Safety Peak

SYSHost

Type Danger
Worm Very High

We recommend removing SYSHost using automatic solution. With this tool you don't need to change Windows files and registry yourself. It's also absolutely safe as against manual removal, because all changes made by SYSHost Removal Solution are restorable at any time.

Automatic SYSHost Removal Solution Download Automatic SYSHost Removal Solution

Human support/removal

If your case so hard, it can't be fixed by Automatic SYSHost Removal Solution, contact our support team. Support professionals check your case, diagnose problem and make individual solution for your problems or fix them manually. Head to support section of the site to make support request.

Manual removal instructions

Here are removal instructions for SYSHost. Using this information you can completely remove this Worm from you computer.

Warning! You make all changes at your own risk. Safety Peak is not responsible for damage that you may cause your system performing manual removal. To safely remove SYSHost, use the Automatic SYSHost Removal Solution.

Registry entries

Locate and delete following registry keys and values associated with SYSHost. You may use Regedit (regedit.exe) which located in Windows folder or any other registry editor. If no root key specified (HKEY_LOCAL_MACHINE, HKEY_CLASSES_ROOT, etc.), key is situated in any registry section (HKEY_CURRENT_USER, HKEY_LOCAL_MACHINE, HKEY_CLASSES_ROOT or HKEY_USERS).

Key
HKEY_CLASSES_ROOT\CLSID\{05EC9C0E-803B-4C5C-AF17-E682C2214A06}
HKEY_CLASSES_ROOT\CLSID\{88B87BC8-3130-4D0C-A9FF-C817FCDA3E4A}
HKEY_CLASSES_ROOT\CLSID\{4FE76A40-6BB8-4E99-A1F8-81F7D23CDBDF}
HKEY_CLASSES_ROOT\CLSID\{346CDBEB-F274-470D-B683-600C5A3E903B}
HKEY_CLASSES_ROOT\CLSID\{5EA5D6EA-3546-4541-84DA-A393C3843BCE}
HKEY_CLASSES_ROOT\CLSID\{2C7297ED-2DB7-4DBD-894F-5FA803866AD5}
HKEY_CLASSES_ROOT\CLSID\{CE9ECAF4-FA19-4151-B08C-BF6CA7C375E6}
HKEY_CLASSES_ROOT\CLSID\{2C805127-433D-4758-8B8D-0F29512BB1AE}
HKEY_CLASSES_ROOT\CLSID\{54DB64E5-05AB-4E88-A4CE-41C2C0D5BD52}
HKEY_CLASSES_ROOT\CLSID\{74049E79-FAEF-4033-827B-89814EB04BFD}

Files

First of all you need to make all hidden and protected system files visible. Then you need to permanently delete (without using the Recycle Bin) all following files. Hold Shift key while deleting files to perfom permanent delete.

Folders which names situated between % symbols like %PROGRAMFILES% mean system Folders specific to current machine. %SYSTEMROOT% means Windows folder, %PROGRAMFILES% means Program Files folder, %PROFILE% means current user's profile folder, etc.

Process
SYSHOST.EXE