SYSHOST.EXE – Trojan FakeAV

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SYSHOST.EXE – Trojan FakeAV removal

FileMD5Virus Alias
SYSHOST.EXE 02f6cd3cfa3f16567a27bc1d45bca5d7 Trojan FakeAV
SYSHOST.EXE 02f6cd3cfa3f16567a27bc1d45bca5d7 Trojan Artemis
SYSHOST.EXE 02f6cd3cfa3f16567a27bc1d45bca5d7 Trojan Dropper.Generic7
SYSHOST.EXE 02f6cd3cfa3f16567a27bc1d45bca5d7 Trojan Generic
SYSHOST.EXE 02f6cd3cfa3f16567a27bc1d45bca5d7 Trojan Agent
SYSHOST.EXE 02f6cd3cfa3f16567a27bc1d45bca5d7 Trojan Kryptik

SYSHOST.EXE size: 131072 bytes
SYSHOST.EXE hash: 02F6CD3CFA3F16567A27BC1D45BCA5D7

Created files:

%WinDir%\Installer\{505412A3-C16F-28EE-8EB5-E1086E95226F}\syshost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\syshost32\Type: 10000000
HKLM\System\CurrentControlSet\Services\syshost32\Start: 02000000
HKLM\System\CurrentControlSet\Services\syshost32\ImagePath: “%WinDir%\Installer\{505412A3-C16F-28EE-8EB5-E1086E95226F}\syshost.exe” /service

Detected by UnHackMe:

SYSHOST.EXE
Default location: %WinDir%\INSTALLER\{505412A3-C16F-28EE-8EB5-E1086E95226F}\SYSHOST.EXE

Dropper information:
MD5: 02f6cd3cfa3f16567a27bc1d45bca5d7
File size: 131072 bytes

Leave a Reply