Solved LaSuperba or some malware has taken over my computer!

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Let's try this:

  • Press the
    WindowsKey.png
    + R on your keyboard at the same time. Type regedit and click OK.
  • Navigate to HKEY_LOCAL_MACHINE --> SYSTEM --> CurrentControlSet --> services
  • Now you need to find TCPIP service
  • Right click on it, choose Permissions and select NETWORK SERVICE
  • Check Full Control and confirm with OK.
  • Restart your PC.

Then for both TCPIP and DHCP services do this:

  • Navigate to both services one by one.
  • Right click on it, choose Permissions, then Advanced and then tick Replace all child object permissions with inheritable permissions from this object.
  • Click OK.
  • After doing this for both services, restart your PC.
Then try to start DHCP service.
 

Halls

New Member
Thread author
Verified
Oct 13, 2015
62
Still won't let me start DHCP. I'm not positive I did the permissions correctly...after checking the "replace all child object permissions..." box I hit apply and it prompted me with a do you wish to continue box, I hit Yes and then the check mark disappears...does that for both DHCP and TCPIP.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Let's try this:


cmd_icon.png
Check Disk
  • Press the
    WindowsKey.png
    + R on your keyboard at the same time. Type cmd and click OK.
  • Copy/Enter the command below and press Enter:
  • Code:
    chkdsk C: /r
  • You should get a message to schedule Check Disk at next system restart. Please type Y and press Enter.
  • All you should do now is to restart your PC and let the Check Disk process finish uninterrupted.
Check Disk report:
  • Press the
    WindowsKey.png
    + R on your keyboard at the same time. Type eventvwr and click OK.
  • In the left panel, expand Windows Logs and then click on Application.
  • Now, on the right side, click on Filter Current Log.
  • Under Event Sources, check only Wininit and click OK.
  • Now you'll be presented with one or multiple Wininit logs.
  • Click on an entry corresponding to the date and time of the disk check.
  • On the top main menu, click Action > Copy > Copy Details as Text.
  • Paste the contents into your next reply.
 

Halls

New Member
Thread author
Verified
Oct 13, 2015
62
No longer getting the "unauthorized Windows" message! But, still not able to connect to my wireless...
 

Halls

New Member
Thread author
Verified
Oct 13, 2015
62
Here are both reports.

I'll have to see if I can connect that way, not sure.
 

Attachments

  • FRST.txt
    61.5 KB · Views: 2
  • Addition.txt
    30.8 KB · Views: 1

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Try and let me know.



FarbarServiceScanner.png
Scan with Farbar Service Scanner

Download Farbar Service Scanner by Farbar and save it to your desktop.

  • Right-click on
    FarbarServiceScanner.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Make sure all of the options are checked!
  • Press Scan.
  • It will create a log (FSS.txt) in the same directory the tool is run.

Please include that log in your next reply.



TDSSKiller_Kaspersky.png
Scan with TDSSKiller

Please download TDSSKiller by Kaspersky and save it to your desktop.

  • Right-click on
    TDSSKiller_Kaspersky.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Click on Change parameters and put a checkmark beside Loaded modules. A reboot will be needed to apply the changes, allow it to do so.
  • Your machine may appear very slow and unusable after that - it's normal.
  • TDSSKiller will run automaticaly. Click on Change parameters and click OK.
  • Click the Start Scan button and wait patiently.

If anything will be found follow this guidelines:
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    If Cure is not available, please choose Skip instead.
  • Do not choose Delete unless instructed!

A report will be created in your root directory, (usually C:\ drive) in the form of TDSSKiller.[Version]_[Date]_[Time]_log.txt. Please include the contents of that file in your next post.
 
Last edited:

Halls

New Member
Thread author
Verified
Oct 13, 2015
62
I've never actually tried to connect to a wired connection before but just tried and keep getting error 651; not sure if I'm doing something incorrectly or what.


Attached are the FSS log. The TDSS scan didn't detect anything but it created 3 reports.
 

Attachments

  • FSS.txt
    3 KB · Views: 5
  • TDSSKiller.3.1.0.5_27.10.2015_22.32.37_log.txt
    490 bytes · Views: 0
  • TDSSKiller.3.1.0.5_27.10.2015_22.32.49_log.txt
    4.7 KB · Views: 0
  • TDSSKiller.3.1.0.5_27.10.2015_22.37.03_log.txt
    720.4 KB · Views: 2

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Let's try this:

subinacl.exe /subkeyreg "HKEY_LOCAL_MACHINE\system\CurrentControlSet\services\dhcp" /grant="Local Service"

subinacl.exe /subkeyreg "HKEY_LOCAL_MACHINE\system\CurrentControlSet\services\tcpip" /grant="Local Service"

subinacl.exe /subkeyreg "HKEY_LOCAL_MACHINE\system\CurrentControlSet\services\dhcp" /grant="Network Service"

subinacl.exe /subkeyreg "HKEY_LOCAL_MACHINE\system\CurrentControlSet\services\dhcp" /grant="Network Service"

Restart your PC.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Let's try to do something from recovery environment:


Please download Farbar Recovery Scan Tool x64 and save it to a flash drive.
  • Plug the flashdrive into the infected PC.
  • Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer
  • Follow the prompt to enter keyboard input method, and then the prompt to enter a password. If the machine does not have a password, simply click Enter.
  • In the Choose Recovery Tool menu select Command Prompt.
  • You will see a big black window with a blinking cursor (command prompt).



    notepad.png
    Access the notepad and identify your USB drive

    In the Command Prompt please type in:
    Code:
    notepad
    and press Enter.
  • When the notepad opens, go to File menu.
  • Select Open.
  • Go to Computer and search there for your USB drive letter.
  • Note down the letter and close the notepad.



    FRST.gif
    Scan with Farbar Recovery Scan Tool

    Once back in the command prompt window, please do the following:
  • Type in e:\frst64.exe and press Enter.
    You need to replace e with the letter of your USB drive taken from notepad!
  • FRST will start to run. Give him a minute or so to load itself.
  • Click Yes to Disclaimer.
  • In the main console, please click Scan and wait.
  • When finished it will produce a logfile named FRST.txt in the root of your pendrive and display it. Close that logfile.

    Transfer it to your clean machine and include it in your next reply.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Okay, let's search from recovery environment too:

FRST.gif
FRST search

Once again we shall use FRST for additional checks. Re-run FRST/FRST64:
  • Copy dnsapi.dll into the Search: field in FRST then click the Search Files button.
  • FRST will search your computer for files and when finished it will produce a log Search.txt in the same directory the tool is run.
  • Please attach it to your reply.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top