snap do spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ericbg, Nov 7, 2012.

  1. ericbg

    ericbg Private E-2

    i seem to have snap.do spyware on my pc. i think i got it from a website form or from an email link to youtube video. here's my scan file. i've had it on ie and chrome for about 2-3 days.
    should i stop using the pc or stop with browsers too.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the C:\MGlogs.zip file that was requested from MGtools before we can continue.
     
  3. ericbg

    ericbg Private E-2

    thanks. i'm sorry i forgot the name of the file and where i saved it to.. thanks for info. here it is.
    so far none of the scans found anything as far as i know in my limited knowledge. but it marked one file as suspicious .. and i think its from a game on my pc. i bought the game.
    i await instructions. thank you.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you download MGtools.exe 4 times????

    You need clean these up as you don't need them. Also you should delete all those XML and JPG files you are saving in the root folder. You should not be making a habit of saving files here.



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=Down...87f-14700e37eb24&searchtype=ds&q={searchTerms}
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=Down...87f-14700e37eb24&searchtype=ds&q={searchTerms}
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://feed.snap.do/?publisher=Down...835-91e3-49d2-a87f-14700e37eb24&searchtype=hp
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=Down...87f-14700e37eb24&searchtype=ds&q={searchTerms}
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=Down...87f-14700e37eb24&searchtype=ds&q={searchTerms}
    O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds