Jump to content
Due to inclement weather in Southwest Florida, our Clearwater support team is offline. Our other offices are available to assist you, however their responses may be delayed. We appreciate your patience and understanding during this time. ×

Removal instructions for StartupMaximizer


Recommended Posts

  • Staff
What is StartupMaximizer?

The Malwarebytes research team has determined that StartupMaximizer is a fake system optimizer. These so-called "system optimizer" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.
More information can be found on our Malwarebytes Unpacked blog.

How do I know if I am infected with StartupMaximizer?

This is how the main screen of the registry cleaning application looks:

warning2sw.png

You will find these icons in your taskbar and on your desktop:

icons.png

And see these warnings during install:

main.png

warning1.png

and these screens during "operations":

warning3.png

warning6.png

You may see this entry in your list of installed programs:

warning4.png

and these tasks in your Task Scheduler:

warning5.png

How did StartupMaximizer get on my computer?

These so-called system optimizer use different methods of getting installed. This particular one was bundled by other software.

How do I remove StartupMaximizer?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of StartupMaximizer?
  • No, Malwarebytes' Anti-Malware removes StartupMaximizer completely.
  • This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this system optimizer.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the StartupMaximizer installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.


 

protection1.png


Technical details for experts

You may see these entries in FRST logs:


 
 (Solid Tech) C:\Program Files (x86)\Startup Maximizer\SMSchedule.exe
 (Solid Tech) C:\Program Files (x86)\Startup Maximizer\StartupMaximizer.exe
 C:\Windows\System32\Tasks\Startup Maximizer Schedule
 C:\Users\{username}\Desktop\Startup Maximizer.lnk
 C:\Users\{username}\Documents\Startup Maximizer
 C:\Users\{username}\AppData\Roaming\Startup Maximizer
 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Maximizer
 C:\Program Files (x86)\Startup Maximizer

Startup Maximizer v4.1 (HKLM-x32\...\Startup Maximizer_is1) (Version: 4.1 - Solid Tech)
Task: {A6AE0E83-03BC-4D23-A444-76AB5F1B241A} - System32\Tasks\Startup Maximizer Schedule => C:\Program Files (x86)\Startup Maximizer\SMSchedule.exe [2016-02-26] (Solid Tech)
Alterations made by the installer:
 

File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\Startup Maximizer
       Adds the file animation.gif"="1/27/2014 9:19 PM, 16555 bytes, A
       Adds the file CookieExclusions.txt"="10/29/2015 1:56 PM, 740 bytes, A
       Adds the file English.ini"="7/19/2015 10:23 PM, 33123 bytes, A
       Adds the file file_id.diz"="11/13/2014 9:51 AM, 908 bytes, A
       Adds the file HomePage.url"="11/13/2014 9:26 AM, 48 bytes, A
       Adds the file scanning.gif"="6/25/2014 8:30 AM, 1504 bytes, A
       Adds the file SDesc.txt"="2/12/2015 1:17 PM, 85607 bytes, A
       Adds the file SMSchedule.exe"="2/26/2016 12:27 PM, 1326776 bytes, A
       Adds the file sqlite3.dll"="4/12/2015 7:25 PM, 673521 bytes, A
       Adds the file StartupMaximizer.chm"="2/17/2016 12:14 PM, 33102 bytes, A
       Adds the file StartupMaximizer.exe"="2/17/2016 12:20 PM, 3754680 bytes, A
       Adds the file unins000.dat"="5/12/2016 8:51 AM, 11898 bytes, A
       Adds the file unins000.exe"="5/12/2016 8:49 AM, 715110 bytes, A
    Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Maximizer
       Adds the file Check updates.lnk"="5/12/2016 8:51 AM, 1156 bytes, A
       Adds the file Help.lnk"="5/12/2016 8:51 AM, 1128 bytes, A
       Adds the file Startup Maximizer on the Web.lnk"="5/12/2016 8:51 AM, 1088 bytes, A
       Adds the file Startup Maximizer.lnk"="5/12/2016 8:51 AM, 1128 bytes, A
       Adds the file Uninstall Startup Maximizer.lnk"="5/12/2016 8:51 AM, 1088 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Startup Maximizer\Backup
    Adds the folder C:\Users\{username}\AppData\Roaming\Startup Maximizer\Log
    Adds the folder C:\Users\{username}\AppData\Roaming\Startup Maximizer\Undo
    In the existing folder C:\Users\{username}\Desktop
       Adds the file Startup Maximizer.lnk"="5/12/2016 8:51 AM, 1110 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file Startup Maximizer Schedule"="5/12/2016 8:51 AM, 3268 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Startup Maximizer_is1]
       "DisplayName"="REG_SZ", "Startup Maximizer v4.1"
       "DisplayVersion"="REG_SZ", "4.1"
       "EstimatedSize"="REG_DWORD", 6475
       "HelpLink"="REG_SZ", "http://solidtechies.com"
       "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\Startup Maximizer"
       "Inno Setup: Deselected Tasks"="REG_SZ", ""
       "Inno Setup: Icon Group"="REG_SZ", "Startup Maximizer"
       "Inno Setup: Language"="REG_SZ", "en"
       "Inno Setup: Selected Tasks"="REG_SZ", "desktopicon"
       "Inno Setup: Setup Version"="REG_SZ", "5.4.2 (a)"
       "Inno Setup: User"="REG_SZ", "{username}"
       "InstallDate"="REG_SZ", "20160512"
       "InstallLocation"="REG_SZ", "C:\Program Files (x86)\Startup Maximizer\"
       "MajorVersion"="REG_DWORD", 4
       "MinorVersion"="REG_DWORD", 1
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "Solid Tech"
       "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\Startup Maximizer\unins000.exe" /SILENT"
       "UninstallString"="REG_SZ", ""C:\Program Files (x86)\Startup Maximizer\unins000.exe""
       "URLInfoAbout"="REG_SZ", "http://solidtechies.com"
       "URLUpdateInfo"="REG_SZ", "http://solidtechies.com"
    [HKEY_CURRENT_USER\Software\Startup Maximizer]
       "AntivirusNotifier"="REG_DWORD", 1
       "AppStart"="REG_DWORD", 1
       "BuildID"="REG_SZ", "BZDV_PCSM_EN_UPCLICK_STARTUPMAX"
       "CacheNotifier"="REG_DWORD", 1
       "CompilerVersion"="REG_SZ", "Feb2016"
       "CrashNotifier"="REG_DWORD", 1
       "DiskNotifier"="REG_DWORD", 1
       "DisplayName"="REG_SZ", "Startup Maximizer"
       "InstallationDate"="REG_BINARY, ....
       "InstallStat"="REG_DWORD", 1
       "ItemsCleaned"="REG_DWORD", 0
       "ItemsFixed"="REG_DWORD", 0
       "ItemsToClean"="REG_DWORD", 485
       "ItemsToFix"="REG_DWORD", 72
       "ItemsToPrivacyScan"="REG_SZ", "1111"
       "ItemsToRecoveryScan"="REG_SZ", "1111"
       "ItemsToRegistryScan"="REG_SZ", "1111111111"
       "JunkFiles"="REG_DWORD", 108
       "JunkFilesCleaned"="REG_DWORD", 0
       "Language"="REG_DWORD", 1
       "LastScanChecked"="REG_SZ", "1111011"
       "LastScanDate"="REG_BINARY, ....
       "LastScanFound"="REG_DWORD", 557
       "LastUpdateChecking"="REG_BINARY, ....
       "LogDir"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Startup Maximizer\Log"
       "MemoryNotifier"="REG_DWORD", 1
       "MinFreeDiskSpace"="REG_DWORD", 10
       "MinFreeMemory"="REG_DWORD", 10
       "NewAppNotifier"="REG_DWORD", 1
       "NewToolbarNotifier"="REG_DWORD", 1
       "Reminder"="REG_DWORD", 1
       "s_Enable"="REG_DWORD", 0
       "s_SmartDate"="REG_BINARY, ....
       "s_SmartMode"="REG_DWORD", 0
       "s_SmartScan"="REG_DWORD", 1
       "s_Time"="REG_BINARY, ....
       "SetupName"="REG_SZ", "C:\Users\{username}\Desktop\StartupMaximizer1014055.exe"
       "ShowRebootMessage"="REG_DWORD", 1
       "ShowRecycleBin"="REG_DWORD", 1
       "StartupNotifier"="REG_DWORD", 0
       "StartWithWindows"="REG_DWORD", 0
       "UndoDir"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Startup Maximizer\Undo"
       "UpdateReminderDisabled"="REG_DWORD", 0
       "UpgradeID"="REG_SZ", "BZDV_PCSM_EN_UPCLICK_STARTUPMAX"
       "UseExclusions"="REG_DWORD", 1
       "Version"="REG_SZ", "4.1"
Malwarebytes Anti-Malware log:
 
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 5/12/2016
Scan Time: 9:00 AM
Logfile: mbamStartupMaximizer.txt
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.05.12.02
Rootkit Database: v2016.05.06.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 311165
Time Elapsed: 8 min, 17 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 2
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\SMSchedule.exe, 2724, Delete-on-Reboot, [32d0e0f55f3a112546cc9536c33ed42c]
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\StartupMaximizer.exe, 2476, Delete-on-Reboot, [8a7892434b4eb383739fb8136899dd23]

Modules: 1
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\sqlite3.dll, Delete-on-Reboot, [39c95b7a2871e45214748d12eb17d927], 

Registry Keys: 3
PUP.Optional.StartupMaximizer, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Startup Maximizer Schedule, Delete-on-Reboot, [ca38845125742a0ca4f3cb0618eb659b], 
PUP.Optional.StartupMaximizer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Startup Maximizer_is1, Quarantined, [39c9e4f1b4e57bbb2c45b02149ba8d73], 
PUP.Optional.StartupMaximizer, HKCU\SOFTWARE\Startup Maximizer, Quarantined, [44beffd65e3baf8798d8fdd4ca393bc5], 

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 7
PUP.Optional.StartupMaximizer, C:\Users\{username}\AppData\Roaming\Startup Maximizer, Quarantined, [43bf65707623270f2364a6f9768c6a96], 
PUP.Optional.StartupMaximizer, C:\Users\{username}\AppData\Roaming\Startup Maximizer\Backup, Quarantined, [43bf65707623270f2364a6f9768c6a96], 
PUP.Optional.StartupMaximizer, C:\Users\{username}\AppData\Roaming\Startup Maximizer\Log, Quarantined, [43bf65707623270f2364a6f9768c6a96], 
PUP.Optional.StartupMaximizer, C:\Users\{username}\AppData\Roaming\Startup Maximizer\Undo, Quarantined, [43bf65707623270f2364a6f9768c6a96], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer, Delete-on-Reboot, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Maximizer, Quarantined, [e61c7c590099d85ea6e33768c53db749], 
PUP.Optional.StartupMaximizer, C:\Users\{username}\Documents\Startup Maximizer, Quarantined, [1ee42baadbbe0e2820748c1352b0817f], 

Files: 22
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\SMSchedule.exe, Delete-on-Reboot, [32d0e0f55f3a112546cc9536c33ed42c], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\StartupMaximizer.exe, Delete-on-Reboot, [8a7892434b4eb383739fb8136899dd23], 
PUP.Optional.StartupMaximizer, C:\Users\{username}\Desktop\StartupMaximizer1014055.exe, Quarantined, [38ca5b7aa5f4102633df616a16eb0ff1], 
PUP.Optional.StartupMaximizer, C:\Users\{username}\Desktop\Startup Maximizer.lnk, Quarantined, [45bde4f15d3cd95da5ca99386e9521df], 
PUP.Optional.StartupMaximizer, C:\Windows\System32\Tasks\Startup Maximizer Schedule, Quarantined, [6e94f3e2d1c82c0a5b3ad6fb0cf74fb1], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\animation.gif, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\CookieExclusions.txt, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\English.ini, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\file_id.diz, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\HomePage.url, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\scanning.gif, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\SDesc.txt, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\sqlite3.dll, Delete-on-Reboot, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\StartupMaximizer.chm, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\unins000.dat, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\Program Files (x86)\Startup Maximizer\unins000.exe, Quarantined, [39c95b7a2871e45214748d12eb17d927], 
PUP.Optional.StartupMaximizer, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Maximizer\Check updates.lnk, Quarantined, [e61c7c590099d85ea6e33768c53db749], 
PUP.Optional.StartupMaximizer, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Maximizer\Help.lnk, Quarantined, [e61c7c590099d85ea6e33768c53db749], 
PUP.Optional.StartupMaximizer, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Maximizer\Startup Maximizer on the Web.lnk, Quarantined, [e61c7c590099d85ea6e33768c53db749], 
PUP.Optional.StartupMaximizer, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Maximizer\Startup Maximizer.lnk, Quarantined, [e61c7c590099d85ea6e33768c53db749], 
PUP.Optional.StartupMaximizer, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Maximizer\Uninstall Startup Maximizer.lnk, Quarantined, [e61c7c590099d85ea6e33768c53db749], 
PUP.Optional.StartupMaximizer, C:\Users\{username}\Documents\Startup Maximizer\CookieExclusions.txt, Quarantined, [1ee42baadbbe0e2820748c1352b0817f], 

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites

 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.