MyStart by Incredibar

MyStart by Incredibar Description


MyStart by Incredibar Screenshot 1MyStart by Incredibar is an adware program that displays advertisements. While similar adware plugins have been known to be bundled with freely-distributed programs, malware experts have also caught websites using browser exploits to install MyStart sans any other software. If you notice symptoms of the presence of Incredibar’s MyStart while you browse the web, you should remove MyStart with anti-malware software that can delete all of MyStart without difficulties, including its Registry-based components. Normal software removal methods have been confirmed to fail on MyStart, although, at this point, malware experts only rank MyStart by Incredibar as a low-level PC threat.

The Not-So-Incredible Services of MyStart by Incredibar


While MyStart would love you to start your day off by using its services to search the web, malware researchers haven’t seen any signs that MyStart has any beneficial features for your PC. Rather than being a search assistant, MyStart is an advertisement-deliverer that generates revenue by redirecting you to irrelevant advertising content. At the time of this writing, the safety levels of advertisements related to MyStart haven’t been verified, and, in most cases, adware-delivered advertisements are potentially hazardous (as in cases of them promoting rogue anti-virus scanners and similar types of scamware).
DOWNLOAD NOW

» Learn more about SpyHunter's Spyware Detection Tool
and steps to uninstall SpyHunter.

In general, MyStart can be considered a minor nuisance, although the content that MyStart promotes may be more overtly malicious than MyStart itself.

MyStart by Incredibar has also been found to change your homepage, change other browser settings or block your access to unrelated sites (especially Google). However, these symptoms may not be evident in all MyStart infections.

Other PC threats that are closely-associated with MyStart include the Web Assistant toolbar and Incredimail, both of which are low-level adware like MyStart. These PC threats, including MyStart, have been noted for their compatibility with several types of popular browsers, such as Internet Explorer and Firefox. MyStart attacks should be considered an active albeit minor threat.

Ways to Keep Your Day from Starting with MyStart


Avoiding websites that are affiliated with MyStart by Incredibar should always be considered the simplest way to protect your browser from a MyStart infection. Sites that are affiliated with MyStart (such as mystart.incredibar.com) may use browser exploits in their attacks. These exploits can install the MyStart browser hijacker without your consent and are especially likely to exploit outdated versions of JavaScript and Flash.

Updating your browser, if necessary, is also recommended, and malware researchers particularly advise you to keep anti-malware software at work in the background consequently able to block malicious sites and content that could be used to promote MyStart, such as drive-by-download exploits.

Aliases


W32.Clodb46.Trojan.d01a [Bkav]Artemis!36C55F1CCDD6 [McAfee]Win32.Troj.Generic.a.(kcloud) [Kingsoft]TROJ_GEN.F47V1004 [TrendMicro-HouseCall]a variant of Win32/Toolbar.Perion.G [ESET-NOD32]Trojan.Win32.A.Agent.188760 [ViRobot]TROJ_GEN.F47V1114 [TrendMicro-HouseCall]a variant of Win32/InstallBrain [ESET-NOD32]Riskware.Win32.InstallBrain (A) [Emsisoft]APPL/InstallBrain.Gen5 [AntiVir]

More aliases (18)


MyStart by Incredibar Automatic Detection Tool (Recommended)


Is your PC infected with MyStart by Incredibar? To safely & quickly detect MyStart by Incredibar we highly recommend you run the malware scanner listed below.



Visual & GUI Characteristics


MyStart by Incredibar Screenshot 2

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
  • The following files were created in the system:
    # File Name Detection Count
    1 %PROGRAMFILES%\ Protector by IB\ ExtensionUpdaterService.exe 7,729
    2 %WINDIR%\ system32\ jmdp\ stij.exe 7,157
    3 %PROGRAMFILES%\ Incredibar.com\ incredibar\ 1.5.3.27\ bh\ incredibar.dll 4,047
    4 %PROGRAMFILES%\ Protector by IB\ Extension32.dll 1,283
    5 %PROGRAMFILES%\ Protector by IB\ Extension64.dll 602
    6 %ALLUSERSPROFILE%\ Dati applicazioni\ IBUpdaterService\ ibsvc.exe 574
    7 %WINDIR%\ system32\ dmwu.exe 354
    8 %PROGRAMFILES(x86)%\Incredibar-Games_EN 297
    9 %UserProfile%\Local Settings\Application Data\Incredibar-Games_EN 294
    10 %UserProfile%\AppData\LocalLow\Incredibar-Games_EN 290
    11 %AppData%\[trojan name]\toolbarcouponscategories.xml N/A
    12 %AppData%\[trojan name]\toolbarcouponsmerchants.xml N/A
    13 %AppData%\[trojan name]\toolbarcouponsmerchants2.xml N/A
    14 %AppData%\[trojan name]\toolbardtx.ini N/A
    15 %AppData%\[trojan name]\toolbarguid.dat N/A
    16 %AppData%\[trojan name]\toolbarlog.txt N/A
    17 %AppData%\[trojan name]\toolbarpreferences.dat N/A
    18 %AppData%\[trojan name]\toolbarstat.log N/A
    19 %AppData%\[trojan name]\toolbarstats.dat N/A
    20 %AppData%\[trojan name]\toolbaruninstallIE.dat N/A
    21 %AppData%\[trojan name]\toolbaruninstallStatIE.dat N/A
    22 %AppData%\[trojan name]\toolbarversion.xml N/A
    23 %Program Files%\Incredibar\Incredibar.exe N/A
    24 %Temp%\bh\incredibar.dll N/A
    25 %Temp%\incredibar.crx N/A
    26 %Temp%\incredibarApp.dll N/A
    27 %Temp%\incredibarEng.dll N/A
    28 %Temp%\incredibarsrv.exe N/A
    29 %Temp%\incredibarTlbr.dll N/A
    30 %Temp%\uninstall.exe N/A
    31 %Temp%\[trojan name]\toolbar-manifest.xml N/A
    32 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Incredibar.lnk N/A
    33 %UserProfile%\Desktop\Incredibar.lnk N/A
    34 %UserProfile%\Start Menu\Incredibar\Help.lnk N/A
    35 %UserProfile%\Start Menu\Incredibar\Incredibar.lnk N/A
    36 %UserProfile%\Start Menu\Incredibar\Registration.lnk N/A
    37 C:\Program Files\Incredibar-Games_EN\GottenAppsContextMenu.xml N/A
    38 C:\Program Files\Incredibar-Games_EN\Incredibar-Games_ENToolbarHelper.exe N/A
    39 C:\Program Files\Incredibar-Games_EN\ldrtbIncr.dll N/A
    40 C:\Program Files\Incredibar-Games_EN\OtherAppsContextMenu.xml N/A
    41 C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll N/A
    42 C:\Program Files\Incredibar-Games_EN\SharedAppsContextMenu.xml N/A
    43 C:\Program Files\Incredibar-Games_EN\tbIncr.dll N/A
    44 C:\Program Files\Incredibar-Games_EN\toolbar.cfg N/A
    45 C:\Program Files\Incredibar-Games_EN\ToolbarContextMenu.xml N/A
    46 C:\Program Files\Incredibar-Games_EN\uninstall.exe N/A

    More files

Registry Modifications

Tutorial: To edit and delete registry entries manually, read the tutorial on how to remove malicious registry entries.

Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Incredibar-Games_ENSoftware\ImInstaller\IncredibarSoftware\Microsoft\Internet Explorer\DOMStorage\incredibar.comSoftware\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Incredibar-Games EN Toolbar{336D0C35-8A85-403a-B9D2-65C292C39087}_is1HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Conduit\RevertSettings "http://mystart.Incredibar.com?a=1ex6GUYANIc&i=38"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main StartPage "http://mystart.Incredibar.com?a=1ex6GUYANIc&i=38"HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\13376694984709702142491016734454HKEY_CURRENT_USER\Software\IM\38 "PPD"HKEY_CURRENT_USER\Software\ImInstaller\IncredibarHKEY_CURRENT_USER\Software\IncredibarHKEY_CURRENT_USER\Software\Incredibar-Games_ENHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "13376694984709702142491016734454"HKEY_LOCAL_MACHINE\SOFTWARE\Conduit\Toolbars "Incredibar-Games EN Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Incredibar-Games_EN\toolbarHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "Incredibar-Games EN Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Incredibar-Games EN Toolbar
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} {322F82C7-DE90-4579-93AA-971DCF45B5E9}{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9}
Posted: January 18, 2012 | By
Share:
Rate this article:
1 Star2 Stars3 Stars4 Stars5 Stars (78 votes, average: 2.51 out of 5)
Loading ... Loading ...
Threat Metric
Threat Level: 5/10
Detection Count: 734,021
Home Malware ProgramsBad Toolbars MyStart by Incredibar

252 Comments

1 2 3 6

Leave a Reply

What is 6 + 7 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)