nengine.dll

nengine

NewNextDotMe

The module nengine.dll, “NewNext Helper Engine” has been detected as adware by 2 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘NextLive’. This file is typically installed with the program Mobogenie by Beijing Yang Fan Jing He Information Consulting Co. Ltd.. The file has been seen being downloaded from www.dllme.com and multiple other hosts.
Publisher:
NewNextDotMe

Product:
nengine

Description:
NewNext Helper Engine

Version:
0.3.2.0

MD5:
366bfbc6a6a9de3204b410b696e03b11

SHA-1:
8e6a6992a3c7fec4000fa1a4d764dd597109e0b5

SHA-256:
63eb9f4a508fd03cc44db0b761faf5986cc8a7c9947adfd957d1a28fb956ddbc

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
1/12/2025 5:02:29 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.NextLive.1
9.0.1.0347

Reason Heuristics
PUP.Startup.NewNextDotMe.H
14.3.1.1

File size:
1.2 MB (1,283,584 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2013

Original file name:
nengine.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Application data\newnext.me\nengine.dll

File PE Metadata
Compilation timestamp:
11/14/2013 4:53:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:fObe3zvVLVGI7FCMR5F3pmMHxCBICXDrENrMX9sG34vfnT+ux:Gq3DpzmEKcrMXB4vfnic

Entry address:
0xCD8EC

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, C1, E4, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 0C, 8D, 46, FF, 85, C6, 74, 14, E8, EF, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, 47, 86, 00, 00, 33, C0, EB, 71, 8B, 4D, 08, 57, 8B, 7D, 10, 85, FF, 74, 18, 3B, F9, 72, 14, E8, CC, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, 24, 86, 00, 00, 33, C0, EB, 4D, 83, FE, 04, 77, 03, 6A, 04, 5E, F7, DF, 4E, 83, E7, 03, 53, 8D, 5C, 37, 04, 8D, 04, 0B...
 
[+]

Code size:
981.5 KB (1,005,056 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NextLive

Command:
C:\Windows\System32\rundll32.exe "C:\Documents and Settings\{user}\Application data\newnext.me\nengine.dll",entrypoint -m l


Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NextLive

Command:
C:\windows\syswow64\rundll32.exe "C:\users\{user}\appdata\roaming\newnext.me\nengine.dll",entrypoint -m l


The file nengine.dll has been discovered within the following program.

Mobogenie  by Beijing Yang Fan Jing He Information Consulting Co. Ltd.
Mobogenie is an Android app store portal that may use the OpenCandy, Quick Downloader, Conduit and various other monetization programs to bundle with third party installers. In many cases some versions (mostly older ones) are bundled by third party distribution platforms.
www.mobogenie.com/pc.html
56% remove it
 
Powered by Should I Remove It?

The file nengine.dll has been seen being distributed by the following 3 URLs.

Remove nengine.dll - Powered by Reason Core Security