We received the file INTELISMARTWEBBINGSVC.DLL and detected that INTELISMARTWEBBINGSVC.DLL is not good.
INTELISMARTWEBBINGSVC.DLL is Adware. You should remove the file INTELISMARTWEBBINGSVC.DLL.
Kill the process INTELISMARTWEBBINGSVC.DLL and remove INTELISMARTWEBBINGSVC.DLL from Windows.
Malware Analysis of INTELISMARTWEBBINGSVC.DLL
Full path on a computer: %Common Appdata%\Intelismart webbing\IntelismartwebbingSvc.dll
Detected by UnHackMe:
INTELISMARTWEBBINGSVC.DLL
Default location: %Common Appdata%\Intelismart webbing\IntelismartwebbingSvc.dll
Removal Results: Success
Number of reboot: 1
INTELISMARTWEBBINGSVC.DLL is known as:
Adware.IntelismartWebbing
INTELISMARTWEBBINGSVC.DLL hash:
- MD5: 3e6b93eb45013695b18ba4104873bc1e
The file tries to download information from some web sites.
How to quickly detect INTELISMARTWEBBINGSVC.DLL presence?
Registry:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{649a450}\UninstallString: “”%SysDir%\RUNDLL32.EXE” “C:\DOCUME~1\ALLUSE~1\APPLIC~1\INTELI~1\INTELI~1.DLL”,_uninstall /un”
- HKLM\System\CurrentControlSet\Services\0649a450\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
- HKLM\System\CurrentControlSet\Services\0649a450\Type: 0×00000010
- HKLM\System\CurrentControlSet\Services\0649a450\Start: 0×00000002
- HKLM\System\CurrentControlSet\Services\0649a450\ErrorControl: 0×00000000
- HKLM\System\CurrentControlSet\Services\0649a450\ImagePath: “”%SysDir%\rundll32.exe” “c:\docume~1\alluse~1\applic~1\inteli~1\IntelismartwebbingSvc.dll”,service”
- HKLM\System\CurrentControlSet\Services\0649a450\DisplayName: “Intelismart webbing”
- HKLM\System\CurrentControlSet\Services\0649a450\ObjectName: “LocalSystem”
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs: “c:\docume~1\alluse~1\applic~1\inteli~1\inteli~1.dll”
Folders:
- %Common Appdata%\Intelismart webbing
Files:
- %Temp%\__tmp_3a614f8f
- %Common Appdata%\Intelismart webbing\Intelismartwebbing.dll
- %Common Appdata%\Intelismart webbing\IntelismartwebbingSvc.dll