nengine.dll

The module nengine.dll has been detected as a potentially unwanted program by 8 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘NextLive’.
MD5:
157684a49da95df0c4c2a7b4cc2bc5e5

SHA-1:
9ff6ad9c7ba28fd234a1ed57b288dc60a3822669

SHA-256:
348b7a131656d7911c301b1a2626972583b684ce5c0a61bdc6d2ff7186d2b19f

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
5/11/2025 12:32:40 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Trash.Gen
7.11.123.226

avast!
Win32:NextLive-A [Adw]
2014.9-140314

Comodo Security
UnclassifiedMalware
17568

Dr.Web
Trojan.Damaged.1
9.0.1.023

IKARUS anti.virus
Packed.Win32.Krap
t3scan.2.2.29

Kaspersky
Packed.Win32.Krap
14.0.0.4421

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10827

VIPRE Antivirus
Backdoor.Win32.Bifrose.fsi
25180

File size:
1.2 MB (1,283,584 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\roaming\newnext.me\nengine.dll

File PE Metadata
Compilation timestamp:
11/14/2013 12:53:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:fObe3zvVLVGI7FCMR5F3pmMHxCBICXDrENrMX9sG34vfnT+ux:Gq3DpzmEKcrMXB4vfnic

Entry address:
0xCD8EC

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, C1, E4, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 0C, 8D, 46, FF, 85, C6, 74, 14, E8, EF, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, 47, 86, 00, 00, 33, C0, EB, 71, 8B, 4D, 08, 57, 8B, 7D, 10, 85, FF, 74, 18, 3B, F9, 72, 14, E8, CC, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, 24, 86, 00, 00, 33, C0, EB, 4D, 83, FE, 04, 77, 03, 6A, 04, 5E, F7, DF, 4E, 83, E7, 03, 53, 8D, 5C, 37, 04, 8D, 04, 0B...
 
[+]

Code size:
981.5 KB (1,005,056 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NextLive

Command:
C:\Windows\System32\rundll32.exe "C:\users\{user}\appdata\roaming\newnext.me\nengine.dll",entrypoint -m l


Remove nengine.dll - Powered by Reason Core Security