alc6379 120 Cookie... That's it Team Colleague

UPDATED 10-02-04-- UPDATED REMOVAL INSTRUCTIONS

Welcome to TechTalkForums!

Many new members have been attracted to our site, presumably as the result of a Google search for bridge.dll, showing up on their PCs at startup.


UPDATE:

Before posting an HJT log, just run a scan with HiJackThis and look for this line:

O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\system32\bridge.dll",Load

Place a check in the box to the left of that, and see if it doesn't fix your issue.
If the entry is also in the 02 line of the hijackthis log, you may need to go to C:\WINDOWS\system32 & delete the file manually as well. At the least, go there to see if it is still there.


___________________________________________________________

BEFORE POSTING A HiJackThis LOG, PLEASE REVIEW THE FOLLOWING LINK:
Link no longer valid-- try the link below:
http://www.2-spyware.com/file-bridge-dll.html

Click to close that popup that comes up, and there's information then.

Bridge.dll is related to WinFavorites, which apparently is spyware. The above link tells you exactly what to do to resolve the issue. If this doesn't fix your problem, THEN AND ONLY THEN should you ask for help. Also, you should only post an HJT log if asked for one.

HiJackThis is an excellent tool, but only in the hands of a user skilled enough to interpret the results. It is unfair just to post an HJT log and basically say, "fix it!". These posts don't contribute anything to the community we're trying to build here, and it indicates a lack of initiative on the part of the original poster, basically showing that the user isn't interested in learning anything, only having their problem fixed. That's not the type of user we want to foster here...

So, before posting an HJT log about bridge.dll, please follow the above link. In case you missed it, here it is again:
Link no longer valid-- try the link below:
http://www.2-spyware.com/file-bridge-dll.html


Thanks,
--The TechTalkForums staff

Dani AI

Generated

Adding a quick playbook that complements ’s note and helps you remove the rest of the Bridge/WinFavorites remnants that often survive a single HijackThis fix.

What you are seeing as bridge.dll is an Internet Explorer Browser Helper Object named “brdg Class” with this CLSID: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF}. It is associated with the WinFavorites adware and typically lands in C:\Windows\System32 or in Downloaded Program Files. (systemlookup.com)

If the O4 “rundll32 ... bridge.dll,Load” entry keeps returning or you still see an O2 BHO entry, clean up these additional artifacts:

  • Remove the BHO registry key (run from an elevated cmd). (dll-files.com)
reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF}" /f
  • Delete the file from both common drop locations (Safe Mode helps if it is locked). (file.net)
del /a:-s-h "%SystemRoot%\System32\bridge.dll"
del /a:-s-h "%SystemRoot%\Downloaded Program Files\bridge.dll"
  • Remove the matching ActiveX control (O16). Look for an item named “brdg Class” or “IEPlugin” tied to the same CLSID and remove it from Downloaded Program Files. This is a frequent reinfection vector. (systemlookup.com)

Afterward, reboot, run a fresh HijackThis scan, and confirm there are no O2 or O4 lines referencing bridge.dll. Also run a reputable on-demand scan to catch any add-ons that came with WinFavorites.

One last caution: do not try to “fix” this by downloading a replacement bridge.dll from DLL sites. That file is widely flagged as part of adware, and reputable repositories intentionally do not offer it for download. Remove the adware instead. (dll-files.com)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.