Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

PRESIDENT.EXE is Trojan Dishigy

$
0
0

We checked some samples of PRESIDENT.EXE and detected the file PRESIDENT.EXE as threat.
Remove the PRESIDENT.EXE file from your computer right now.
Removal tool: http://www.unhackme.com

Malware Analysis of PRESIDENT.EXE
Full path on a computer: %WinDir%\president.exe

Detected by UnHackMe:

Item Name: president-kbr
Author:
Current Setting: %WinDir%\president.exe
Type: Auto Services

Item Name: president.exe
Author: Unknown
Related File: %WinDir%\PRESIDENT.EXE
Type: Running Processes

After first reboot detected by UnHackMe:

Item Name: president-kbr
Author:
Related File: %WinDir%\president.exe
Type: Services detected by Partizan

Removal Results: Success
Number of reboot: 1

PRESIDENT.EXE is known as:

Trojan.Dishigy, Spyware.Password, Trojan.Spy.Delf.pke, Spyware ( 004458f01 ), Trojan.Staser., Trojan.Zbot, Agent.AZBAW, Trojan.Staser.tbn, Trojan.Staser.cvapis, Trojan.Agent.Gen-Symmi, Troj.FakeAV-HCS, Trojan.PWS.Tibia.2497, Trojan.Dishigy.i (v), Troj.Undef.(kcloud), Trojan.Dishigy.I, Trojan.Xema, W32.Trojan.WMNM-8824, Win32.Spy.Delf.PKE, BehavesLikeTrojan.ShellObject, W32.Staser.TBN.tr, Trojan.Staser.app

PRESIDENT.EXE hash:

  • MD5: ff140e30290f28e80c0924f85ca8fa4b
How to quickly detect PRESIDENT.EXE presence?
Registry:
  • HKLM\System\CurrentControlSet\Services\president-kbr\ImagePath: “%WinDir%\president.exe”
  • HKLM\System\CurrentControlSet\Services\president-kbr\DisplayName: “president”
Files:
  • %Common Appdata%\systemskey.ini
  • C:\Documents and Settings\LocalService\Application Data\ffifssssfdfsf4f.ini
  • %WinDir%\president.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>