SYSHOST.EXE – Fake Antivirus SecurityTool

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SYSHOST.EXE – Fake Antivirus SecurityTool removal

File MD5 Virus Alias
SYSHOST.EXE 83b9bbfdbdba03381cb70355796bdfa8 Fake Antivirus SecurityTool
SYSHOST.EXE 83b9bbfdbdba03381cb70355796bdfa8 Trojan FakeAV

SYSHOST.EXE size: 172032 bytes

Created files:

%WinDir%\Installer\{AD812E66-DB5B-5CBF-0213-20CAE1F28D2D}\syshost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\syshost32\Type: 10000000
HKLM\System\CurrentControlSet\Services\syshost32\Start: 02000000
HKLM\System\CurrentControlSet\Services\syshost32\ImagePath: “%WinDir%\Installer\{AD812E66-DB5B-5CBF-0213-20CAE1F28D2D}\syshost.exe” /service

Detected by UnHackMe:

SYSHOST.EXE
Default location: %WinDir%\INSTALLER\{AD812E66-DB5B-5CBF-0213-20CAE1F28D2D}\SYSHOST.EXE

Leave a Reply