SYSHOST.EXE – Trojan FakeAV

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SYSHOST.EXE – Trojan FakeAV removal

FileMD5Virus Alias
SYSHOST.EXE 30be146fec610970ce994bc12564d340 Trojan FakeAV
SYSHOST.EXE 30be146fec610970ce994bc12564d340 Trojan Eldorado
SYSHOST.EXE 30be146fec610970ce994bc12564d340 Trojan Downloader
SYSHOST.EXE 30be146fec610970ce994bc12564d340 Trojan Agent
SYSHOST.EXE 30be146fec610970ce994bc12564d340 Trojan Kryptik

SYSHOST.EXE size: 339968 bytes
SYSHOST.EXE hash: 30BE146FEC610970CE994BC12564D340

Created files:

%WinDir%\Installer\{0C114254-EEA8-70D6-70A0-775A507FF8C4}\syshost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\syshost32\Type: 10000000
HKLM\System\CurrentControlSet\Services\syshost32\Start: 02000000
HKLM\System\CurrentControlSet\Services\syshost32\ImagePath: “%WinDir%\Installer\{0C114254-EEA8-70D6-70A0-775A507FF8C4}\syshost.exe” /service

Detected by UnHackMe:

SYSHOST.EXE
Default location: %WinDir%\INSTALLER\{0C114254-EEA8-70D6-70A0-775A507FF8C4}\SYSHOST.EXE

Dropper information:
MD5: 30be146fec610970ce994bc12564d340
File size: 339968 bytes

Leave a Reply