Type: Rogue Application
Malware Author: Unknown
Threat Level: Critical
Screenshot:
How to remove Presto TuneUp manually:
It's possible to remove Presto TuneUp manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.
The files to be deleted:
%UserProfile%\Application Data\Presto TuneUp
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Presto TuneUp.lnk
%UserProfile%\Application Data\Presto TuneUp\Autorun.ico
%UserProfile%\Application Data\Presto TuneUp\cookies.sqlite
%UserProfile%\Application Data\Presto TuneUp\places.sqlite
%UserProfile%\Application Data\Presto TuneUp\Process.ico
%UserProfile%\Application Data\Presto TuneUp\Service.ico
%UserProfile%\Desktop\AutorunManager.lnk
%UserProfile%\Desktop\Presto TuneUp.lnk
%UserProfile%\Desktop\ProcessManager.lnk
%UserProfile%\Desktop\ServiceManager.lnk
%UserProfile%\Start Menu\Presto TuneUp.lnk
%UserProfile%\Start Menu\Programs\Presto TuneUp.lnk
c:\Documents and Settings\All Users\Application Data\SystemBackup
c:\Documents and Settings\All Users\Application Data\345d567
c:\Documents and Settings\All Users\Application Data\345d567\mozcrt19.dll
c:\Documents and Settings\All Users\Application Data\345d567\PrestoTuneUp.exe
c:\Documents and Settings\All Users\Application Data\345d567\sqlite3.dll
c:\Documents and Settings\All Users\Application Data\345d567\working.log
c:\Documents and Settings\All Users\Application Data\345d567\SystemBackup
c:\Documents and Settings\All Users\Application Data\SystemBackup\backup.dat
Remove registry entries:
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\PrestoTuneUp.DocHostUIHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "URPRTUP[]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Presto TuneUp"
Please be careful because manual removal of Presto TuneUp may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.
No comments:
Post a Comment