Yesterday, my google was hijacked. Eveytime I click a google link I am redirected to a "bad" page or shady advertising. I believe there is a well known exploit which involves a program wdmaud.drv which is misdirected to the trojan. wdmaud is normally stored in the system32\drivers directory but this exploit puts a trojan of the same name in the system32 directory. Deleting him solves the problem for about one or two searches, then wdmaud reappears and I am hijacked again. Obviously, there is another component to this I can not find and neither can Malewarebyte, Superantispyware and McAfee.
Anyone had any experience with this bug? So far Chrome is unaffected.


Reply With Quote