We checked some samples of PRESIDENT.EXE and detected the file PRESIDENT.EXE as threat.
Remove the PRESIDENT.EXE file from your computer right now.
Removal tool: http://www.unhackme.com
Malware Analysis of PRESIDENT.EXE
Full path on a computer: %WinDir%\president.exe
Detected by UnHackMe:
Item Name: president-kbr
Author:
Current Setting: %WinDir%\president.exe
Type: Auto Services
Item Name: president.exe
Author: Unknown
Related File: %WinDir%\PRESIDENT.EXE
Type: Running Processes
After first reboot detected by UnHackMe:
Item Name: president-kbr
Author:
Related File: %WinDir%\president.exe
Type: Services detected by Partizan
Removal Results: Success
Number of reboot: 1
PRESIDENT.EXE is known as:
Trojan.Dishigy, Spyware.Password, Trojan.Spy.Delf.pke, Spyware ( 004458f01 ), Trojan.Staser., Trojan.Zbot, Agent.AZBAW, Trojan.Staser.tbn, Trojan.Staser.cvapis, Trojan.Agent.Gen-Symmi, Troj.FakeAV-HCS, Trojan.PWS.Tibia.2497, Trojan.Dishigy.i (v), Troj.Undef.(kcloud), Trojan.Dishigy.I, Trojan.Xema, W32.Trojan.WMNM-8824, Win32.Spy.Delf.PKE, BehavesLikeTrojan.ShellObject, W32.Staser.TBN.tr, Trojan.Staser.app
PRESIDENT.EXE hash:
- MD5: ff140e30290f28e80c0924f85ca8fa4b
- HKLM\System\CurrentControlSet\Services\president-kbr\ImagePath: “%WinDir%\president.exe”
- HKLM\System\CurrentControlSet\Services\president-kbr\DisplayName: “president”
- %Common Appdata%\systemskey.ini
- C:\Documents and Settings\LocalService\Application Data\ffifssssfdfsf4f.ini
- %WinDir%\president.exe