SantaFeBill
Veteran Member
On both my and my wife's computer, there are a large number of registry entries that reference files with the extension 'yax'.
These files can't be found with any of the ways that I have to search for files on the hd in WinXP. Also, the registry entries are a string of nonsense syllables - in short, classic symptoms of malware.
I've done extensive searches on the Web, and have only come up with the info that there is an XML extension library called 'YAX'.
But if the registry entries represent something legitimate, why the lengths to hide what's going on? Why would legit apps create registry entries with nonsense strings, and no indication of what apps they're related to?
Here's an example:
Key Name: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
Class Name: NO CLASS
Last Write Time: 9/3/2009 - 7:42 PM
Value 0
Name: HRZR_PGYFRFFVBA
Type: REG_BINARY
Data:
00000000 45 68 51 0e 01 00 00 00 - EhQ.....
Value 1
Name: HRZR_EHACVQY:%pfvqy2%\Jvaqbjf Zrqvn Cynlre.yax
Type: REG_BINARY
Data:
00000000 01 00 00 00 13 00 00 00 - 54 87 4f 61 08 2d ca 01 ........
Value 2
Name: HRZR_EHACVQY:%pfvqy2%\Npprffbevrf\Gbhe Jvaqbjf KC.yax
Type: REG_BINARY
Data:
00000000 01 00 00 00 12 00 00 00 - 54 87 4f 61 08 2d ca 01 ........
Value 3
Name: HRZR_EHACVQY:%pfvqy2%\Npprffbevrf\Flfgrz Gbbyf\Svyrf naq Frggvatf Genafsre Jvmneq.yax
Type: REG_BINARY
Data:
00000000 01 00 00 00 11 00 00 00 - 54 87 4f 61 08 2d ca 01 ........
Saving from REGEDIT to a text file truncates some values, but I think you can get the idea.
Given the number entries and the fact that they are on both my and my wife's computers, I'm hesitant to rip them out until I can find more about them, so any help would be very much appreciated.
These files can't be found with any of the ways that I have to search for files on the hd in WinXP. Also, the registry entries are a string of nonsense syllables - in short, classic symptoms of malware.
I've done extensive searches on the Web, and have only come up with the info that there is an XML extension library called 'YAX'.
But if the registry entries represent something legitimate, why the lengths to hide what's going on? Why would legit apps create registry entries with nonsense strings, and no indication of what apps they're related to?
Here's an example:
Key Name: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
Class Name: NO CLASS
Last Write Time: 9/3/2009 - 7:42 PM
Value 0
Name: HRZR_PGYFRFFVBA
Type: REG_BINARY
Data:
00000000 45 68 51 0e 01 00 00 00 - EhQ.....
Value 1
Name: HRZR_EHACVQY:%pfvqy2%\Jvaqbjf Zrqvn Cynlre.yax
Type: REG_BINARY
Data:
00000000 01 00 00 00 13 00 00 00 - 54 87 4f 61 08 2d ca 01 ........
Value 2
Name: HRZR_EHACVQY:%pfvqy2%\Npprffbevrf\Gbhe Jvaqbjf KC.yax
Type: REG_BINARY
Data:
00000000 01 00 00 00 12 00 00 00 - 54 87 4f 61 08 2d ca 01 ........
Value 3
Name: HRZR_EHACVQY:%pfvqy2%\Npprffbevrf\Flfgrz Gbbyf\Svyrf naq Frggvatf Genafsre Jvmneq.yax
Type: REG_BINARY
Data:
00000000 01 00 00 00 11 00 00 00 - 54 87 4f 61 08 2d ca 01 ........
Saving from REGEDIT to a text file truncates some values, but I think you can get the idea.
Given the number entries and the fact that they are on both my and my wife's computers, I'm hesitant to rip them out until I can find more about them, so any help would be very much appreciated.