Link to home
Start Free TrialLog in
Avatar of daviddo
daviddo

asked on

C\Windows\Downloaded Program Files\Bridge.dll. The specified module could not be found.

WIndows XP
After running Norton Antivirus, I receive the Following Error Message "Error loading. C\WINDOWS\Downloaded Program Files\bridge.dll. The specified module could not be found" every time I startup my Windows XP program.  My windows XP program seems running slow although I disable all startup programs at MSCONFIG.
Could you help me to fix this problem? Thanks.
David
Avatar of SheharyaarSaahil
SheharyaarSaahil
Flag of United Arab Emirates image

Hello daviddo =)

Download HijackThis v1.98.2, run it, Save the LOG file and Post it here:
http://tools.radiosplace.com/HijackThis.exe
ASKER CERTIFIED SOLUTION
Avatar of SheharyaarSaahil
SheharyaarSaahil
Flag of United Arab Emirates image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of daviddo
daviddo

ASKER

Here are the logfiles of HijackThis. What should I do next? Thanks
Logfile of HijackThis v1.98.2
Scan saved at 8:20:20 PM, on 8/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
D:\PROGRA~1\NORTON~4\GHOSTS~2.EXE
D:\Program Files\Norton Antivirus\navapsvc.exe
D:\PROGRA~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\snmp.exe
D:\PROGRA~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Norton Antivirus\SAVScan.exe
C:\Program Files\LIUtilities\SpeedUpMyPC\SpeedUpMyPC.exe
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\iolo\System Mechanic 4 Professional\PopupStopper.exe
C:\PROGRA~1\iolo\SYSTEM~1\SEARCH~1\DiskImageService.exe
C:\Program Files\LIUtilities\SpeedUpMyPC\helper.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Juno\bin\juno.exe
C:\PROGRA~1\DAP\DAP.EXE
D:\My Documents\My download softwares\LinhTinh\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://yahoo.com/
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: twaintecObj Class - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6AA73F79-B433-70ED-D15E-65557CD47A48} - C:\WINDOWS\System32\amm.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - (no file)
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem218.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton Antivirus\NavShExt.dll
O3 - Toolbar: (no name) - {3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [SpeedUpMyPC] C:\Program Files\LIUtilities\SpeedUpMyPC\SpeedUpMyPC.exe traybar
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AcctMgr] D:\Program Files\Password Manager\AcctMgr.exe /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4 Professional\PopupStopper.exe"
O4 - HKCU\..\Run: [Search and Recover Disk Image Service] C:\PROGRA~1\iolo\SYSTEM~1\SEARCH~1\DiskImageService.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/actions/review.htm
O9 - Extra button: Sidesearch - {000007C6-17DF-4438-92A4-DE5537471BA3} - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Alexa - {9D74677A-E227-40fb-9511-F7E92EA4083A} - (no file)
O9 - Extra 'Tools' menuitem: Alexa Toolbar - {9D74677A-E227-40fb-9511-F7E92EA4083A} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)
O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_cracks.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {55F2FE00-C6E1-11D4-84BC-009027889212} (Seagate DiscWizard English) - http://www.seagate.com/support/disc/asp/dw/English/bin/npdscwiz.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2000i\AcDcToday.ocx
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - http://static.flingstone.com/cab/2000XP/CDTInc/bridge-c1.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (NOXLATE) - file://C:\Program Files\AutoCAD 2000i\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2000i\AcPreview.ocx

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: twaintecObj Class - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: (no name) - {6AA73F79-B433-70ED-D15E-65557CD47A48} - C:\WINDOWS\System32\amm.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - (no file)
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem218.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O3 - Toolbar: (no name) - {3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} - (no file)
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load
O9 - Extra button: Sidesearch - {000007C6-17DF-4438-92A4-DE5537471BA3} - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Alexa - {9D74677A-E227-40fb-9511-F7E92EA4083A} - (no file)
O9 - Extra 'Tools' menuitem: Alexa Toolbar - {9D74677A-E227-40fb-9511-F7E92EA4083A} - (no file)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)
O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_cracks.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - http://static.flingstone.com/cab/2000XP/CDTInc/bridge-c1.cab
=========================================================

put a check mark against these lines and click on Fix Checked !!!!
>> F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,

then u have a problem with this line.... the value for this line shud be userinit.exe instead of this wsaupdater.exe
so do this..... goto Start>Run>type regedit (hit OK)
and navigate to the following key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

look in the right pane for an entry called Userinit, right click it and click Modify

u will see the Value Data as >> C:\Windows\System32\wsaupdater.exe,

chnage it to >> C:\Windows\System32\userinit.exe,
(Note the comma following the file path information)

hit OK and close regedit
reboot ur system run hijackthis again to check if the value is correct now,,, if YES then u can download the follwoing tools and can run them in Safemode to delete the remainents of malware from ur system !!!

========================================================
AdAware ==> http://www.lavasoftusa.com/support/download/
SpyBot  ==> http://www.spychecker.com/program/spybot.html
CoolWebShredder ==> http://www.spychecker.com/program/coolwebshredder.html
Stinger >> http://vil.nai.com/vil/stinger
========================================================

post back if u want to ask anything :)
Avatar of daviddo

ASKER

The Error message about "bridge.dll" was removed. I downloadeed Adaware, Spybot and Stinger. Should I run all 3 programs? and How do I run Windows in Safe Mode?.I appreciate your help ! Thanks again.
How do I start Windows in Safe Mode?:
http://www.winxptutor.com/safemode.htm

How to safe-guard my system from spyware?:
http://www.winxptutor.com/antispy.htm
>> I downloadeed Adaware, Spybot and Stinger. Should I run all 3 programs?

yes u shud run all these three programs and shud delete everything they detect :)
Getting Into Windows Safemode >> http://www.computerhope.com/issues/chsafe.htm
Avatar of daviddo

ASKER

After downloading these 3 antivirus programs I could only install Adaware and Spybot. The 3rd one (Stinger) I received an error message when I try to open and install.

Standalone anti-virus scanner for certain viruses
Error signature
AppName: Stinger.exe     AppVer. 2.3.8.0     ModName: stinger.exe
ModVer. 2.3.8.0     Offset:  001bab40

The following information about your process will bbe reported.
Exception information
Code : 0x0000005       Flags: 0x00000000
Record: 0x0000000000000000       Address: 0x00000000005ab40

System information
Windows NT 5.1     Build: 2600
CPU Vendor code: 756E6547 – 49656E69 – 6C65746E
CPU Version: 00000673       CPU Feature code: 0383F9FF
CPU AMD Feature code: 00A8E*24

Module 1
Stinger.exe
Image base 0x00400000       Image Size: 0x00000000
Checksum: 0x00000000        Time stamp: 0x4117e658
Version Information

The following files will be included in this error report:
C:\DOCUME~1\david\LOCALS~1\Temp\WER30.tmp.dir00\appcompat.txt

Also when I open Internet  Explorer (v.6)  I click on the link of the website it opens a blank windows which is running and never stop. I have DSL connection. Could tell me how to fix those problems. Thank you.
try running this tool:
http://www.mvps.org/sramesh2k/IEFIX.htm

Also did u try running Stinger in Safemode or..??
Avatar of daviddo

ASKER

I downloaded all 3 of them in normal mode but i could only install 2 (Adaware and Spybot) and they work fine in normal mode. Thanks.
and does they report anything wrong with ur system,,, try some online virus scans if stinger is not working,,,,,
if both virus scanners and Adware and Spybot come as clean, ur system can be labelled as Clean :)

ONLINE VIRUS SCANNERS:
--------------------------------------
1. http://us.mcafee.com/root/mfs/default.asp?cid=9059 
2. http://security.symantec.com/
3. http://housecall.trendmicro.com/ 
4. http://www.pandasoftware.com/activescan/com/activescan_principal.htm
5. http://www.pcpitstop.com/antivirus/default.asp

what abt IE's problem,,,, solved or still there ??
Avatar of daviddo

ASKER

Yes, they (Adaware, Spybot) found a lot trash and I followed your instruction to delete them (virus infected files) all. Only the "Stinger" does not open when I tried to install from the downloaded file and it gives me the error message that I mail to you. I am at work now so I can not do anything to fix my home computer yet. I will do that (the antivrus software and the IE problem) at 3pm today when I am home. Nice to "talk" to you.
sure, good luck :)
Avatar of daviddo

ASKER

Hi SheharyaarSaahil,
It's me again. It took me 2 days to fix the IE (of course in my spare time). Now i get back pictures & everything when I click on the link. However I have  little problem on it which is when I start my Windows it gives me a message "Desktop: Internet Explorer 6 has been removed from this computer. Do you want to clean up your personalized setting for this program? Yes/No". Of course I clicked  No and everything runs normally, but when I re-open my Windows this message appears again.
Please show me how do I get rid of it ?. Thanks
personalized settings means settings in Tools>Internet Options
and the toolbar view etc etc

u can set it back if u choose Yes on Startup,,,, u will get IE like when u first time opened it, coz it has been reconfigured :)
Hi SheharyaarSaahil. I see this thread is a bit dated, but if you ever have someone with this bridge.dll problem again, you might want to check this out.

http://securityresponse.symantec.com/avcenter/venc/data/adware.winfavorites.html
thanx payton323 for the link,,, i have added it in my list now :)