We received the file SYSTEMBOOSTERSVC.DLL and detected that SYSTEMBOOSTERSVC.DLL is not good.
SYSTEMBOOSTERSVC.DLL is Adware. You should remove the file SYSTEMBOOSTERSVC.DLL.
Kill the process SYSTEMBOOSTERSVC.DLL and remove SYSTEMBOOSTERSVC.DLL from Windows.
Malware Analysis of SYSTEMBOOSTERSVC.DLL
Full path on a computer: %Common Appdata%\System Booster\SystemBoosterSvc.dll
Detected by UnHackMe:
SYSTEMBOOSTERSVC.DLL
Default location: %Common Appdata%\System Booster\SystemBoosterSvc.dll
Removal Results: Success
Number of reboot: 1
SYSTEMBOOSTERSVC.DLL is known as:
Adware.SProtector.D
SYSTEMBOOSTERSVC.DLL hash:
- MD5: 878a84ba6e4f09a137b2e92531cf99a5
The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.
How to quickly detect SYSTEMBOOSTERSVC.DLL presence?
Registry:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{39294157}\UninstallString: “”%SysDir%\RUNDLL32.EXE” “C:\DOCUME~1\ALLUSE~1\APPLIC~1\SYSTEM~1\SYSTEM~1.DLL”,_uninstall /un”
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{39294157}\DisplayName: “System Booster”
- HKLM\System\CurrentControlSet\Services\39294157\ImagePath: “”%SysDir%\rundll32.exe” “c:\docume~1\alluse~1\applic~1\system~1\SystemBoosterSvc.dll”,service”
- HKLM\System\CurrentControlSet\Services\39294157\DisplayName: “System Booster”
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs: “c:\docume~1\alluse~1\applic~1\system~1\system~1.dll”
Folders:
- %Common Appdata%\System Booster
Files:
- %Temp%\__tmp_0e6b0c80
- %Common Appdata%\System Booster\SystemBooster.dll
- %Common Appdata%\System Booster\SystemBoosterSvc.dll