Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Snap.Do and Snap.Do.Engine will not uninstall [Solved]


  • This topic is locked This topic is locked

#16
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

I MANAGED TO GET ON TODAY (FRIDAY). COMPUTER IS RUNNING GOOD. NO ISSUES. 


  • 0

Advertisements


#17
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

COMPUTER SEEMS TO BE RUNNING FASTER. I CHECKED THE CONTROL PANEL AND SNAPDO IS GONE. WOW! ARE WE FINISHED?


  • 0

#18
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts

WOW! ARE WE FINISHED?

 
Not yet. Some portions of important scans are left. However, I promise you, you'll get rid of me very soon. :)
 
Step 1. AdwCleaner scan.
  • Right click on adwcleaner.exe file on your Desktop->Run as Administrator.
  • Adwcleaner window should appear.
  • Click on the Clean button.
  • Click on OK.
  • Computer will be rebooted automatically, when program will finish it's job.
After reboot:
  • Right click on adwcleaner.exe file on your Desktop->Run as Administrator.
  • AdwCleaner window should appear.
  • Click on the Scan button.
  • When scan will be finished, click Report button.
  • Now ahould appear Notepad window with report. Post the contents of the report in your next message.
Step 2. MBAM scan.

bf_new.gif Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup<build number here>.exe to install the application.
  • Make sure a checkmark is placed next to Launch Malwarebytes' Anti-Malware.
  • Make sure that checkmark is NOT placed next to Enable free trial of Malwarebytes Anti-Malware Premium.
  • Click Finish.
  • Malwarebytes Anti-Malware will be launched.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, click big green button Scan now.
  • The scan may take some time to finish, so please be patient.
  • When the scan is completed, click Copy to Clipboard button.
  • Click Cancel, after that - Yes.
  • Paste the entire report in your next reply.
Step 3. ESET Online Scanner scan.

Please run a free online scan with the ESET Online Scanner.

Vista / Win7 users: Right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator.

Note: This scan works with Internet Explorer or Mozilla FireFox.

You will need to disable your current installed Anti-Virus for the duration of the online scan, how to do so can be read here.

If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
  • Click the green ESET Online Scanner box.
  • Tick the box next to YES, I accept the Terms of Use then click on: Start.
  • You may see a panel towards the top of the screen telling you the website wants to install an addon... click and allow it to install. If your firewall asks whether you want to allow installation, say yes.
  • Make sure that the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click on Start
  • The virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close, make sure you copy the logfile first!
  • Then click on: Finish.
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
So, please, don't forget to post in your next message:
  • AdwCleaner's log
  • MBAM log
  • ESET Online Scanner's log

  • 0

#19
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

I checked my Control Panel and SnapDo is gone. Computer is running good. 


  • 0

#20
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts

But how about logs?


  • 0

#21
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

You have been fantastically helpful! Here is AdwCleaner Notepad contents.

 

# AdwCleaner v3.023 - Report created 11/04/2014 at 13:50:28
# Updated 01/04/2014 by Xplode
# Operating System : Windows 8.1  (64 bits)
# Username : Kim - KIMSHIP
# Running from : C:\Users\Kim\Downloads\adwcleaner (2).exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.16518
 
 
-\\ Google Chrome v34.0.1847.116
 
[ File : C:\Users\Kim\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [5381 octets] - [26/03/2014 18:38:14]
AdwCleaner[R1].txt - [855 octets] - [11/04/2014 13:45:41]
AdwCleaner[R2].txt - [716 octets] - [11/04/2014 13:50:28]
AdwCleaner[S0].txt - [4946 octets] - [26/03/2014 19:15:15]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [835 octets] ##########
 

  • 0

#22
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts

Where is Malwarebytes log? And where is ESET log? :)


  • 0

#23
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

Sorry Phel. I forgot the other Steps. Here they are...

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 4/14/2014
Scan Time: 10:40:17 PM
Logfile: 
Administrator: Yes
 
Version: 2.00.1.1004
Malware Database: v2014.04.15.02
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Kim
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 242874
Time Elapsed: 15 min, 8 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 1
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
 
 
 
 

  • 0

#24
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
ESET Threats Found.
 
C:\temp\t.msi Win32/AdWare.Adpeak.B application deleted - quarantined
C:\Users\Kim\AppData\Local\Temp\dlmAC44.tmp\OutfoxTV_silent_nopopup_addon_151.exe a variant of Win32/Toolbar.Besttoolbars.G potentially unwanted application deleted - quarantined
C:\Users\Kim\Downloads\cbsidlm-cbsi188-AdwCleaner-SEO-75851221 (1).exe a variant of Win32/CNETInstaller.B potentially unwanted application deleted - quarantined
C:\Users\Kim\Downloads\cbsidlm-cbsi188-AdwCleaner-SEO-75851221.exe a variant of Win32/CNETInstaller.B potentially unwanted application deleted - quarantined
C:\Windows\Installer\17a7d3e2.msi Win32/AdWare.Adpeak.B application deleted - quarantined
C:\Windows\Installer\80fac05.msi a variant of MSIL/Toolbar.Linkury.C potentially unwanted application deleted - quarantined
 

  • 0

#25
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

Would this be the correct ESET log file?

 

 
[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799
 

  • 0

Advertisements


#26
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

My computer has Program Files and Program Files (x86). I found the log file under the Program Files (x86).

 

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=5590c04e3d439b43a383a632cf5242ac
# engine=17889
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-04-15 05:58:48
# local_time=2014-04-15 01:58:48 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.2.9200 NT 
# compatibility_mode=5893 16776574 100 94 1744323 21501221 0 0
# scanned=154970
# found=6
# cleaned=6
# scan_time=9782
# nod_component=V3 Build:0x30000000
sh=6205DDE47C041E3B67EFC540F89F24344835EE11 ft=0 fh=0000000000000000 vn="Win32/AdWare.Adpeak.B application (deleted - quarantined)" ac=C fn="C:\temp\t.msi"
sh=948D04D349CA065C192323470A4DF26FC2AD0E33 ft=1 fh=5864273236276c65 vn="a variant of Win32/Toolbar.Besttoolbars.G potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Kim\AppData\Local\Temp\dlmAC44.tmp\OutfoxTV_silent_nopopup_addon_151.exe"
sh=19876B0C21073CE7AC4725124851FC36B7EA7301 ft=1 fh=31b372839de59c7b vn="a variant of Win32/CNETInstaller.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Kim\Downloads\cbsidlm-cbsi188-AdwCleaner-SEO-75851221 (1).exe"
sh=19876B0C21073CE7AC4725124851FC36B7EA7301 ft=1 fh=31b372839de59c7b vn="a variant of Win32/CNETInstaller.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Kim\Downloads\cbsidlm-cbsi188-AdwCleaner-SEO-75851221.exe"
sh=6205DDE47C041E3B67EFC540F89F24344835EE11 ft=0 fh=0000000000000000 vn="Win32/AdWare.Adpeak.B application (deleted - quarantined)" ac=C fn="C:\Windows\Installer\17a7d3e2.msi"
sh=4E2FFDA2B4D7081B06D0B608D60683838A94C5F7 ft=0 fh=0000000000000000 vn="a variant of MSIL/Toolbar.Linkury.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Windows\Installer\80fac05.msi"
 
 
 
 

  • 0

#27
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts
I found the log file under the Program Files (x86).

 

Sorry about that. Yes, it's the right log.

 

Okay, let's clean it:

 

  1. Run Malwarebytes Anti-Malware.
  2. If an update is found, it will download and install the latest version.
  3. Once the program has loaded, click big green button Scan now.
  4. The scan may take some time to finish, so please be patient.
  5. When the scan is completed, click Apply Actions button.
  6. When finished, reboot your computer.

  • 0

#28
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

The Registry Data: 1 PUP.Optional.SnapDo.A, (etc.) was cleaned up.

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 4/17/2014
Scan Time: 5:22:45 PM
Logfile: 
Administrator: Yes
 
Version: 2.00.1.1004
Malware Database: v2014.04.17.07
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Kim
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 243977
Time Elapsed: 16 min, 13 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 1
PUP.Optional.SnapDo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://feed.snapdo.c...OcjuRXcBm2E,&q={searchTerms}, Good: (www.google.com), Bad: (http://feed.snapdo.com/?p=mKO_AwFzXIpYRbaPuJho93q_rwYmLYBecCau0A8gUQbjoqmOnNhRG2FlxZ76a_gLeJP6pf6EksVtTQC5nRD9lYVOkL322WxRLJsYSaoLngcRB4vDtIpRNAkFb4aOvuT2g6zc0moF3o20MKwqRJ35ZP1iK5RgLHwGNDPkeuq1LInzU-g-JtUWOcjuRXcBm2E,&q={searchTerms}),No Action By User,[8be0969527546accd6c7fc2126de2dd3]
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 

 


  • 0

#29
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts

So, do you still have any problems?


  • 0

#30
sugarbee

sugarbee

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

No problems.It's all good.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP