Can't remove Snap.do

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by zeroth01, Mar 26, 2013.

  1. zeroth01

    zeroth01 Private E-2

    Hi Major Geeks,
    Whilst my significant other was using the computer she inadvertently installed something and since then Internet Explorer always starts up at search.snap.do. Firefox however doesn't currently have the problem, although it may have initially - I can't remember nowas this happened around 2 months ago. I have followed the steps in the 'READ & RUN ME FIRST Malware Removal Guide', Please see the logs attached.
    Before coming to Major Geeks I tried a number of things including:
    • Uninstalling Snap.do and other seemingly related items from IEs addons. (I wish I had taken notes of exactly everything done, however I didn't as I never thought it would be this difficult to remove!)
    • Uninstalling snap.do using Control Panel - Programs and Features. Snap.do no longer appears there however it is still appears when starting IE.
    • running Malwarebytes - I will attach the previous logs in another post.
     

    Attached Files:

    Last edited by a moderator: Mar 26, 2013
  2. zeroth01

    zeroth01 Private E-2

    As mentioned in my first post please see the additional log files attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rerun Hitman and have it delete Potential Unwanted Programs if any remain.

    also... [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  4. zeroth01

    zeroth01 Private E-2

    Thanks Kestrel,

    I ran Hitman and a number of registry keys were reported - I had Hitman delete them, please see the logs attached. I then ran the Junkware Removal Tool see the log attached. Unfortunately the problem still remains.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  6. zeroth01

    zeroth01 Private E-2

    Thanks again for your help, I ran OTL please see the logs attached. Problem still remains.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I know its still an issue. Tell me, which browser does this affect please?
     
  8. zeroth01

    zeroth01 Private E-2

    It affects Internet Explorer (version 9). I also have Firefox installed and it works without issue. Thanks again
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Update to IE10 and tell me if it continues...
     
  10. zeroth01

    zeroth01 Private E-2

    Bugger - I upgraded to IE 10 and thought that it was sure to fix the problem, but alas snap.do still remains.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall this:
    • GetSavin

    Delete this folder:
    C:\ProgramData\Strongvault Online Backup


    Run this and attach the results.

    Using ESET's Online Scanner

    Still the same or has it gone?
     
  12. zeroth01

    zeroth01 Private E-2

    I went to programs and features in control panel and tried to uninstall GetSavin. However and error was displayed:

    "An error occurred while trying to uninstall GetSavin. It may have already been uninstalled.

    Would you like to remove GetSavin from the Programs and Features list?"
    Yes | No

    I selected Yes.

    I could not find a folder C:\ProgramData\Strongvault Online Backup

    I ran the ESET scan please see the results attached.
     

    Attached Files:

  13. zeroth01

    zeroth01 Private E-2

    I forgot to mention that Snap.Do still remains
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, zeroth01

    Let's see if this tool removes it.

    Please download AdwCleaner by Xplode and save it to your Desktop.

    Using AdwCleaner
    • Double-click AdwCleaner.exe to run it. (Vista & Win7 users should right-click and "Run As Administrator")
    • Click on Delete
    • Your pc should now automatically re-boot
    • AdwCleaner will display a log showing the files, folders, and registry entries that were removed.
    • Attach this log to your next reply.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  16. zeroth01

    zeroth01 Private E-2

    I ran AdwCleaner please see the log attached.
    I installed Revo Uninstaller however it also didn't list GetSavin
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now shut down your protection software (antivirus, antispyware...etc) to avoid possible conflicts.
    • Double-click OTL.exe to run. (if running Vista, Win7, or Win8 use right-click and select Run as Administrator)
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    :OTL
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = [URL]http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox[/URL]
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = [URL]http://au.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF[/URL]
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = [URL]http://en.wikipedia.org/wiki/Special:Search?search={searchTerms[/URL]}
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = [URL]http://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms[/URL]}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = [URL]http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox[/URL]
    CHR - default_search_provider: SweetIM Search (Enabled)
    CHR - Extension: GetSavin = C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjildcbkilmkddbbpbjljljdmmlfeppl\5.0_0\
    CHR - Extension: No name found = C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\licjnkifamhpbaefhdpacpmihicfbomb\2.1.0.22_0\
    CHR - Extension: GetSavin = C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjildcbkilmkddbbpbjljljdmmlfeppl\5.0_0\
    O2 - BHO: (GetSavin 5.0) - {4334C8BB-FA2D-4464-91BB-E8A1DDE49507} - C:\Users\Sarah\AppData\Local\getsavin\ie\getsavin_1364257202.dll File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
     
    :Files
    C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjildcbkilmkddbbpbjljljdmmlfeppl
    C:\Users\Sarah\AppData\Local\getsavin
    
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GetSavin]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GetSavin]
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    [REBOOT]
    • Now click the [​IMG] button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)

    Please follow the instructions in the below link to Reset IE back to defaults.

    http://windows.microsoft.com/en-us/windows7/reset-internet-explorer-settings-in-internet-explorer-9

    Make sure you now exit IE and then restart it before doing the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell us how things are working now!
     
  18. zeroth01

    zeroth01 Private E-2

    Thanks Chaslang,
    Please see the requested logs attached. Unfortunately IE still starts up at http://search.snap.do/
    It's certainly stubborn!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you mean that when you start IE that your home page is that URL then just change it to what you desire.

    Also you still need to delete the below folder which Kestrel13! requested earlier. It does exist in your new logs. So you need to make sure you are looking properly.

    C:\ProgramData\Strongvault Online Backup


    Ooops! It appears that you did not get MGtools to run properly. Please shutdown protection software and run it again as requested. You last log is not fully updated.
     
    Last edited: Apr 1, 2013
  20. zeroth01

    zeroth01 Private E-2

    Yes when I open IE it opens at Snap.Do, however my homepage is set to www.google.com. When I click the Home icon it correctly goes to google.

    I can't find C:\ProgramData\Strongvault Online Backup
    I have "Show hidden files, folders, and drives" enabled and "Hide protected operating system files" disabled.

    I reran C:\MGtools\GetLogs.bat please see the logs attached. I use Microsoft Security Essentials and had it disabled to run the bat file.
     

    Attached Files:

  21. zeroth01

    zeroth01 Private E-2

    I reran the full MGTools see the log attached
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please put copies of the below 3 files into a ZIP file and attach it here:

    Code:
     
    1,375 2013-01-18 02:46:44  C:\Users\Sarah\Desktop\Internet Explorer.lnk 
    1,410 2013-03-12 01:26:15  C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Convert.lnk
    1,431 2013-03-29 23:14:00  C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    
     
  23. zeroth01

    zeroth01 Private E-2

    Please see the shortcuts attached.
    Cheers
     

    Attached Files:

  24. zeroth01

    zeroth01 Private E-2

    Chaslang your a legend!
    Those link files were directing Internet Explorer to the snap.do website. I deleted the reference to snap.do in the target section of the link and now IE seems to be working fine.

    Thanks to you Kestrel13! and dr.moriarty for your help.
    Are there any cleanup operations I need to perform?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds