0

Hi.... Im new to the forum..... but ive been using it to try and solve my problem w/ bridge.dll Ive done everything that was recommended w/ HijakThis and had it delete/fix the 2 bridge files that show up on there. But bridge.dll just keeps coming back everytime i turn my computer on, about 10 mins after startup, it just re-appears, i HijakThis it, and it goes away for as long as i leave my comp on..... but next time i restart, its back again..... Help me stop this enless cycle... Plz!!!!

4
Contributors
12
Replies
13
Views
13 Years
Discussion Span
Last Post by caperjack
0

Hi.... Im new to the forum..... but ive been using it to try and solve my problem w/ bridge.dll Ive done everything that was recommended w/ HijakThis and had it delete/fix the 2 bridge files that show up on there. But bridge.dll just keeps coming back everytime i turn my computer on, about 10 mins after startup, it just re-appears, i HijakThis it, and it goes away for as long as i leave my comp on..... but next time i restart, its back again..... Help me stop this enless cycle... Plz!!!!

http://www.2-spyware.com/file-bridge-dll.html
http://www.daniweb.com/techtalkforums/thread7370.html

0

Please reboot and run hijackthis again, post the new hijackthis log ,thanks.
Edit : Root ,perfect timing !:)

0

Heres the HijakThis, this is right after i rebooted.....
Bridge.dll will pop back up in the next few mins


Logfile of HijackThis v1.98.0
Scan saved at 11:01:29 PM, on 7/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\scvhost.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [AutoUpdate] C:\WINDOWS\scvhost.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

Thanks for the help

0

change that, it doesnt show up on HijakThis, but if i do windows search for "bridge", the bridge.dll shows up as a file on the comp

0

ok.... now the game i was playing just kicked me back to desktop, and when i did HijackThis, this is the new log that turned up..... If i just remove the two bridge files, it will be back after i restart.

Logfile of HijackThis v1.98.0
Scan saved at 11:11:58 PM, on 7/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\scvhost.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Gravity\RagnarokOnline\ragexe.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: brdg Class - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\System32\bridge.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKCU\..\Run: [AutoUpdate] C:\WINDOWS\scvhost.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

Again... thanks for any and all help

0

There is a simple solution for this. this is for most windows programs that allow access to msconfig.


to get rid of the bridge.dll popup,,,, you need to left click on start(bottem left corner of screen),, and then left click on run.

in the box that comes up,,, type in msconfig and then click on ok.

In the new window that comes up,, go to the top right and click on the tab labeled "Startup".

you will see a list of items that have a box that can be checked to the left of each one with green checks in them.

find the one with bridge in the text line and uncheck that box.

click apply towards the bottem of the window

click restart when prompted.

when computer restarts a box will popup saying you have used the system config utility,blah,blah,blah click the box that says dont show this again,,, and then click ok. Problem gone :twisted:

0

There is a simple solution for this. this is for most windows programs that allow access to msconfig.


to get rid of the bridge.dll popup,,,, you need to left click on start(bottem left corner of screen),, and then left click on run.

in the box that comes up,,, type in msconfig and then click on ok.

In the new window that comes up,, go to the top right and click on the tab labeled "Startup".

you will see a list of items that have a box that can be checked to the left of each one with green checks in them.

find the one with bridge in the text line and uncheck that box.

click apply towards the bottem of the window

click restart when prompted.

when computer restarts a box will popup saying you have used the system config utility,blah,blah,blah click the box that says dont show this again,,, and then click ok. Problem gone :twisted:

You are right that will do it ,Fininf the idems with Bridge in it with hijackthis will also .but there are other isuses with this log also ,other files left by trojans ..
Also msconfig is a diagonstic tool and not reall meant to be altered and left that way ,it is best to remove these entrys from the registery and that is what hijackthis does.!:)

0

StarJoe please do the following !

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.

NOTE: Please copy and paste this post into notepad and save to you desktop. or print a copy of these instructions because you will be working with all windows closed except HijackThis.


O2 - BHO: brdg Class - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\System32\bridge.dll

O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load

O4 - HKCU\..\Run: [AutoUpdate] C:\WINDOWS\scvhost.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)


Now reboot into safe mode and delete the following files and folders if found ."Fix Checked"...Reboot to SAFE mode to delete files ,How to start computer in safe mode


C:\WINDOWS\scvhost.exe delete file ,note the different spelling this one is spelt SCVhost and not like the good file SVChost

C:\WINDOWS\System32\bridge.dll.....dlete file


to delete the above files and folder you will need to do the following
go to Show hidden files & folders
"Fix Checked"...Reboot to SAFE mode to delete files
How to start computer in safe mode
reboot computer and post a new log

0

Thanks for all the help, i think my computer is now clean....
I hope AdAware + SpywareBlaster + SpywareGuard = Clean Comp

Just to check, here is my new HijakThis Scan

Logfile of HijackThis v1.98.0
Scan saved at 6:23:17 PM, on 7/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

Again, Thank you very much for your help

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.