Very Suspicious DLL

Reply

Join Date: Apr 2007
Posts: 2
Reputation: fatrcat is an unknown quantity at this point 
Solved Threads: 0
fatrcat fatrcat is offline Offline
Newbie Poster

Very Suspicious DLL

 
0
  #1
Apr 23rd, 2007
Hi everyone-
I have just come across a .dll in my startup list that has me baffled and a bit concerned as to just what it is. In the past, a Google search has always provided something on any file name I have ever checked, but this one returns zip.

The name is hurwenf.dll

In msconfig the startup item is listed simply as hurwenf, with the command being C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\hurwenf.dll,uyesscc

In looking at it's properties it only declares association to an unknown program.

I did a basic files/folders search for all instances of hurwenf, and again looking for the phrase uyesscc. All that was returned was the .dll itself, present in the Windows/system32 folder, and 2 referenced files found in an orphaned program folder belonging to a long-removed spyware detection/removal program, SpyHunter, which I had likely tried out and quickly removed. One file is a support log, which merely lists the item as being one of the items in normal startup. The other I'm unfortunately a bit vague on except for recalling it as an xml file, or having seen xml in the name. When I could find no valid reason for this dll to be in action, I turned it off in msconfig and rebooted to see if any of my programs had any problems without it. Only then did I think to go back and examine the "xml" file further, discovering it had now disappeared. Restoring startup status to the unknown dll and re-starting in hopes it would also re-initiate the mystery file did not work as I thought it might; the file has not returned, leaving only the support log. Obviously since it vanished into thin air it could not have been an xml, and I'm smacking my head on the desk for having failed to not have at least jotted the full name down before making any changes; it didn't occur to me this file would go "poof" as it did.

Attempting decompile on a copy of the dll fails stating it was not built with VB 5 or 6, so I do not have a way to do this.

In opening the dll with Notepad the one only discernable reference I found reads:
hurwenf.dll DllCanUnloadNow DllGetClassObject DllRegisterServer DllUnregisterServer uyesscc

The one potential clue to it's origin/nature that strikes me is maybe held in the disappearance of the mystery file; could this suggest that hurwenf.dll was a leftover of the SpyHunter program, rather than part of something SpyHunter tagged as an invader?

Any info or suggestions would be greatly appreciated; I won't rest easy until knowing just what the devil this thing is.

Thanks!
Reply With Quote Quick reply to this message  
Join Date: Apr 2005
Posts: 16,273
Reputation: jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all 
Solved Threads: 544
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is offline Offline
Moderator

Re: Very Suspicious DLL

 
0
  #2
Apr 23rd, 2007
Sounds suspicious, so run sfc /scannow as well as a a full spyware/antivirus scan.

If they come back clean then the dll is most likely a leftover. many av programs leave dlls for there resident shield in the windows dir.
Last edited by jbennet; Apr 23rd, 2007 at 5:16 am.
If i am helpful, please give me reputation points.
Reply With Quote Quick reply to this message  
Join Date: Apr 2007
Posts: 2
Reputation: fatrcat is an unknown quantity at this point 
Solved Threads: 0
fatrcat fatrcat is offline Offline
Newbie Poster

Re: Very Suspicious DLL

 
0
  #3
Apr 23rd, 2007
Thanks for the input jbennet- those steps have been taken. I "run a tight ship" where it comes to my PC; Dual firewalled with a business-class router, OS & AV always up to date, Windows Defender running too, no acceptance of Active X or Java without permission, so on & so forth. Sometimes it's a real pain, checking every new little thing before allowing to run or not, but I've also been incredibly pleased by the lack of instance where a breach has occurred. I've sent email to SpyHunter with query on the dll, and hopefully they can confirm it as part of a past program release.

Hate like h%## to act like an alarmist, but after the Google search and local data came up empty I decided it was time to go to PC DEFCON 2; equal levels to graceful acceptance of being found stupid or being damned thankful you went ahead and pushed the big red button. I had my first ever major hard drive crash last fall which appears to have simply been due a mechanical failure but still in question, and the creation date of the dll dates back to the same time period, making it equally possible to be something unwittingly acquired during data recovery processes or like you said, a leftover from one of the numerous security-related programs I tested out at that time.

Many Thanks for the input!
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: Very Suspicious DLL

 
0
  #4
Apr 24th, 2007
..remove the startup entry, then delete it in safe mode.
Last edited by gerbil; Apr 24th, 2007 at 1:20 am.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum


Views: 1223 | Replies: 3
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC