Home Possibly Unwanted Program MyStart Toolbar

MyStart Toolbar

Posted: October 9, 2014

Threat Metric

Ranking: 3,447
Threat Level: 2/10
Infected PCs: 49,430
First Seen: October 9, 2014
Last Seen: October 15, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Local\Temp\91A0tmp\mystarttb_5.4.1.4_sambamedia.exe File name: mystarttb_5.4.1.4_sambamedia.exe
Size: 5.46 MB (5464760 bytes)
MD5: 0bf4df5eea355a176d50139360a68ea0
Detection count: 176
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\91A0tmp\mystarttb_5.4.1.4_sambamedia.exe
Group: Malware file
Last Updated: June 6, 2023
C:\Users\<username>\AppData\Local\Temp\3b309cec-d61d-412b-b22d-3b6881f39aef\mystarttb_5.5.0.2_samba.exe File name: mystarttb_5.5.0.2_samba.exe
Size: 4.53 MB (4539240 bytes)
MD5: 663aa5dc1a25dda4fca8872277d2a025
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\3b309cec-d61d-412b-b22d-3b6881f39aef\mystarttb_5.5.0.2_samba.exe
Group: Malware file
Last Updated: September 2, 2022
C:\Users\<username>\AppData\Local\Temp\1a081bdc-2ddf-4d2c-9fab-afc8c173181b\mystarttb_5.5.0.2_samba.exe File name: mystarttb_5.5.0.2_samba.exe
Size: 4.23 MB (4238376 bytes)
MD5: cd9ce5f337b3ddde97464f846939b853
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\1a081bdc-2ddf-4d2c-9fab-afc8c173181b\mystarttb_5.5.0.2_samba.exe
Group: Malware file
Last Updated: October 30, 2022

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttps_www.mystart.com_0.localstoragehttps_www.mystart.com_0.localstorage-journalmystarttb_Install_Log.txtHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\mystarttbSoftware\Microsoft\Internet Explorer\DOMStorage\mystart.comSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\${ieUtilsLightElevationPolicyID}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0C5365B7-358F-402d-A440-F1270AEF1175}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607b689f-7600-45e4-b8e5-887f72dab15c}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mystart.comSoftware\Microsoft\Internet Explorer\LowRegistry\DOMStorage\toolbar.mystart.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.mystart.comSOFTWARE\mystarttbSOFTWARE\Wow6432Node\Google\Chrome\Extensions\higmobnhnmdjomklfkmhpmmcoediaaocSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\${ieUtilsLightElevationPolicyID}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0C5365B7-358F-402d-A440-F1270AEF1175}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607b689f-7600-45e4-b8e5-887f72dab15c}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}SOFTWARE\Wow6432Node\mystarttbHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}mystarttb

Additional Information

The following directories were created:
%LOCALAPPDATA%\Packages\windows_ie_ac_001\AC\mystarttb%PROGRAMFILES%\mystarttb%PROGRAMFILES(x86)%\mystarttb%USERPROFILE%\AppData\LocalLow\mystarttb%appdata%\mystarttb

Related Posts

Loading...