm.cab
O16 - DPF: {1CC506A7-1B8D-11D4-BDD5-0060977007E0} (CrazyTalk Player) -
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) -
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} -
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = zooville
O17 - HKLM\System\CCS\Services\Tcpip\..\{06E088B0-49A0-415D-8C6E-35C6E72CBD8C}: Domain = zooville
O17 - HKLM\System\CCS\Services\Tcpip\..\{06E088B0-49A0-415D-8C6E-35C6E72CBD8C}: NameServer = ,
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = zooville
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = zooville,mindspring.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{06E088B0-49A0-415D-8C6E-35C6E72CBD8C}: Domain = zooville
O17 - HKLM\System\CS1\Services\Tcpip\..\{06E088B0-49A0-415D-8C6E-35C6E72CBD8C}: NameServer = ,
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = zooville
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = zooville,mindspring.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{06E088B0-49A0-415D-8C6E-35C6E72CBD8C}: Domain = zooville
O17 - HKLM\System\CS2\Services\Tcpip\..\{06E088B0-49A0-415D-8C6E-35C6E72CBD8C}: NameServer = ,
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = zooville,mindspring.com
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\ipod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

Hi nooklogan,

First of all- welcome to TechTalk :)

We ask that members not tag their questions on to a thread previously started by another member (regardless of how similar your problem might seem). Not only does it divert the focus of the thread away from the original poster's problem, but it also makes it less likely that you yourself will get the individual attention that you need.

Please start your own thread and post your HijackThis log in that thread. Once you start the new thread, we will assist you there.

For a full description of our posting guidelines and general rules of conduct, please see this page:

http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq#faq_rules


Thanks for understanding.

Namine, please start a new thread with this problem.

Don't 'piggyback' onto another thread.

We'll help ya in the new thread.

Thanks.

How come i cant download the Hijack utility i have the exact same problem

Hi Bonoreborn.

First of all- welcome to Daniweb :).

We ask that members not piggy-back questions on to a thread previously started by another member here in the Viruses, Spyware & other Nasties forum, (regardless of how similar your problem might seem). Not only does it divert the focus of the thread away from the original poster's problem, but it also makes it less likely that you yourself will get the individual attention that you need.

Please start your own thread and post your question there. When you do, please try to give us as much specific info as possible regarding the problem (exact error messages, system specs, etc.).

For a full description of our posting guidelines and general rules of conduct, please see this page:

http://www.daniweb.com/forums/faq.php?faq=daniweb_policies


Thanks for understanding.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.