-1

HI THERE

I also when I boot up my computer, a RUNDLL window pops up stating "error loading "C:\WINDOWS\SYSTEM\BRIDGE.DLL" the system cannot find the file specified.
THIS IS MY LOG, please help meeeeeeeeeeeeeeeee!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!


Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Symantec_Client_Security\Symantec AntiVirus2\DefWatch.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\Archivos de programa\Symantec_Client_Security\Symantec AntiVirus2\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
C:\ARCHIV~1\SYMANT~1\SYMANT~1\vptray.exe
C:\winnt\msbb.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\ARCHIV~1\Grisoft\AVG6\AVGCC32.EXE
C:\ARCHIV~1\Grisoft\AVG6\avgw.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\ARCHIV~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis1977\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotbar.com/dyn/hotbar/3....rchPageHome.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vênculos
F0 - system.ini: Shell=
F2 - REG:system.ini: Shell=
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\Downloaded Program Files\bridge.dll",Load
O4 - HKLM\..\Run: [vptray] C:\ARCHIV~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [wzmhuryf] C:\WINNT\wzmhuryf.exe
O4 - HKLM\..\Run: [alchem] C:\WINNT\alchem.exe
O4 - HKLM\..\Run: [msbb] C:\winnt\msbb.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.c...8111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/...ash/swflash.cab

THANK YOUUUUUUUUUUUUUUUUUUUUUUUUUU
:cry:

4
Contributors
12
Replies
13
Views
13 Years
Discussion Span
Last Post by DMR
0

guata,

You've now posted this question in no less that 3 different threads as far as I can tell. Please read the "Forum rules when posting" Announcement at the top of each forum to familiarize yourself them, especially these:

"Do not flood the forum
Do not flood the forum posting the same question in multiple forums, or multiple ways. All that happens is it gets confusing. It's a lot easier for everyone to get the answers they need if everything is kept in one place."

and:

"Post in the correct place
There are more than enough forums here for everyone to find somewhere suitable to post their computer support related questions. Please take the extra minute to make sure you are correctly posting in the correct place. Every question or new thought should have its own thread. Replies to a previous post should be thread replies to that particular thread. Do not piggyback threads by posting your question as a reply to another question. Any threads in an unsuitable forum will be moved to another at the administrator's/moderator's discretion."

Please keep this question in this thread form now on; I'm deleting your duplicate posts in the other threads.

Thanks for understanding.

:)

0

I AM SOOOOOOOOOOOO SORRYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
I AM A NEW MEMBER HERE
SORRYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
I wont do it anymore
:rolleyes:

0

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotbar.com/dyn/hotbar/3....rchPageHome.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vênculos
F0 - system.ini: Shell=
F2 - REG:system.ini: Shell=

O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)

O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\Downloaded Program Files\bridge.dll",Load
O4 - HKLM\..\Run: [wzmhuryf] C:\WINNT\wzmhuryf.exe
O4 - HKLM\..\Run: [alchem] C:\WINNT\alchem.exe
O4 - HKLM\..\Run: [msbb] C:\winnt\msbb.exe

Reboot into safe mode following the instructions here & navigate to & delete

C:\WINNT\wzmhuryf.exe< file
C:\WINNT\alchem.exe< file
C:\winnt\msbb.exe< file

Reboot normally after doing the above then post a fresh log plz.

0

HEY! THANKKKKKKKKKKKKKKK YOUUUUUUUUUUUUUUUUUUUUUUU
I DONT GET THE ERROR ANYMORE
Anyway...I wasn´t able to check this (on the HIJACK box)
04 - HKLM\..\Run: [msbb] C:\winnt\msbb.exe ....because when I scanned that box wasn't there!!!!!

Same thing when I did a reboot in safe mode I wasn´t able to delete this files C:\WINNT\wzmhuryf.exe< file
C:\WINNT\alchem.exe< file
C:\winnt\msbb.exe< file .... due they weren't there

Anyway here is my log, please tell me if i need to do something extra
AND THANKS AGAIN! LOVE YA


Logfile of HijackThis v1.97.7
Scan saved at 0:03:25, on 12-05-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\VetMsgNT.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\unzipped\hijackthis1977\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/dialercab/WebRecomendada.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/es/SysWebTelecom.cab

0

You got two more already. Have hijackthis fix these:

O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/diale...Recomendada.cab
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/es/SysWebTelecom.cab

Download & install spywareblaster from www.javacoolsoftware.com to prevent these installs. Keep it updated regularly.

Also, it looks like you have two anti virus programs running. You should take one off the start up menu as they may conflict. Use one as an on-demand scanner.

0

OK
I downloaded the file you mention, I will keep it uploaded
This is my new log
Am I on now? :eek:
Logfile of HijackThis v1.97.7
Scan saved at 3:09:00, on 12-05-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\VetMsgNT.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\Yahoo!\Messenger\YPager.exe
C:\Archivos de programa\Soulseek\slsk.exe
C:\Archivos de programa\WinMX\WinMX.exe
C:\WINNT\explorer.exe
C:\Archivos de programa\Winamp\Winamp.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\SpywareBlaster\spywareblaster.exe
C:\unzipped\hijackthis1977\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab


THANKS AGAIN, you are the best! :D

0

I also stopped one of the antivirus from Start-up!!!!!

0

Looks ok now.

From answers that work:

These two background programs implement the OCR Aware feature of OmniPage in the later versions of OmniPage (this is called OmniPage/OCR Aware in other versions of OmniPage). This feature inserts the Acquire Text option in the File menu of Office Suites (Microsoft Office, Lotus SmartSuite, Corel WordPerfect). By clicking on "Acquire Text" you can scan a page of text and have it OCR’ed by OmniPage straight into your wordprocessor, spreadsheet, or presentation, all in one operation. When it works it is a great feature and a much simpler operation than opening OmniPage, scanning, converting, and saving into a file.

Recommendation :
Unfortunately there are many documented conflicts between these background programs and other applications such as applications using your modem (!!), or other applications which need to use the scanner. Our recommendation, therefore, is that, unless you do a lot of conversion-to-text scanning (OCR) and you are not experiencing general PC problems or problems with other programs, then you should disable this feature and get used to manually opening OmniPage to scan text. You can disable the feature as follows :
(1) Open OmniPage.
(2) Choose the "Tools \ OCR Aware" menu option.
(3) Remove the check mark against the "Enable OCR Aware" option.

0

THANK YOU THANK YOU THANK YOUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
LOVE U!!!!!

One question: I should be let the SPYWAREBLASTER running (open) when I use the computer or just I must update it!???
THANKS AGAIN , HUGS FROM SANTIAGO; CHILE

this is my new log
Logfile of HijackThis v1.97.7
Scan saved at 14:05:48, on 12-05-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\VetMsgNT.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Archivos de programa\Soulseek\slsk.exe
C:\Archivos de programa\WinMX\WinMX.exe
C:\WINNT\explorer.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\Yahoo!\Messenger\YPager.exe
C:\Archivos de programa\ZMatrix\matrix.exe
C:\ARCHIV~1\Grisoft\AVG6\AVGCC32.EXE
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Winamp\Winamp.exe
C:\unzipped\hijackthis1977\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Startup: ZMatrix.lnk = C:\Archivos de programa\ZMatrix\matrix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: Bajar web con LeechGet - file://C:\Archivos de programa\LeechGet 2004\\Parser.html
O8 - Extra context menu item: Descargar usando el Asistente de Descargas - file://C:\Archivos de programa\LeechGet 2004\\Wizard.html
O8 - Extra context menu item: Descargar usando LeechGet - file://C:\Archivos de programa\LeechGet 2004\\AddUrl.html
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

0

Just check for updates once a week (it has it's own update checker) . It does not have to be running for it to work, so only open it to update it.
No worries either, am happy to help.

0

hi, i'm having the same problem on another computer in my house. but it also won't connect to the internet so it is a little difficult to get the logs and all of that. it probably isn't connected with the bridge.dll error (not being able to get the internet), but i need this done anyway

the log:

Logfile of HijackThis v1.97.7
Scan saved at 6:26:47 PM, on 5/19/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\ATI Multimedia\main\launchpd.exe
A:\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
O1 - Hosts: 207.36.196.189 auto.search.msn.com
O1 - Hosts: 207.36.196.189 search.netscape.com
O1 - Hosts: 207.36.196.189 ieautosearch
O1 - Hosts: €J¼€J¼`¼`¼˜¼˜¼¼¼x¼x¼èƼÿ¼È˼È˼X]¼X]¼`û¼`û¼0ž¼sؼؼ¼¼è¼è¼ð¼ð¼ø¼ø¼ ˆ¼¼¼˜¼˜¼¼¼¨¼¨¼°¼°¼¸¼¸¼À¼À¼È¼È¼¼¼Ø¼Ø¼¼¼è¼è¼ð¼ð¼ø¼ø¼
O1 - Hosts: ¼˜¼˜¼¼¼¨¼¨¼°¼°¼¸¼¸¼À¼À¼È¼È¼¼¼Ø¼Ø¼¼¼è¼è¼ð¼ð¼ø¼ø¼
O1 - Hosts: ¼˜¼˜¼,s,s¨¼¨¼°¼°¼¸¼¸¼À¼À¼È¼È¼¼¼Ø¼Ø¼¼¼è¼è¼ð¼ð¼ø¼ø¼
O1 - Hosts: øz„î xɀɀɈɈÉÉɘɘÉÉɨɨɰɰɸɸÉÀÉÀÉÈÉÈÉÉÉØÉØÉÉÉèÉèÉðÉðÉøÉøÉ ˆÉÉɘɘÉÉɨɨɰɰɸɸÉÀÉÀÉÈÉÈÉÉÉØÉØÉÉÉèÉèÉðÉðÉøÉøÉ
O1 - Hosts: ɘɘÉÉɨɨɰɰɸɸÉÀÉÀÉÈÉÈÉÉÉØÉØÉÉÉèÉèÉðÉðÉøÉøÉ
O1 - Hosts: €JÈ€JÈÈȘȘÈÈȨȨȰȰȸȸÈÀÈÀÈÈÈÈÈÈÈØÈØÈÈÈèÈèÈðÈðÈøÈøÈ ˆÈÈȘȘÈÈȨȨȰȰȸȸÈÀÈÀÈÈÈÈÈÈÈØÈØÈÈÈèÈèÈðÈðÈøÈøÈ
O1 - Hosts: ȘȘÈÈȨȨȰȰȸȸÈÀÈÀÈÈÈÈÈÈÈØÈØÈÈÈèÈèÈðÈðÈøÈøÈ
O1 - Hosts: €J¸€J¸¸¸˜¸˜¸¸¸¨¸¨¸°¸°¸¸¸¸¸À¸À¸È¸È¸¸¸Ø¸Ø¸¸¸è¸è¸@S¸@S¸ø¸ø¸ ˆ¸¸¸˜¸˜¸¸¸¨¸¨¸°¸°¸¸¸¸¸À¸À¸È¸È¸¸¸Ø¸Ø¸¸¸è¸è¸ð¸ð¸ø¸ø¸
O1 - Hosts: ¸˜¸˜¸¸¸¨¸¨¸°¸°¸¸¸¸¸À¸À¸È¸È¸¸¸Ø¸Ø¸¸¸è¸è¸ð¸ð¸ø¸ø¸
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\system32\bridge.dll",Load
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ATI TV (HKLM)
O9 - Extra button: AIM (HKLM)
O10 - Broken Internet access because of LSP provider 'c:\winnt\system32\inetadpt.dll' missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab

0

dofml,

This being your first post I'm sure that you aren't aware of our posting guidelines, but we do ask that members not tag their questions on to a thread previously started by another member. Answering multiple members' problems in a single thread can quickly get quite confusing.

Please post this question in its own thread, and have a read through the "Forum rules when posting" announcement at the top of each forum's main page for more info on our general guidelines for using this forum.


Thanks,

-DMR

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.