Snap.do

Snap.do Description

Snap.do Image 1The Snap.do website is associated with the Smartbar toolbar for your web browser. This toolbar is actually an adware component. Even though Snap.do claims that Snap.do can simplify the way you access your favorite websites, this website and its associated toolbar have several unwanted behaviors that are more closely associated with known malware infections than with legitimate applications. Most of the time, the Snap.do toolbar will be bundled along with freeware programs, included in the installation process.

Reading the 'official' description of Snap.do, it would be hard to guess that this website is linked to malware. The people behind Snap.do claim that this website's vision is to become an industry leader in providing simple, smart web solutions to their clients as well as complementary programs that improve browser efficiency and make browsing simply with interfaces and technologies that computer users are already used to utilize. However, this vision does not match up well to reality, since products associated with Snap.do have various components that are more commonly associated with adware. There are three reasons why products associated with Snap.do are considered unsafe for your computer:

  1. Products associated with Snap.do may have spyware capabilities. That is, this website and software associated with Snap.do will collect your personal data and then distribute it to a third party without your authorization.
  2. The Snap.do website and software associated with Snap.do may also be considered adware. This is because Snap.do is designed to deliver intrusive advertisements based on private data collected about your browsing behaviors. These advertisements may appear as pop-up windows or embedded in web pages.
  3. Snap.do is also linked to browser hijackers. These kinds of components are designed to change your web browser's settings, affecting which websites you are able to visit and alters the way you browse the Internet.

While many websites associated with browser hijackers may, in themselves, be perfectly safe, this is not the case with Snap.do and software associated with this website. Due to their adware and browser hijacker components, any contact with the Snap.do website or with software associated with Snap.do should be followed with a thorough scan of your machine with a capable anti-malware application.

Aliases: PE:Malware.RDM.26!5.20[F1], Adware.Win32.Linkury.U, a variant of Win32/Toolbar.Linkury.U.gen potential, TR/Trash.Gen, Bloodhound.MalPE [Symantec], a variant of MSIL/Toolbar.Linkury.AD potentially u, PUP/Win32.Toolbar [AhnLab-V3], Adware.MSIL.Linkury.AD and Adware.Linkury (fs).

Technical Information

File System Details

Snap.do creates the following file(s):
# File Name Size MD5 Detection Count
1 %ALLUSERSPROFILE%\cloudprinter\cloudprinter.dat 54,272 cecec73094ba3e1b7abe788ae5a5204a 265,768
2 %ALLUSERSPROFILE%\quoteex\lexistring.dll 342,528 bac6f8dcf34e0cc8ba6f32d34cad332c 187,323
3 %ALLUSERSPROFILE%\lamzap\gravefresh.dat 252,928 09eab69315e00b74dfa2ca27a5542829 124,803
4 \??\C:\ProgramData\Utatity\Toughtip_IObitDel.dll\Toughtip_IObitDel.dll 342,528 999259b797b41f66383baef4c0b9b8a3 57,001
5 %SYSTEMDRIVE%\Users\Karolukas\AppData\Local\Hotity.exe\Hotity.exe 1,630,720 69c8ef945e58622533a175aabca0ff77 22,564
6 %ALLUSERSPROFILE%\appnegylop\appnegylop.exe 1,446,912 ebc4060fbab66858946b4c2ed38fd446 9,772
7 %ALLUSERSPROFILE%\tolnix\tolnix.dat 18,432 2fec597e9623bb7cf1b0421d2d88cab1 9,456
8 uninstall.ico 1,150 f0629844b82419eb727a3858f31dc85a 1,576
9 %SYSTEMDRIVE%\Users\LeeTingHin\AppData\Local\Rancore.exe\Rancore.exe 1,995,264 7011d2064e7d653e3c2a8fa91504e468 666
10 %ALLUSERSPROFILE%\awna\awna.exe 400,896 b78bfb23a0fc01e216c40d63687da071 149
11 %ALLUSERSPROFILE%\AppdnifmiN\AppdnifmiN.exe 400,896 24a74f120eccbec5942ce9c627c31db4 69
12 %ALLUSERSPROFILE%\Affenpinscher\Affenpinscher.exe 400,896 5bb426416d26df31746803b905486292 64
13 %ALLUSERSPROFILE%\ocep\ocep.exe 400,896 2cf641c23d296a503827f6d409e0435d 50
14 %PROGRAMFILES(x86)%\Gorny\gld.exe\gld.exe 61,103 c5ea20f32c1ad46670b6a6442ddd04d6 37
15 %PROGRAMFILES(x86)%\basque\emphasising.exe\emphasising.exe 37,758 25034e95214d42e20e9383a353c125f6 36
16 %ALLUSERSPROFILE%\AppgnielbuoD\AppgnielbuoD.exe 400,896 b5284765a908b8ec8916728f906f5d49 31
17 %PROGRAMFILES(x86)%\patience\patience.exe\patience.exe 9,216 069ad9a7445f11563b2919a5f006979c 31
18 %ALLUSERSPROFILE%\Plusdax\Plusdax.exe 981,504 257307e67723a3b4532a858e83862986 27
19 %SYSTEMDRIVE%\Users\N.Ulziisaikhan\AppData\Local\Flex-Phase.exe\Flex-Phase.exe 1,995,264 68379a5bb3a8532611c0d4834b5341a0 25
20 %ALLUSERSPROFILE%\AppxedtatS\AppxedtatS.exe 400,896 402ebaea21791ea8d4b92a30b239978d 24
21 %ALLUSERSPROFILE%\Quoteex\Quoteex.exe 692,736 016384a52fa6d1ff5c7b6a3e8ac7df2d 24
22 %ALLUSERSPROFILE%\Hotfresh\Hotfresh.exe 692,736 bad3323eee5e6b00d16abdacb5d14250 18
23 %COMMONPROGRAMFILES(x86)%\zathlax\uninstall.dat 140,800 660fd6596a4ed4e26d1962233ed39c53 12
24 C:\Users\user\AppData\Local\Sumlight.exe 2,296,832 32bb17b31df0349847a32ac90c703448 5
25 %ALLUSERSPROFILE%\NetworkPacketManitor\crambo.exe 2,927,912 7ce53c9cc3d30ab0df7d0e0849c9a7bf 1
More files

Registry Details

Snap.do creates the following registry entry or registry entries:
File name without path
Alphatax.exe
Alphatop.exe
Bam-Phase.exe
Daltla.exe
Domnimdex.exe
Doublelax.exe
Fasecore.exe
FaseSaostock.exe
Laquonix.exe
OpeZamjob.exe
SailLatsing.exe
Salttrax.exe
StrongDonlab.exe
Trueex.exe
Unodex.exe
ZerCom.exe
Zunlotlight.exe
Regexp file mask
%appdata%\agent.dat
%appdata%\giftbag.db
%appdata%\installationconfiguration.xml
%appdata%\noah.dat
%appdata%\uninstall_temp.ico
%localappdata%\agent.dat
%LOCALAPPDATA%\dongls.exe
%localappdata%\freshlab.exe
%localappdata%\funzap.exe
%localappdata%\giftbag.db
%LOCALAPPDATA%\Greenjob.[RANDOM CHARACTERS]
%localappdata%\hatcof.exe
%localappdata%\installationconfiguration.xml
%LOCALAPPDATA%\JobSilsing.exe
%localappdata%\main.dat
%localappdata%\newstatdex.exe
%localappdata%\noah.dat
%localappdata%\qvotop.exe
%localappdata%\relam.exe
%localappdata%\saoeco.exe
%LOCALAPPDATA%\sha.db
%localappdata%\sham.db
%localappdata%\silverity.exe
%localappdata%\silversanair.exe
%localappdata%\yearfix.exe
%userprofile%\local settings\application data\funzap.exe
%userprofile%\local settings\application data\hatcof.exe
%UserProfile%\Local Settings\Application Data\sha.db
%userprofile%\local settings\application data\yearfix.exe
%windir%\system32\config\systemprofile\appdata\local\agent.dat
%windir%\system32\config\systemprofile\appdata\local\applicationhosting.dat
%windir%\system32\config\systemprofile\appdata\local\config.xml
%windir%\system32\config\systemprofile\appdata\local\lobby.dat
%windir%\system32\config\systemprofile\appdata\local\main.dat
%windir%\system32\config\systemprofile\appdata\local\md.xml
%windir%\system32\config\systemprofile\appdata\local\noah.dat
%WINDIR%\System32\config\systemprofile\AppData\Local\sha.db
%windir%\system32\config\systemprofile\appdata\local\sham.db
%windir%\system32\config\systemprofile\appdata\local\uninstall_temp.ico
%windir%\syswow64\config\systemprofile\appdata\local\agent.dat
%windir%\syswow64\config\systemprofile\appdata\local\applicationhosting.dat
%windir%\syswow64\config\systemprofile\appdata\local\config.xml
%windir%\syswow64\config\systemprofile\appdata\local\lobby.dat
%windir%\syswow64\config\systemprofile\appdata\local\main.dat
%windir%\syswow64\config\systemprofile\appdata\local\md.xml
%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\sha.db
%windir%\syswow64\config\systemprofile\appdata\local\sham.db
%windir%\syswow64\config\systemprofile\appdata\local\uninstall_temp.ico
Directory
%ALLUSERSPROFILE%\Anwendungsdaten\Logic Cramble
%ALLUSERSPROFILE%\appcognap
%ALLUSERSPROFILE%\Application Data\AppoxinloK
%ALLUSERSPROFILE%\Application Data\apptreppabm
%ALLUSERSPROFILE%\Application Data\apptreppabms
%ALLUSERSPROFILE%\Application Data\appxafmads
%ALLUSERSPROFILE%\Application Data\Graveairs
%ALLUSERSPROFILE%\Application Data\kipolam
%ALLUSERSPROFILE%\Application Data\mbappert
%ALLUSERSPROFILE%\Application Data\mbapperts
%ALLUSERSPROFILE%\Application Data\pangoc
%ALLUSERSPROFILE%\Application Data\pangocs
%ALLUSERSPROFILE%\Application Data\tolnix
%ALLUSERSPROFILE%\Application Data\tolnixs
%ALLUSERSPROFILE%\Application Data\Zonsoft
%ALLUSERSPROFILE%\Application Data\Zonsofts
%ALLUSERSPROFILE%\AppnegyloP
%ALLUSERSPROFILE%\AppnorriA
%ALLUSERSPROFILE%\AppnorriAs
%ALLUSERSPROFILE%\AppoxinloK
%ALLUSERSPROFILE%\AppoxinloKs
%ALLUSERSPROFILE%\apppitsirt
%ALLUSERSPROFILE%\ApppotriA
%ALLUSERSPROFILE%\ApppotriAs
%ALLUSERSPROFILE%\apprelrons
%ALLUSERSPROFILE%\apprelronss
%ALLUSERSPROFILE%\AppthgildeMs
%ALLUSERSPROFILE%\apptreppabm
%ALLUSERSPROFILE%\apptreppabms
%ALLUSERSPROFILE%\appxafmads
%ALLUSERSPROFILE%\AppxelosknoK
%ALLUSERSPROFILE%\appxinlot
%ALLUSERSPROFILE%\BluetoothPoint
%ALLUSERSPROFILE%\BluetoothPoints
%ALLUSERSPROFILE%\Dados de aplicativos\Logic Cramble
%ALLUSERSPROFILE%\Daltit
%ALLUSERSPROFILE%\Daltits
%ALLUSERSPROFILE%\Dane aplikacji\Logic Cramble
%ALLUSERSPROFILE%\Dati applicazioni\Logic Cramble
%ALLUSERSPROFILE%\Datos de programa\Logic Cramble
%ALLUSERSPROFILE%\ecivreSevaS
%ALLUSERSPROFILE%\ecivreSevaSs
%ALLUSERSPROFILE%\Graveairs
%ALLUSERSPROFILE%\Hotfreshs
%ALLUSERSPROFILE%\iretadpUMGRs
%ALLUSERSPROFILE%\kipolam
%ALLUSERSPROFILE%\loceps
%ALLUSERSPROFILE%\mbappert
%ALLUSERSPROFILE%\mbapperts
%ALLUSERSPROFILE%\ohnuze
%ALLUSERSPROFILE%\ohnuzes
%ALLUSERSPROFILE%\pangoc
%ALLUSERSPROFILE%\pangocs
%ALLUSERSPROFILE%\Pitachoks
%ALLUSERSPROFILE%\Polygen
%ALLUSERSPROFILE%\Polygens
%ALLUSERSPROFILE%\Silsolis
%ALLUSERSPROFILE%\Silsoliss
%ALLUSERSPROFILE%\Singdaxs
%ALLUSERSPROFILE%\tolnix
%ALLUSERSPROFILE%\tolnixs
%ALLUSERSPROFILE%\Trioflex
%ALLUSERSPROFILE%\Trioflexs
%ALLUSERSPROFILE%\Viaair
%ALLUSERSPROFILE%\Viaairs
%ALLUSERSPROFILE%\xifss
%ALLUSERSPROFILE%\Zonsoft
%ALLUSERSPROFILE%\Zonsofts
%COMMONPROGRAMFILES%\Alphafan
%COMMONPROGRAMFILES%\Alphait
%COMMONPROGRAMFILES%\AlphaString
%COMMONPROGRAMFILES%\Alphatone
%COMMONPROGRAMFILES%\Apfix
%COMMONPROGRAMFILES%\Apsing
%COMMONPROGRAMFILES%\Betastrong
%COMMONPROGRAMFILES%\Bio-Com
%COMMONPROGRAMFILES%\biojob
%COMMONPROGRAMFILES%\Biolight
%COMMONPROGRAMFILES%\Cantrax
%COMMONPROGRAMFILES%\Confind
%COMMONPROGRAMFILES%\dentozimeco
%COMMONPROGRAMFILES%\Doublelab
%COMMONPROGRAMFILES%\Ecojob
%COMMONPROGRAMFILES%\Finphase
%COMMONPROGRAMFILES%\Fixfax
%COMMONPROGRAMFILES%\Goodlex
%COMMONPROGRAMFILES%\Grooveair
%COMMONPROGRAMFILES%\Groovecof
%COMMONPROGRAMFILES%\GrooveTax
%COMMONPROGRAMFILES%\HatTrax
%COMMONPROGRAMFILES%\Hometough
%COMMONPROGRAMFILES%\Icetech
%COMMONPROGRAMFILES%\Inchair
%COMMONPROGRAMFILES%\Inchstrong
%COMMONPROGRAMFILES%\IndigoNix
%COMMONPROGRAMFILES%\Joy-Com
%COMMONPROGRAMFILES%\kanis
%COMMONPROGRAMFILES%\Kanla
%COMMONPROGRAMFILES%\kay-dax
%COMMONPROGRAMFILES%\Key-Soft
%COMMONPROGRAMFILES%\KinDom
%COMMONPROGRAMFILES%\Kinin
%COMMONPROGRAMFILES%\Labzap
%COMMONPROGRAMFILES%\Lamcof
%COMMONPROGRAMFILES%\Lamity
%COMMONPROGRAMFILES%\Matstrong
%COMMONPROGRAMFILES%\Medis
%COMMONPROGRAMFILES%\Ontofan
%COMMONPROGRAMFILES%\OpenOvedom
%COMMONPROGRAMFILES%\Openzap
%COMMONPROGRAMFILES%\OpeTough
%COMMONPROGRAMFILES%\OverLab
%COMMONPROGRAMFILES%\Ozercom
%COMMONPROGRAMFILES%\Physlab
%COMMONPROGRAMFILES%\Quojob
%COMMONPROGRAMFILES%\Quotelux
%COMMONPROGRAMFILES%\Qvoity
%COMMONPROGRAMFILES%\Ranfresh
%COMMONPROGRAMFILES%\Rantax
%COMMONPROGRAMFILES%\Rantip
%COMMONPROGRAMFILES%\Runtax
%COMMONPROGRAMFILES%\Soling
%COMMONPROGRAMFILES%\Stockphase
%COMMONPROGRAMFILES%\Strongtech
%COMMONPROGRAMFILES%\Strongtip
%COMMONPROGRAMFILES%\Subsoft
%COMMONPROGRAMFILES%\Tanity
%COMMONPROGRAMFILES%\Tipeco
%COMMONPROGRAMFILES%\Tonphase
%COMMONPROGRAMFILES%\ToughHold
%COMMONPROGRAMFILES%\Trusting
%COMMONPROGRAMFILES%\Truststring
%COMMONPROGRAMFILES%\Ventodex
%COMMONPROGRAMFILES%\Ventotone
%COMMONPROGRAMFILES%\vialax
%COMMONPROGRAMFILES%\Vilaflex
%COMMONPROGRAMFILES%\Villabam
%COMMONPROGRAMFILES%\VolCore
%COMMONPROGRAMFILES%\Voya-Strong
%COMMONPROGRAMFILES%\zaamtom
%COMMONPROGRAMFILES%\Zonlex
%COMMONPROGRAMFILES%\Zoomtip
%COMMONPROGRAMFILES%\Zoteco
%COMMONPROGRAMFILES%\ZummaFan
%COMMONPROGRAMFILES%\Zunhold
%COMMONPROGRAMFILES%\Zuntough
%COMMONPROGRAMFILES(x86)%\Alphafan
%COMMONPROGRAMFILES(x86)%\Alphait
%COMMONPROGRAMFILES(x86)%\AlphaString
%COMMONPROGRAMFILES(x86)%\Alphatone
%COMMONPROGRAMFILES(x86)%\An-Eco
%COMMONPROGRAMFILES(x86)%\Apfix
%COMMONPROGRAMFILES(x86)%\Apsing
%COMMONPROGRAMFILES(x86)%\Betastrong
%COMMONPROGRAMFILES(x86)%\BigHotis
%COMMONPROGRAMFILES(x86)%\Bio-Com
%COMMONPROGRAMFILES(x86)%\Biodonkix
%COMMONPROGRAMFILES(x86)%\biojob
%COMMONPROGRAMFILES(x86)%\Biolight
%COMMONPROGRAMFILES(x86)%\Cantrax
%COMMONPROGRAMFILES(x86)%\Cofgohold
%COMMONPROGRAMFILES(x86)%\Confind
%COMMONPROGRAMFILES(x86)%\dentozimeco
%COMMONPROGRAMFILES(x86)%\Donsillax
%COMMONPROGRAMFILES(x86)%\Doublelab
%COMMONPROGRAMFILES(x86)%\Ecojob
%COMMONPROGRAMFILES(x86)%\FaseQuoit
%COMMONPROGRAMFILES(x86)%\Finphase
%COMMONPROGRAMFILES(x86)%\Fix-Fan
%COMMONPROGRAMFILES(x86)%\fixcom
%COMMONPROGRAMFILES(x86)%\Fixfax
%COMMONPROGRAMFILES(x86)%\freshhome
%COMMONPROGRAMFILES(x86)%\Freshlatlex
%COMMONPROGRAMFILES(x86)%\FreshReddax
%COMMONPROGRAMFILES(x86)%\Goodlex
%COMMONPROGRAMFILES(x86)%\Grooveair
%COMMONPROGRAMFILES(x86)%\Groovecof
%COMMONPROGRAMFILES(x86)%\GrooveTax
%COMMONPROGRAMFILES(x86)%\HatTrax
%COMMONPROGRAMFILES(x86)%\Hometough
%COMMONPROGRAMFILES(x86)%\Icetech
%COMMONPROGRAMFILES(x86)%\Inchair
%COMMONPROGRAMFILES(x86)%\Inchstrong
%COMMONPROGRAMFILES(x86)%\IndigoNix
%COMMONPROGRAMFILES(x86)%\Jobwarm
%COMMONPROGRAMFILES(x86)%\Joy-Com
%COMMONPROGRAMFILES(x86)%\kanis
%COMMONPROGRAMFILES(x86)%\Kanla
%COMMONPROGRAMFILES(x86)%\Kayhold
%COMMONPROGRAMFILES(x86)%\KinDom
%COMMONPROGRAMFILES(x86)%\Kinin
%COMMONPROGRAMFILES(x86)%\KonkDondax
%COMMONPROGRAMFILES(x86)%\Konksailnix
%COMMONPROGRAMFILES(x86)%\Labzap
%COMMONPROGRAMFILES(x86)%\Lamcof
%COMMONPROGRAMFILES(x86)%\Lamity
%COMMONPROGRAMFILES(x86)%\math-plus
%COMMONPROGRAMFILES(x86)%\Math-Tax
%COMMONPROGRAMFILES(x86)%\Matstrong
%COMMONPROGRAMFILES(x86)%\Medis
%COMMONPROGRAMFILES(x86)%\Ontofan
%COMMONPROGRAMFILES(x86)%\Ontolight
%COMMONPROGRAMFILES(x86)%\OpeHotcom
%COMMONPROGRAMFILES(x86)%\OpenOvedom
%COMMONPROGRAMFILES(x86)%\Openzap
%COMMONPROGRAMFILES(x86)%\OpeTough
%COMMONPROGRAMFILES(x86)%\OverLab
%COMMONPROGRAMFILES(x86)%\Overron
%COMMONPROGRAMFILES(x86)%\Ozercom
%COMMONPROGRAMFILES(x86)%\Physlab
%COMMONPROGRAMFILES(x86)%\Quojob
%COMMONPROGRAMFILES(x86)%\Quotelux
%COMMONPROGRAMFILES(x86)%\Qvoity
%COMMONPROGRAMFILES(x86)%\Ranfresh
%COMMONPROGRAMFILES(x86)%\Rantax
%COMMONPROGRAMFILES(x86)%\Rantip
%COMMONPROGRAMFILES(x86)%\Runtax
%COMMONPROGRAMFILES(x86)%\S-tax
%COMMONPROGRAMFILES(x86)%\Sailsaobam
%COMMONPROGRAMFILES(x86)%\Soling
%COMMONPROGRAMFILES(x86)%\Statphase
%COMMONPROGRAMFILES(x86)%\Stockphase
%COMMONPROGRAMFILES(x86)%\Strongtech
%COMMONPROGRAMFILES(x86)%\Strongtip
%COMMONPROGRAMFILES(x86)%\Subsoft
%COMMONPROGRAMFILES(x86)%\SumLax
%COMMONPROGRAMFILES(x86)%\Sunlam
%COMMONPROGRAMFILES(x86)%\Tanity
%COMMONPROGRAMFILES(x86)%\Tinfresh
%COMMONPROGRAMFILES(x86)%\Tipeco
%COMMONPROGRAMFILES(x86)%\Tonphase
%COMMONPROGRAMFILES(x86)%\Top-Sing
%COMMONPROGRAMFILES(x86)%\ToughFlex
%COMMONPROGRAMFILES(x86)%\ToughHold
%COMMONPROGRAMFILES(x86)%\Tresstring
%COMMONPROGRAMFILES(x86)%\Trippletantip
%COMMONPROGRAMFILES(x86)%\Trisla
%COMMONPROGRAMFILES(x86)%\Trusting
%COMMONPROGRAMFILES(x86)%\Truststring
%COMMONPROGRAMFILES(x86)%\Vento-Zap
%COMMONPROGRAMFILES(x86)%\Ventodex
%COMMONPROGRAMFILES(x86)%\Ventotone
%COMMONPROGRAMFILES(x86)%\Ventotop
%COMMONPROGRAMFILES(x86)%\vialax
%COMMONPROGRAMFILES(x86)%\Vilaflex
%COMMONPROGRAMFILES(x86)%\Villabam
%COMMONPROGRAMFILES(x86)%\VolCore
%COMMONPROGRAMFILES(x86)%\Voya-Strong
%COMMONPROGRAMFILES(x86)%\Xxx-Ransoft
%COMMONPROGRAMFILES(x86)%\Y--Tex
%COMMONPROGRAMFILES(x86)%\zaamtom
%COMMONPROGRAMFILES(x86)%\Zerex
%COMMONPROGRAMFILES(x86)%\Zonlex
%COMMONPROGRAMFILES(x86)%\Zoomstock
%COMMONPROGRAMFILES(x86)%\Zoomtip
%COMMONPROGRAMFILES(x86)%\ZooSiltam
%COMMONPROGRAMFILES(x86)%\Zoteco
%COMMONPROGRAMFILES(x86)%\ZummaFan
%COMMONPROGRAMFILES(x86)%\Zunhold
%COMMONPROGRAMFILES(x86)%\Zuntough
%PROGRAMFILES%\eakzaihjajkuc
%PROGRAMFILES%\eauknrbnwrpu2
%PROGRAMFILES%\owdbzuqlndefnbhfezr
%PROGRAMFILES%\patience
%PROGRAMFILES%\rfwjmjnpstqu2
%PROGRAMFILES(x86)%\eakzaihjajkuc
%PROGRAMFILES(x86)%\eauknrbnwrpu2
%PROGRAMFILES(x86)%\owdbzuqlndefnbhfezr
%PROGRAMFILES(x86)%\patience
%PROGRAMFILES(x86)%\rfwjmjnpstqu2
%TEMP%\eakzaihjajkuc
%TEMP%\eauknrbnwrpu2
%TEMP%\owdbzuqlndefnbhfezr
%TEMP%\rfwjmjnpstqu2
Registry key
SOFTWARE\Microsoft\Tracing\appmallosayov_RASAPI32
SOFTWARE\Microsoft\Tracing\appmallosayov_RASMANCS
SOFTWARE\Microsoft\Tracing\AppoxinloK_RASAPI32
SOFTWARE\Microsoft\Tracing\AppoxinloK_RASMANCS
SOFTWARE\Microsoft\Tracing\AppxeetouQ_RASAPI32
SOFTWARE\Microsoft\Tracing\AppxeetouQ_RASMANCS
SOFTWARE\Microsoft\Tracing\Duosing_RASAPI32
SOFTWARE\Microsoft\Tracing\Duosing_RASMANCS
SOFTWARE\Microsoft\Tracing\Hotfresh_RASAPI32
SOFTWARE\Microsoft\Tracing\Hotfresh_RASMANCS
SOFTWARE\Microsoft\Tracing\Kipolam_RASAPI32
SOFTWARE\Microsoft\Tracing\Kipolam_RASMANCS
SOFTWARE\Microsoft\Tracing\Kolnixo_RASAPI32
SOFTWARE\Microsoft\Tracing\Kolnixo_RASMANCS
SOFTWARE\Microsoft\Tracing\locep_RASAPI32
SOFTWARE\Microsoft\Tracing\locep_RASMANCS
SOFTWARE\Microsoft\Tracing\mbappert_RASAPI32
SOFTWARE\Microsoft\Tracing\mbappert_RASMANCS
SOFTWARE\Microsoft\Tracing\Pangoc_RASAPI32
SOFTWARE\Microsoft\Tracing\Pangoc_RASMANCS
SOFTWARE\Microsoft\Tracing\Pluslax_RASAPI32
SOFTWARE\Microsoft\Tracing\Pluslax_RASMANCS
SOFTWARE\Microsoft\Tracing\Polygen_RASAPI32
SOFTWARE\Microsoft\Tracing\Polygen_RASMANCS
SOFTWARE\Microsoft\Tracing\snorler_RASAPI32
SOFTWARE\Microsoft\Tracing\snorler_RASMANCS
SOFTWARE\Microsoft\Tracing\Tolnix_RASAPI32
SOFTWARE\Microsoft\Tracing\Tolnix_RASMANCS
SOFTWARE\Microsoft\Tracing\Voyasollam_RASAPI32
SOFTWARE\Microsoft\Tracing\Voyasollam_RASMANCS
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appmallosayov.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppoxinloK.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppxeetouQ.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Hotfresh.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Kipolam.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Kolnixo.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\locep.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbappert.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Pangoc.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Pitachok.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Pluslax.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Polygen.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quoteex.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snorler.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Tolnix.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Voyasollam.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\snp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\appmallosayov.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\AppoxinloK.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\AppxeetouQ.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Hotfresh.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Kipolam.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Kolnixo.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\locep.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\mbappert.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Pangoc.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Pluslax.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Polygen.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\snorler.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Tolnix.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Voyasollam.exe
SOFTWARE\mtappmallosayov
SOFTWARE\mtAppoxinloK
SOFTWARE\mtAppxeetouQ
SOFTWARE\mtHotfresh
Software\mtKolnixo
SOFTWARE\mtlocep
SOFTWARE\mtmbappert
SOFTWARE\mtPangoc
SOFTWARE\mtPitachok
SOFTWARE\mtPluslax
SOFTWARE\mtPolygen
SOFTWARE\mtTolnix
SOFTWARE\WOW6432Node\Microsoft\Tracing\appmallosayov_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\appmallosayov_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\AppoxinloK_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\AppoxinloK_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Tracing\AppxeetouQ_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\AppxeetouQ_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Tracing\Duosing_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\Duosing_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Tracing\Hotfresh_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\Hotfresh_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Tracing\Kipolam_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\Kipolam_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Tracing\Kolnixo_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\Kolnixo_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\locep_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\locep_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\mbappert_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\mbappert_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\Pangoc_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\Pangoc_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Tracing\Pitachok_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\Pitachok_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Tracing\Pluslax_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\Pluslax_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Tracing\Polygen_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\Polygen_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\snorler_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\snorler_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\Tolnix_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\Tolnix_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Tracing\Voyasollam_RASAPI32
SOFTWARE\WOW6432Node\Microsoft\Tracing\Voyasollam_RASMANCS
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appmallosayov.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppoxinloK.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppxeetouQ.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Hotfresh.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Kipolam.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Kolnixo.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\locep.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbappert.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Pangoc.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Pitachok.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Pluslax.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Polygen.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quoteex.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snorler.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Tolnix.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Voyasollam.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\appmallosayov.exe
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\AppoxinloK.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\AppxeetouQ.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Hotfresh.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Kipolam.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Kolnixo.exe
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\locep.exe
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\mbappert.exe
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Pangoc.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Pitachok.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Pluslax.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Polygen.exe
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\snorler.exe
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Tolnix.exe
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Voyasollam.exe
SOFTWARE\Wow6432Node\mtappmallosayov
SOFTWARE\Wow6432Node\mtAppoxinloK
SOFTWARE\Wow6432Node\mtAppxeetouQ
SOFTWARE\Wow6432Node\mtHotfresh
Software\WOW6432Node\mtKolnixo
SOFTWARE\Wow6432Node\mtlocep
SOFTWARE\Wow6432Node\mtmbappert
SOFTWARE\Wow6432Node\mtPangoc
SOFTWARE\Wow6432Node\mtPitachok
SOFTWARE\Wow6432Node\mtPluslax
SOFTWARE\Wow6432Node\mtPolygen
SOFTWARE\Wow6432Node\mtTolnix
SYSTEM\ControlSet001\services\appmallosayov
SYSTEM\ControlSet001\services\AppxeetouQ
SYSTEM\ControlSet001\services\Quoteex
SYSTEM\ControlSet001\services\Voyasollam
SYSTEM\ControlSet002\services\appmallosayov
SYSTEM\ControlSet002\services\AppxeetouQ
SYSTEM\ControlSet002\services\Quoteex
SYSTEM\ControlSet002\services\Voyasollam
SYSTEM\CurrentControlSet\services\appmallosayov
SYSTEM\CurrentControlSet\services\AppxeetouQ
SYSTEM\CurrentControlSet\services\Quoteex
SYSTEM\CurrentControlSet\services\Voyasollam
Cookies
feed.snap.do

More Details on Snap.do

The following cookies were found:
  • feed.snap.do

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

2 Comments

  • Douglas Wright:

    I searched n searched the web for a way to remove snapdo from my computer after not being able to find it in my list of programs in the control panel and resetting my browser setting, i finally recognized the icon in my programs x86 it may come up as PRODUCTUI go in that folder and select uninstall.exe. it is now removed as of 2 mins ago.

  • rizwana minhaj:

    i searched and searched the web to remove snapdo virus from my computer

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.