Welcome, Guest. Please login or register.
July 20, 2025, 10:02:01 AM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: WTF is up with Google... 0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: WTF is up with Google...  (Read 4439 times)
Merusk
Terracotta Army
Posts: 27449

Badge Whore


on: January 18, 2009, 06:12:33 AM

Ok in the last week any google searches I've done have wound-up with a page and a half of crappy redirects masquerading as real links.  For example this morning right before this post I searched "Harry Potter" to check.  The first 5 answers said "Official Site" or "Wikipedia" in the title, but if you look at the link they're redirects to spyware, adware etc.   I did a search a few minutes before that on "what do you call people with black hair" and yep, the same problem.

Anyone else having the same problem? Has google finally been gamed into uselessness or am I riddled with spyware that I'll have to beat someone in the family for?

The past cannot be changed. The future is yet within your power.
Cadaverine
Terracotta Army
Posts: 1655


Reply #1 on: January 18, 2009, 06:19:56 AM

At a guess I'd say spyware.  I googled 'what do you call people with black hair', and it came up with links to Yahoo answers, WikiAnswer, and some other sites.

And I call them brunettes, for what it's worth.  Oh ho ho ho. Reallllly?

Every normal man must be tempted at times to spit on his hands, hoist the black flag, and begin to slit throats.
Trippy
Administrator
Posts: 23657


Reply #2 on: January 18, 2009, 06:20:49 AM

Your computer is very likely hosed.

If you go here:

C:\Windows\system32\drivers\etc

do you see a file called "hosts"? If so what's in it (you can open it with Notepad or any text editor).

Are you using some sort of search toolbar to search Google? If so is it built into browser or was it something you installed separately?
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #3 on: January 18, 2009, 06:57:35 AM

All I have in hosts is the local host. 127.0.0.1

No search toolbar other than the one in basic Firefox - the little drop-down in the upper right. Now that you mention it, though, there was one installed a few weeks ago that I uninstalled. I think it was a yahoo bar and I have no idea who put it there.

I just did another google search and noticed something; it's going to 7.7.7.0 for the results. That doesn't seem normal, either.  Fuck me.

The past cannot be changed. The future is yet within your power.
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #4 on: January 18, 2009, 07:00:24 AM

At a guess I'd say spyware.  I googled 'what do you call people with black hair', and it came up with links to Yahoo answers, WikiAnswer, and some other sites.

And I call them brunettes, for what it's worth.  Oh ho ho ho. Reallllly?

Yeah I got those answers, too on the headings.  But the links go to clickndirect.com, hairbykayla.com, toseeka.com for the first 3 results.

Also, brunette isn't technically right.  That's brown hair.  Oh ho ho ho. Reallllly?

The past cannot be changed. The future is yet within your power.
Trippy
Administrator
Posts: 23657


Reply #5 on: January 18, 2009, 07:14:16 AM

Your browser may be setup to go through a (bogus) proxy then.

Do you get the same result if you try a different browser?

What happens if you go to, say, here:

http://74.125.19.147/  (that's a valid www.google.com IP address)

If you bring up a command prompt and type in:

nslookup www.google.com

do you see various 74.125.19.XXX IP addresses?
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #6 on: January 18, 2009, 07:15:43 AM

Found it on a search on the wife's machine.  It's a relatively new malware that installs itself via java/ adobe pdfs.  It's in system32/wdmaud.sys

Thanks for the help, folks.

The past cannot be changed. The future is yet within your power.
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #7 on: January 18, 2009, 07:20:04 AM

Hrm.. that file is labeled 4/13/08.  Deleting it did fix the redirect problem, though.

trip, that page still redirected me. It's a redirect that's messing with google searches themselves in the OS apparently. 

« Last Edit: January 18, 2009, 07:21:53 AM by Merusk »

The past cannot be changed. The future is yet within your power.
Aez
Terracotta Army
Posts: 1369


Reply #8 on: January 18, 2009, 07:35:06 AM

I chekeced my Host file.  Is this text normal?
Quote
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

127.0.0.1       localhost
Xuri
Terracotta Army
Posts: 1199

몇살이세욬ㅋ 몇살이 몇살 몇살이세욬ㅋ!!!!!1!


WWW
Reply #9 on: January 18, 2009, 07:42:35 AM

Yep, looks normal to me.

-= Ho Eyo He Hum =-
NiX
Wiki Admin
Posts: 7770

Locomotive Pandamonium


Reply #10 on: January 18, 2009, 09:17:28 AM

That's the default hosts file.

Seems like Merusk is finally paying for the death of Elf porn.
Hawkbit
Terracotta Army
Posts: 5531

Like a Klansman in the ghetto.


Reply #11 on: January 18, 2009, 09:19:41 AM

I picked up a naaaasty virus about 2 months ago that applied itself off a stupid wrestling movie that someone linked off another forum.  As soon as I clicked on the play button on the movie I was hosed.  

I could open a normal browser and run a search for Star Wars and get back some fairly relevant links, but most of them were caches from long ago pages.  Or else it would redirect me to spyware removal sits.  The irony is when I would search for spyware removal and do any searches for the virus name that hit me, it would redirect me to either pr0n sites or fake spyware removal sites.  

Those little malicious geniuses.... making a virus to sell you anti-virus software.   swamp poop
Ubvman
Terracotta Army
Posts: 182


Reply #12 on: January 21, 2009, 12:23:23 AM

If you think you caught the malware, perhaps your machine is still caching the bad dns?

Open up a command line and type:

ipconfig /flushdns

See if that fixes the problem.
MahrinSkel
Terracotta Army
Posts: 10859

When she crossed over, she was just a ship. But when she came back... she was bullshit!


Reply #13 on: January 21, 2009, 02:40:09 AM

Get Sandboxie.  I use it for everything I'm not totally comfortable with (that includes most of the links you freaks post).  Worst that can happen is that you have to flush a Sandbox, and lose any reconfigurations you've done it or installs you've made.

--Dave

Edit by Trippy: fixed link
« Last Edit: January 21, 2009, 02:52:13 AM by Trippy »

--Signature Unclear
Draegan
Terracotta Army
Posts: 10043


Reply #14 on: January 26, 2009, 08:56:44 AM

My coworker has this same issue.  I tried the a few of the things listed here to no avail it still directs to different sites.  For instance clicking on Continental Airlines homepage brings you to cheap ticket sites.

wdmaud.sys is in the \system32\drivers folder and a few other places like \386\ and in a few sp3 and sp2 .cab's.  I delete the few that were in the directories but the one in the drivers folder keeps popping up with a 4/13/2008 date.

Any ideas?
Engels
Terracotta Army
Posts: 9029

inflicts shingles.


Reply #15 on: January 26, 2009, 09:12:06 AM

Uhm, that file is an audio driver file. Aparently there is a trojan that infects it, but you will still need to replace it with a real one.

C:\WINDOWS\system32\Drivers\wdmaud.sys <=this one is legit

C:\WINDOWS\system32\wdmaud.sys <=this one is not!
« Last Edit: January 26, 2009, 09:14:43 AM by Engels »

I should get back to nature, too.  You know, like going to a shop for groceries instead of the computer.  Maybe a condo in the woods that doesn't even have a health club or restaurant attached.  Buy a car with only two cup holders or something. -Signe

I LIKE being bounced around by Tonkors. - Lantyssa

Babies shooting themselves in the head is the state bird of West Virginia. - schild
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #16 on: January 26, 2009, 09:50:37 AM

What Engles said.

Also, when you click the link check the status bar at the bottom of the browser window for where it's connecting to.  When I noticed it was going to 7.7.7.0 I did a google search on a clean machine for "7.7.7.0 virus" and found the solution.  It could be that there's variants out there now redirecting to different sites and using different file names.

The past cannot be changed. The future is yet within your power.
Pages: [1] Go Up Print 
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: WTF is up with Google...  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC