I have a friends windows 7 (64bit) computer that has a DNS hijack in it.
Steps I have done currently to remove the DNS and viruses:
- disconnected internet
- Ran: AdwCleaner, JRT, Emsisoft, Kaspersky, ReasonCore, Zemana, and lastly RogueKiller to remove the current DNS changes.
- Reset DNS and ran TweakingRepair to do a full fix
- Reset internet options in control panel (removing cookies)
- Removed all unknown services and startup items.
- Used autoruns to remove any unknown or malicious startup as well.
While disconnected from any network and internet, it will keep the dns malware removed whenever I run roguekiller. However as soon as I reconnect it to network it instantly gets the malware DNS changes again.
I am wondering what else can I run to possibly remove a DNS hijack? Because I am thinking there must be some exploit or hidden script running that recreates the DNS changes every time it connects to network.
The short story of this is, she got called from someone claiming to be from Rwglobal Tech Repair. SCAM website: http://www.rwglobal.us/
Anyone know about what they do in particular?