Solved! Use SYSHOST.EXE (Trojan FakeAV) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SYSHOST.EXE – Trojan FakeAV removal

File MD5 Virus Alias
SYSHOST.EXE 29d49e9514ea32061c249d0a6880089a Trojan FakeAV
SYSHOST.EXE 29d49e9514ea32061c249d0a6880089a Trojan Artemis
SYSHOST.EXE 29d49e9514ea32061c249d0a6880089a Trojan Generic
SYSHOST.EXE 29d49e9514ea32061c249d0a6880089a Trojan Eldorado
SYSHOST.EXE 29d49e9514ea32061c249d0a6880089a Trojan Kryptik
SYSHOST.EXE 29d49e9514ea32061c249d0a6880089a Trojan Crypt

SYSHOST.EXE size: 295936 bytes
SYSHOST.EXE hash: 29D49E9514EA32061C249D0A6880089A

Created files:

%WinDir%\Installer\{BDBB4B68-D156-A659-0B90-AAB5E9F99D36}\syshost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\syshost32\Type: 10000000
HKLM\System\CurrentControlSet\Services\syshost32\Start: 02000000
HKLM\System\CurrentControlSet\Services\syshost32\ImagePath: “%WinDir%\Installer\{BDBB4B68-D156-A659-0B90-AAB5E9F99D36}\syshost.exe” /service

Detected by UnHackMe:

SYSHOST.EXE
Default location: %WinDir%\INSTALLER\{BDBB4B68-D156-A659-0B90-AAB5E9F99D36}\SYSHOST.EXE

Dropper information:
MD5: 29d49e9514ea32061c249d0a6880089a
File size: 295936 bytes

Leave a Reply