0

Hello everyone,

Bridge.dll keeps on coming out everytime I restarted my computer. I tried to search for a solution to this and I found out this forum. I already run Hijackthis and this is the log.

Logfile of HijackThis v1.98.0
Scan saved at 9:05:01 AM, on 6/30/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\FIVEAN~1\Active play.exe
C:\Program Files\Microsoft Firewall Client\ISATRAY.EXE
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\sea\client\BIN\siebel.exe
C:\sea\client\BIN\siebel.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\RODERI~1.SAT\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search200.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sykesasia.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search200.com/searchbar.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = PHCEBISA001:8080
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\roderick.satina\Application Data\Mozilla\Profiles\default\oeum7pbu.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\roderick.satina\Application Data\Mozilla\Profiles\default\oeum7pbu.slt\prefs.js)
O1 - Hosts: 64.28.155.62 ussmcc004
O1 - Hosts: 64.28.155.126 ussmcc005
O1 - Hosts: 64.28.155.60 crmsvc00.palmone.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Send Poke - {3BCF8BBF-8BBF-ED11-82F6-F513D2FF2DAE} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Chic cool - {F8A9C87E-8DA3-4000-2A20-11F49295EA00} - C:\PROGRA~1\COMPWI~1\Funkopen.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRONoMgrWired] c:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\system32\bridge.dll",Load
O4 - HKLM\..\Run: [boobmix] C:\PROGRA~1\FIVEAN~1\Active play.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Program Files\Microsoft Firewall Client\ISATRAY.EXE
O4 - Global Startup: palm.bat
O14 - IERESET.INF: START_PAGE_URL=http://www.sykesasia.com
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.roings.com/cabs/mp3.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = apac.sykes.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = apac.sykes.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = apac.sykes.com

I would greatly appreaciate if someone can help me with this.
Thanks.

2
Contributors
4
Replies
5
Views
13 Years
Discussion Span
Last Post by rc_satina
0

Hi. Just to let you know, there is a thread at the top of this forum dealing with bridge.dll :) but as you have other problems as well, we will give you a fix :) .

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or directly on the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search200.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search200.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search200.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search200.com/searchbar.html

O2 - BHO: Send Poke - {3BCF8BBF-8BBF-ED11-82F6-F513D2FF2DAE} - C:\PROGRA~1\COMPWI~1\Funkopen.dll

O3 - Toolbar: Chic cool - {F8A9C87E-8DA3-4000-2A20-11F49295EA00} - C:\PROGRA~1\COMPWI~1\Funkopen.dll

O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\system32\bridge.dll",Load
O4 - HKLM\..\Run: [boobmix] C:\PROGRA~1\FIVEAN~1\Active play.exe

O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.roings.com/cabs/mp3.cab

Reboot into safe mode following the instructions here & navigate to & delete the following if found:

C:\PROGRA~1\FIVEAN~1< folder
C:\PROGRA~1\COMPWI~1< folder

Reboot normally.

Plz do the following also.
Lop.com uninstaller.
http://lop.com/new_uninstall.exe

0

Thank you so much for your reply crunchie..
This is my first time actually to join in a forum that's why I'm not that familiar with the thread or something..I was having a problem creating a new thread before, it took me about 10 minutes because as I've said I'm not familiar or I'm not used to join in a forum..but anyways, thank you so much crunchie for your time..

I did what your told me to do and it works!!I also did the Lop.com uninstaller. I would like to ask, what would the lop.com uninstaller do to the computer?is it like the adaware or spybot?what does it do?

0

Lop uninstaller does just what it says. Removes any Lop installs & leftovers from your computer. As you have probably guessed, Lop is an uninvited guest. (No pun intended :) )

0

I thank you for helping me with this..I don't have any problem with my computer now..
Again Thank you so much!!!(,")

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.