snap.do has taken over internet exp and will not uninstall

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rory56, Apr 10, 2013.

  1. rory56

    rory56 Private E-2

    I have anHP Pavillion notebook running Windows 7 (64-bit)

    I accidentally downloaded snap.do and it immediatiately changed my internet explorer 9 icon; and default search engine. It has also caused my keyboard to not recgonize letters when typing. I changed the default search engine and tried to uninsall snap.do however it will not allow me to. I changed the "target" and then tried to uninstall but then snap.do went into hidden mode. I ran malwarebytes and it did not find any malware. So then I began searching the internet and found major geeks website. I read and completed the READ ME thread on removing malware and completed the steps exactly as instructed.

    Roquekiller found something but did not repair per instructions.
    MB.exe found no malware
    Hitman Pro found no malware
    tdsskiller found no malware

    When I ran MGtools it had an error that read it was unable to create a zip log and instructed me to let you know.

    I have attached my logs below. Please help and thank you
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [RUN][SUSP PATH] HKCU\[...]\Run : Browser Infrastructure Helper (C:\Users\Shelley\AppData\Local\Smartbar\Application\SnapDo.exe startup) [7] -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-179986196-3503877819-2988626173-1001[...]\Run : Browser Infrastructure Helper (C:\Users\Shelley\AppData\Local\Smartbar\Application\SnapDo.exe startup) [7] -> FOUND
      [TASK][SUSP PATH] thpm3094005370439433157 : \\.\globalroot\Device\HarddiskVolume2\Users\Shelley\AppData\Local\Temp\thpm3094005370439433157.tmp [x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now rerun Hitman and have it delete all that it found.

    Reboot and rescan with both RogueKiller and Hitman and attach those new logs as well.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds