My apologies for not posting back on here. I had actually forgotten until receiving your email notification.
I also still had exactly the same popups that you are describing, except in my case the DNSUnlocker went away after I reset the Hosts file but was replaced soon after by the dnsqa.me.
I also had a tech try to tell me I would have to reformat the drive and start again, but I didn't listen and tried something else. This is what I did and, believe it or not, it worked for me.
I completely uninstalled every trace of RunasXP Outlook Express 6. (You may not have this email app on your computer so forget this step if you have not.) The only reason I removed this app was because a tech pointed out several dll files belonging to the
app which were named with numbers followed by the word "locker" (e.g. xxx.xxlocker.dll where
x denotes a number). The files passed all of the anti-malware and anti-virus scans, but he felt they looked suspicious enough to warrant complete removal of the app.
I then completely uninstalled Google Chrome. (By "completely" I mean I removed all traces of leftover files and folders after uninstalling it).
I have had no problems with malware for over a week. No pop ups, no suspicious downloading, and no redirecting at all!!! The techs would not believe me, but they ran all of the scans and agreed with me. My PC is now clean.
It seems whatever I had on my computer had somehow burrowed its way into the main exe or dll files of my default browser (and possibly also my default email app). By completely removing them the infection was wiped out.
edit: I am just coming back to add a few more details.
I have nothing against Chrome personally, but I suggest:
- Try using a different browser from now on. There are plenty of these available that are just as good, if not better.
- Be very careful downloading any adobe products in future unless you are getting them from the official adobe site. I removed most of my adobe products except for the reader. I firmly believe that what caused my infection was I inadvertently installed
malware that was disguising itself as adobe. Now that I think back on it, I do seem to recall downloading Adobe Flash from a third party website. Before I reset my Hosts file I had about 40 hosts running in the background called "adobe" and they were multiplying
as time went by. They were opening channels and pulling my internet in many different directions. They were well disguised as they could fool all of the anti-virus and the majority of anti-malware software. Nevertheless the majority of them were rogue. I strongly
suspect these are what corrupted my browser.
- Considering you have been having problems with malware, it may be a good idea to dispense with Adobe Flash and not re-install it (at least for the time being).