<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Google, MSN, Yahoo Search 7.7.7.0 Redirector Malware HiJack</title>
	<atom:link href="http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/</link>
	<description>All things involving technology.</description>
	<lastBuildDate>Fri, 05 Mar 2010 21:22:19 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jordan</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-3/#comment-1477</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Wed, 20 Jan 2010 01:42:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-1477</guid>
		<description>Same problem... except I deleted Wdmaud and I still have it. And on my computer, no matter how much I delete Wdmaud, it keeps coming back.</description>
		<content:encoded><![CDATA[<p>Same problem&#8230; except I deleted Wdmaud and I still have it. And on my computer, no matter how much I delete Wdmaud, it keeps coming back.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike`</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-3/#comment-785</link>
		<dc:creator>Mike`</dc:creator>
		<pubDate>Wed, 23 Dec 2009 04:20:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-785</guid>
		<description>I forgot to mention,  It happens in both Firefox (latest version) and IE8</description>
		<content:encoded><![CDATA[<p>I forgot to mention,  It happens in both Firefox (latest version) and IE8</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike`</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-3/#comment-783</link>
		<dc:creator>Mike`</dc:creator>
		<pubDate>Wed, 23 Dec 2009 04:16:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-783</guid>
		<description>I have the same problem.
If I click on any link displayed in Google or Bing, or msn search, I get redirected to an unrelated website, which is different each time.

Sometimes it is to a travel website, sometimes to a shopping website, somethings to a rogue spyware site that pretends to scan your PC for viruses and malware. Clicking CANCEL on the page does nothing, you have to click the X close box, top right.
Malwarebytes, spybot, adaware, norton 360, avg, Microsoft security essentials, all report the system as clean.

I have booted and scanned in SAFE mode for those programs that allow a safe mode scan.

I have checked, I do not have the c:\windows\system32\wdmaud.sys file.
I do have c:\windows\system32\drivers\wdmaud.sys

I have checked the  C:\WINDOWS\SYSTEM32\DRIVERS\etc\hosts file

The only URL shown is 127.0.0.1   LOCAL HOST
Other lines in the file are all prefixed with #   (assumed to be a comment)

I have checked the running processes and loaded files using Hijackthis
There appears to be nothing unusual.


Any ideas would be greatly appreciated, I have spend two days on this, I am tearing my hair out!</description>
		<content:encoded><![CDATA[<p>I have the same problem.<br />
If I click on any link displayed in Google or Bing, or msn search, I get redirected to an unrelated website, which is different each time.</p>
<p>Sometimes it is to a travel website, sometimes to a shopping website, somethings to a rogue spyware site that pretends to scan your PC for viruses and malware. Clicking CANCEL on the page does nothing, you have to click the X close box, top right.<br />
Malwarebytes, spybot, adaware, norton 360, avg, Microsoft security essentials, all report the system as clean.</p>
<p>I have booted and scanned in SAFE mode for those programs that allow a safe mode scan.</p>
<p>I have checked, I do not have the c:\windows\system32\wdmaud.sys file.<br />
I do have c:\windows\system32\drivers\wdmaud.sys</p>
<p>I have checked the  C:\WINDOWS\SYSTEM32\DRIVERS\etc\hosts file</p>
<p>The only URL shown is 127.0.0.1   LOCAL HOST<br />
Other lines in the file are all prefixed with #   (assumed to be a comment)</p>
<p>I have checked the running processes and loaded files using Hijackthis<br />
There appears to be nothing unusual.</p>
<p>Any ideas would be greatly appreciated, I have spend two days on this, I am tearing my hair out!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-3/#comment-571</link>
		<dc:creator>Tony</dc:creator>
		<pubDate>Wed, 09 Dec 2009 23:20:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-571</guid>
		<description>Amoss,

your hosts file looks normal to me. mine actually had a whole list of things that shouldn&#039;t have been there, which i managed to delete, but the google results redirecting is still happening. and malware bytes still doesn&#039;t find anything wrong.</description>
		<content:encoded><![CDATA[<p>Amoss,</p>
<p>your hosts file looks normal to me. mine actually had a whole list of things that shouldn&#8217;t have been there, which i managed to delete, but the google results redirecting is still happening. and malware bytes still doesn&#8217;t find anything wrong.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amoss</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-3/#comment-544</link>
		<dc:creator>Amoss</dc:creator>
		<pubDate>Mon, 07 Dec 2009 02:05:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-544</guid>
		<description>Hi.
PLEASE HELP!!!!!
Every time i click on a link on google i get redirected to some other site. Mainly advertising sites.
I have tried to restore my default settings on the browser, i have scanned with Malewarebytes and it found stuff and deleted them already, i have sacnned with avast anti virus and that deleted files but the problem is still happening.
Im not very good with computers and need help.
This is what it says in my hosts file in noteped:

# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a &#039;#&#039; symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

127.0.0.1	localhost


To be honest i wouldn&#039;t know if there was something wrong with that or not????? :s
I am a bit concerned with these 3 files that avast picked up and i cant get rid of them, they are:

kernel32.dll
winsock.dll
wsock32.dll

All in system32 folder...
Someone please help me. it happens all the time, even brings up new pages.....</description>
		<content:encoded><![CDATA[<p>Hi.<br />
PLEASE HELP!!!!!<br />
Every time i click on a link on google i get redirected to some other site. Mainly advertising sites.<br />
I have tried to restore my default settings on the browser, i have scanned with Malewarebytes and it found stuff and deleted them already, i have sacnned with avast anti virus and that deleted files but the problem is still happening.<br />
Im not very good with computers and need help.<br />
This is what it says in my hosts file in noteped:</p>
<p># Copyright (c) 1993-1999 Microsoft Corp.<br />
#<br />
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.<br />
#<br />
# This file contains the mappings of IP addresses to host names. Each<br />
# entry should be kept on an individual line. The IP address should<br />
# be placed in the first column followed by the corresponding host name.<br />
# The IP address and the host name should be separated by at least one<br />
# space.<br />
#<br />
# Additionally, comments (such as these) may be inserted on individual<br />
# lines or following the machine name denoted by a &#8216;#&#8217; symbol.<br />
#<br />
# For example:<br />
#<br />
#      102.54.94.97     rhino.acme.com          # source server<br />
#       38.25.63.10     x.acme.com              # x client host</p>
<p>127.0.0.1	localhost</p>
<p>To be honest i wouldn&#8217;t know if there was something wrong with that or not????? :s<br />
I am a bit concerned with these 3 files that avast picked up and i cant get rid of them, they are:</p>
<p>kernel32.dll<br />
winsock.dll<br />
wsock32.dll</p>
<p>All in system32 folder&#8230;<br />
Someone please help me. it happens all the time, even brings up new pages&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-2/#comment-507</link>
		<dc:creator>Tony</dc:creator>
		<pubDate>Wed, 02 Dec 2009 14:23:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-507</guid>
		<description>Yeah, well I have this google redirect thing on my computer and MalwareBytes, and it doesn&#039;t remove it. This problem came after I got the AdvancedVirusRemover infection, this thing that tries to pass itself off as a virus remover, came out of nowhere while on my college&#039;s website. MalwareBytes removed that, but this is a lingering problem that won&#039;t go away. Of course I find this site a few days after you have removed the tool.</description>
		<content:encoded><![CDATA[<p>Yeah, well I have this google redirect thing on my computer and MalwareBytes, and it doesn&#8217;t remove it. This problem came after I got the AdvancedVirusRemover infection, this thing that tries to pass itself off as a virus remover, came out of nowhere while on my college&#8217;s website. MalwareBytes removed that, but this is a lingering problem that won&#8217;t go away. Of course I find this site a few days after you have removed the tool.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Kreider</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-2/#comment-473</link>
		<dc:creator>Richard Kreider</dc:creator>
		<pubDate>Fri, 27 Nov 2009 17:23:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-473</guid>
		<description>The file has been removed due to the fact MalwareBytes Anti-Malware scanner picks up this infection and fixes it.  You can get Malwarebytes from http://www.malwarebytes.org/</description>
		<content:encoded><![CDATA[<p>The file has been removed due to the fact MalwareBytes Anti-Malware scanner picks up this infection and fixes it.  You can get Malwarebytes from <a href="http://www.malwarebytes.org/" rel="nofollow">http://www.malwarebytes.org/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karen</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-2/#comment-320</link>
		<dc:creator>Karen</dc:creator>
		<pubDate>Sat, 07 Nov 2009 02:01:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-320</guid>
		<description>I&#039;m having a problem with the Redirect Virus, and would like to use your tool, but the zip file does not seem to exisit.  Is there a way to get hold of it?</description>
		<content:encoded><![CDATA[<p>I&#8217;m having a problem with the Redirect Virus, and would like to use your tool, but the zip file does not seem to exisit.  Is there a way to get hold of it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve S</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-2/#comment-139</link>
		<dc:creator>Steve S</dc:creator>
		<pubDate>Mon, 03 Aug 2009 17:18:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-139</guid>
		<description>Btw I&#039;m also getting windows-like warning popups saying various files are corrupt and I need to run Chkdsk.</description>
		<content:encoded><![CDATA[<p>Btw I&#8217;m also getting windows-like warning popups saying various files are corrupt and I need to run Chkdsk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve S</title>
		<link>http://www.techish.net/2009/01/10/google-7770-redirector-malware-tool/comment-page-2/#comment-138</link>
		<dc:creator>Steve S</dc:creator>
		<pubDate>Mon, 03 Aug 2009 17:16:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.techish.net/?p=386#comment-138</guid>
		<description>I deactivated Adobe Reader javascript and installed NoScript in Firefox.

Did a full recursive scan of C:\ with 7770finder, it didn&#039;t find any infections but it did skip 41 files.

Tried installing malwarebytes&#039; tool from an external drive, but the setup script halts before finishing.

So I&#039;m still being redirected.  THis is one nasty piece of work.  I&#039;ll try installing AVG but I&#039;m not hopeful.  Could be it&#039;s time for an XP reinstallation...</description>
		<content:encoded><![CDATA[<p>I deactivated Adobe Reader javascript and installed NoScript in Firefox.</p>
<p>Did a full recursive scan of C:\ with 7770finder, it didn&#8217;t find any infections but it did skip 41 files.</p>
<p>Tried installing malwarebytes&#8217; tool from an external drive, but the setup script halts before finishing.</p>
<p>So I&#8217;m still being redirected.  THis is one nasty piece of work.  I&#8217;ll try installing AVG but I&#8217;m not hopeful.  Could be it&#8217;s time for an XP reinstallation&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
