syshost.exe – Trojan ZBot

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

syshost.exe – Trojan ZBot removal

FileVirus Alias
syshost.exe Trojan ZBot

Created files:

%WinDir%\Installer\{ADC2C38E-5200-722A-8869-D3C1684A1A5B}\syshost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\syshost32\Type: 10000000
HKLM\System\CurrentControlSet\Services\syshost32\Start: 02000000
HKLM\System\CurrentControlSet\Services\syshost32\ImagePath: “%WinDir%\Installer\{ADC2C38E-5200-722A-8869-D3C1684A1A5B}\syshost.exe” /service

Detected by UnHackMe:

syshost.exe
Default location: %WinDir%\Installer\{ADC2C38E-5200-722A-8869-D3C1684A1A5B}\syshost.exe

Dropper information:
SHA256: 3946613ea5153fb6e220facbff4f8b66fad9926706887955354a51870e68687f
SHA1: 63a90d10a6a97bbab7b0e9a40f1e9f4bff435ae0
MD5: 461b890f08c3c0b4928471ac682834fe
File size: 115200 bytes

Leave a Reply