PDA

View Full Version : Manual Removal Guide for MyStart.Toolbar



Friday
2015-02-16, 17:24
The following instructions have been created to help you to get rid of "MyStart.Toolbar" manually.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.

If this guide was helpful to you, please consider donating towards this site (http://www.safer-networking.org/index.php?page=donate).

Threat Details:

Categories:
adware
bho

Description:
MyStart.Toolbar is an adware toolbar for browsers.
Removal Instructions:

Installed Software List:

You can try to uninstall products with the names listed below; for items identified by other properties or to avoid malware getting active again on uninstallation, use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) or RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer) to locate and get rid of these entries.

Products that have a key or property named "mystarttb".

Files:

Please use Windows Explorer or another file manager of your choice to locate and delete these files.

The file at "<$APPDATA>\mystarttb\alert.json".
The file at "<$APPDATA>\mystarttb\dtuser.exe".
The file at "<$APPDATA>\mystarttb\dtx.ini".
The file at "<$APPDATA>\mystarttb\geodata.xml".
The file at "<$APPDATA>\mystarttb\guid.dat".
The file at "<$APPDATA>\mystarttb\log.txt".
The file at "<$APPDATA>\mystarttb\preferences.dat".
The file at "<$APPDATA>\mystarttb\stats.dat".
The file at "<$APPDATA>\mystarttb\uninstallIE.dat".
The file at "<$APPDATA>\mystarttb\version.xml".
The file at "<$APPDATA>\mystarttb\weatherbutton_prefs.xml".
The file at "<$LOCALSETTINGS>\Temp\mystart-manifest.xml".
The file at "<$LOCALSETTINGS>\Temp\mystarttb_Install_Log.txt".
The file at "<$LOCALSETTINGS>\Temp\mystart-toolbar.xml".
The file at "<$PROGRAMFILES>\mystarttb\dtuser.exe".
The file at "<$PROGRAMFILES>\mystarttb\ieUtilsLite.exe".
The file at "<$PROGRAMFILES>\mystarttb\install.ico".
The file at "<$PROGRAMFILES>\mystarttb\manifest.xml".
The file at "<$PROGRAMFILES>\mystarttb\mystartDx.dll".
The file at "<$PROGRAMFILES>\mystarttb\mystarttb.dll".
The file at "<$PROGRAMFILES>\mystarttb\search.ico".
The file at "<$PROGRAMFILES>\mystarttb\ToolbarCleaner.exe".
The file at "<$PROGRAMFILES>\mystarttb\toolbarcleaner.ini".
The file at "<$PROGRAMFILES>\mystarttb\uninstall.exe".
Make sure you set your file manager to display hidden and system files. If MyStart.Toolbar uses rootkit technologies, use the rootkit scanner integrated into Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) 2.x or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify files!

Important: There are more files that cannot be safely described in simple words. Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) to remove them.

Folders:

Please use Windows Explorer or another file manager of your choice to locate and delete these folders.

The directory at "<$APPDATA>\mystarttb\chrome\content\lib".
The directory at "<$APPDATA>\mystarttb\chrome\content\modules".
The directory at "<$APPDATA>\mystarttb\chrome\content\newtab\images".
The directory at "<$APPDATA>\mystarttb\chrome\content\newtab".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa\collection".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa\css".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa\images".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa\js".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa\panel".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa\skin\css".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa\skin\images".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa\skin\scripts".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa\skin".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.alexa".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.AmazonShortcut".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.Coupons_v5\icons".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.Coupons_v5\images".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.Coupons_v5\thumbs".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.Coupons_v5".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.ebayshortcut".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.FacebookShortcut".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.smartsearch\img".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.smartsearch".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.TuneIn".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.TwitterShortcut".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets\net.vmn.www.YouTubeShortcut".
The directory at "<$APPDATA>\mystarttb\chrome\content\widgets".
The directory at "<$APPDATA>\mystarttb\chrome\content".
The directory at "<$APPDATA>\mystarttb\chrome\data\search".
The directory at "<$APPDATA>\mystarttb\chrome\data".
The directory at "<$APPDATA>\mystarttb\chrome\skin\ico".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\css".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\default\css".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\default\images".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\default\scripts".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\default".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\images".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\js\fancybox\_notes".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\js\fancybox\helpers".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\js\fancybox".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels\js".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\panels".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\radio\css".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\radio\images".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\radio".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\uwa".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\weatherbutton\icons".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\weatherbutton\panels\images".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\weatherbutton\panels".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib\weatherbutton".
The directory at "<$APPDATA>\mystarttb\chrome\skin\lib".
The directory at "<$APPDATA>\mystarttb\chrome\skin\options".
The directory at "<$APPDATA>\mystarttb\chrome\skin".
The directory at "<$APPDATA>\mystarttb\chrome".
The directory at "<$APPDATA>\mystarttb\coupons".
The directory at "<$APPDATA>\mystarttb\weather".
The directory at "<$APPDATA>\mystarttb".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\lib".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\modules".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\newtab\images".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\newtab".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Alexa\css".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Alexa\images".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Alexa\js".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Alexa\panel".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Alexa\skin\css".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Alexa\skin\images".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Alexa\skin\scripts".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Alexa\skin".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Alexa".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.AmazonShortcut".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Coupons_v5\icons".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Coupons_v5\images".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.Coupons_v5".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.ebayshortcut".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.FacebookShortcut".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.smartsearch\img".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.smartsearch".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.TuneIn".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.TwitterShortcut".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets\net.vmn.www.YouTubeShortcut".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content\widgets".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\content".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\data\search".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\data".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\ico".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\css".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\default\css".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\default\images".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\default\scripts".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\default".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\images".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\js\fancybox\_notes".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\js\fancybox\helpers".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\js\fancybox".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels\js".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\panels".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\radio\css".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\radio\images".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\radio".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\uwa".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\weatherbutton\icons".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\weatherbutton\panels\images".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\weatherbutton\panels".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib\weatherbutton".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\lib".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin\options".
The directory at "<$PROGRAMFILES>\mystarttb\chrome\skin".
The directory at "<$PROGRAMFILES>\mystarttb\chrome".
The directory at "<$PROGRAMFILES>\mystarttb\components".
The directory at "<$PROGRAMFILES>\mystarttb".
Make sure you set your file manager to display hidden and system files. If MyStart.Toolbar uses rootkit technologies, use our RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify folders!

Registry:

You can use regedit.exe (included in Windows) to locate and delete these registry entries.

Delete the registry key "${ieUtilsLightElevationPolicyID}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{0C5365B7-358F-402d-A440-F1270AEF1175}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{607b689f-7600-45e4-b8e5-887f72dab15c}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{62155D33-3CE2-401E-8967-5A270628A3D5}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{A2159D33-3CE2-401B-8967-1B270628A311}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "mystarttb" at "HKEY_CURRENT_USER\Software\".
Delete the registry key "mystarttb" at "HKEY_LOCAL_MACHINE\SOFTWARE\".
If MyStart.Toolbar uses rootkit technologies, use our RegAlyzer (http://www.safer-networking.org/index.php?page=regalyzer), RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).

Browser:

The following browser plugins or items can either be removed directly in your browser, or through the help of e.g. Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) or RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer).

Please check your bookmarks for links to "mystart.com".

Final Words:

If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
Please read these instructions (http://forums.spybot.info/showthread.php?t=288) before requesting assistance,
Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a volunteer analyst will advise you as soon as available.