There are two suspicious dll files for which I would like an explanation -- LogonDll.dll (Winlogon notify) & streamhlp.dll (this one I have no clue). Having queried Google, I came up empty. These two don't look legitimate, & I have no idea where they slid in. My hijackthis log follows:

Logfile of HijackThis v1.99.1
Scan saved at 5:58:16 PM, on 5/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Erasure\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Erasure\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\Erasure\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\Erasure\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Erasure\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Erasure\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOCUME~1\Saliva\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Erasure\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Erasure\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Erasure\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Erasure\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [THGuard] C:\Erasure\TrojanHunter\THGuard.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O20 - Winlogon Notify: DfLogon - C:\WINDOWS\SYSTEM32\LogonDll.dll
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Erasure\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Erasure\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Erasure\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Erasure\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

Dani AI

Generated

Unknown DLLs that show up as Winlogon "notify" entries deserve immediate attention: Winlogon loads notification-package DLLs at logon from the registry location shown below, and that mechanism is commonly abused for persistence by malware. (learn.microsoft.com)

Immediate triage (short list)

  • Isolate the machine from the network and back up personal files to clean media.
  • Move HijackThis out of Temp into a permanent folder (for reliable re-scans) as recommended.
  • Inspect the Winlogon notify keys with Autoruns (look for the same name shown in HijackThis) and check the DLL path. Autoruns shows Winlogon notify entries and links into Process Explorer for live inspection. (learn.microsoft.com)

Quick checks you can run (no assumptions)

  • Look up the registry key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
  • Use Process Explorer / ListDLLs to see whether winlogon.exe actually has the DLL mapped (that proves it ran). (learn.microsoft.com)

  • Use Sigcheck to view Authenticode info and the file hash; Sigcheck can also query or upload to VirusTotal for multi‑engine scanning. Don’t delete until you have a signature/hash and an independent scan. (learn.microsoft.com)

If it’s malicious (safe removal path)

  • Disable/delete the Notify entry with Autoruns, then reboot into Safe Mode or use offline rescue media and remove/rename the file. Run an offline scan (Microsoft Defender Offline or a reputable rescue ISO) to find rootkit-style persistence. After cleanup, change passwords from a clean device. If credential-stealing malware is confirmed, a full reinstall is the safest recovery. (support.microsoft.com)

Notes and cautions

  • False positives and legitimate software can also install Winlogon notify DLLs; always verify signer, file properties, and multiple AV results before acting. The steps above let you triage reliably without throwing away evidence. Thanks to for moving this to the proper removal forum — that’s where specialists can help interpret the results if you need follow‑up.

Recommended Answers

All 3 Replies

Those files seem to be parts of an intruder of some type.

Please post HijackThis logs ONLY in our 'Viruses, Spyware etc...' section, and that is the appropriate section to get help with your problem in any case. I've moved this topic there for you.

Before you fix anything with HijackThis, you should move it from the Temp folder it's in to it's own permanent folder (like c:\HJT\hijackthis.exe)

I believe LogonDll.dll is bad, but I don't think streamhlp.dll is; you can have them both checked here:

streamhlp.dll, as i now know, is a harmless ad stream (although I'm not sure to which app it's associated with). LongonDll, according to the ppl at TDS-3, is a password stealer. I have reformatted my box since, so my worries are buried yet again in the neverland of paranoia. :cheesy:

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.