The Mudcat Café TM
Thread #118606   Message #2566118
Posted By: Malcolm Douglas
13-Feb-09 - 01:53 PM
Thread Name: Tech: Google results hi-jacked on Firefox
Subject: RE: Tech: Google results hi-jacked on Firefox
Don't do anything without reading both of the pages I linked to: there is important additional info in the second one. The "waiting for 7.7.7.0" message relates to one particular instance of wdmaud.sys which is typically a lot smaller than the others and may have the description "Miekiemoes rules" that McGrath noticed. The others are legit Windows files and should be left well alone unless you particularly want to lose sound on your machine.

If you don't see a file extension, that will be because your machine is set by default to hide some kinds. This can be changed in the Folder Options dialog.

Earlier forms of the worm or whatever you want to call it were tied to a different file and returned a different message ("waiting for 1.2.3.0" is one), so be sure to check the exact symptoms you are getting and search for any message, if different, via Google, before deleting anything. The chances are that SRS has a different infection from McGrath.

The problem may recur, so keep checking for the underlying infection. There seem to be a number of variations on the theme and it's liable to take the various antivirus programs etc a while to catch up. As to the source, one suggestion is that the infection is transmitted via pdf files.