Monday, August 13, 2012

Incredibar Mystart (Hijack software, BeWare!!!)

Where to begin?   I down loaded SpyBot which is free from the internet, and started it scanning my computer with a program called Search and Destroy.....

And it found all this incredibar and mystart stuff and identified itself as a trojan...  It offered to remove all of the offending files and I thought I was done with it..... Wrong....

The program said the some of the files were attached as being used by a program and couldn't be removed....  By that time it was way into the middle of the night, and I left the program on its slow scan after a clean reboot where none of the programs had been started except the SpyBot itself....

It ran most of the morning, because when I put the computer down last night, it went to sleep and shut down the scan.....  I went on a scooter ride!!

It still wasn't done when I came back because once I set the machine down it went to sleep again....  So I had to babysit it to keep it awake, and eventually it found a couple of the files and we removed them too.

Well that's the end of that, I thought........... Wrong...

As I was using the computer again tonight, I found that my search engine was still using My Start by Incredibar.....  Grrrrrrrrrrrrrr!

This time I used the computer explorer and searched on the above terms and removed any file that had that name in it manually..........  A bunch of cookies and stuff...  Then dumped the recycle bin....  But as I was about to  go back into the browser, (Chrome)  I noticed that a download that I hadn't initiated began to download ....................INCREDIBAR..............................  I quickly halted that and deleted the file.....  dumping the recycle bin as well.......

It's still listed as my preferred browser as well here on google chrome....   Must be some cookie that is calling for the download of this trojan. I may have to dump all of the cookies as well just as a precaution.  I'll do that next....

I went into Wrench, Settings, and Search where I managed the available search engines and hovered over My Start and killed it with the X that shows up over to the right of the line...  I selected google again, but will it stay...

I started MS IE, and they had a dialog box asking if my search engine had been changed in their browser and even though it hadn't been changed yet, I answered yes and sent it back to mother MS IE...  So they must be all over this....

It hasn't found or attacked my LINUX box yet, just the windows laptop......    Maybe I will just shut down the Microsoft computers completely until this goes away....  Loyce, go back to your apple will you!

Yep, there were a bunch of cookies in the Chrome cookie folders.....  With that offending name in them...  They're gone now.....

Retired Rod

1 comment:

  1. I feel your pain. I hope I never get that particular problem. It sounds like the fake Windows "you have a virus" alert that goes around. It was a real brute to get rid of as well.

    Hope you are successful in killing it dead. Reminds me, I should create a 'system image' of my Windows 7 desktop right now just in case.

    ReplyDelete

Anonymous comments had to be eliminated.... For the most part this has removed unwanted responses.. If you can't post your comments, please email me and we will make other arrangements...