Andy Bumatai Tweetup

Andy Bumatai Tweetup

Group photo from tonight’s Andy Bumatai Show. He put out a tweet about a week ago inviting the Hawaii tweeps to a special show on social media. A couple dozen or so of us dropped in on the iNG Direct Cafe. Check out the conversation going on off camera.

Troublesome Google hijacking – redirects results through 7.7.7.0

So a user at the office tells me that his Google is messed up. And by messed up, I mean the results appear to be legitimate at first glance. If you look closer, the descriptions are accurate, but they link to useless, if not blatantly spammy sites. See screencap below.

google_results_corrupt_thumb

This happened around mid-December and all of the usual AV tricks I tried could not find the source of the infection. The search hijacking affected multiple browsers and search engines.

Both IE and Firefox were compromised, but not Google Chrome. It also hijacked search results from Google, Yahoo, and I think MSN Live. Luckily OpenDNS’s search was clean. I made the user use these workarounds up until this afternoon.

Today I noticed that this search hijacking was running a bit slower than usual and I saw that search results were waiting on something from IP address 7.7.7.0. I searched for malware originating from that IP and came across this blog entry.

Deleting C:\windows\system32\wdmaud.sys has worked so far. The user’s search results are now clean. I recommend uploading any suspect file in the C:\windows\* through Virus Total before deleting it though. Better to be safe than sorry, especially when fiddling with the Windows system folder.

I’m now running more malware scans on the infected computer. This time using Malwarebytes in addition to SuperAntiSpyware. Superantispyware didn’t catch anything the last time I ran it, but Malwarebytes found a similar piece of malware in C:\WINDOWS\system32\sysaudio.sys, and Virustotal confirmed it.

This piece of malware was harder than usual to diagnose because searching for “Google hijack” didn’t return any useful results. Hopefully this little post will push this Google Hijacking description a little higher up in the ranking. And kudos to the Podnutz Podcast for turning me on to Malwarebytes.

Round Top Sunset Time Lapse

Round Top Sunset Time Lapse

[display_podcast]

My friend Joe Philipson arranged for a Flickr meetup at Puu Ualakaa Park around sunset yesterday to hang out and practice time lapse photography. I’ve got a Canon A630 which I hacked with the CHDK firmware. I’ve tried stitching together time lapse photos before, but they never quite worked for me. I think I’m starting to ge the hang of it now.

Music for the video is “Restless for the Sun” by Jimmie Bratcher.