We received the file BROWSERSYSTEMENAHNCERSVC.DLL and detected that BROWSERSYSTEMENAHNCERSVC.DLL is not good.
BROWSERSYSTEMENAHNCERSVC.DLL is Adware. You should remove the file BROWSERSYSTEMENAHNCERSVC.DLL.
Kill the process BROWSERSYSTEMENAHNCERSVC.DLL and remove BROWSERSYSTEMENAHNCERSVC.DLL from Windows.
Malware Analysis of BROWSERSYSTEMENAHNCERSVC.DLL
Full path on a computer: %Common Appdata%\Browser System Enahncer\BrowserSystemEnahncerSvc.dll
Detected by UnHackMe:
BROWSERSYSTEMENAHNCERSVC.DLL
Default location: %Common Appdata%\Browser System Enahncer\BrowserSystemEnahncerSvc.dll
Removal Results: Success
Number of reboot: 1
BROWSERSYSTEMENAHNCERSVC.DLL is known as:
Adware.BrowserSystemEnahncer
BROWSERSYSTEMENAHNCERSVC.DLL hash:
- MD5: 110a6bb2661ec95c042770fb887dbd8c
The file tries to connect to the dangerous web site.
How to quickly detect BROWSERSYSTEMENAHNCERSVC.DLL presence?
Registry:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{19275d4b}\UninstallString: “”%SysDir%\RUNDLL32.EXE” “C:\DOCUME~1\ALLUSE~1\APPLIC~1\BROWSE~1\BROWSE~1.DLL”,_uninstall /un”
- HKLM\System\CurrentControlSet\Services\19275d4b\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
- HKLM\System\CurrentControlSet\Services\19275d4b\Type: 0×00000010
- HKLM\System\CurrentControlSet\Services\19275d4b\Start: 0×00000002
- HKLM\System\CurrentControlSet\Services\19275d4b\ErrorControl: 0×00000000
- HKLM\System\CurrentControlSet\Services\19275d4b\ImagePath: “”%SysDir%\rundll32.exe” “c:\docume~1\alluse~1\applic~1\browse~1\BrowserSystemEnahncerSvc.dll”,service”
- HKLM\System\CurrentControlSet\Services\19275d4b\DisplayName: “Browser System Enahncer”
- HKLM\System\CurrentControlSet\Services\19275d4b\ObjectName: “LocalSystem”
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs: “c:\docume~1\alluse~1\applic~1\browse~1\browse~1.dll”
Folders:
- %Common Appdata%\Browser System Enahncer
Files:
- %Temp%\__tmp_12abc094
- %Common Appdata%\Browser System Enahncer\BrowserSystemEnahncer.dll
- %Common Appdata%\Browser System Enahncer\BrowserSystemEnahncerSvc.dll