Solved LaSuperba or some malware has taken over my computer!

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Download RepairDNS to your Desktop and run it. Press GO. Restart your PC. Attach its report




cmd_icon.png
Command Prompt
  • Press the
    WindowsKey.png
    + R on your keyboard at the same time. Type services.msc and click OK.
  • Scroll down until you find DNS Client service.
  • Next to its name you should see Started or Stopped.
  • If it is stopped, right click and click Start.
  • Let me know if it started without problems.


cmd_icon.png
Command Prompt
  • Press the
    WindowsKey.png
    + R on your keyboard at the same time. Type services.msc and click OK.
  • Scroll down until you find DHCP Client service.
  • Next to its name you should see Started or Stopped.
  • If it is stopped, right click and click Start.
  • Let me know if it started without problems.
 
Last edited:

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Okay. Let's see what else we can do.

Go to this location:

C:\Windows\System32

and this location

C:\Windows\SysWOW64

Find dnsapi.dll file in both folders.

=========================================

  • Right click it and then select Properties.
  • Select Security tab and then click Edit
  • Click on Users and then make a picture of this screen.
  • Do this for both files in both folders.
 

Halls

New Member
Thread author
Verified
Oct 13, 2015
62
Ok, not positive this is the right thing but here are the two pictures.
 

Attachments

  • System32.png
    System32.png
    140.8 KB · Views: 8
  • SysWOW64.png
    SysWOW64.png
    167.8 KB · Views: 8

Halls

New Member
Thread author
Verified
Oct 13, 2015
62
The DNS Client service now has Started next to its name but I get the same error message when I try to start the DHCP Client service.

Oh! And I just realized that I missed your instruction on downloading RepairDNS...I just tried to and my computer (not the infected one) won't let me download it, saying it's a dangerous file or something like that.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
It is not dangerous, disable your antivirus and try again please.


FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 

Halls

New Member
Thread author
Verified
Oct 13, 2015
62
Here are the three files (RepairDNS report, FRST.txt & Addition.txt).
 

Attachments

  • RepairDNS.txt
    509 bytes · Views: 1
  • FRST.txt
    61.2 KB · Views: 0
  • Addition.txt
    31 KB · Views: 3

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Yes, one service is disabled and we need to restore its functionality.

  • Press the
    WindowsKey.png
    + R on your keyboard at the same time. Type regedit and click OK.
  • Navigate to HKEY_LOCAL_MACHINE --> SYSTEM --> CurrentControlSet --> services
  • Now you need to find Dhcp service
  • Right click on it, choose Permissions and select NETWORK SERVICE
  • Check Full Control and confirm with OK.
  • Restart your PC and then try to start this service again, like you did before.
 

Halls

New Member
Thread author
Verified
Oct 13, 2015
62
I tried to start the Dhcp service after restarting and it's still giving me the same error.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Can you make a picture of DHCP service permissions in registry? Sorry, but it is really difficult for me and I believe for you to work like this. These are some non-standard and rarely seen procedures. I haven't had something like this in years.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top