Home Malware Programs Bad Toolbars MyStart by Incredibar

MyStart by Incredibar

Posted: January 18, 2012

Threat Metric

Ranking: 589
Threat Level: 5/10
Infected PCs: 796,323
First Seen: February 28, 2012
Last Seen: October 17, 2023
OS(es) Affected: Windows

MyStart by Incredibar Screenshot 1MyStart by Incredibar is an adware program that displays advertisements. While similar adware plugins have been known to be bundled with freely-distributed programs, malware experts have also caught websites using browser exploits to install MyStart sans any other software. If you notice symptoms of the presence of Incredibar's MyStart while you browse the web, you should remove MyStart with anti-malware software that can delete all of MyStart without difficulties, including its Registry-based components. Normal software removal methods have been confirmed to fail on MyStart, although, at this point, malware experts only rank MyStart by Incredibar as a low-level PC threat.

The Not-So-Incredible Services of MyStart by Incredibar

While MyStart would love you to start your day off by using its services to search the web, malware researchers haven't seen any signs that MyStart has any beneficial features for your PC. Rather than being a search assistant, MyStart is an advertisement-deliverer that generates revenue by redirecting you to irrelevant advertising content. At the time of this writing, the safety levels of advertisements related to MyStart haven't been verified, and, in most cases, adware-delivered advertisements are potentially hazardous (as in cases of them promoting rogue anti-virus scanners and similar types of scamware). In general, MyStart can be considered a minor nuisance, although the content that MyStart promotes may be more overtly malicious than MyStart itself.

MyStart by Incredibar has also been found to change your homepage, change other browser settings or block your access to unrelated sites (especially Google). However, these symptoms may not be evident in all MyStart infections.

Other PC threats that are closely-associated with MyStart include the Web Assistant toolbar and Incredimail, both of which are low-level adware like MyStart. These PC threats, including MyStart, have been noted for their compatibility with several types of popular browsers, such as Internet Explorer and Firefox. MyStart attacks should be considered an active albeit minor threat.

Ways to Keep Your Day from Starting with MyStart

Avoiding websites that are affiliated with MyStart by Incredibar should always be considered the simplest way to protect your browser from a MyStart infection. Sites that are affiliated with MyStart (such as mystart.incredibar.com) may use browser exploits in their attacks. These exploits can install the MyStart browser hijacker without your consent and are especially likely to exploit outdated versions of JavaScript and Flash.

Updating your browser, if necessary, is also recommended, and malware researchers particularly advise you to keep anti-malware software at work in the background consequently able to block malicious sites and content that could be used to promote MyStart, such as drive-by-download exploits.

MyStart by Incredibar Screenshot 2

Aliases

Artemis!36C55F1CCDD6 [McAfee]APPL/InstallBrain.Gen5 [AntiVir]ApplicUnwnt.Win32.AdWare.IBrain.B [Comodo]Win32:PUP-gen [PUP] [Avast]W32/IBrain.B.gen!Eldorado [F-Prot]Unwanted-Program [K7AntiVirus]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\AdwCleaner\Quarantine\v1\20201016.122001\1\dmwu.exe#99CB3988B192FEAC File name: dmwu.exe#99CB3988B192FEAC
Size: 3.03 MB (3039536 bytes)
MD5: 6718d6a986ff9314d372c61c2fac0941
Detection count: 12,083
Mime Type: unknown/exe#99CB3988B192FEAC
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\v1\20201016.122001\1\dmwu.exe#99CB3988B192FEAC
Group: Malware file
Last Updated: September 26, 2023
C:\Windows\System32\ddddeeee.exe File name: ddddeeee.exe
Size: 2.37 MB (2375984 bytes)
MD5: 1129e42e4affc7e3a2c61281b2ea6e03
Detection count: 499
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\System32\ddddeeee.exe
Group: Malware file
Last Updated: February 8, 2023
C:\Windows\System32\ddddeeee.exe File name: ddddeeee.exe
Size: 3.03 MB (3037488 bytes)
MD5: 11112007c8f18113a8c6b859a4e923bc
Detection count: 356
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\System32\ddddeeee.exe
Group: Malware file
Last Updated: September 18, 2023
C:\found.003\file0008.chk File name: file0008.chk
Size: 2.14 MB (2140464 bytes)
MD5: 9f59670d799c63208da2724ab3dd0cee
Detection count: 269
Mime Type: unknown/chk
Path: C:\found.003\file0008.chk
Group: Malware file
Last Updated: July 26, 2022
%WINDIR%\System32\ddddeeee.exe File name: ddddeeee.exe
Size: 2.93 MB (2930992 bytes)
MD5: bcd9aff5f895e3d6a320c555c2f908e3
Detection count: 253
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\System32\ddddeeee.exe
Group: Malware file
Last Updated: July 19, 2022
C:\Windows\System32\ddddeeee.exe File name: ddddeeee.exe
Size: 2.61 MB (2610992 bytes)
MD5: 10331cf8d064469c1610b0b49dc1241e
Detection count: 185
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\System32\ddddeeee.exe
Group: Malware file
Last Updated: May 7, 2023
C:\Windows\System32\ddddeeee.exe File name: ddddeeee.exe
Size: 2.63 MB (2637104 bytes)
MD5: 47b45182844044c7d56a6a9bc4ee246b
Detection count: 157
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\System32\ddddeeee.exe
Group: Malware file
Last Updated: April 19, 2022
C:\Windows\System32\ddddeeee.exe File name: ddddeeee.exe
Size: 2.47 MB (2473264 bytes)
MD5: 36e30d1e00c2a691b54991a7cd7efada
Detection count: 122
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\System32\ddddeeee.exe
Group: Malware file
Last Updated: August 3, 2022
C:\Windows\System32\ddddeeee.exe File name: ddddeeee.exe
Size: 2.37 MB (2375984 bytes)
MD5: da0ba0a3eff6b4323d648f404458e8a8
Detection count: 103
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\System32\ddddeeee.exe
Group: Malware file
Last Updated: October 30, 2022
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.93 MB (2931504 bytes)
MD5: a0a813efb18c6f51111d44f06e6af17f
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: October 20, 2018
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.97 MB (2972464 bytes)
MD5: 208168cd196a4991bb8a2d5a7574ec46
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: March 15, 2020
C:\Windows\system32\dmwu.exe File name: dmwu.exe
Size: 2.41 MB (2416776 bytes)
MD5: 954d4b8d0757b493e105a847fa901333
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\system32\dmwu.exe
Group: Malware file
Last Updated: June 14, 2022
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.93 MB (2930992 bytes)
MD5: c8c0dcdddbe55f56e0b3dcda33fbce06
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: February 11, 2022
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.13 MB (2137904 bytes)
MD5: 5bc4b339e7f6810ea64ae00556f703e0
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: July 11, 2014
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.61 MB (2610992 bytes)
MD5: c02e46c35c545ec7c87353e672a62e14
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: July 21, 2014
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.93 MB (2931504 bytes)
MD5: 9a28e7d8ff6bca09537fc7ffd4382cc8
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: September 22, 2014
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.38 MB (2387760 bytes)
MD5: e40a10978ed314705964d5f31f56ab7f
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 15, 2014
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 580.82 KB (580824 bytes)
MD5: 462e8cdac95771c1bde275588db927ec
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 7, 2014
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.91 MB (2919728 bytes)
MD5: 6ad90022eb835343f53ad7a30ee14fa2
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 10, 2014
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.38 MB (2388784 bytes)
MD5: 6ea4316f80921a24c4aaafdbef4f2861
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: September 26, 2014
%WINDIR%\system32\dmwu.exe File name: dmwu.exe
Size: 2.93 MB (2930992 bytes)
MD5: 512336457f427b20ae50174933c4fc3c
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 18, 2014
%Program Files%\Incredibar\Incredibar.exe File name: %Program Files%\Incredibar\Incredibar.exe
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Desktop\Incredibar.lnk File name: %UserProfile%\Desktop\Incredibar.lnk
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Start Menu\Incredibar\Incredibar.lnk File name: %UserProfile%\Start Menu\Incredibar\Incredibar.lnk
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Start Menu\Incredibar\Help.lnk File name: %UserProfile%\Start Menu\Incredibar\Help.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Start Menu\Incredibar\Registration.lnk File name: %UserProfile%\Start Menu\Incredibar\Registration.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Incredibar.lnk File name: %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Incredibar.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%Temp%\bh\incredibar.dll File name: %Temp%\bh\incredibar.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\incredibar.crx File name: %Temp%\incredibar.crx
Mime Type: unknown/crx
Group: Malware file
%Temp%\incredibarApp.dll File name: %Temp%\incredibarApp.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\incredibarEng.dll File name: %Temp%\incredibarEng.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\incredibarsrv.exe File name: %Temp%\incredibarsrv.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\incredibarTlbr.dll File name: %Temp%\incredibarTlbr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\uninstall.exe File name: %Temp%\uninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Incredibar-Games_EN\toolbar.cfg File name: C:\Program Files\Incredibar-Games_EN\toolbar.cfg
Mime Type: unknown/cfg
Group: Malware file
C:\Program Files\Incredibar-Games_EN\uninstall.exe File name: C:\Program Files\Incredibar-Games_EN\uninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Incredibar-Games_EN\Incredibar-Games_ENToolbarHelper.exe File name: C:\Program Files\Incredibar-Games_EN\Incredibar-Games_ENToolbarHelper.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Incredibar-Games_EN\GottenAppsContextMenu.xml File name: C:\Program Files\Incredibar-Games_EN\GottenAppsContextMenu.xml
Mime Type: unknown/xml
Group: Malware file
C:\Program Files\Incredibar-Games_EN\tbIncr.dll File name: C:\Program Files\Incredibar-Games_EN\tbIncr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll File name: C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\Incredibar-Games_EN\ldrtbIncr.dll File name: C:\Program Files\Incredibar-Games_EN\ldrtbIncr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\Incredibar-Games_EN\ToolbarContextMenu.xml File name: C:\Program Files\Incredibar-Games_EN\ToolbarContextMenu.xml
Mime Type: unknown/xml
Group: Malware file
C:\Program Files\Incredibar-Games_EN\SharedAppsContextMenu.xml File name: C:\Program Files\Incredibar-Games_EN\SharedAppsContextMenu.xml
Mime Type: unknown/xml
Group: Malware file
C:\Program Files\Incredibar-Games_EN\OtherAppsContextMenu.xml File name: C:\Program Files\Incredibar-Games_EN\OtherAppsContextMenu.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarstat.log File name: %AppData%\[trojan name]\toolbarstat.log
Mime Type: unknown/log
Group: Malware file
%Temp%\[trojan name]\toolbar-manifest.xml File name: %Temp%\[trojan name]\toolbar-manifest.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarversion.xml File name: %AppData%\[trojan name]\toolbarversion.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarcouponsmerchants2.xml File name: %AppData%\[trojan name]\toolbarcouponsmerchants2.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarcouponsmerchants.xml File name: %AppData%\[trojan name]\toolbarcouponsmerchants.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarcouponscategories.xml File name: %AppData%\[trojan name]\toolbarcouponscategories.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarlog.txt File name: %AppData%\[trojan name]\toolbarlog.txt
Mime Type: unknown/txt
Group: Malware file
%AppData%\[trojan name]\toolbardtx.ini File name: %AppData%\[trojan name]\toolbardtx.ini
Mime Type: unknown/ini
Group: Malware file
%AppData%\[trojan name]\toolbaruninstallIE.dat File name: %AppData%\[trojan name]\toolbaruninstallIE.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\[trojan name]\toolbarstats.dat File name: %AppData%\[trojan name]\toolbarstats.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\[trojan name]\toolbaruninstallStatIE.dat File name: %AppData%\[trojan name]\toolbaruninstallStatIE.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\[trojan name]\toolbarpreferences.dat File name: %AppData%\[trojan name]\toolbarpreferences.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\[trojan name]\toolbarguid.dat File name: %AppData%\[trojan name]\toolbarguid.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9}{322F82C7-DE90-4579-93AA-971DCF45B5E9}HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Conduit\RevertSettings "http://mystart.Incredibar.com?a=1ex6GUYANIc&i=38"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main StartPage "http://mystart.Incredibar.com?a=1ex6GUYANIc&i=38"HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\13376694984709702142491016734454HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "13376694984709702142491016734454"HKEY_CURRENT_USER\Software\ImInstaller\IncredibarHKEY_CURRENT_USER\Software\IncredibarHKEY_CURRENT_USER\Software\IM\38 "PPD"HKEY_CURRENT_USER\Software\Incredibar-Games_ENHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "Incredibar-Games EN Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Incredibar-Games EN ToolbarHKEY_LOCAL_MACHINE\SOFTWARE\Conduit\Toolbars "Incredibar-Games EN Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Incredibar-Games_EN\toolbarHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Incredibar-Games_ENSOFTWARE\Classes\esrv.IncredibarESrvcSOFTWARE\IB UpdaterSoftware\IBUpdaterServiceSoftware\ImInstaller\IncredibarSoftware\IncredibarSOFTWARE\Incredibar-Games_ENSOFTWARE\Incredibar.comSoftware\Microsoft\Internet Explorer\DOMStorage\incredibar.comSoftware\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCSSOFTWARE\Wow6432Node\Incredibar.comSYSTEM\CurrentControlSet\Services\IBUpdaterServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}incredibarIncredibar-Games EN Toolbar{336D0C35-8A85-403a-B9D2-65C292C39087}_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\IBUpdaterService%ALLUSERSPROFILE%\Dati applicazioni\IBUpdaterService%ALLUSERSPROFILE%\IBUpdaterService%APPDATA%\IBUpdaterService%AppData%\Incredibar%PROGRAMFILES%\IB Updater%PROGRAMFILES%\Incredibar-Games_EN%PROGRAMFILES%\Incredibar.com%PROGRAMFILES%\Incredibar.com\incredibar%PROGRAMFILES(x86)%\IB Updater%PROGRAMFILES(x86)%\Incredibar-Games_EN%PROGRAMFILES(x86)%\Incredibar.com%TEMP%\mt_ffx\Incredibar.com%UserProfile%\AppData\LocalLow\Incredibar-Games_EN
The following URL's were detected:
http://mystart.incredibar.com/mystart.Incredibar.com

231 Comments

Loading...