Home Malware Programs Adware PrestoSavings

PrestoSavings

Posted: January 28, 2015

Threat Metric

Threat Level: 2/10
Infected PCs: 260
First Seen: January 28, 2015
Last Seen: June 16, 2023
OS(es) Affected: Windows

PrestoSavings is adware that injects its personal advertising content into each Web page loaded by your browser. These advertisement injections may hinder your regular use of a website by interfering with menu navigation or content accessibility, and may cause problems with other browser add-ons associated with password management. These unwarranted browser issues, combined with the questionable safety of PrestoSavings's chosen advertising affiliates, has forced malware researchers to endorse deleting PrestoSavings with appropriate security software.

The Firefox Presto Problem

Long used as an incantation in stage magic to suggest rapid transmutation, 'Presto Chango' now is gathering associations with an adware add-on that makes equally drastic changes to your browser. Malware researchers saw Firefox users being primarily affected by PrestoSavings, although PrestoSavings also includes some components related to the Chrome browser. Most adware programs are identifiable by their automatic generation of advertisements in-browser – a characteristic that PrestoSavings continues to espouse.

PrestoSavings may modify Firefox and other browsers with the constant injection of additional iFrame elements into unrelated Web pages. These injections may occur without any regard for the original content of the sites being visited and may include advertisements for other services and vendors. PrestoSavings advertisements also may block normal Web content or cause other, unintended problems with website interactions. Similar iFrame exploits also sometimes are used by other PC threats, including exploit kits like the Blackhole Exploit Kit, to cause undetectable, threatening HTML elements to load automatically.

PrestoSavings also may conflict with the form-autofill features of some browsers and add-ons, such as password and username managers. Generic messages may occur as a result, but PrestoSavings doesn't monitor or collect passwords (or any other, equivalently information).

Making PrestoSavings Pull a Vanishing Act

Just as any magic trick requires the audience's consent for being fooled, PrestoSavings stays on your PC largely by tricking you into believing that its coupon-based advertisements are beneficial to your browser. To date, malware researchers have seen no evidence of PrestoSavings being subverted for threatening purposes. In spite of that caveat, adware affiliates may play various roles in distributing misleading tactics and Potentially Unwanted Programs that are less of an advantage than a detriment to your computer. Removing PrestoSavings, like any invasive extension, is both advisable and should be undertaken with the help of robust security software.

PrestoSavings may be found online in appropriate add-on databases, but also sometimes is installed automatically. Ordinarily, the latter is the result of bundled software being downloaded from a potentially threatening or untrustworthy source, such as a torrent or unofficial website. In some circumstances, threats also may install PrestoSavings and other adware, which is why you should consider availing your PC of reasonably thorough system scans during PrestoSavings's removal process.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



PrestoSavings-prsto.1.11.1.exe File name: PrestoSavings-prsto.1.11.1.exe
Size: 718.51 KB (718512 bytes)
MD5: f670518c9d8aeee0be5ec897e4da3298
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 28, 2015

Registry Modifications

The following newly produced Registry Values are:

CLSID{55068883-BC74-42EA-9B20-31ED4E4428EA}{61FC239E-FFCD-4F74-B709-47772F636B57}{9754A33D-37F9-4629-B1EB-C65CF8F526D5}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{55068883-BC74-42EA-9B20-31ED4E4428EA}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{9754A33D-37F9-4629-B1EB-C65CF8F526D5}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{55068883-BC74-42EA-9B20-31ED4E4428EA}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{9754A33D-37F9-4629-B1EB-C65CF8F526D5}SOFTWARE\Wow6432Node\{61FC239E-FFCD-4F74-B709-47772F636B57}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{61FC239E-FFCD-4F74-B709-47772F636B57}

Additional Information

The following directories were created:
%LOCALAPPDATA%\PrestoSavings%PROGRAMFILES%\PrestoSavings%PROGRAMFILES(x86)%\PrestoSavings
Loading...