Home Malware Programs Adware SW.Booster

SW.Booster

Posted: June 10, 2014

Threat Metric

Ranking: 7,016
Threat Level: 2/10
Infected PCs: 100,340
First Seen: June 10, 2014
Last Seen: March 7, 2025
OS(es) Affected: Windows


SW.Booster is a component of Installerex, a utility that third parties use to distribute adware and other Potentially Unwanted Programs throughout the Web. Malware researchers currently categorize SW.Booster as a Potentially Unwanted Program. Removing SW.Booster also may require the removal of adware and other applications affecting your browser, during which you should be happy to use anti-adware tools as they're needed.

The Mastermind Behind Your Browser's (Unwanted) Add-Ons

Malware researchers previously examined Installerex, which is a general installation application that may be used for a range of different programs. However, its history especially is filled with the promotion of adware, browser hijackers and other kinds of PUPs that change your browser to your detriment – and their profits. SW.Booster is a secondary PC threat that may be installed along with Installerex's main programs.

SW.Booster also is distributed in other variants, presumably to prevent you (or PC security companies) from identifying SW.Booster immediately. Malware experts have been able to identify the following variations on SW.Booster:

The add-ons benefiting from SW.Booster's dubious protection typically redirect your online searches, inject advertisements into your browser or perform other acts that are drawbacks to your Web-surfing security and enjoyment. Although these programs only are categorized as PUPs, malware experts do recommend their removal, along with SW.Booster and Installerex.

Boosting Your Browser out of the SW.Booster's Influence

There are few ways of acquiring a SW.Booster installation without making some mistakes in your file-downloading habits, such as trusting unsafe websites or links from suspicious sources. Along with watching your own online behavior, malware experts also suggest scanning files that could include Installerex, SW.Booster or other PUPs. Security products whose scope includes adware and threats may be able to identify these programs before they've installed software onto your computer and, hence, negatively impacted your Web browser. Browsers affected may include Chrome, Firefox and Internet Explorer, but other browsers shouldn't be excluded.

SW.Booster may pretend to provide benefits to your browser, but its tactic should be easily seen through by anyone who knows even a slight amount about computers. Considering the drawbacks implicit in letting other programs control what's on your system, malware experts always find removing SW.Booster to be the right thing to do.

Aliases

Adware/SProtector [Fortinet]PUA.SProtector [Ikarus]Adware/Win64.SProtector [AhnLab-V3]Trojan-FakeAV.Win64.Agent.sn [Kaspersky]Win64:Dropper-gen [Drp] [Avast]Artemis!2D0EBD4619BD [McAfee]Generic_r.DWJ [AVG]AdWare.SProtector [Ikarus]Trj/Genetic.gen [Panda]Generic PUA EP [Sophos]Adware/Symmi.39749.1 [AntiVir]Trojan.Win32.Bromngr.co [Kaspersky]Win32:Adware-gen [Adw] [Avast]Trj/CI.A [Panda]Generic_r.NU [AVG]
More aliases (42)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\progra~2\skenha~1\psupport.dll File name: psupport.dll
Size: 857.6 KB (857600 bytes)
MD5: 898bdcc577a2b49e8eacaf18ddbb3e7b
Detection count: 11,659
File type: Dynamic link library
Mime Type: unknown/dll
Path: c:\progra~2\skenha~1\psupport.dll
Group: Malware file
Last Updated: May 23, 2022
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\072fa92c7B5\temp\usetup.exe File name: usetup.exe
Size: 773.63 KB (773632 bytes)
MD5: deba33db167548f8bbac30f5d78eb168
Detection count: 10,912
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\072fa92c7B5\temp\usetup.exe
Group: Malware file
Last Updated: September 25, 2024
C:\AdwCleaner\Quarantine\C\ProgramData\Performance Optimizer\PerformanceOptimizer.dll.vir File name: PerformanceOptimizer.dll.vir
Size: 4.12 MB (4125184 bytes)
MD5: 7ed4c9a78317bbfaddfe719d2963fe64
Detection count: 7,467
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\ProgramData\Performance Optimizer\PerformanceOptimizer.dll.vir
Group: Malware file
Last Updated: January 20, 2023
c:\progra~3\winspeed\winspeed.dll File name: winspeed.dll
Size: 4.12 MB (4127232 bytes)
MD5: 803d35bc5a4cab86343b0e3f9c687b31
Detection count: 2,928
File type: Dynamic link library
Mime Type: unknown/dll
Path: c:\progra~3\winspeed\winspeed.dll
Group: Malware file
Last Updated: September 4, 2023
c:\progra~3\winspeed\WinSpeedSvc.dll File name: WinSpeedSvc.dll
Size: 186.19 KB (186192 bytes)
MD5: e453e992598f5614eb4966b6442d871b
Detection count: 2,876
File type: Dynamic link library
Mime Type: unknown/dll
Path: c:\progra~3\winspeed\WinSpeedSvc.dll
Group: Malware file
Last Updated: September 24, 2023
%ALLUSERSPROFILE%\Dane aplikacji\Performance Optimizer\PerformanceOptimizerSvc.dll File name: PerformanceOptimizerSvc.dll
Size: 186.19 KB (186192 bytes)
MD5: 7a6d380be44e6896e6d53e60f4fdbdb9
Detection count: 248
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Dane aplikacji\Performance Optimizer
Group: Malware file
Last Updated: October 13, 2014
%ALLUSERSPROFILE%\Performance Optimizer\PerformanceOptimizer.dll File name: PerformanceOptimizer.dll
Size: 4.12 MB (4127744 bytes)
MD5: 9461e2b38705e58c7fae4803352cdd79
Detection count: 159
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Performance Optimizer
Group: Malware file
Last Updated: October 13, 2014
%ALLUSERSPROFILE%\Performance Optimizer\PerformanceOptimizer_x64.dll File name: PerformanceOptimizer_x64.dll
Size: 4.2 MB (4209664 bytes)
MD5: af274fcc0f66d3f4cdfb930e6afc9bd2
Detection count: 96
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Performance Optimizer
Group: Malware file
Last Updated: October 13, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathSk-Enhancer-S-5499298658.jobSk-Enhancer-S-5902107913.jobRegexp file mask%LOCALAPPDATA%\ws_updater.exe%windir%\System32\Tasks\GS_Booster-S[RANDOM CHARACTERS]%windir%\Tasks\GS_Booster-S[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}SOFTWARE\GS-EnablerSOFTWARE\GS_BoosterSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\GS_Booster-S-576482620.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\GS_Booster-S-576482620.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Sk-Enabler-S-245486970.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Sk-Enabler-S-245486970.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\SN.Booster-S-5796263543.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\SN.Booster-S-5796263543.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\WS-Enabler-S-1404196680.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\WS-Enabler-S-1404196680.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GS-Enabler-S-960308484SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OptimizerPro-S-5920013820SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sk-Enabler-S-245486970SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sk-Enhancer-S-5499298658SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sk-Enhancer-S-5902107913SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SW-Booster-S-619517029SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SW_Booster-S-4558057540SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WS-Booster-S-596631634SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WS-Enabler-S-1404196680SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-1404196680SOFTWARE\PC_BoosterSOFTWARE\Sk-EnablerSOFTWARE\Sk-EnhancerSOFTWARE\SN.BoosterSOFTWARE\SW-BoosterSOFTWARE\SW_BoosterSOFTWARE\Wow6432Node\GS-EnablerSOFTWARE\Wow6432Node\GS_BoosterSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\S-1404196680SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\S-619517029SOFTWARE\Wow6432Node\PC_BoosterSOFTWARE\Wow6432Node\Sk-EnablerSOFTWARE\Wow6432Node\Sk-EnhancerSOFTWARE\Wow6432Node\SN.BoosterSOFTWARE\Wow6432Node\SW-BoosterSOFTWARE\Wow6432Node\SW_BoosterSOFTWARE\Wow6432Node\WS-BoosterSOFTWARE\Wow6432Node\WS-EnablerSOFTWARE\WS-BoosterSOFTWARE\WS-EnablerSYSTEM\ControlSet001\services\1a34a8e0SYSTEM\ControlSet001\services\248642b4SYSTEM\ControlSet001\services\3e9deacaSYSTEM\ControlSet001\services\4d349a54SYSTEM\ControlSet001\services\699fd52fSYSTEM\ControlSet001\services\70e6ca8cSYSTEM\ControlSet001\services\be0fb33bSYSTEM\ControlSet001\Services\c67abfdbSYSTEM\ControlSet001\services\d0e87c27SYSTEM\ControlSet001\services\dfc86759SYSTEM\ControlSet001\services\eb12ba5eSYSTEM\ControlSet001\Services\f1f78e38SYSTEM\ControlSet001\services\f7dc94c1SYSTEM\ControlSet002\services\1a34a8e0SYSTEM\ControlSet002\services\248642b4SYSTEM\ControlSet002\services\3e9deacaSYSTEM\ControlSet002\services\4d349a54SYSTEM\ControlSet002\services\699fd52fSYSTEM\ControlSet002\services\70e6ca8cSYSTEM\ControlSet002\Services\c67abfdbSYSTEM\ControlSet002\services\d0e87c27SYSTEM\ControlSet002\services\dfc86759SYSTEM\ControlSet002\services\eb12ba5eSYSTEM\ControlSet002\Services\f1f78e38SYSTEM\ControlSet002\services\f7dc94c1SYSTEM\CurrentControlSet\services\1a34a8e0SYSTEM\CurrentControlSet\services\248642b4SYSTEM\CurrentControlSet\services\3e9deacaSYSTEM\CurrentControlSet\services\4d349a54SYSTEM\CurrentControlSet\services\699fd52fSYSTEM\CurrentControlSet\services\70e6ca8cSYSTEM\CurrentControlSet\services\be0fb33bSYSTEM\CurrentControlSet\Services\c67abfdbSYSTEM\CurrentControlSet\services\d0e87c27SYSTEM\CurrentControlSet\services\dfc86759SYSTEM\CurrentControlSet\services\eb12ba5eSYSTEM\CurrentControlSet\Services\f1f78e38SYSTEM\CurrentControlSet\services\f7dc94c1HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}S-1345357427S-1448266893S-1884037147S-2123451703S-245486970S-3444175751S-480333868S-493389286S-5499298658S-576482620S-5902107913S-5920013820S-596631634S-792098896S-960308484S-993492499{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fa6789c5}{5F189DF5-2D05-472B-9091-84D9848AE48B}{248642b4}{5F189DF5-2D05-472B-9091-84D9848AE48B}{3e9deaca}{5F189DF5-2D05-472B-9091-84D9848AE48B}{4d349a54}{5F189DF5-2D05-472B-9091-84D9848AE48B}{84ef8d51}{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\MiniApp%ALLUSERSPROFILE%\Application Data\Trusted Publisher\PC_Booster%ALLUSERSPROFILE%\Application Data\Trusted Publisher\SW-Booster%ALLUSERSPROFILE%\Application Data\allaboutapp%ALLUSERSPROFILE%\Application Data\application fields software%ALLUSERSPROFILE%\Application Data\brilliantinstaller%ALLUSERSPROFILE%\Application Data\greatsoft%ALLUSERSPROFILE%\Application Data\itsreadyapp%ALLUSERSPROFILE%\Application Data\puresafe%ALLUSERSPROFILE%\Application Data\rightapp software%ALLUSERSPROFILE%\Application Data\softwarehouse%ALLUSERSPROFILE%\Application Data\superbapp%ALLUSERSPROFILE%\Application Data\topapp software%ALLUSERSPROFILE%\BlueOcean\SW-Booster%ALLUSERSPROFILE%\ClearAsky Installer\PC_Booster%ALLUSERSPROFILE%\FreeWorldApp\GS_Booster%ALLUSERSPROFILE%\GreenBay App\PC_Booster%ALLUSERSPROFILE%\KeepAppIt Software\GS_Booster%ALLUSERSPROFILE%\MiniApp%ALLUSERSPROFILE%\Trusted Publisher\PC_Booster%ALLUSERSPROFILE%\Trusted Publisher\SW-Booster%ALLUSERSPROFILE%\Trusted Publisher\SoftwareAmplifier%ALLUSERSPROFILE%\Trusted Publisher\SystemFixer%ALLUSERSPROFILE%\Wideblue installer\PC_Booster%ALLUSERSPROFILE%\allaboutapp%ALLUSERSPROFILE%\application fields software%ALLUSERSPROFILE%\brilliantinstaller%ALLUSERSPROFILE%\greatsoft%ALLUSERSPROFILE%\itsreadyapp%ALLUSERSPROFILE%\puresafe%ALLUSERSPROFILE%\rightapp software%ALLUSERSPROFILE%\safesoft%ALLUSERSPROFILE%\softwarehouse%ALLUSERSPROFILE%\superbapp%ALLUSERSPROFILE%\topapp software%PROGRAMFILES%\GS Supporter%PROGRAMFILES%\GS.Enabler%PROGRAMFILES%\GS_Booster%PROGRAMFILES%\PC_Booster%PROGRAMFILES%\SW_Booster%PROGRAMFILES%\Ss-Supporter%PROGRAMFILES%\Supporter%PROGRAMFILES%\WS-Booster%PROGRAMFILES%\ss helper%PROGRAMFILES(X86)%\SW_Booster%PROGRAMFILES(x86)%\GS Supporter%PROGRAMFILES(x86)%\GS.Enabler%PROGRAMFILES(x86)%\GS_Booster%PROGRAMFILES(x86)%\PC_Booster%PROGRAMFILES(x86)%\Ss-Supporter%PROGRAMFILES(x86)%\Supporter%PROGRAMFILES(x86)%\WS-Booster%PROGRAMFILES(x86)%\ss helper%ProgramFiles%\GS-Enabler%ProgramFiles%\SW-Booster%ProgramFiles%\Sk-Enabler%ProgramFiles%\Sk-Enhancer%ProgramFiles%\Ss-Helper%ProgramFiles%\WS-Enabler%ProgramFiles(x86)%\GS-Enabler%ProgramFiles(x86)%\SW-Booster%ProgramFiles(x86)%\Sk-Enabler%ProgramFiles(x86)%\Sk-Enhancer%ProgramFiles(x86)%\Ss-Helper%ProgramFiles(x86)%\WS-Enabler
Loading...