Threat Database Browser Hijackers MyStart IncrediBar

MyStart IncrediBar

By CagedTech in Browser Hijackers

Threat Scorecard

Popularity Rank: 2,086
Threat Level: 50 % (Medium)
Infected Computers: 346,173
First Seen: February 28, 2012
Last Seen: January 18, 2026
OS(es) Affected: Windows

Aliases

6 security vendors flagged this file as malicious.

Antivirus Vendor Detection
McAfee Artemis!36C55F1CCDD6
AntiVir APPL/InstallBrain.Gen5
Comodo ApplicUnwnt.Win32.AdWare.IBrain.B
Avast Win32:PUP-gen [PUP]
F-Prot W32/IBrain.B.gen!Eldorado
K7AntiVirus Unwanted-Program

SpyHunter Detects & Remove MyStart IncrediBar

File System Details

MyStart IncrediBar may create the following file(s):
# File Name MD5 Detections
1. dmwu.exe#99CB3988B192FEAC 6718d6a986ff9314d372c61c2fac0941 5,169
2. incredibar.dll.vir 8b98614e51db02ba75859ad4b827deeb 2,601
3. ExtensionUpdaterService.exe 6b272502304dde4cb552c8cdd90b9cd0 2,021
4. A0096661.exe 302a025cab861cfbc06dda6d6f67e790 1,917
5. A15A9CFD-EB1B-9A69-9778-445885328414 87fd7ae5432d5eee6f5776da866fa01c 1,783
6. Extension32.dll 4a4ddd9a42046ff4ceecc3707d7b8469 1,625
7. A0205795.dll 3fc38b1f037120559fdeb6e89f75439d 1,299
8. PCperformer_Setup (1).exe c73979282f0b3e3b07475771e12f4ce6 247
9. file0008.chk 9f59670d799c63208da2724ab3dd0cee 116
10. dmwu.exe.vir 26fec007e1ef608c1fa67960180f541a 100
11. wrtc.exe 35aed5849a6032e077108f767a9d7b5f 68
12. incredimail_install.exe d785355f276fc063e879c1035c224e40 54
13. wrtc.exe.vir 43f9ce2ff049ee7c927032b44607d269 53
14. STIJ.EXE 41b93be7a41fa8fe24d4ade9ab3b0d8a 53
15. ddddeeee.exe 36e30d1e00c2a691b54991a7cd7efada 53
16. dmwu.exe_old 382f8e1cf75dd68050e96b5150f6fc37 47
17. $REOHG4C.dll 199d2bcb915be153f54bb58dbf16992d 45
18. ExTEnsion32.dll.vir 2894b9b023ad33b7fd4e42f91eae2379 39
19. stij.exe.vir aecd7c4e1b046d0a7d443e4bdb7b9386 21
20. A0196086.exe f946a65b60f27ad97a70143e3a6656d1 12
More files

Registry Details

MyStart IncrediBar may create the following registry entry or registry entries:
CLSID
{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9}
{322F82C7-DE90-4579-93AA-971DCF45B5E9}
Software\AppDataLow\Software\Incredibar-Games_EN
SOFTWARE\Classes\esrv.IncredibarESrvc
SOFTWARE\IB Updater
Software\IBUpdaterService
Software\ImInstaller\Incredibar
Software\Incredibar
SOFTWARE\Incredibar-Games_EN
SOFTWARE\Incredibar.com
Software\Microsoft\Internet Explorer\DOMStorage\incredibar.com
Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32
SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS
SOFTWARE\Wow6432Node\Incredibar.com
SYSTEM\CurrentControlSet\Services\IBUpdaterService
incredibar
Incredibar-Games EN Toolbar
{336D0C35-8A85-403a-B9D2-65C292C39087}_is1

Directories

MyStart IncrediBar may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\IBUpdaterService
%ALLUSERSPROFILE%\Dati applicazioni\IBUpdaterService
%ALLUSERSPROFILE%\IBUpdaterService
%APPDATA%\IBUpdaterService
%AppData%\Incredibar
%PROGRAMFILES%\IB Updater
%PROGRAMFILES%\Incredibar-Games_EN
%PROGRAMFILES%\Incredibar.com
%PROGRAMFILES%\Incredibar.com\incredibar
%PROGRAMFILES(x86)%\IB Updater
%PROGRAMFILES(x86)%\Incredibar-Games_EN
%PROGRAMFILES(x86)%\Incredibar.com
%TEMP%\mt_ffx\Incredibar.com
%UserProfile%\AppData\LocalLow\Incredibar-Games_EN

URLs

MyStart IncrediBar may call the following URLs:

mystart.incredibar.com

Analysis Report

General information

Family Name: MyStart IncrediBar
Signature status: No Signature

Known Samples

MD5: f55266fb97637a2092d63abfa18d165e
SHA1: 0889c759df3bf9703fa6bbe45c1983ca59a4b440
SHA256: DE56CEC40635159EF74BB8BCAB6CAA2DF2E3A08AF990E3614DE4A44C97550FD6
File Size: 1.13 MB, 1126378 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name IncrediBar
File Description IB Updater Setup
Product Name IB Updater
Product Version 2.0.0.578

Trending

Most Viewed

Loading...