ixyaosk.exe - Undocumented mal? Need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by mrk0, Jul 3, 2008.

  1. mrk0

    mrk0 Private E-2

    Hey all, first post here as I'm hurtin' for some help.

    I tend to be able to clear most mal and spy as it comes up from time to time by doing some research, following steps, using Hijackthis, Ad-aware etc..

    but this one is a doozy!

    ixyaosk.exe?

    For the past week or so, Firefox has just been randomly crashing with no error message or anything. It isn't even a freeze-crash, the window literally just closes like someone pressed the "X" at the top right...

    Then when I restarted my comp, Norton (which is since long expired) tells me that "ixyaosk.exe" is attempting to access the internet. I obviously click "Never allow" and went on my way to find out a little bit about this bugger.

    Here's the interesting (and frustrating) thing. If I so much as search "ixyaosk" in Google or any search engine...my browser closes! Every single time.

    Furthermore, with some websites such as Symantec, if I search Ixyaosk it will also crash the browser.

    This must be built in to the code of this mal as it intentially doesn't want you finding anything out about it or how to get rid of it!

    So I hopped on to another computer in the house to google some info about this thing: All I found were 3-4 references to it in what appeared to be Malware support entries on different websites, but no proper indentification or instructions on how to get rid of it.

    Interestingly, one of these websites indicated that the origin of Ixyaosk is probably from China. When you search google for Ixyaosk you'll also get a few returns at the bottom of the page which appear to link of abscure Chinese websites.

    I did a search on my computer for this thing and I came up with:

    IXYAOSK.EXE-0A639750.pf

    It's located in: Windows > Prefetch


    I downloaded and ran Spybot Search & Destroy and it found quite a few entries of bad things which I promptly got rid of, sadly none of them had any reference to IXYAOSK.EXE


    So without any documentation about this thing, and no one talking about it or seeming to be effected by it- I'm left pretty hopeless.


    Can anyone help me out?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. mrk0

    mrk0 Private E-2

    So I went though the READ ME FIRST thing and did all those steps as best I could like it was posted.

    1. I couldn't launch MSCONFIG - the window would open and then immediately close.

    2. Couldn't empty Norton quarantine folder because my 2005 product is expired.

    Attached are the logs.

    This thing is really frustrating, it seemingly detects any time I am searching or looking for anything to do with it, when I search for it on Google or view any website containing this things name, it crashes. Even this every thread!

    I'm having to type this from an alternate computer because of it!

    Any help would be appreciated, otherwise, I may simply just reformat.
     

    Attached Files:

  4. mrk0

    mrk0 Private E-2

    and the MG logs.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you should uninstall this as you need to have a current antivirus program that gets updates.

    Are the below folders that you created for things you use?
    Code:
    2008-06-26 12:11 . 2008-06-26 12:11 <DIR> d-------- C:\Documents and Settings\Mark\Application Data\fhnetwork.com
    2008-06-15 12:26 . 2008-06-15 12:26 <DIR> d-------- C:\WebUpdater
    2008-06-15 12:26 . 2008-06-15 12:29 <DIR> d-------- C:\CNNANT2009
    2008-06-05 18:36 . 2008-06-06 23:14 <DIR> d-------- C:\Custom Icons
    

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O4 - HKLM\..\Run: [dbyitxf] C:\Program Files\Common Files\System\wngbaqu.exe
    O4 - HKLM\..\Run: [vcspaiu] C:\Program Files\Common Files\Microsoft Shared\ixyaosk.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. mrk0

    mrk0 Private E-2

    Well things seem to be better from what I can tell. My browser and applications no longer close immediately when I type in or view anything containing the name of the mal.

    I'll be cautious as I don't know if and when this thing might come back-

    For the time being, attached are the two logs you wanted, also the fixme.reg successfully entered in to the system.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about my question on those folders?

    And also what about the below folder?
    C:\Program Files\1964
     
  8. mrk0

    mrk0 Private E-2

    Those folders were all from programs and stuff that I installed, they're non-malicious.

    Any idea on what I should go with now to keep my comp safe? I was thinking updating my Norton 2005...

    Do you happen to know if I update my subscription of 2005, do I automatically get 2008 or is that an entirely different product that I'd have to buy?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In my final instructions further down.


    Unknown. You would be better off asking in the Software Forum.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds