snapdo.exe
Smartbar by ReSoft LTD. (Signed)
Warning 29 antivirus scanners has detected malware in various versions of snapdo.exe.
Overview
snapdo.exe has 9 known versions, the most recent one is 10.231.1.13231. snapdo.exe is run as a standard windows process with the logged in user's account privileges. By adding a startup entry to the run registry key, the file will be executed when the user logs into Windows. The average file size is about 18.76 KB. It is an authenticode code-signed executable issued to ReSoft LTD. by the certification authority COMODO CA Limited. Some variations of the file have been seen to be installed with the program Snap.Do from ReSoft Ltd.. This is a .NET Common Language Runtime (CLR) assembly. During the process's lifecycle, the typical CPU resource utilization is less than 0.01%, the average private memory consumption is about 102.29 MB. Addionally, typically read and write I/O disk operations is about 4.48 MB per minute for reads and 47.79 KB per minute for writes.
What is snapdo.exe?
Smartbar (Snap.Do) is a web browser addin/toolbar with Internet Explorer, Chrome and Firefox. Snap.Do provides social integration features for Facebook and Twitter. Privacy Policy: In order to facilitate, refine, personalize and match the identification and presentation of our products results to your browsing preferences and habits, we collect information regarding your use of our Product including URL and information of websites you browse while Smartbar is installed.
About snapdo.exe (from ReSoft LTD.)
“Snap.do works on all 3 major web browsers – Google Chrome, Mozilla Firefox and Internet Explorer. Simply get it now to start snapping! Snap.do will always be there when you need it. Once you got it yo”
Details |
File name: | snapdo.exe |
Publisher: | Smartbar |
Product name: | Smartbar |
Typical file path: | C:\users\user\appdata\local\smartbar\application\snapdo.exe |
Original name: | Smartbar.exe |
Certificate |
Issued to: | ReSoft LTD. |
Authority (CA): | COMODO CA Limited |
Expiration date: | Tuesday, July 30, 2013 |
Programs installed in
(Note, the programs listed below are for all versions of Smartbar.)
Snap.Do is a web browser addin/toolbar (depending on the browser it is installed within) that plugs into all the major web browsers including Internet Explorer, Chrome and Firefox. Snap.Do provides th...
Behaviors
(Note, the behaviors below are for all versions of snapdo.exe, select a unique version for details.)
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'Browser Infrastructure Helper' → C:\users\user\appdata\Local\Smartbar\Application\SnapDo.exe startup
Malware detections
Based on 40+ industry antivirus scanners, 29 of them detected the following malware.
Antivirus engine | Engine version | Detection | File version |
Agnitum |
5.5.1.3 |
Adware.Agent!XDj2iZ2S7lE |
1.6.1.737 |
AhnLab V3 Internet Security |
2013.08.07 |
Win-AppCare/Agent.K.13824.IQ |
1.6.1.737 |
Avira AntiVir |
7.11.95.146 |
TR/Rogue.kdv.845746.1 |
1.6.1.737 |
AVG |
2014.0.3629 |
Toolbar.NC |
1.6.1.737 |
Comodo Internet Security |
16720 |
ApplicUnwnt |
1.6.1.737 |
Dr.Web |
8.13.10.6 |
Trojan.MulDrop4.24551 |
1.6.1.737 |
Dr.Web |
8.13.10.10 |
Adware.Linkury.1 |
1.102.1.11691 |
Dr.Web |
8.13.11.25 |
Adware.Linkury.1 |
1.96.1.11688 |
ESET NOD32 |
7.8682 |
a variant of Win32/Toolbar.Linkury.A |
1.8.1.10725 |
ESET NOD32 |
7.8657 |
a variant of Win32/Toolbar.Linkury.A |
1.6.1.737 |
ESET NOD32 |
7.8887 |
a variant of Win32/Toolbar.Linkury.A |
1.102.1.11691 |
ESET NOD32 |
7.8965 |
a variant of Win32/Toolbar.Linkury.A |
1.96.1.11688 |
Fortinet |
5.1.146.0 |
Adware/MSIL_Agent |
1.6.1.737 |
Ikarus |
T3.1.4.3.0 |
not-a-virus:AdWare.MSIL |
1.6.1.737 |
Kingsoft |
2013.4.9.267 |
Win32.Troj.Generic.a.(kcloud) |
1.102.1.11691 |
Kingsoft |
2013.4.9.267 |
Win32.Troj.Generic.a.(kcloud) |
1.96.1.11688 |
McAfee |
5.600.1067 |
Artemis!E8F4096521DC |
1.6.1.737 |
McAfee Gateway Anti-Malware |
v2013-dat |
Artemis!E8F4096521DC |
1.6.1.737 |
Symantec |
20131.1.0.101 |
WS.Reputation.1 |
1.6.1.737 |
Trend Micro |
9.740.0.1012 |
ADW_LINKURY |
1.8.1.10725 |
Trend Micro HouseCall |
9.700.0.1001 |
ADW_LINKURY |
1.8.1.10725 |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.RCBB1E3 |
1.6.1.737 |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.F47V0816 |
1.102.1.11691 |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.F47V0808 |
1.96.1.11688 |
Vba32 AntiVirus |
3.12.22.3 |
AdWare.MSIL.Agent |
1.6.1.737 |
VIPRE Antivirus |
20466 |
Adware.Linkury (fs) |
1.8.1.10725 |
VIPRE Antivirus |
20216 |
Adware.Linkury (fs) |
1.6.1.737 |
VIPRE Antivirus |
22170 |
Adware.Linkury (fs) |
1.102.1.11691 |
VIPRE Antivirus |
22714 |
Adware.Linkury (fs) |
1.96.1.11688 |
All file variations of snapdo.exe
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate N |
53.85% |
|
Windows 7 Home Premium |
15.38% |
|
Windows 8.1 |
7.69% |
|
Windows 7 Ultimate |
7.69% |
|
Windows 7 Professional |
7.69% |
|
Windows Vista Home Premium |
7.69% |
|
Distribution by country
United States installs about 61.54% of Smartbar.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Dell |
44.44% |
|
Lenovo |
22.22% |
|
Toshiba |
22.22% |
|
Acer |
11.11% |
|