Posted 27 December 2009 - 12:19 AM
I've read the preparation guide and heres my complete list of problems.
A few days ago this computer was receiving attack messages from nortons internet security every 30minutes to an hour. After that the web browsers installed would open up random windows, this computer uses firefox and IE. If you click a website on the google page it redirects you to another site, they're all different each time. When I searched google for the file or name of whatever is attacking the computer it would always redirect to more fake websites. Not all websites have problems, but other sites like Symantec and Wikipedia do not work. I have to cut/copy/paste into the browser bar to get it to work. Sometimes 6 different tabs are opened up everytime firefox is started up.
Now then, the problem with DDS.scr nortons thinks its a virus for some reason and removes it/deletes it everytime i try to install it. When I tried to install RootRepeal the computer restarted on its own! When I try to install either (the second time) it says its finished removing the virus and I now have to restart to fix the problem.
I've not had problems like this with a virus in the past so i'm at a loss as to what to do, is nortons corrupted? Is nortons the problem? Is a virus pretending to be nortons "pop ups"?
1. Nortons scan, result nothing but tracking cookies.
2. Malwarebytes AntiMalware scan, result nothing but tracking cookies.
3. Outdated Adaware Lavasoft scan, result nothing but more tracking cookies.
4. This forum
I've just had the attack pop up, it says "a58990058.cn" is the attacker and risk name is listed as "HTTPS Tidserv C and C Domain Request" with application path \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SVCHOST.EXE
Let me know how to get the logs posted and I will, until then this is all the information I can give about my problem. I need further help, thanks.