• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 23:30
CET 05:30
KST 13:30
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 3 - Playoffs Preview0RSL Season 3 - RO16 Groups C & D Preview0RSL Season 3 - RO16 Groups A & B Preview2TL.net Map Contest #21: Winners12Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10
Community News
Weekly Cups (Dec 1-7): Clem doubles, Solar gets over the hump0Weekly Cups (Nov 24-30): MaxPax, Clem, herO win2BGE Stara Zagora 2026 announced15[BSL21] Ro.16 Group Stage (C->B->A->D)4Weekly Cups (Nov 17-23): Solar, MaxPax, Clem win3
StarCraft 2
General
Weekly Cups (Dec 1-7): Clem doubles, Solar gets over the hump Chinese SC2 server to reopen; live all-star event in Hangzhou Maestros of the Game: Live Finals Preview (RO4) BGE Stara Zagora 2026 announced Weekly Cups (Nov 24-30): MaxPax, Clem, herO win
Tourneys
StarCraft2.fi 15th Anniversary Cup Tenacious Turtle Tussle Sparkling Tuna Cup - Weekly Open Tournament RSL Offline Finals Info - Dec 13 and 14! StarCraft Evolution League (SC Evo Biweekly)
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 503 Fowl Play Mutation # 502 Negative Reinforcement Mutation # 501 Price of Progress Mutation # 500 Fright night
Brood War
General
BGH Auto Balance -> http://bghmmr.eu/ BW General Discussion Foreign Brood War Data analysis on 70 million replays MBCGame Torrents
Tourneys
[Megathread] Daily Proleagues Small VOD Thread 2.0 [BSL21] RO16 Group D - Sunday 21:00 CET [BSL21] RO16 Group A - Saturday 21:00 CET
Strategy
Current Meta Game Theory for Starcraft How to stay on top of macro? PvZ map balance
Other Games
General Games
Stormgate/Frost Giant Megathread Nintendo Switch Thread Path of Exile ZeroSpace Megathread The Perfect Game
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Mafia Game Mode Feedback/Ideas TL Mafia Community Thread
Community
General
European Politico-economics QA Mega-thread Things Aren’t Peaceful in Palestine US Politics Mega-thread Russo-Ukrainian War Thread The Big Programming Thread
Fan Clubs
White-Ra Fan Club
Media & Entertainment
Anime Discussion Thread [Manga] One Piece Movie Discussion!
Sports
2024 - 2026 Football Thread Formula 1 Discussion
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
TL+ Announced Where to ask questions and add stream? The Automated Ban List
Blogs
I decided to write a webnov…
DjKniteX
Physical Exertion During Gam…
TrAiDoS
James Bond movies ranking - pa…
Topin
Thanks for the RSL
Hildegard
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1545 users

Lurking in TL saved my PC

Blogs > JieXian
Post a Reply
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
Last Edited: 2011-07-14 06:43:42
July 14 2011 05:52 GMT
#1
Referring to this post, sorry if it's pure common sense to some of you but it certainly wasn't for me. I haven't encountered this ever since I was using a win95 PC. Also I hope this might be of use to someone.

I was lurking around reading posts about 1 month ago when today my father was clicking on some link he claims he does everyday from a blog to some "UK newspaper" site about "How to buy gold" <--- my spider sense detects inconsistency at this point. But no point arguing with him.

----------------------------------------------------------------------------------------------------------------------------
EDIT: Later he came back and offered to show me what he did earlier and it was a life feed link from a blog and looking legit, I clicked it (knowing how to solve the problem) and got here (just in case you're worried, it really is): http://www.telegraph.co.uk/finance/personalfinance/investing/gold/8635523/How-to-invest-in-gold.html . Showing him the article, he said he didn't see this page earlier. Based on how he spoke and knowing his .. routines, I have some confidence that that's what happened. If it's true than it's really scary.

On second thought, it could be due to some link he clicked earlier since programs take some time to finish installing. That makes more sense.
----------------------------------------------------------------------------------------------------------------------------


The program "Security protection" had all the pictures used by Win7, the firewall and the shield thing and for moment I thought it was from windows, until I saw the shortcut icon on the desktop which meant that a program was installed. Moreover I couldn't close it and any program I execute just dies after 2 seconds so I can't use the task manager to kill the process or restore it to and earlier state.

And it scanned my pc automatically and detected some win32Gen-Child-Porn which made me panic a while. This was before I saw the shortcut icon on my desktop.

So at first I tried to out maneuver it by trying to kill the process with the task manager faster than it could kill the task manager.

Didn't work.

Next, after trying to alt f4 and right click it from the task bar in vain, I went to the 'settings' tab and saw options to "Start Security Protection on startup" and "Scan PC on startup". Seeing a glimmer of hope, I pounced on both the checkboxes and promtly restarted my computer.

Only to be greeted by the the same scareware again.

After staring and thinking for a few minutes, I suddenly recalled reading something about safe mode and hoped that it will allow me to restore my backup. Sure enough, in safe mode, the "Security Protection" scareware didn't startup and neither did MsnMessenger or anything else. Without anything stopping me, I was able to restore my computer to an earlier state.

And sure it did :D

After restoring, I quickly loaded the thread I bookmarked and couldn't be more grateful.

Download Combofix ( http://www.bleepingcomputer.com/combofix/how-to-use-combofix )

Also download hijackthis ( http://free.antivirus.com/hijackthis/ )

What you want to do is boot into safe-mode and run hijackthis first, after that run combofix. Once combofix finishes its going to reboot your computer. Running both of them should do quite the trick to speed up your computer.

After that I would run malwarebytes ( http://www.malwarebytes.org/ )

I used to work at a PC repair shop and those 3 programs solved 95+% of our issues.



Thank you so very very much Halfwarr!!!!!

*****
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
Alabasern
Profile Blog Joined September 2010
United States4005 Posts
July 14 2011 06:12 GMT
#2
TeamLiquid is a splendid resource indeed.
Support your esport!
Mickey
Profile Blog Joined July 2005
United States2606 Posts
July 14 2011 06:17 GMT
#3
Combofix is an amazing utility that has saved me so many times.
Z3kk
Profile Blog Joined December 2009
4099 Posts
July 14 2011 06:22 GMT
#4
Wait, how were you able to download those two things and run then successfully if everything you opened got closed? :o

Thanks for this; good to know for future reference
Failure is not falling down over and over again. Failure is refusing to get back up.
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
Last Edited: 2011-07-14 06:40:49
July 14 2011 06:34 GMT
#5
Opps I forgot to describe the most important part. Added it to the OP

Basically when I start up in safe mode (keep mashing F8 during booting). None of the programs will launch at startup, and that includes the scareware.

So I was able to safely restore my computer to an earlier state. Program files -->Accessories --> {something about restoring backup or System restore} (currently using a Spanish interface to learn the language)

I didn't download the programs because this was easier and I didn't have any work that will be lost if I were to restore to the state it was 2 days ago. Anyways I'm going to download those 2 programs right now just in case this happens again.
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
Kyuukyuu
Profile Blog Joined January 2009
Canada6263 Posts
July 14 2011 06:40 GMT
#6
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?
Cr4zyH0r5e
Profile Blog Joined November 2007
Peru1308 Posts
Last Edited: 2011-07-14 06:42:04
July 14 2011 06:41 GMT
#7
you could have also googled how to get rid of the scareware and you would have found out that you can start your computer in safe mode, locate the installed file and delete it from your computer, then find it on your registry, and delete its entrance as well. You wouldnt' have had to restore your computer to an earlier state assuming there was something that you would have rather not deleted. Nonetheless, I'm glad you managed to get rid of it. =]

Edit: You ninja'd me with your edit 2 posts above.
Diamond 4 Jungle/Support - http://www.twitch.tv/cr4zyh0r5e/c/3051057 Zyra support 101
Dakk
Profile Blog Joined June 2010
Sweden572 Posts
July 14 2011 06:44 GMT
#8
On July 14 2011 15:22 Z3kk wrote:
Wait, how were you able to download those two things and run then successfully if everything you opened got closed? :o

Thanks for this; good to know for future reference

He opened windows in safe mode when he restarted the PC. This prevents stuff to execute themselves somewhat and it makes you able to do stuff you otherwise cannot do.
I will not fear, Fear is the mindkiller. Fear is the little death.
Z3kk
Profile Blog Joined December 2009
4099 Posts
July 14 2011 06:45 GMT
#9
On July 14 2011 15:40 Kyuukyuu wrote:
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?


Yeah, I was like "wait a minute..." when I read that post :o
Failure is not falling down over and over again. Failure is refusing to get back up.
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
Last Edited: 2011-07-14 06:53:15
July 14 2011 06:46 GMT
#10
On July 14 2011 15:41 Cr4zyH0r5e wrote:
you could have also googled how to get rid of the scareware and you would have found out that you can start your computer in safe mode, locate the installed file and delete it from your computer, then find it on your registry, and delete its entrance as well. You wouldnt' have had to restore your computer to an earlier state assuming there was something that you would have rather not deleted. Nonetheless, I'm glad you managed to get rid of it. =]

Edit: You ninja'd me with your edit 2 posts above.


Thanks, that is actually simpler...
EDIT: if I don't have anything to lose wouldn't restoring be safer since I may not be able to completely remove everything manually?

On July 14 2011 15:40 Kyuukyuu wrote:
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?


Actually what I learnt from the post was to run in safe mode :D I just wanted to quickly solve the problem.
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
July 14 2011 06:48 GMT
#11
On July 14 2011 15:45 Z3kk wrote:
Show nested quote +
On July 14 2011 15:40 Kyuukyuu wrote:
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?


Yeah, I was like "wait a minute..." when I read that post :o


After staring and thinking for a few minutes, I suddenly recalled reading something about safe mode and hoped that it will allow me to restore my backup.




Didn't mean to mislead. I only remembered the "safe mode" part of the post.
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
MiraKul
Profile Blog Joined November 2010
Malaysia498 Posts
July 14 2011 08:44 GMT
#12
ehh bleepingcomputer.com is down? The link is dead.
ovrpwrd
FlaminGinjaNinja
Profile Blog Joined January 2011
United Kingdom879 Posts
July 14 2011 11:41 GMT
#13
On July 14 2011 15:22 Z3kk wrote:
Wait, how were you able to download those two things and run then successfully if everything you opened got closed? :o

Thanks for this; good to know for future reference


When booting in safe mode only critical drivers are loaded, the absolute minimum to still allow the PC to run. That means that no start-up programs and no specialised drivers will start. Because of this the program cloing everything that installed itself does not start and therefore can not close down the things you open.

It's important to note that if you need to download programs from the internet to solve your issue you will need to boot in safe-mode with networking, because normal safe-mode does not load the drivers nessasary to connect to a network

Also, malwarebytes rocks!
GinjaNinja.661 EU I'd like to thank my sh*t keyyboard for always messing up my 'Y's
Please log in or register to reply.
Live Events Refresh
Next event in 7h 30m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
WinterStarcraft393
RuFF_SC2 93
CosmosSc2 35
StarCraft: Brood War
Zeus 4821
Leta 178
Snow 137
Noble 27
Icarus 7
Bale 5
Dota 2
monkeys_forever631
NeuroSwarm154
League of Legends
C9.Mang0145
Nathanias24
Other Games
summit1g10641
shahzam587
JimRising 575
Organizations
Other Games
gamesdonequick1034
BasetradeTV170
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 13 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
League of Legends
• Rush765
• Lourlo722
Other Games
• Scarra959
Upcoming Events
WardiTV 2025
7h 30m
StarCraft2.fi
11h 30m
PiGosaur Monday
20h 30m
StarCraft2.fi
1d 12h
Tenacious Turtle Tussle
1d 19h
The PondCast
2 days
WardiTV 2025
2 days
StarCraft2.fi
2 days
WardiTV 2025
3 days
StarCraft2.fi
4 days
[ Show More ]
RSL Revival
4 days
IPSL
4 days
Sziky vs JDConan
RSL Revival
5 days
Classic vs TBD
herO vs Zoun
WardiTV 2025
5 days
IPSL
5 days
Tarson vs DragOn
Wardi Open
6 days
Replay Cast
6 days
Liquipedia Results

Completed

Acropolis #4 - TS3
RSL Revival: Season 3
Kuram Kup

Ongoing

IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
YSL S2
BSL Season 21
Slon Tour Season 2
WardiTV 2025
META Madness #9
SL Budapest Major 2025
ESL Impact League Season 8
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22

Upcoming

BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
Bellum Gens Elite Stara Zagora 2026
HSC XXVIII
Big Gabe Cup #3
RSL Offline Finals
PGL Cluj-Napoca 2026
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter Qual
eXTREMESLAND 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.