Home Malware Programs Bad Toolbars MyStart by Incredibar

MyStart by Incredibar

Posted: January 18, 2012

Threat Metric

Ranking: 720
Threat Level: 5/10
Infected PCs: 809,205
First Seen: February 28, 2012
Last Seen: March 10, 2025
OS(es) Affected: Windows

MyStart by Incredibar Screenshot 1MyStart by Incredibar is an adware program that displays advertisements. While similar adware plugins have been known to be bundled with freely-distributed programs, malware experts have also caught websites using browser exploits to install MyStart sans any other software. If you notice symptoms of the presence of Incredibar's MyStart while you browse the web, you should remove MyStart with anti-malware software that can delete all of MyStart without difficulties, including its Registry-based components. Normal software removal methods have been confirmed to fail on MyStart, although, at this point, malware experts only rank MyStart by Incredibar as a low-level PC threat.

The Not-So-Incredible Services of MyStart by Incredibar

While MyStart would love you to start your day off by using its services to search the web, malware researchers haven't seen any signs that MyStart has any beneficial features for your PC. Rather than being a search assistant, MyStart is an advertisement-deliverer that generates revenue by redirecting you to irrelevant advertising content. At the time of this writing, the safety levels of advertisements related to MyStart haven't been verified, and, in most cases, adware-delivered advertisements are potentially hazardous (as in cases of them promoting rogue anti-virus scanners and similar types of scamware). In general, MyStart can be considered a minor nuisance, although the content that MyStart promotes may be more overtly malicious than MyStart itself.

MyStart by Incredibar has also been found to change your homepage, change other browser settings or block your access to unrelated sites (especially Google). However, these symptoms may not be evident in all MyStart infections.

Other PC threats that are closely-associated with MyStart include the Web Assistant toolbar and Incredimail, both of which are low-level adware like MyStart. These PC threats, including MyStart, have been noted for their compatibility with several types of popular browsers, such as Internet Explorer and Firefox. MyStart attacks should be considered an active albeit minor threat.

Ways to Keep Your Day from Starting with MyStart

Avoiding websites that are affiliated with MyStart by Incredibar should always be considered the simplest way to protect your browser from a MyStart infection. Sites that are affiliated with MyStart (such as mystart.incredibar.com) may use browser exploits in their attacks. These exploits can install the MyStart browser hijacker without your consent and are especially likely to exploit outdated versions of JavaScript and Flash.

Updating your browser, if necessary, is also recommended, and malware researchers particularly advise you to keep anti-malware software at work in the background consequently able to block malicious sites and content that could be used to promote MyStart, such as drive-by-download exploits.

MyStart by Incredibar Screenshot 2

Aliases

Artemis!36C55F1CCDD6 [McAfee]APPL/InstallBrain.Gen5 [AntiVir]ApplicUnwnt.Win32.AdWare.IBrain.B [Comodo]Win32:PUP-gen [PUP] [Avast]W32/IBrain.B.gen!Eldorado [F-Prot]Unwanted-Program [K7AntiVirus]

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to MyStart by Incredibar may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\AdwCleaner\Quarantine\v1\20201016.122001\1\dmwu.exe#99CB3988B192FEAC File name: dmwu.exe#99CB3988B192FEAC
Size: 3.03 MB (3039536 bytes)
MD5: 6718d6a986ff9314d372c61c2fac0941
Detection count: 12,097
Mime Type: unknown/exe#99CB3988B192FEAC
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\v1\20201016.122001\1\dmwu.exe#99CB3988B192FEAC
Group: Malware file
Last Updated: February 24, 2025
%PROGRAMFILES%\Video downloader\ExtensionUpdaterService.exe File name: ExtensionUpdaterService.exe
Size: 188.76 KB (188760 bytes)
MD5: 6b272502304dde4cb552c8cdd90b9cd0
Detection count: 4,733
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Video downloader
Group: Malware file
Last Updated: May 20, 2020
C:\System Volume Information\_restore{077CCF56-F149-484A-8E84-4192EB0F2888}\RP169\A0096661.exe File name: A0096661.exe
Size: 362.1 KB (362104 bytes)
MD5: 302a025cab861cfbc06dda6d6f67e790
Detection count: 4,490
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{077CCF56-F149-484A-8E84-4192EB0F2888}\RP169\A0096661.exe
Group: Malware file
Last Updated: May 7, 2024
C:\System Volume Information\_restore{630EA792-27DF-47FE-B8C1-20FE5945941A}\RP669\A0205795.dll File name: A0205795.dll
Size: 201.72 KB (201728 bytes)
MD5: 3fc38b1f037120559fdeb6e89f75439d
Detection count: 3,042
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\System Volume Information\_restore{630EA792-27DF-47FE-B8C1-20FE5945941A}\RP669\A0205795.dll
Group: Malware file
Last Updated: September 21, 2021
C:\Users\<username>\Downloads\PCperformer_Setup (1).exe File name: PCperformer_Setup (1).exe
Size: 320.44 KB (320440 bytes)
MD5: c73979282f0b3e3b07475771e12f4ce6
Detection count: 578
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\PCperformer_Setup (1).exe
Group: Malware file
Last Updated: April 17, 2021
C:\found.003\file0008.chk File name: file0008.chk
Size: 2.14 MB (2140464 bytes)
MD5: 9f59670d799c63208da2724ab3dd0cee
Detection count: 269
Mime Type: unknown/chk
Path: C:\found.003\file0008.chk
Group: Malware file
Last Updated: July 26, 2022
C:\Documenti\vecchio computer Marilena\AdwCleaner\Quarantine\C\WINDOWS\system32\dmwu.exe.vir File name: dmwu.exe.vir
Size: 1.63 MB (1633072 bytes)
MD5: 26fec007e1ef608c1fa67960180f541a
Detection count: 234
Mime Type: unknown/vir
Path: C:\Documenti\vecchio computer Marilena\AdwCleaner\Quarantine\C\WINDOWS\system32\dmwu.exe.vir
Group: Malware file
Last Updated: July 28, 2023
C:\Windows\System32\ARFC\wrtc.exe File name: wrtc.exe
Size: 22.32 KB (22320 bytes)
MD5: 35aed5849a6032e077108f767a9d7b5f
Detection count: 159
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\System32\ARFC\wrtc.exe
Group: Malware file
Last Updated: January 31, 2024
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Windows\SysWOW64\ARFC\wrtc.exe.vir File name: wrtc.exe.vir
Size: 21.8 KB (21808 bytes)
MD5: 43f9ce2ff049ee7c927032b44607d269
Detection count: 124
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Windows\SysWOW64\ARFC\wrtc.exe.vir
Group: Malware file
Last Updated: July 13, 2023
C:\WINDOWS\SYSWOW64\JMDP\STIJ.EXE File name: STIJ.EXE
Size: 1.1 MB (1100592 bytes)
MD5: 41b93be7a41fa8fe24d4ade9ab3b0d8a
Detection count: 124
File type: Executable File
Mime Type: unknown/EXE
Path: C:\WINDOWS\SYSWOW64\JMDP\STIJ.EXE
Group: Malware file
Last Updated: November 12, 2021
C:\Windows\System32\ddddeeee.exe File name: ddddeeee.exe
Size: 2.47 MB (2473264 bytes)
MD5: 36e30d1e00c2a691b54991a7cd7efada
Detection count: 124
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\System32\ddddeeee.exe
Group: Malware file
Last Updated: March 4, 2024
C:\WINDOWS\System32\dmwu.exe_old File name: dmwu.exe_old
Size: 1.76 MB (1764656 bytes)
MD5: 382f8e1cf75dd68050e96b5150f6fc37
Detection count: 110
Mime Type: unknown/exe_old
Path: C:\WINDOWS\System32\dmwu.exe_old
Group: Malware file
Last Updated: July 19, 2022
C:\$RECYCLE.BIN\S-1-5-21-3006487391-4159226546-500921184-1001\$REOHG4C.dll File name: $REOHG4C.dll
Size: 162.81 KB (162816 bytes)
MD5: 199d2bcb915be153f54bb58dbf16992d
Detection count: 105
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\$RECYCLE.BIN\S-1-5-21-3006487391-4159226546-500921184-1001\$REOHG4C.dll
Group: Malware file
Last Updated: October 12, 2022
C:\Qoobox\Quarantine\C\Program Files\Web Assistant\ExTEnsion32.dll.vir File name: ExTEnsion32.dll.vir
Size: 162.81 KB (162816 bytes)
MD5: 2894b9b023ad33b7fd4e42f91eae2379
Detection count: 91
Mime Type: unknown/vir
Path: C:\Qoobox\Quarantine\C\Program Files\Web Assistant\ExTEnsion32.dll.vir
Group: Malware file
Last Updated: November 14, 2021
C:\AdwCleaner\Quarantine\C\Windows\System32\ljkb\stij.exe.vir File name: stij.exe.vir
Size: 1.31 MB (1317680 bytes)
MD5: aecd7c4e1b046d0a7d443e4bdb7b9386
Detection count: 49
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Windows\System32\ljkb\stij.exe.vir
Group: Malware file
Last Updated: March 12, 2023
C:\System Volume Information\_restore{5C6C14FD-1904-4D7F-8F6D-6A11E56C8411}\RP1052\A0196086.exe File name: A0196086.exe
Size: 19.24 KB (19248 bytes)
MD5: f946a65b60f27ad97a70143e3a6656d1
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{5C6C14FD-1904-4D7F-8F6D-6A11E56C8411}\RP1052\A0196086.exe
Group: Malware file
Last Updated: August 18, 2022
%Program Files%\Incredibar\Incredibar.exe File name: %Program Files%\Incredibar\Incredibar.exe
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Desktop\Incredibar.lnk File name: %UserProfile%\Desktop\Incredibar.lnk
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Start Menu\Incredibar\Incredibar.lnk File name: %UserProfile%\Start Menu\Incredibar\Incredibar.lnk
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Start Menu\Incredibar\Help.lnk File name: %UserProfile%\Start Menu\Incredibar\Help.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Start Menu\Incredibar\Registration.lnk File name: %UserProfile%\Start Menu\Incredibar\Registration.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Incredibar.lnk File name: %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Incredibar.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%Temp%\bh\incredibar.dll File name: %Temp%\bh\incredibar.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\incredibar.crx File name: %Temp%\incredibar.crx
Mime Type: unknown/crx
Group: Malware file
%Temp%\incredibarApp.dll File name: %Temp%\incredibarApp.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\incredibarEng.dll File name: %Temp%\incredibarEng.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\incredibarsrv.exe File name: %Temp%\incredibarsrv.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\incredibarTlbr.dll File name: %Temp%\incredibarTlbr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\uninstall.exe File name: %Temp%\uninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Incredibar-Games_EN\toolbar.cfg File name: C:\Program Files\Incredibar-Games_EN\toolbar.cfg
Mime Type: unknown/cfg
Group: Malware file
C:\Program Files\Incredibar-Games_EN\uninstall.exe File name: C:\Program Files\Incredibar-Games_EN\uninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Incredibar-Games_EN\Incredibar-Games_ENToolbarHelper.exe File name: C:\Program Files\Incredibar-Games_EN\Incredibar-Games_ENToolbarHelper.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Incredibar-Games_EN\GottenAppsContextMenu.xml File name: C:\Program Files\Incredibar-Games_EN\GottenAppsContextMenu.xml
Mime Type: unknown/xml
Group: Malware file
C:\Program Files\Incredibar-Games_EN\tbIncr.dll File name: C:\Program Files\Incredibar-Games_EN\tbIncr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll File name: C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\Incredibar-Games_EN\ldrtbIncr.dll File name: C:\Program Files\Incredibar-Games_EN\ldrtbIncr.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Program Files\Incredibar-Games_EN\ToolbarContextMenu.xml File name: C:\Program Files\Incredibar-Games_EN\ToolbarContextMenu.xml
Mime Type: unknown/xml
Group: Malware file
C:\Program Files\Incredibar-Games_EN\SharedAppsContextMenu.xml File name: C:\Program Files\Incredibar-Games_EN\SharedAppsContextMenu.xml
Mime Type: unknown/xml
Group: Malware file
C:\Program Files\Incredibar-Games_EN\OtherAppsContextMenu.xml File name: C:\Program Files\Incredibar-Games_EN\OtherAppsContextMenu.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarstat.log File name: %AppData%\[trojan name]\toolbarstat.log
Mime Type: unknown/log
Group: Malware file
%Temp%\[trojan name]\toolbar-manifest.xml File name: %Temp%\[trojan name]\toolbar-manifest.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarversion.xml File name: %AppData%\[trojan name]\toolbarversion.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarcouponsmerchants2.xml File name: %AppData%\[trojan name]\toolbarcouponsmerchants2.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarcouponsmerchants.xml File name: %AppData%\[trojan name]\toolbarcouponsmerchants.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarcouponscategories.xml File name: %AppData%\[trojan name]\toolbarcouponscategories.xml
Mime Type: unknown/xml
Group: Malware file
%AppData%\[trojan name]\toolbarlog.txt File name: %AppData%\[trojan name]\toolbarlog.txt
Mime Type: unknown/txt
Group: Malware file
%AppData%\[trojan name]\toolbardtx.ini File name: %AppData%\[trojan name]\toolbardtx.ini
Mime Type: unknown/ini
Group: Malware file
%AppData%\[trojan name]\toolbaruninstallIE.dat File name: %AppData%\[trojan name]\toolbaruninstallIE.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\[trojan name]\toolbarstats.dat File name: %AppData%\[trojan name]\toolbarstats.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\[trojan name]\toolbaruninstallStatIE.dat File name: %AppData%\[trojan name]\toolbaruninstallStatIE.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\[trojan name]\toolbarpreferences.dat File name: %AppData%\[trojan name]\toolbarpreferences.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\[trojan name]\toolbarguid.dat File name: %AppData%\[trojan name]\toolbarguid.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9}{322F82C7-DE90-4579-93AA-971DCF45B5E9}HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Conduit\RevertSettings "http://mystart.Incredibar.com?a=1ex6GUYANIc&i=38"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main StartPage "http://mystart.Incredibar.com?a=1ex6GUYANIc&i=38"HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\13376694984709702142491016734454HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "13376694984709702142491016734454"HKEY_CURRENT_USER\Software\ImInstaller\IncredibarHKEY_CURRENT_USER\Software\IncredibarHKEY_CURRENT_USER\Software\IM\38 "PPD"HKEY_CURRENT_USER\Software\Incredibar-Games_ENHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "Incredibar-Games EN Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Incredibar-Games EN ToolbarHKEY_LOCAL_MACHINE\SOFTWARE\Conduit\Toolbars "Incredibar-Games EN Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Incredibar-Games_EN\toolbarHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Incredibar-Games_ENSOFTWARE\Classes\esrv.IncredibarESrvcSOFTWARE\IB UpdaterSoftware\IBUpdaterServiceSoftware\ImInstaller\IncredibarSoftware\IncredibarSOFTWARE\Incredibar-Games_ENSOFTWARE\Incredibar.comSoftware\Microsoft\Internet Explorer\DOMStorage\incredibar.comSoftware\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCSSOFTWARE\Wow6432Node\Incredibar.comSYSTEM\CurrentControlSet\Services\IBUpdaterServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}incredibarIncredibar-Games EN Toolbar{336D0C35-8A85-403a-B9D2-65C292C39087}_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\IBUpdaterService%ALLUSERSPROFILE%\Dati applicazioni\IBUpdaterService%ALLUSERSPROFILE%\IBUpdaterService%APPDATA%\IBUpdaterService%AppData%\Incredibar%PROGRAMFILES%\IB Updater%PROGRAMFILES%\Incredibar-Games_EN%PROGRAMFILES%\Incredibar.com%PROGRAMFILES%\Incredibar.com\incredibar%PROGRAMFILES(x86)%\IB Updater%PROGRAMFILES(x86)%\Incredibar-Games_EN%PROGRAMFILES(x86)%\Incredibar.com%TEMP%\mt_ffx\Incredibar.com%UserProfile%\AppData\LocalLow\Incredibar-Games_EN
The following URL's were detected:
mystart.incredibar.com

231 Comments

Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.