Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I've use ad-aware to remove the contamined folder n' file. than after restarting my computer I'm getting a message that I am missing a bridge.dll file when I start my computer.
Kinomoto Sakura
Jya~Ne

Restore the file from Adaware's quarantine list. Then select and place it in the ignore list, as your system requires it use. This should resolve your problem.

Do not restore the Bridge.dll file from AdAware's backup folder. That is the main part of the spyware the AA killed. Restoring it may restore the spyware on your system.
Go here: http://www.spywareinfo.com/~merijn/downloads.html
Download HiJack This, and Cool Web Shredder; create a new Folder in Explore/Program Files and label it SECURITY (or whatever you want);
Into it drag and drop Ad Aware, HiJack This, Cool Web Shredder, SpyBot, and Spyware Blaster (you can find them by Google search).Run Cool Web Shredder, allow it to kill anything it finds. Same for all the others.
Now shut down all your open programs, especially any open internet browsers. Run HiJack This and post the results here.
Since the posts on this forum age quickly (move down the line) and don't refresh you might want to move fairly soon. :0)

start ... run ... msconfig ... start up
disable bridge.dll
Today's subliminal thought is: 'Calm down ... it's only ones and zeros.'

Mattie: that will not remove it and several other associated files from your computer which can cause you dirt later.

Please help me with this! I too have the bridge.dll issue. Here's my Hijackthis log.
I have no idea what to deleteLogfile of HijackThis v1.97.7
Scan saved at 09:15:44, on 14.05.2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\winnt\System32\smss.exe
C:\winnt\system32\winlogon.exe
C:\winnt\system32\services.exe
C:\winnt\system32\lsass.exe
C:\winnt\system32\svchost.exe
C:\winnt\system32\spoolsv.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\NAgent\NSCAGENT.exe
c:\Designer9i\bin\agntsrvc.exe
C:\Program Files\ProtectTools\Personal Secure Drive\PSDsrvc.exe
C:\winnt\system32\cmd.exe
c:\Designer9i\bin\dbsnmp.exe
C:\winnt\system32\regsvc.exe
C:\winnt\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\winnt\System32\WBEM\WinMgmt.exe
C:\winnt\system32\svchost.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\winnt\kdx\KHost.exe
C:\winnt\system32\internat.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.exe
C:\Compaq\EAKDRV\EAUSBKBD.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.exe
C:\winnt\explorer.exe
C:\Program Files\Avant Browser\iexplore.exe
C:\Designer9i\bin\sqlplusw.exe
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\aheckel\Local Settings\Temp\HijackThis.exe
C:\winnt\system32\notepad.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sanja/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = bumbar:8080
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [kdx] C:\winnt\kdx\KHost.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\Downloaded Program Files\bridge.dll",Load
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38015.1869791667
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) - http://erc-aheckel:8888/forms90/jinitiator/jinit.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dpzagreb.hep.hr
O17 - HKLM\System\CCS\Services\Tcpip\..\{41FDF5DD-0514-4ACF-811F-91F3462299AC}: Domain = dpzagreb.hep.hr
O17 - HKLM\System\CCS\Services\Tcpip\..\{41FDF5DD-0514-4ACF-811F-91F3462299AC}: NameServer = 220.10.0.10,220.10.0.12
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dpzagreb.hep.hr
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dpzagreb.hep.hr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dpzagreb.hep.hr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = dpzagreb.hep.hr
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = dpzagreb.hep.hr

Here is the bridge.dll fix from Aaron Hulett, the Chief Research Officer | Lavasoft Research and a Microsoft Certified Professional:
[QUOTE](ahulett @ Mar 21 2004, 06:29 PM)[/QUOTE]Open notepad, and copy this information:
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RunDLL"=-
Then, save as bridge-repair.reg (make sure you change the Save As Type from .txt to All Files), and then right-click that .reg file and choose Merge. Tell it yes to merge it in, and then you should be all set.

Hi ana... sorry to hear of your problems.
First, before HT log do this.
On your C drive in Program Files, create a new folder and lable it SECURITY (or whatever you want). Download and drag&drop into this folder the following free programs from the web:
AD Aware: http://www.lavasoftusa.com/software/adaware/
SPYBOT:http://www.safer-networking.org/
SPYWAREBLASTER: http://www.javacoolsoftware.com/spywareblaster.html
COOL WEB SHREDDER:
http://www.spywareinfo.com/~merijn/index.html
(AT this point I don't think you have Cool Web Search infection, but it doesn't hurt.)Also, Drag & Drop HiJack This program into this folder. Okay, now you have them all together. There are many virus/spyware (such as Cool Web Search) that prevent you from accessing antispyware sites; they can do nothing if you already have the programs on your computer.
Now Install the programs in the order I have here. BEFORE you run them, update all the indexes from within each program first!
This does not apply to CWS-you must occasionally download the new program when he updates it.Then run them and allow them to kill anything that they find.
After that, run HiJack This and post the new log. Be sure to close all open programs, especially web browsers, before you run it or you will get a false reading.

Hi again ana...
Try cannymum's method above first... Lavasoft must have provided a new fix.
I haven't had the time to deep scan your log, but I see some entrys I will have to investigate. It will not hurt to do what I suggested above, and in the future those programs will prove invaluable if you contact another malware.

Thank you to cannymum, the fix worked a treat on my Mom's computer, as she has been pulling her hair out to get rid of the missing bridge message. I am no expert ( by any means ) but I found this site, and with cannymum's details I have solved the problem.
Thank you

Not that it makes much difference but link to homepage was incorrect.
Now changed.
Thanks again to cannymum

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |