Avast WEBforum

Other => Viruses and worms => Topic started by: jagdeep Bajaj on September 09, 2013, 06:33:18 AM

Title: snap do virus
Post by: jagdeep Bajaj on September 09, 2013, 06:33:18 AM
hello
whenever i open my browser i see this search engine snap.do(search.snapdo.com/?st=nt&q=). it looks like a nagging virus/malware to me. it has slowed down my laptop. the dds.txt and attact.txt are attached.
kindly help me out
thank you
Title: Re: snap do virus
Post by: mikaelrask on September 09, 2013, 07:25:06 AM
hey and welcome to the forum. please follow this guide and attach your logs.

http://forum.avast.com/index.php?topic=53253.0

a malware expert will help you from there. 
Title: Re: snap do virus
Post by: argus on September 09, 2013, 08:19:02 AM
Hi jagdeep Bajaj, download and run AdwCleaner

http://forum.avast.com/index.php?topic=53253.0


------ Next ------




Please download zoek.zip ((http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png)) from here (http://hijackthis.nl/smeenk) or here (http://home.kpn.nl/stefsmeenk/zoek.exe) and save it to your Desktop.
Unpack the archive...
Code: [Select]
filesrcm;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;
Title: Re: snap do virus
Post by: argus on September 09, 2013, 11:10:46 AM


thyself helping magna here

http://forum.avast.com/index.php?topic=134082.msg986121#new
Title: Re: snap do virus
Post by: jagdeep Bajaj on September 10, 2013, 04:55:11 AM
hello
yes magna is helping me in another thread but that is of my office P.C. and it is almost solved.
the problem mentioned here is of my home laptop.
i ran zoek as per your instructions and the log is attached 
Title: Re: snap do virus
Post by: argus on September 10, 2013, 08:22:26 AM
Re-run zoek with this script

Code: [Select]
emptyclsid;
C:\Program Files (x86)\Winamp Toolbar;fs
C:\users\Jagdeep\AppData\Local\Winamp Toolbar;fs
C:\ProgramData\Winamp Toolbar;fs
C:\Users\Jagdeep\AppData\Local\Smartbar\Application;fs
[HKEY_USERS\S-1-5-21-2382360282-1360722930-1941866962-1000\Software\Microsoft\Windows\CurrentVersion\Run];r
"Browser Infrastructure Helper"=-;r
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run];r
"Browser Infrastructure Helper"=-;r
amfclgbdpgndipgoegfpkkgobahigbcl;chr
{006ee092-9658-4fd6-bd8e-a21a348e59f5};c
{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C};c
iedefaults;
emptyalltemp;
autoclean;
Title: Re: snap do virus
Post by: jagdeep Bajaj on September 12, 2013, 07:04:56 AM
the log is attached
Title: Re: snap do virus
Post by: argus on September 12, 2013, 09:47:43 AM
Whether it is okay?
Title: Re: snap do virus
Post by: jagdeep Bajaj on September 12, 2013, 05:34:59 PM
the snapdo has not gone it is still there in chrome
Title: Re: snap do virus
Post by: argus on September 12, 2013, 07:34:35 PM
Rerun zoek with this script:

Code: [Select]
chrdefaults;
emptyclsid;
autoclean;


(http://imageshack.us/a/img841/7292/thisisujrt.gif)  Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/) to your desktop.
Title: Re: snap do virus
Post by: jagdeep Bajaj on September 13, 2013, 08:32:13 AM
the files are attached
Title: Re: snap do virus
Post by: argus on September 13, 2013, 09:41:49 AM
Feedback??
Title: Re: snap do virus
Post by: jagdeep Bajaj on September 13, 2013, 05:21:11 PM
 snapdo is gone i suppose as it is not appearing in chrome.
thanks :)
Title: Re: snap do virus
Post by: argus on September 13, 2013, 05:25:11 PM
OK, remove DDS and zoek, greeting.