Jump to content

Shopperz dnsapi.dll problem


Recommended Posts

  • Replies 72
  • Created
  • Last Reply

Top Posters In This Topic

Is possible dependencies are maybe needing to be started before DHCP client is running...

 

Ok try these commands from elevated command prompt: Select enter after each one..

 

net start nsi

net start tdx

net start afd

Finally

 

net start dhcp

 

Do those command work ok, or do you get any errors?
 

Link to post
Share on other sites

Maybe there is a permissions problem, are you ok with the registry? if so do the following:

 

Select the widows key and the R key together, The RUN box will open type regedit click ok, accept UAC if offered Regedit should open.

Expand the following reg keys:

HKEY_local_machine > System > CurrentControlSet > Services > right click direct onto this folder Dhcp then select Permissions in the new window make sure Full control is checked for "System" and "Administrator" groups.

Link to post
Share on other sites

100% yes on the professional question, if I could see the logs from FRST i`d probably have you up and running too.... i was hoping the LastRegBack: yyyy:mm:dd time would have predated your issue even by one day, with that available we could have used that line in FRST fix to restore your registry hives... ah well, if only never gets us anywhere...

 

let me know if the pro route is what you intend..

Link to post
Share on other sites

Ok give this a try with Malwarebytes...

 

Please open Malwarebytes Anti-Malware.

  • On the Settings tab > Detection and Protection sub tab, Detection Options, tick the box "Scan for rootkits" <<<--- This setting is very important and must be selected....
  • Under Non-Malware Protection sub tab Change PUP and PUM entries to Treat detections as Malware
  • Click on the Scan tab, then click on Scan Now >> . If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, click Apply Actions. if applicable
  • Wait for the prompt to restart the computer to appear (if applicable), then click on Yes.

 

check MB log, were any changes made?

Link to post
Share on other sites

Yes you can remove them, but no fix for internet...... I`m really struggling with no logs, no way to get them either... The issue is the infection and the changes that were made, two files were altered

 

C:\Windows\System32\dnsapi.dll
C:\Windows\SysWOW64\dnsapi.dll

 

Other changes were made to permissions etc.... without logs to look at from FRST it really is like being stuck between a rock and a hard place....

 

Can you navigate to C:\Windows\System32\dnsapi.dll right click direct onto dnsapi.dll select "Properties" then select the "Security" Tab.  Highlite "System" do the settings look anything like the attached image?

 

Do the same for C:\Windows\SysWOW64\dnsapi.dll

 

 

post-3601-0-53738500-1452387797_thumb.pn

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.