SYSHOST.EXE – Fake Antivirus SecurityTool

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SYSHOST.EXE – Fake Antivirus SecurityTool removal

File MD5 Virus Alias
SYSHOST.EXE 7bb0790902b9866a7521b249527f56e7 Fake Antivirus SecurityTool
SYSHOST.EXE 7bb0790902b9866a7521b249527f56e7 Trojan Kryptik
SYSHOST.EXE 7bb0790902b9866a7521b249527f56e7 Trojan FakeAV

SYSHOST.EXE size: 143360 bytes

Created files:

%WinDir%\Installer\{9E52F7D0-A24B-ADBD-2E73-0F910E52ADF2}\syshost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\syshost32\Type: 10000000
HKLM\System\CurrentControlSet\Services\syshost32\Start: 02000000
HKLM\System\CurrentControlSet\Services\syshost32\ImagePath: “%WinDir%\Installer\{9E52F7D0-A24B-ADBD-2E73-0F910E52ADF2}\syshost.exe” /service

Detected by UnHackMe:

SYSHOST.EXE
Default location: %WinDir%\INSTALLER\{9E52F7D0-A24B-ADBD-2E73-0F910E52ADF2}\SYSHOST.EXE

Leave a Reply