5663BE.SYS – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

5663BE.SYS – Trojan Downloader removal

File MD5 Virus Alias
5663BE.SYS d0655621120f17ecfd3787e6e3606f4f Trojan Downloader
5663BE.SYS d0655621120f17ecfd3787e6e3606f4f Trojan SuspiciousFile
5663BE.SYS d0655621120f17ecfd3787e6e3606f4f Trojan Generic
5663BE.SYS d0655621120f17ecfd3787e6e3606f4f Trojan Agent
5663BE.SYS d0655621120f17ecfd3787e6e3606f4f Trojan Crypt

5663BE.SYS size: 60416 bytes
5663BE.SYS hash: D0655621120F17ECFD3787E6E3606F4F

Created files:

%SysDir%\drivers\5663be.sys
%WinDir%\Temp\Cyxey\amqyxe.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\5663be\Type: 01000000
HKLM\System\CurrentControlSet\Services\5663be\Start: 01000000
HKLM\System\CurrentControlSet\Services\5663be\DisplayName: amqyxe.exe
HKLM\System\CurrentControlSet\Services\5663be\ImagePath: %WinDir%\System32\drivers\5663be.sys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Amqyxe: %WinDir%\Temp\Cyxey\amqyxe.exe

Detected by UnHackMe:

5663BE.SYS
Default location: %SYSDIR%\DRIVERS\5663BE.SYS

Dropper information:
MD5: fb846c192daec98c78cf88801a955e84
File size: 438272 bytes

Leave a Reply