-Any website may or may not load on the first try.
-Yahoo.com would usually come up garbled and malformed with images missing, page formatting incorrect, and with some encrypted/compiled looking text.
-Bing.com would usually flash multiple times while loading and finish with "Internet Explorer cannot display the webpage".
-Google.com would usually never come up and end with the same message as Bing.
-Downloading malware removing tools like rkill and Malwarebytes would usually prompt IE9 to display "this file has been reported unsafe".
-RDP connections to the infected computer would be terminated within seconds of loggin in.
-The graphical display of any VNC connections from the infected computer would result in horizontal colored bars with many artifacts. VNC connection would freeze then eventually terminate.
-Many images on web pages will look like they were half downloaded and half corrupt with the same visual distortion described above.
-When Malwarebytes would attempt to download definitions, the download bar would just keep starting over when it reached the end.
-ComboFix would attempt to download updates but would fail and the exe would become corrupt.
Since I had just reinstalled my computer the day before, I decided to just start fresh and reinstall again. This time I was more cautious about what programs I installed and what data I copied. The infection has returned and has now spread to my Windows 7 laptop with the same behavior.
I have recently tried Safari 5.1.7 to try something different and when it fails to load a page, its Activity Window says "cannot decode raw data"
Here are the tools I have used to attempt the rescue of my own computer:
Microsoft Security Essentials
Trend Micro WFBS
Linux scanners via bootable USB
AVIRA AntiVir Rescue Disk
BitDefender Rescue Disk
Kaspersky Rescue CD
Pandad Safe CD
AVG Rescue CD
Dr. Web Live CD
Some viruses and trojans were found and removed with the linux scanners which did not return with subsequent scans. All-in-all, I have been trying to remove this virus for about a week now.
Thanks in advance.
Edited by Kzatu, 18 September 2012 - 07:34 PM.