Tuesday, July 24, 2012

Remove Police Central e-crime Unit Virus (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Picture this, you turn on your computer and there's a message from Police Central e-crime Unit accusing you of an internet crime (illegally distributing copyrighted files and pornography) and then it demands money. If you were faced with this fake message then your computer is infected with a virus called ransomware. And you're certainly not alone. These scams are spreading like wild fire and can definitely cause you trouble whether you give your money to the scammers or not.

Similar scams have also been out there claiming to be from FBI and U.S. Justice Department. Whether it would be the Police Central e-crime Unit virus or any other similar scam they all have one thing in common, they lock down your computer and then demand money. If you pay the scammers to unlock your computer, they may actually dot but will most likely continue to use your computer secretly to launch even more virus attacks and internet scams.

So far, we've seen two slightly different variants of Police Central e-crime Unit ransomware. The first variant belongs to the Win32/Weelsof malware family. Basically, it's a Trojan that allows hackers to perform a number of actions on the infected computer. And they certain can launch such fake Police warnings as shown in the image below.



While this one is clearly targeting UK users, scammers have very similar scams ready to be used in other countries as well.

The Weelsof Trojan is a new piece of malware. It was documented earlier this year (June, 2012). Please note that ransomware scam is only one of its payloads. Fortunately, most antivirus programs will detect this ransomware right away but if your computer caches this virus then you need to get a better protection.

The second variant of Police Central e-crime Unit (PCeU) ransomware belongs to the Win32/Reveton malware family. As you can see, the fake waning is slightly different, more sophisticated, claiming to be from Specialist Crime Directorate rather than Metropolitan Police.



They even added a web cam image to give the impression that the victim is under surveillance. Of course, they do not actually activate your web cam even if you have it. Scammers display the same picture on every infected machine. So, don’t worry about that.



Very often, people download and install such scams voluntarily. Malware applications are usually disguised as a software upgrade. People don't know what that is and they think they need it because it looks like they do. Besides, something as simple as opening PDF file can infect computer or allow scammers to download Police Central e-crime Unit virus on your computer. Keep in mind that other software applications are vulnerable too.



Scammers exploit Java and Flash vulnerabilities to load the malicious code on targeted computers. It's very important to keep your machine updated. What is more, cyber criminals use valid software certificates and other possible methods to avoid detection and to infect as many computers as possible.

So, if you got infected with this fake Police Ukash virus, please follow the steps in the removal guide below. Sometimes, users can restart infected computers in Safe Mode. That makes the removal procedure a lot easier. Unfortunately, most of the time this ransomware comes bundled with other malware that locks down the computer completely. In such case, Live CD is the only option. We will show you how to remove Police Central e-crime Unit virus using Kaspersky Rescue Disk. Hopefully, this virus will only cost you time without taking your money too.

If you have any questions about this infection or need help removing it, please leave a comment below. Good luck!

Source: http://spywareremovalx.blogspot.com


Method 1: Police Central e-crime Unit virus removal instructions using System Restore in Safe Mode with Command Prompt:

1. Unplug your network cable and manually turn your computer off. Reboot your computer is "Safe Mode with Command Prompt". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Command Prompt" and press Enter key.



2. Make sure you log in to an account with administrative privileges (login as admin).

3. Once the Command Prompt appears you have few seconds to type in explorer and hit Enter. If you fail to do it within 2-3 seconds, the Police Central e-crime Unit ransomware will take over and will not let you type anymore.

4. If you managed to bring up Windows Explorer you can now browse into:
  • Win XP: C:\windows\system32\restore\rstrui.exe and press Enter
  • Win Vista/Seven: C:\windows\system32\rstrui.exe and press Enter
5. Follow the steps to restore your computer into an earlier day.

6. Download recommended anti-malware software (direct download) and run a full system scan to remove the remnants of Police Central e-crime Unit virus.


Method 2: Police Central e-crime Unit virus removal instructions using System Restore in Safe Mode:

1. Power off and restart your computer. As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Once in there, go to Start menu and search for "system restore". Or you can browse into the Windows Restore folder and run System Restore utility from there:
  • Win XP: C:\windows\system32\restore\rstrui.exe double-click or press Enter
  • Win Vista/7/8: C:\windows\system32\rstrui.exe double-click or press Enter
3. Select Restore to an earlier time or Restore system files... and continue until you get into the System Restore utility.

4. Select a restore point from well before the Police Central e-crime Unit virus appeared, two weeks should be enough.

5. Restore it. Please note, it can take a long time, so be patient.

6. Once restored, restart your computer and hopefully this time you will be able to login (Start Windows normally).

7. At this point, download recommended anti-malware software (direct download) and run a full system scan to remove the Police Central e-crime Unit virus.


Method 3: Police Central e-crime Unit virus removal instructions using MSConfig in Safe Mode:

1. Power off and restart your computer. As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Once in there, go to Start menu and search for "msconfig". Launch the application. If you're using Windows XP, go to Start then select Run.... Type in "msconfig" and click OK.

3. Select Startup tab. Expand Command column and look for a startup entry that launches randomly named file from %AppData% or %Temp% folders using rundll32.exe. See example below:

C:\Windows\System32\rundll32.exe C:\Users\username\appdata\local\temp\regepqzf.dll,H1N1

4. Disable the malicious entry and click OK to save changes.

5. Restart your computer. This time Start Windows normally. Hopefully, you won't be prompted with a fake Police Central e-crime Unit virus screen.

6. Finally, download recommended anti-malware software (direct download) and run a full system scan to remove the Police Central e-crime Unit virus.



Method 4: Police Central e-crime Unit Ransomware removal using Kaspersky Rescue Disk:

1. Download the Kaspersky Rescue Disk iso image from the Kaspersky Lab server. (Direct download link)
Please note that this is a large downloaded, so please be patient while it downloads.

2. Record the Kaspersky Rescue Disk iso image to a CD/DVD. You can use any CD/DVD record software you like. If you don't have any, please download and install ImgBurn. Small download, great software. You won't regret it, we promise.

For demonstration purposes we will use ImgBurn.

So, open up ImgBurn and choose Write image file to disc.



Click on the small Browse for file icon as show in the image. Browse into your download folder and select kav_rescue_10.iso as your source file.



OK, so know we are ready to burn the .iso file. Simply click the Write image file to disc button below and after a few minutes you will have a bootable Kaspersky Rescue Disk 10.



3. Configure your computer to boot from CD/DVD. Use the Delete or F2, F11 keys, to load the BIOS menu. Normally, the information how to enter the BIOS menu is displayed on the screen at the start of the OS boot.



The keys F1, F8, F10, F12 might be used for some motherboards, as well as the following key combinations:
  • Ctrl+Esc
  • Ctrl+Ins
  • Ctrl+Alt
  • Ctrl+Alt+Esc
  • Ctrl+Alt+Enter
  • Ctrl+Alt+Del
  • Ctrl+Alt+Ins
  • Ctrl+Alt+S
If you can enter Boot Menu directly then simply select your CD/DVD-ROM as your 1st boot device.

If you can't enter Boot Menu directly then simply use Delete key to enter BIOS menu. Select Boot from the main BIOS menu and then select Boot Device Priority.



Set CD/DVD-ROM as your 1st Boot Device. Save changes and exist BIOS menu.



4. Let's boot your computer from Kaspersky Rescue Disk.

Restart your computer. After restart, a message will appear on the screen: Press any key to enter the menu. So, press Enter or any other key to load the Kaspersky Rescue Disk.



5. Select your language and press Enter to continue.



6. Press 1 to accept the End User License Agreement.



7. Select Kaspersky Rescue Disk. Graphic Mode as your startup method. Press Enter. Once the actions described above have been performed, the operating system starts.



8. Click on the Start button located in the left bottom corner of the screen. Run Kaspersky WindowsUnlocker to remove Windows system and registry changes made by Police Central e-crime Unit virus. It won't take very long.



9. Click on the Start button once again and fire up the Kaspersky Rescue Disk utility. First, select My Update Center tab and press Start update to get the latest malware definitions. Don't worry if you can't download the updates. Just proceed to the next step.



10. Select Object Scan tab. Place a check mark next to your local drive C:\. If you have two or more local drives make sure to check those as well. Then click Start Objects Scan to scan your computer for malicious software.



11. Quarantine (recommended) or delete every piece of malicious code detected during the system scan.



12. You can now close the Kaspersky Rescue Disk utility. Click on the Start button and select Restart computer.



13. Please restart your computer into the normal Windows mode. Download recommended anti-malware software (direct download) and run a full system scan to remove the remnants of Police Central e-crime Unit virus and to protect your computer against these types of threats in the future.

For for information about ransomware threats and possible removal methods, please read the general ransomware removal guide.

Tell your friends:

Monday, July 23, 2012

Remove International Police Association (I.P.A.) Virus (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
We ran across a new piece of ransomware that uses the branding of International Police Association (I.P.A.) to deceive you into paying a 'fine' to have your computer unlocked.

This infection is classified as a Trojan:Win32/LockScreen.CI. Ransomware applications from the LockScreen family have been targeting European internet users recently. However, the malicious code can be easily changed to target users in United States, Canada or any other country/region. Ransomware's characteristics change slightly depending on the IP address of the infected computer.

Currently, there are numerous reported infections in Austria, Belgium, Switzerland, Germany, Spain, France, Greece, Italy, Finland, Nederland, Poland, Portugal and Sweden. It's rather surprising that they decided to skip UK and U.S., at least for now. Usually, these countries are the prime targets.



When the International Police Association (I.P.A.) virus has infected your computer, it simply prevents you from accessing The Desktop and displays a fake warning claiming that the system was locked by I.P.A because you were watching and/or distributing illegal content.

Usually, cyber criminals include some scary text about child pornography and copyrighted files. We have to admit that the fake warning is incredibly realistic. We've talked with some people about similar infections and they all admitted that they were scared to death when they saw these police warnings. Few of them even paid 'fines', usually $50 or $100.

Although, there are really nasty and sophisticated ransomware applications out there, International Police Association virus is not one of them, thankfully. It doesn't encrypt files and it doesn't make complex system modifications. The scheme is very simple: once the Trojan is executed, it determines your IP address, changes numerous system settings, creates a full screen window, loads fake warning text and then downloads all the necessary graphics from remote server. For example, if you live in Spain, this virus will load Spanish warning text and download Spain flag from a remote server. And that's it.

Most of the time, victims are urged to pay a 'fine' using a UKash voucher. Surprisingly, you can choose how much you are willing to pay; it's either 50 or 100 euros. That's kind of weird. However, this is a scam. Do not transfer any money or purchase vouchers. Please also note that UKash is a legitimate firm and is not involved in this International Police Association ransomware scam.

International Police Association (I.P.A.) virus warning in different countries:

Ihr Computer wurde gesperrt
Ihr Computer wurde durch das System der automatischen Informationskontrolle gesperrt



Votre ordinateur est bloqué
Votre ordinateur a été bloqué par le système de contrôle automatique informationnel



El ordenador suyo esta bloqueado
El ordenador suyo fue bloqueado por el sistema del control informativo automatizado



O υπολογιστής σας έχει μπλοκαριστεί



.
.
.

Il suo computer è stato bloccato
il suo computer è stato bloccato da sistema di controllo d'informazione automatico

Tietokoneenne lukkiutui

Uw computer is geblokkeerd
Uw computer is geblokkeerd door het systeem van een automatische informatiecontrole

Ten komputer został zablokowany
Ten komputer został zablokowany przez system automatycznej kontroli informacyjnej

O seu computador foi bloqueado
O seu computador foi bloqueado pelo sistema do controlo automatico de informação

Datorn har blockerats
Datorn har blockerats av ett system för avtomatisk information kontroll

If you have ever tried to get rid of ransomware you may have thought its darn near impossible. The good news is that International Police Association (I.P.A.) virus isn't very aggressive unless it comes bundled with other malware. Most of the time, this ransowmare allows victims to reboot their PCs in Safe Mode with Networking and download anti-malware software. Anti-malware software removes the virus and you can happily user your computer once again. But if you were 'lucky' enough to get modified version of this ransomware then it's definitely a nuisance. In such case, you will have to use Kaspersky Rescue CD or any other Live CD to remove International Police Association virus from your computer. Both removal methods are described in details below. So, fist of all, try to reboot your computer in Safe Mod and if it doesn't work then follow the alternate removal guide.

If you have any questions are need extra help removing this ransomware from your computer, please leave comments below. Good luck!

Source: http://spywareremovalx.blogspot.com


Quick 'International Police Association' Ransomware removal instructions (System Restore, may not work for all users):

1. Reboot your computer in Safe Mode with Command Prompt. As the computer is booting tap the F8 key continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to Safe Mode with Command Promptand press Enter key.



2. Make sure you log in to an account with administrative privileges (login as admin).

3. Once the Command Prompt appears you have few seconds to type in explorer and hit Enter. If you fail to do it within 5 seconds, the 'International Police Association' ransomware will take over and will not let you type anymore.

4. If you managed to bring up Windows Explorer you can now browse into:
  • Win XP: C:\windows\system32\restore\rstrui.exe and press Enter
  • Win Vista/Seven: C:\windows\system32\rstrui.exe and press Enter
5. Follow the steps to restore your computer into an earlier day when it wasn't infected.

6. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove the remnants of International Police Association (I.P.A.) virus and to protect your computer against these types of threats in the future.


International Police Association Ransomware removal using Kaspersky Rescue Disk:

1. Download the Kaspersky Rescue Disk iso image from the Kaspersky Lab server. (Direct download link)
Please note that this is a large downloaded, so please be patient while it downloads.

2. Record the Kaspersky Rescue Disk iso image to a CD/DVD. You can use any CD/DVD record software you like. If you don't have any, please download and install ImgBurn. Small download, great software. You won't regret it, we promise.

For demonstration purposes we will use ImgBurn.

So, open up ImgBurn and choose Write image file to disc.



Click on the small Browse for file icon as show in the image. Browse into your download folder and select kav_rescue_10.iso as your source file.



OK, so know we are ready to burn the .iso file. Simply click the Write image file to disc button below and after a few minutes you will have a bootable Kaspersky Rescue Disk 10.



3. Configure your computer to boot from CD/DVD. Use the Delete or F2, F11 keys, to load the BIOS menu. Normally, the information how to enter the BIOS menu is displayed on the screen at the start of the OS boot.



The keys F1, F8, F10, F12 might be used for some motherboards, as well as the following key combinations:
  • Ctrl+Esc
  • Ctrl+Ins
  • Ctrl+Alt
  • Ctrl+Alt+Esc
  • Ctrl+Alt+Enter
  • Ctrl+Alt+Del
  • Ctrl+Alt+Ins
  • Ctrl+Alt+S
If you can enter Boot Menu directly then simply select your CD/DVD-ROM as your 1st boot device.

If you can't enter Boot Menu directly then simply use Delete key to enter BIOS menu. Select Boot from the main BIOS menu and then select Boot Device Priority.



Set CD/DVD-ROM as your 1st Boot Device. Save changes and exist BIOS menu.



4. Let's boot your computer from Kaspersky Rescue Disk.

Restart your computer. After restart, a message will appear on the screen: Press any key to enter the menu. So, press Enter or any other key to load the Kaspersky Rescue Disk.



5. Select your language and press Enter to continue.



6. Press 1 to accept the End User License Agreement.



7. Select Kaspersky Rescue Disk. Graphic Mode as your startup method. Press Enter. Once the actions described above have been performed, the operating system starts.



8. Click on the Start button located in the left bottom corner of the screen. Run Kaspersky WindowsUnlocker to remove Windows system and registry changes made by International Police Association (I.P.A.) Virus. It won't take very long.



9. Click on the Start button once again and fire up the Kaspersky Rescue Disk utility. First, select My Update Center tab and press Start update to get the latest malware definitions. Don't worry if you can't download the updates. Just proceed to the next step.



10. Select Object Scan tab. Place a check mark next to your local drive C:\. If you have two or more local drives make sure to check those as well. Then click Start Objects Scan to scan your computer for malicious software.



11. Quarantine (recommended) or delete every piece of malicious code detected during the system scan.



12. You can now close the Kaspersky Rescue Disk utility. Click on the Start button and select Restart computer.



13. Please restart your computer into the normal Windows mode. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove the remnants of International Police Association (I.P.A.) virus and to protect your computer against these types of threats in the future.

For for information about ransomware threats and possible removal methods, please read the general ransomware removal guide.

Tell your friends:

Wednesday, July 18, 2012

Remove MyStart by IncrediBar Search and Toolbar (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
For a few weeks now, we have been receiving an increasing number of emails from our readers asking us how to remove MyStart by IncrediBar search engine and the MyStart IncrediBar toolbar. We read all of the mail you send to us. Unfortunately, we are unable to respond to everyone individually.

Instead, we took a closer look at this issue and wrote comprehensive step-by-step removal instructions that apply to all Incredibar toolbars on all major web browsers: Internet Explorer, Mozilla Firefox and Google Chrome. If you don't want to read detailed analysis about this software and came here only for mystart toolbar removal instructions, please scroll the page down a bit.



If you do a quick Google search for MyStart by IncrediBar you’ll find many forum threads and posts about this toolbar. Surprisingly, most people think that they apparently ended up with the Incredibar MyStart virus, Trojan horse or some sort of malicious software. That’s not quite true. It’s a potentially unwanted application or a browser hijacker at worse if you like but not a virus. However, incredibar certainly won't go away that easy. That's why it's classified as PUA.

On the other hand, our readers confirmed that this toolbar causes unexpected web browser crashes, takes over the browser, substitutes Incredibar for the home page and http://mystart.incredibar.com for the search engine. Pretty much everything leads to MyStart page. It also redirects search results to their own search engine which is powered by Google (at least that’s what they say) and even displays annoying ads/pop-ups.

McAfee detects Incredibar installer as Heuristic.LooksLike.Win32.Suspicious.B. TrendMicro detects it as TROJ_ENCPK_0000009.TOMA and finally ESET also sees it as a threat Win32/ImInstaller potentially unwanted application.



Some behavior-based antivirus programs block My Start by IncrediBar too. So, even thought, it’s not a virus there’s definitely something wrong with this toolbar.

Incredibar toolbar is developed and published by Perion Network Ltd. They started in Tel Aviv about twelve years ago. Now they have an office in Redmond, WA. There are three version of this toolbar: essentials, music and games. We believe that he most popular is Incredibar Games. But Incredibar is not their only software product. They have other brands as well. First of all, the most popular product called Incredimail. It’s designed to enrich your emails with colorful graphics, animations, etc. If you choose to install Incredimail on your computer you may end up with MyStart by IncrediBar as well. Then there’s also a photo organization software product called PhotoJoy. Smilebox and even online safety and security software called Dr. CleanUp. We’ve never heard of it before.

MyStart by IncrediBar comes bundled with all their brand communication, photo sharing and safety products. What is more, this toolbar is distributed with the help of other freeware and shareware, codecs and HD video players. Most of the time, users can choose not to install this toolbar and we haven’t find any silent installers whatsoever. But we found a few reports indicating that this toolbar was distributed in rather misleading ways. In one particular case the user wasn't informed about the installation of this toolbar when he was installing a video converter. Image his surprise when MyStart by IncrediBar and the IncrediBar toolbar showed up on all web browsers.

IncrediBar toolbar can be uninstalled just by going to Control Panel and selecting Add/Remove Programs. But for some reasons, the folks at Perion forgot to mention that there’s also an application called Web Assistant. It must be uninstalled as well (see the removal instructions below). So, removing IncrediBar toolbar is not a big deal. But it’s a completely different story when it comes to MyStart by IncrediBar search page.

To remove MyStart by IncrediBar in Internet Explorer you need to manually remove the MyStart search engine provider and restore your default home page. It’s relatively easy. The same can be said about Google Chrome. You just need to manually remove IncrediBar extension and restore your default home page. But it really messes up with Mozilla Firefox. It modifies keyword.URL, browser.newtab.url and some other web browser settings. It goes without saying that most Firefox users don’t even know such settings exist and almost certainly do not know how to restore them. For example, if you won’t restore the keyword.URL string data value, you will be redirected http://mystart.incredibar.com when searching directly from the URL address bar. That’s really annoying.

For step-by-step instructions on how to remove MyStart by IncrediBar search engine and toolbar from your computer, please read the directions below. Please note, MyStart by IncrediBar and Incredibar settings apply to Internet Explorer, Mozilla Firefox, Google Chrome and Opera. From what I've seen so far removing incredibar from chrome is probably the most challenging task. Not the toolbar itself but the changes it made to the browser. Uninstall mystart search from major web browser isn't that easy either. This is especially true for Mozilla Firefox. Too many changes are made and if you choose to reset your web browser to its default state, you will lose your bookmarks, save passwords and browsing history. If you have nothing to lose then yeah, save yourself time and reset it. But if you don't want to lose anything, then follow the removal instructions below. If you need further assistance with this issue, please leave a comment below. Good luck!

Source: http://spywareremovalx.blogspot.com


MyStart by IncrediBar toolbar removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this browser hijacker. Hopefully you won't have to do that.





2. Go to the Start Menu. Select Control Panel → Add/Remove Programs.
If you are using Windows Vista or Windows 7, select Control Panel → Uninstall a Program.



3. Search for IncrediBar* toolbar and Web Assistant in the list. Select the program and click Remove button. Remove both components!

If you are using Windows Vista/7, click Uninstall up near the top of that window.



Alternate removal: run C:\Program Files\Incredibar*\uninstall.exe

* This is the name of the toolbar you downloaded (i.e. Incredibar Games, Incredibar Essentials or Incredibar Music).


Remove MyStart by IncrediBar in Internet Explorer:

1. Open Internet Explorer. Go to Tools → Manage Add-ons.



2. Select Search Providers. First of all, choose Bing or Live Search search engine and make it your default web search provider (Set as default).



3. Remove MyStart Search and Incredibar Customized Web Search web search providers. Close the window.



4. Go to Tools → Internet Options. Select General tab and click Use default button or enter your own website, e.g. google.com instead of http://mystart.incredibar.com. Click OK to save the changes. And that's about it for Internet Explorer.




Remove MyStart by IncrediBar in Mozilla Firefox:

1. Open Mozilla Firefox. Go to Tools → Add-ons.



2. Select Extensions. Remove IncrediBar* toolbar. Close the window.



3. Click on the magnifying glass search icon as shown in the image below and select Manage Search Engines....



4. Choose MyStart Search from the list and click Remove to remove it. Click OK to save changes.



5. Go to Tools → Options. Under the General tab reset the startup homepage or change it to google.com, etc.



6. In the URL address bar, type about:config and hit Enter.



Click I'll be careful, I promise! to continue.



In the filter at the top, type: mystart



Now, you should see all the preferences that were changed by IncrediBar toolbar. Right-click on the preference and select Reset to restore default value. Reset all found preferences!



And that's it for Mozilla Firefox!


Remove MyStart by IncrediBar in Google Chrome:

1. Click on Customize and control Google Chrome icon. Go to Tools → Extensions.



2. Select IncrediBar and click on the small recycle bin icon to remove the toolbar.



3. Click on Customize and control Google Chrome icon once again and now select Settings.



4. Click the Manage search engines... button.



5. Select Google or any other search engine you like from the list and make it your default search engine.



6. Select MyStart Search from the list and remove it by clicking the "X" mark as shown in the image below.



That's it!


Associated MyStart by IncrediBar files and registry values:

Files:
  • C:\Program Files\Incredibar-Games_EN\GottenAppsContextMenu.xml
  • C:\Program Files\Incredibar-Games_EN\Incredibar-Games_ENToolbarHelper.exe
  • C:\Program Files\Incredibar-Games_EN\ldrtbIncr.dll
  • C:\Program Files\Incredibar-Games_EN\OtherAppsContextMenu.xml
  • C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll
  • C:\Program Files\Incredibar-Games_EN\SharedAppsContextMenu.xml
  • C:\Program Files\Incredibar-Games_EN\tbIncr.dll
  • C:\Program Files\Incredibar-Games_EN\toolbar.cfg
  • C:\Program Files\Incredibar-Games_EN\ToolbarContextMenu.xml
  • C:\Program Files\Incredibar-Games_EN\uninstall.exe
Registry values:
  • HKEY_CURRENT_USER\Software\Conduit\RevertSettings "http://mystart.Incredibar.com?a=1ex6GUYANIc&i=38"
  • HKEY_CURRENT_USER\Software\IM\38 "PPD"
  • HKEY_CURRENT_USER\Software\ImInstaller\Incredibar
  • HKEY_CURRENT_USER\Software\Incredibar
  • HKEY_CURRENT_USER\Software\Incredibar-Games_EN
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main StartPage "http://mystart.Incredibar.com?a=1ex6GUYANIc&i=38"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Conduit\Toolbars "Incredibar-Games EN Toolbar"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Incredibar-Games_EN\toolbar
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "Incredibar-Games EN Toolbar"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Incredibar-Games EN Toolbar
Tell your friends:

 
//PART 2