How to Remove PUA:Win32/Presenoker uTorrent Virus

uTorrent has been known as Presenoker by the Windows Defender. As Microsoft does not share any data, no one knows which versions of the uTorrent cause the issue and whether they carry the real Presenoker or just flagged as security risks.

For those who are not familiar with Presenoker, it is the name of one of the most common Trojan Horses that faced by the build in Windows Defender because of the file types it is carried by, especially some instances of uTorrent.exe.

Most of the cases are not truly malware in the classic sense, but rather files that are marked as unsafe by the AV industry.

Presenoker and uTorrent

Presenoker is a given name to a Trojan Horse that is usually detected by the Windows Defender as Trojan: Win32/Presenoker or PUA:Win32/Presenoker. The user issues mainly come when Windows Defender detects Presenoker but repeatedly fails to remove it.

Apparently, the proper removal of Presenoker is done through the common way but it will need a bit of explanation. Please read below to understand what you are doing.

Presenoker Technical Summary

  • Name: Presenoker
  • Type: Adware, PUP
  • Detection Name: PUA:Win32/Presenoker, Adware.Presenoker
  • Distribution Method: Software bundling, Intrusive advertisement, redirects to shady sites, and so on

How to remove the PUA:Win32/Presenoker? Before anything, you will have to look if there are any programs installed by Presenoker while it was active on your system. After that, please follow these steps. A quick way to remove it is to type appwiz.cpl in your Windows Search box and click it.

It will take you to the Control Panel. When you are there, look for programs installed around the time you started facing the issues. Looking at the publisher is the easiest way to find the Presenoker or the other malware programs. In case there is no name, please click the Uninstall button.

It should be done to make sure the Presenoker does not get installed again by another malware program once the removal is complete. Please take a good look at anything that you think might be suspicious.

Removal process

The rest of the removal process will ask you to go in the native folders of the Windows Defender. Apparently, a few folders that you will access are hidden. In case you cannot see the hidden folders, please go in any folder that you want, click on the View Tab button, and then click on the Hidden Items.

Now, it is time for you to navigate to C:\ProgramData\Microsoft\Windos Defender\Scans\History\Service. For those who access the Scans for the first time, you will have to get the admin privileges and choose Continue.

Once you have access to the Service, you should see Detection History. All that you have to do is to delete this folder and then everything should be done.

If you want to instantly remove the PUA:Win32/Presenoker, you are suggested to scan the infected computer with the powerful anti-malware tool called Malwarebytes. This one has the ability to detect and get rid of Trojans, malware, viruses, and adware from the infected computer.

If you want to fully protect the computer against the PUA:Win32/Presenoker or some similar things, you are able to activate the Malwarebytes to have the real time scanning and full defense against any kinds of threats.

Installation process

The first thing that you will have to do is to download Malwarebytes Anti Malware from here:

Do not forget to save the file on your hard drive. Once it is downloaded, double click on the file MBSetup.exe to run the program. Then, choose the option that you want whether you are installing on Personal Computer or Work Computer.

On the next step, you will need to click on the Install button in order to load the basic requirements to run the Malwarebytes Anti-malware. It asks for the License Agreement, so please accept this and click the Next button. follow the steps until you reach the window that says Installing…

The process of installation will take less than a minute and the program should run automatically after the setup process. When the Malwarebytes Anti-Malware interface shows up, you will have to select Scan from the menu to start the process. It will check for any available update before proceeding.

Remember to not skip this step. Scanning viruses may take a while, so please be patient and wait for the process to be done. When the scanning finishes, Malwarebytes Anti-Malware will be shown in the list of the identified threats. It is time for you to remove all the identified threats and restart the computer to finalize the scan process.

Apart from Malwarebytes Anti-Malware, another recommended tool that you can use is called GridinSoft Anti-Malware. Just like Malwarebytes Anti-Malware, GridinSoft Anti-Malware will also scan and clean your computer for free in the free trial period.

The free version of the tool comes with the real time protection for the first two days. For those who want to be fully protected at all times, purchasing a full version is recommended.

In order to remove the Presenoker or PUA:Win32/Presenoker by using GridinSoft Anti-Malware, first of all, you will need to download the GridinSoft Anti-Malware by clicking PUA:Win32/Presenoker. When the setup file has been downloaded, double click on the install-antimalware-fix.exe file to install GridinSoft Anti-Malware on your system.

Doing so will open a User Account Control that will ask you to allow the GridinSoft Anti-Malware to make changes to your device. In this case, please click Yes to continue with the installation. Then, press the Install button. Once the tool is installed, it will automatically run.

Scanning process

After that, you will just have for the Anti-Malware to complete the scan. The thing known as GridinSoft Anti-Malware will automatically start scanning your system for Presenoker files and the other suspicious programs.

The scanning process can take about 20 to 30 minutes, so you are encouraged to periodically check on the status of the scan process. When it is done, you will see the list of the infections that have been detected. Please click on the Clean Now button to remove them all.

Leave a Reply

Your email address will not be published. Required fields are marked *