What is Simple Malware Protector?
Simple Malware Protector is a system optimizer that triggers our PUP detection rules. By doing so we offer users a choice to consider whether they want to use this software. More information can be found on our Malwarebytes Labs blog.
How do I know if I am affected by Simple Malware Protector?
This is how the main screen of the system optimizer looks:

You will find these icons in your taskbar, your startmenu, and on your desktop:

and see these types of windows during install:


and this type of screens during operations:


You may see this entry in your list of installed programs:

and this task in your list of Scheduled Tasks:

How did Simple Malware Protector get on my computer?
These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their website.

How do I remove Simple Malware Protector?
Our program Malwarebytes can detect and remove this PUP.
- Please download Malwarebytes for Windows to your desktop.
- Double-click MBSetup.exe and follow the prompts to install the program.
- When your Malwarebytes for Windows installation completes, the program opens to the Welcome to Malwarebytes screen.
- Click on the Get started button.
- Click Scan to start a Threat Scan.
- When the scan is finished click Quarantine to remove the found threats.
- Reboot the system if prompted to complete the removal process.
- No, Malwarebytes removes Simple Malware Protector completely.
- This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Heres how to do it.
- Open Malwarebytes for Windows.
- Click the Detection History
- Click the Allow List
- To add an item to the Allow List, click Add.
- Select the exclusion type Allow a file or folder and use the Select a folder button to select the main folder for the software that you wish to keep.
- Repeat this for any secondary files or folder(s) that belong to the software.
How would the full version of Malwarebytes help protect me?
We hope our application and this guide have helped you in dealing with this system optimizer.
As you can see below the full version of Malwarebytes would have warned you against the Simple Malware Protector installer.
Technical details for experts
You may see these entries in FRST logs:
(Corel Corporation -> SimpleStar) C:\Program Files (x86)\Simple Malware Protector\SimpleMalwareProtector.exe Task: {22ED5DB2-3333-4853-8E3A-EE8E7FAA1E60} - System32\Tasks\smp_notifier_executor => C:\Program Files (x86)\Simple Malware Protector\notifier.exe [1891016 2021-01-27] (Corel Corporation -> Corel Corporation) Task: {E3740806-B555-4383-8694-7E3E38FF006B} - System32\Tasks\Simple Malware Protector_startup => C:\Program Files (x86)\Simple Malware Protector\SimpleMalwareProtector.exe [7681736 2021-01-27] (Corel Corporation -> SimpleStar) C:\Users\{username}\AppData\Local\SimpleStar C:\Windows\system32\Tasks\smp_notifier_executor C:\Windows\system32\Tasks\Simple Malware Protector_startup C:\ProgramData\Desktop\Simple Malware Protector.lnk C:\Users\{username}\AppData\Roaming\SimpleStar C:\ProgramData\SimpleStar C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Simple Malware Protector C:\Program Files (x86)\Simple Malware Protector (Corel Corporation) C:\Windows\system32\smpnative64.exe (SimpleStar ) C:\Users\{username}\Desktop\Simple_Setup.exe Simple Malware Protector (HKLM-x32\...\E33A688D-A9DE-4653-9D98-86CBB8910021_SimpleStar_~542DC577_is1) (Version: 2.1.1000.26615 - SimpleStar)Alterations made by the installer:
File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\Simple Malware Protector Adds the file AppManager.exe"="1/27/2021 2:11 PM, 505032 bytes, A Adds the file AppResource.dll"="1/27/2021 2:11 PM, 13105352 bytes, A Adds the file categories.ini"="10/30/2020 11:40 AM, 44596 bytes, A Adds the file Chinese_asp_ZH-CN.ini"="1/19/2021 11:45 AM, 55864 bytes, A Adds the file danish_asp_DA.ini"="1/19/2021 11:45 AM, 99052 bytes, A Adds the file dutch_asp_NL.ini"="1/19/2021 11:45 AM, 99440 bytes, A Adds the file eng_asp_en.ini"="1/19/2021 11:45 AM, 54191 bytes, A Adds the file Finnish_asp_FI.ini"="1/19/2021 11:45 AM, 99206 bytes, A Adds the file french_asp_FR.ini"="1/19/2021 11:45 AM, 110672 bytes, A Adds the file german_asp_DE.ini"="1/19/2021 11:45 AM, 109028 bytes, A Adds the file helper.dll"="1/27/2021 2:11 PM, 2339528 bytes, A Adds the file Interop.IWshRuntimeLibrary.dll"="1/27/2021 2:12 PM, 57032 bytes, A Adds the file italian_asp_IT.ini"="1/19/2021 11:45 AM, 104274 bytes, A Adds the file japanese_asp_JA.ini"="1/19/2021 11:45 AM, 67834 bytes, A Adds the file lci.lci"="3/18/2021 9:07 AM, 664 bytes, H Adds the file loading_withWhiteBG.avi"="1/18/2021 12:20 PM, 103936 bytes, A Adds the file Microsoft.Win32.TaskScheduler.DLL"="1/27/2021 2:12 PM, 123080 bytes, A Adds the file norwegian_asp_NO.ini"="1/19/2021 11:45 AM, 94786 bytes, A Adds the file notifier.exe"="1/27/2021 2:12 PM, 1891016 bytes, A Adds the file portuguese_asp_PT-BR.ini"="1/19/2021 11:45 AM, 101156 bytes, A Adds the file russian_asp_ru.ini"="1/19/2021 11:45 AM, 101630 bytes, A Adds the file scandll.dll"="1/27/2021 2:11 PM, 58568 bytes, A Adds the file SimpleMalwareProtector.exe"="1/27/2021 2:12 PM, 7681736 bytes, A Adds the file SimpleMalwareProtector.exe.config"="1/18/2021 12:19 PM, 6214 bytes, A Adds the file smp.ico"="1/18/2021 12:20 PM, 34494 bytes, A Adds the file spanish_asp_ES.ini"="1/19/2021 11:45 AM, 106462 bytes, A Adds the file swedish_asp_SV.ini"="1/26/2021 1:03 PM, 96526 bytes, A Adds the file System.Core.dll"="1/27/2021 2:12 PM, 675528 bytes, A Adds the file System.Data.SQLite.dll"="1/27/2021 2:12 PM, 894152 bytes, A Adds the file tray.exe"="1/27/2021 2:11 PM, 2059976 bytes, A Adds the file unins000.dat"="3/18/2021 9:07 AM, 98275 bytes, A Adds the file unins000.exe"="3/18/2021 9:07 AM, 1217224 bytes, A Adds the file unins000.msg"="3/18/2021 9:07 AM, 22701 bytes, A Adds the file unrar.dll"="1/27/2021 2:12 PM, 219848 bytes, A Adds the file Xceed.Compression.dll"="1/27/2021 2:12 PM, 110280 bytes, A Adds the file Xceed.Compression.Formats.dll"="1/27/2021 2:12 PM, 73416 bytes, A Adds the file Xceed.FileSystem.dll"="1/27/2021 2:12 PM, 130760 bytes, A Adds the file Xceed.Zip.dll"="1/27/2021 2:12 PM, 204488 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Simple Malware Protector Adds the file Register Simple Malware Protector.lnk"="3/18/2021 9:07 AM, 1233 bytes, A Adds the file Simple Malware Protector.lnk"="3/18/2021 9:07 AM, 1207 bytes, A Adds the file Uninstall Simple Malware Protector.lnk"="3/18/2021 9:07 AM, 1137 bytes, A Adds the folder C:\ProgramData\SimpleStar\Simple Malware Protector Adds the file AddonSafelist"="1/18/2021 12:20 PM, 13312 bytes, A Adds the file log.xslt"="1/18/2021 12:20 PM, 24753 bytes, A Adds the folder C:\ProgramData\SimpleStar\Simple Malware Protector\signatures Adds the file completedatabase.db"="3/18/2021 9:13 AM, 262275072 bytes, A Adds the file Cookies.bin"="3/18/2021 9:13 AM, 233960 bytes, A Adds the file DigSign.bin"="3/18/2021 9:14 AM, 132248 bytes, A Adds the file FilePaths.bin"="3/18/2021 9:13 AM, 5846920 bytes, A Adds the file FileSignature.bin"="3/18/2021 9:14 AM, 39806312 bytes, A Adds the file Folders.bin"="3/18/2021 9:14 AM, 1698944 bytes, A Adds the file Md5.bin"="3/18/2021 9:14 AM, 129842640 bytes, A Adds the file Registry.bin"="3/18/2021 9:14 AM, 39300384 bytes, A Adds the file SetupSign.bin"="3/18/2021 9:14 AM, 13504 bytes, A Adds the file StrSetupSign.bin"="3/18/2021 9:14 AM, 1824 bytes, A Adds the folder C:\ProgramData\SimpleStar\Simple Malware Protector\updates Adds the file 3262completedatabase.zip"="3/18/2021 9:11 AM, 36169813 bytes, A Adds the file 4221mupdate.zip"="3/18/2021 9:13 AM, 108841406 bytes, A Adds the file 4222update.zip"="3/18/2021 9:13 AM, 413832 bytes, A Adds the file 4223update.zip"="3/18/2021 9:13 AM, 671671 bytes, A Adds the file 4224update.zip"="3/18/2021 9:13 AM, 175199 bytes, A Adds the file 4225update.zip"="3/18/2021 9:13 AM, 18596 bytes, A Adds the file 4226update.zip"="3/18/2021 9:13 AM, 191470 bytes, A Adds the folder C:\Users\{username}\AppData\Local\SimpleStar\Simple Malware Protector Adds the file ScanEngineErrorLog.txt"="3/18/2021 9:17 AM, 6083 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\SimpleStar\Simple Malware Protector Adds the file ASPLog.txt"="3/18/2021 9:18 AM, 6520 bytes, A Adds the file QDetail.db"="3/18/2021 9:07 AM, 4096 bytes, A Adds the file Settings.db"="3/18/2021 9:17 AM, 12288 bytes, A Adds the file Update.ini"="3/18/2021 9:10 AM, 2360 bytes, A Adds the file uuid.txt"="3/18/2021 9:07 AM, 35 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\SimpleStar\Simple Malware Protector\Logs Adds the file log_18-03-21_09-17-10.xml"="3/18/2021 9:17 AM, 70532 bytes, A Adds the file SMLog.xml"="3/18/2021 9:17 AM, 3376 bytes, A In the existing folder C:\Users\Public\Desktop Adds the file Simple Malware Protector.lnk"="3/18/2021 9:07 AM, 1189 bytes, A In the existing folder C:\Windows\System32 Adds the file smpnative64.exe"="1/27/2021 2:12 PM, 29384 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file Simple Malware Protector_startup"="3/18/2021 9:07 AM, 3116 bytes, A Adds the file smp_notifier_executor"="3/18/2021 9:07 AM, 3634 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\E33A688D-A9DE-4653-9D98-86CBB8910021_SimpleStar_~542DC577_is1] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Simple Malware Protector\SimpleMalwareProtector.exe" "DisplayName"="REG_SZ", "Simple Malware Protector" "DisplayVersion"="REG_SZ", "2.1.1000.26615" "EstimatedSize"="REG_DWORD", 32132 "HelpLink"="REG_SZ", "https://goto.simplestar.com/action/?product=SMP&LinkType=Support/" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\Simple Malware Protector" "Inno Setup: Icon Group"="REG_SZ", "Simple Malware Protector" "Inno Setup: Language"="REG_SZ", "en" "Inno Setup: Setup Version"="REG_SZ", "5.5.9 (u)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20210318" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\Simple Malware Protector\" "MajorVersion"="REG_DWORD", 2 "MinorVersion"="REG_DWORD", 1 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "SimpleStar" "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\Simple Malware Protector\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\Simple Malware Protector\unins000.exe"" "URLInfoAbout"="REG_SZ", "https://www.simplestar.com" "VersionMajor"="REG_DWORD", 2 "VersionMinor"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\SimpleStar\Params] "affiliateid"="REG_SZ", "" "SMPInstalledPath"="REG_SZ", "C:\Program Files (x86)\Simple Malware Protector" "TELNO"="REG_SZ", "" "utm_campaign"="REG_SZ", "default" "utm_medium"="REG_SZ", "newbuild" "utm_source"="REG_SZ", "simplestar" "x-at"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\SimpleStar\Simple Malware Protector] "affiliateid"="REG_SZ", "" "afterInstallUrl"="REG_SZ", "https://goto.simplestar.com/action/?product=SMP&LinkType=Install&BuildID=5&t=" "buildid"="REG_SZ", "5" "BuyNowURL"="REG_SZ", "https://goto.simplestar.com/action/?product=SMP&LinkType=Purchase&BuildID=5&t=" "BuyNowURLADU"="REG_SZ", "" "BuyNowURLASP"="REG_SZ", "" "BuyNowURLPB"="REG_SZ", "" "BuyNowURLRCP"="REG_SZ", "" "cmd_t"="REG_SZ", "" "Expired"="REG_DWORD", 0 "InstalledPath"="REG_SZ", "C:\Program Files (x86)\Simple Malware Protector" "isphone"="REG_SZ", "0" "IsScanOptional"="REG_DWORD", 1 "issilent"="REG_DWORD", 1 "MaxFixLimit"="REG_DWORD", 0 "REGVER"="REG_DWORD", 0 "REGVER-UNINSTALL"="REG_DWORD", 0 "RenewNowURL"="REG_SZ", "https://goto.simplestar.com/action/?product=SMP&LinkType=Renew&BuildID=5&t=" "RenewNowURLADU"="REG_SZ", "" "RenewNowURLASP"="REG_SZ", "" "RenewNowURLPB"="REG_SZ", "" "RenewNowURLRCP"="REG_SZ", "" "showbc"="REG_DWORD", 0 "showfth"="REG_DWORD", 0 "showfthsetting"="REG_DWORD", 0 "showpb"="REG_DWORD", 0 "showsm"="REG_DWORD", 1 "support_email"="REG_SZ", "[email protected]" "SUPPORT_URL"="REG_SZ", "https://goto.simplestar.com/action/?product=SMP&LinkType=Support&BuildID=5&t=" "TELNO"="REG_SZ", "" "TELNOFR"="REG_SZ", "" "uid"="REG_SZ", "72205a28-a34819b8-a4bb0795-f972a54c" "utm_campaign"="REG_SZ", "default" "utm_medium"="REG_SZ", "newbuild" "utm_source"="REG_SZ", "simplestar" "x-at"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\SimpleStar\Simple Malware Protector\LANG] "LangCode"="REG_SZ", "en" "LangID"="REG_DWORD", 0 [HKEY_CURRENT_USER\Software\SimpleStar\params] "SMPInstalledPath"="REG_SZ", "C:\Program Files (x86)\Simple Malware Protector" [HKEY_CURRENT_USER\Software\SimpleStar\Simple Malware Protector] "affiliateid"="REG_SZ", "" "buildid"="REG_SZ", "5" "cmd_t"="REG_SZ", "" "CurrentScanTime"="REG_BINARY, ........ "FirstInstallDate"="REG_SZ", "18-03-2021" "InstalledPath"="REG_SZ", "C:\Program Files (x86)\Simple Malware Protector" "StrLastErrorsFixed"="REG_SZ", "0" "StrLastScanResults"="REG_SZ", "92" "TELNO"="REG_SZ", "" "TELNOFR"="REG_SZ", "" "utm_campaign"="REG_SZ", "default" "utm_days"="REG_SZ", "0" "utm_medium"="REG_SZ", "newbuild" "utm_source"="REG_SZ", "simplestar" "x-at"="REG_SZ", "" [HKEY_CURRENT_USER\Software\SimpleStar\Simple Malware Protector\2.1.1000.26615] [HKEY_CURRENT_USER\Software\SimpleStar\Simple Malware Protector\LANG] "LangCode"="REG_SZ", "en" "LangID"="REG_DWORD", 0Malwarebytes log:
Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 3/18/21 Scan Time: 9:26 AM Log File: a1d5a9f6-87c3-11eb-934c-080027235d76.json -Software Information- Version: 4.3.0.98 Components Version: 1.0.1217 Update Package Version: 1.0.38331 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {username}-PC\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 233646 Threats Detected: 12 Threats Quarantined: 12 Time Elapsed: 3 min, 6 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 1 PUP.Optional.AdvancedSystemProtector, C:\PROGRAM FILES (X86)\SIMPLE MALWARE PROTECTOR\SIMPLEMALWAREPROTECTOR.EXE, Quarantined, 869, 911866, , , , , 20B90A718CF55D95616A79342DBA5D06, C88800519501E455CF6A45CD88776E54CE094A90B03312CF5ACBC796932E3A42 Module: 2 PUP.Optional.AdvancedSystemProtector, C:\PROGRAM FILES (X86)\SIMPLE MALWARE PROTECTOR\SIMPLEMALWAREPROTECTOR.EXE, Quarantined, 869, 911866, , , , , 20B90A718CF55D95616A79342DBA5D06, C88800519501E455CF6A45CD88776E54CE094A90B03312CF5ACBC796932E3A42 PUP.Optional.AdvancedSystemProtector, C:\PROGRAM FILES (X86)\SIMPLE MALWARE PROTECTOR\SCANDLL.DLL, Quarantined, 869, 911917, , , , , 3614951BABCC88D57F1A26AA2042666D, 92AD4CCA4ECCEC613CF4D58917901A50C4BE2C44845E1E81DDAB7D18AC4033D2 Registry Key: 3 PUP.Optional.AdvancedSystemProtector, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Simple Malware Protector_startup, Quarantined, 869, 911866, , , , , , PUP.Optional.AdvancedSystemProtector, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E3740806-B555-4383-8694-7E3E38FF006B}, Quarantined, 869, 911866, , , , , , PUP.Optional.AdvancedSystemProtector, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{E3740806-B555-4383-8694-7E3E38FF006B}, Quarantined, 869, 911866, , , , , , Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 6 PUP.Optional.AdvancedSystemProtector, C:\WINDOWS\SYSTEM32\TASKS\Simple Malware Protector_startup, Quarantined, 869, 911866, , , , , 71C36A0F2F183A885E5F26F5867423AA, 9B20A18FC5FAB6BFCFBB08871730B07D13B0131175F1A882BCF3AB429921AC34 PUP.Optional.AdvancedSystemProtector, C:\DOCUMENTS AND SETTINGS\PUBLIC\Desktop\Simple Malware Protector.lnk, Quarantined, 869, 911866, , , , , 6AD0A9E4EF88F0AF810329B557F6631E, 9F988C7F8E3F5C1D5AD382CA90073DCEBB4D1530D3FAA3DCD03E254465EB083B PUP.Optional.AdvancedSystemProtector, C:\PROGRAM FILES (X86)\SIMPLE MALWARE PROTECTOR\SIMPLEMALWAREPROTECTOR.EXE, Quarantined, 869, 911866, 1.0.38331, , ame, , 20B90A718CF55D95616A79342DBA5D06, C88800519501E455CF6A45CD88776E54CE094A90B03312CF5ACBC796932E3A42 PUP.Optional.AdvancedSystemProtector, C:\PROGRAM FILES (X86)\SIMPLE MALWARE PROTECTOR\SCANDLL.DLL, Quarantined, 869, 911917, 1.0.38331, , ame, , 3614951BABCC88D57F1A26AA2042666D, 92AD4CCA4ECCEC613CF4D58917901A50C4BE2C44845E1E81DDAB7D18AC4033D2 PUP.Optional.AdvancedSystemProtector, C:\PROGRAM FILES (X86)\SIMPLE MALWARE PROTECTOR\APPMANAGER.EXE, Quarantined, 869, 911911, 1.0.38331, , ame, , 8E5255733B46E1835407C6411FCCCEBE, 13061DB0897E812E0749903B7C9F800936854805D4323755765C55307F36837D PUP.Optional.SimpleStar, C:\USERS\{username}\DESKTOP\SIMPLE_SETUP.EXE, Quarantined, 1659, 921088, 1.0.38331, , ame, , 60157D8096122784436BD1748C2C0C58, 24E3E15DAEE753690446A2FB09F8AB410F05B4C0D5F25AC4318CFADE2D429487 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end)As mentioned before the full version of Malwarebytes could have protected your computer against this potentially unwanted program.
We use different ways of protecting your computer(s):
- Dynamically Blocks Malware Sites & Servers
- Malware Execution Prevention