• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 06:03
CET 12:03
KST 20:03
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 3 - RO16 Groups C & D Preview0RSL Season 3 - RO16 Groups A & B Preview2TL.net Map Contest #21: Winners12Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13
Community News
Weekly Cups (Nov 10-16): Reynor, Solar lead Zerg surge1[TLMC] Fall/Winter 2025 Ladder Map Rotation14Weekly Cups (Nov 3-9): Clem Conquers in Canada4SC: Evo Complete - Ranked Ladder OPEN ALPHA8StarCraft, SC2, HotS, WC3, Returning to Blizzcon!45
StarCraft 2
General
[TLMC] Fall/Winter 2025 Ladder Map Rotation RotterdaM "Serral is the GOAT, and it's not close" Weekly Cups (Nov 10-16): Reynor, Solar lead Zerg surge Mech is the composition that needs teleportation t RSL Season 3 - RO16 Groups C & D Preview
Tourneys
2025 RSL Offline Finals Dates + Ticket Sales! $5,000+ WardiTV 2025 Championship RSL Revival: Season 3 Sparkling Tuna Cup - Weekly Open Tournament Constellation Cup - Main Event - Stellar Fest
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 500 Fright night Mutation # 499 Chilling Adaptation Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened
Brood War
General
FlaSh on: Biggest Problem With SnOw's Playstyle What happened to TvZ on Retro? BGH Auto Balance -> http://bghmmr.eu/ SnOw's ASL S20 Finals Review BW General Discussion
Tourneys
[BSL21] GosuLeague T1 Ro16 - Tue & Thu 22:00 CET [Megathread] Daily Proleagues Small VOD Thread 2.0 [BSL21] RO32 Group D - Sunday 21:00 CET
Strategy
Current Meta How to stay on top of macro? PvZ map balance Simple Questions, Simple Answers
Other Games
General Games
Stormgate/Frost Giant Megathread Clair Obscur - Expedition 33 Beyond All Reason Should offensive tower rushing be viable in RTS games? Path of Exile
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
Russo-Ukrainian War Thread US Politics Mega-thread The Games Industry And ATVI Things Aren’t Peaceful in Palestine About SC2SEA.COM
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
Movie Discussion! [Manga] One Piece Anime Discussion Thread Korean Music Discussion Series you have seen recently...
Sports
2024 - 2026 Football Thread Formula 1 Discussion NBA General Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Dyadica Gospel – a Pulp No…
Hildegard
Coffee x Performance in Espo…
TrAiDoS
Saturation point
Uldridge
DnB/metal remix FFO Mick Go…
ImbaTosS
Reality "theory" prov…
perfectspheres
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1952 users

Lurking in TL saved my PC

Blogs > JieXian
Post a Reply
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
Last Edited: 2011-07-14 06:43:42
July 14 2011 05:52 GMT
#1
Referring to this post, sorry if it's pure common sense to some of you but it certainly wasn't for me. I haven't encountered this ever since I was using a win95 PC. Also I hope this might be of use to someone.

I was lurking around reading posts about 1 month ago when today my father was clicking on some link he claims he does everyday from a blog to some "UK newspaper" site about "How to buy gold" <--- my spider sense detects inconsistency at this point. But no point arguing with him.

----------------------------------------------------------------------------------------------------------------------------
EDIT: Later he came back and offered to show me what he did earlier and it was a life feed link from a blog and looking legit, I clicked it (knowing how to solve the problem) and got here (just in case you're worried, it really is): http://www.telegraph.co.uk/finance/personalfinance/investing/gold/8635523/How-to-invest-in-gold.html . Showing him the article, he said he didn't see this page earlier. Based on how he spoke and knowing his .. routines, I have some confidence that that's what happened. If it's true than it's really scary.

On second thought, it could be due to some link he clicked earlier since programs take some time to finish installing. That makes more sense.
----------------------------------------------------------------------------------------------------------------------------


The program "Security protection" had all the pictures used by Win7, the firewall and the shield thing and for moment I thought it was from windows, until I saw the shortcut icon on the desktop which meant that a program was installed. Moreover I couldn't close it and any program I execute just dies after 2 seconds so I can't use the task manager to kill the process or restore it to and earlier state.

And it scanned my pc automatically and detected some win32Gen-Child-Porn which made me panic a while. This was before I saw the shortcut icon on my desktop.

So at first I tried to out maneuver it by trying to kill the process with the task manager faster than it could kill the task manager.

Didn't work.

Next, after trying to alt f4 and right click it from the task bar in vain, I went to the 'settings' tab and saw options to "Start Security Protection on startup" and "Scan PC on startup". Seeing a glimmer of hope, I pounced on both the checkboxes and promtly restarted my computer.

Only to be greeted by the the same scareware again.

After staring and thinking for a few minutes, I suddenly recalled reading something about safe mode and hoped that it will allow me to restore my backup. Sure enough, in safe mode, the "Security Protection" scareware didn't startup and neither did MsnMessenger or anything else. Without anything stopping me, I was able to restore my computer to an earlier state.

And sure it did :D

After restoring, I quickly loaded the thread I bookmarked and couldn't be more grateful.

Download Combofix ( http://www.bleepingcomputer.com/combofix/how-to-use-combofix )

Also download hijackthis ( http://free.antivirus.com/hijackthis/ )

What you want to do is boot into safe-mode and run hijackthis first, after that run combofix. Once combofix finishes its going to reboot your computer. Running both of them should do quite the trick to speed up your computer.

After that I would run malwarebytes ( http://www.malwarebytes.org/ )

I used to work at a PC repair shop and those 3 programs solved 95+% of our issues.



Thank you so very very much Halfwarr!!!!!

*****
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
Alabasern
Profile Blog Joined September 2010
United States4005 Posts
July 14 2011 06:12 GMT
#2
TeamLiquid is a splendid resource indeed.
Support your esport!
Mickey
Profile Blog Joined July 2005
United States2606 Posts
July 14 2011 06:17 GMT
#3
Combofix is an amazing utility that has saved me so many times.
Z3kk
Profile Blog Joined December 2009
4099 Posts
July 14 2011 06:22 GMT
#4
Wait, how were you able to download those two things and run then successfully if everything you opened got closed? :o

Thanks for this; good to know for future reference
Failure is not falling down over and over again. Failure is refusing to get back up.
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
Last Edited: 2011-07-14 06:40:49
July 14 2011 06:34 GMT
#5
Opps I forgot to describe the most important part. Added it to the OP

Basically when I start up in safe mode (keep mashing F8 during booting). None of the programs will launch at startup, and that includes the scareware.

So I was able to safely restore my computer to an earlier state. Program files -->Accessories --> {something about restoring backup or System restore} (currently using a Spanish interface to learn the language)

I didn't download the programs because this was easier and I didn't have any work that will be lost if I were to restore to the state it was 2 days ago. Anyways I'm going to download those 2 programs right now just in case this happens again.
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
Kyuukyuu
Profile Blog Joined January 2009
Canada6263 Posts
July 14 2011 06:40 GMT
#6
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?
Cr4zyH0r5e
Profile Blog Joined November 2007
Peru1308 Posts
Last Edited: 2011-07-14 06:42:04
July 14 2011 06:41 GMT
#7
you could have also googled how to get rid of the scareware and you would have found out that you can start your computer in safe mode, locate the installed file and delete it from your computer, then find it on your registry, and delete its entrance as well. You wouldnt' have had to restore your computer to an earlier state assuming there was something that you would have rather not deleted. Nonetheless, I'm glad you managed to get rid of it. =]

Edit: You ninja'd me with your edit 2 posts above.
Diamond 4 Jungle/Support - http://www.twitch.tv/cr4zyh0r5e/c/3051057 Zyra support 101
Dakk
Profile Blog Joined June 2010
Sweden572 Posts
July 14 2011 06:44 GMT
#8
On July 14 2011 15:22 Z3kk wrote:
Wait, how were you able to download those two things and run then successfully if everything you opened got closed? :o

Thanks for this; good to know for future reference

He opened windows in safe mode when he restarted the PC. This prevents stuff to execute themselves somewhat and it makes you able to do stuff you otherwise cannot do.
I will not fear, Fear is the mindkiller. Fear is the little death.
Z3kk
Profile Blog Joined December 2009
4099 Posts
July 14 2011 06:45 GMT
#9
On July 14 2011 15:40 Kyuukyuu wrote:
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?


Yeah, I was like "wait a minute..." when I read that post :o
Failure is not falling down over and over again. Failure is refusing to get back up.
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
Last Edited: 2011-07-14 06:53:15
July 14 2011 06:46 GMT
#10
On July 14 2011 15:41 Cr4zyH0r5e wrote:
you could have also googled how to get rid of the scareware and you would have found out that you can start your computer in safe mode, locate the installed file and delete it from your computer, then find it on your registry, and delete its entrance as well. You wouldnt' have had to restore your computer to an earlier state assuming there was something that you would have rather not deleted. Nonetheless, I'm glad you managed to get rid of it. =]

Edit: You ninja'd me with your edit 2 posts above.


Thanks, that is actually simpler...
EDIT: if I don't have anything to lose wouldn't restoring be safer since I may not be able to completely remove everything manually?

On July 14 2011 15:40 Kyuukyuu wrote:
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?


Actually what I learnt from the post was to run in safe mode :D I just wanted to quickly solve the problem.
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
July 14 2011 06:48 GMT
#11
On July 14 2011 15:45 Z3kk wrote:
Show nested quote +
On July 14 2011 15:40 Kyuukyuu wrote:
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?


Yeah, I was like "wait a minute..." when I read that post :o


After staring and thinking for a few minutes, I suddenly recalled reading something about safe mode and hoped that it will allow me to restore my backup.




Didn't mean to mislead. I only remembered the "safe mode" part of the post.
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
MiraKul
Profile Blog Joined November 2010
Malaysia498 Posts
July 14 2011 08:44 GMT
#12
ehh bleepingcomputer.com is down? The link is dead.
ovrpwrd
FlaminGinjaNinja
Profile Blog Joined January 2011
United Kingdom879 Posts
July 14 2011 11:41 GMT
#13
On July 14 2011 15:22 Z3kk wrote:
Wait, how were you able to download those two things and run then successfully if everything you opened got closed? :o

Thanks for this; good to know for future reference


When booting in safe mode only critical drivers are loaded, the absolute minimum to still allow the PC to run. That means that no start-up programs and no specialised drivers will start. Because of this the program cloing everything that installed itself does not start and therefore can not close down the things you open.

It's important to note that if you need to download programs from the internet to solve your issue you will need to boot in safe-mode with networking, because normal safe-mode does not load the drivers nessasary to connect to a network

Also, malwarebytes rocks!
GinjaNinja.661 EU I'd like to thank my sh*t keyyboard for always messing up my 'Y's
Please log in or register to reply.
Live Events Refresh
Next event in 57m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Reynor 156
SortOf 136
ProTech121
Livibee 94
StarCraft: Brood War
Calm 6580
GuemChi 2011
Stork 599
Pusan 438
BeSt 377
Larva 376
Leta 192
Zeus 189
EffOrt 155
Killer 126
[ Show more ]
Rush 70
Dewaltoss 67
hero 62
ToSsGirL 60
ZerO 52
Mind 40
Barracks 32
yabsab 31
Movie 29
Noble 10
Terrorterran 9
Icarus 1
Dota 2
XaKoH 449
Gorgc95
XcaliburYe89
Counter-Strike
olofmeister1654
shoxiejesuss661
x6flipin184
allub89
Other Games
summit1g15094
ceh9502
Fuzer 241
Pyrionflax197
crisheroes164
B2W.Neo53
NeuroSwarm39
Trikslyr36
ZerO(Twitch)7
Organizations
Dota 2
PGL Dota 2 - Main Stream11971
PGL Dota 2 - Secondary Stream2476
Other Games
gamesdonequick599
BasetradeTV34
StarCraft: Brood War
lovetv 13
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 13 non-featured ]
StarCraft 2
• Berry_CruncH175
• LUISG 27
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
League of Legends
• Stunt677
Upcoming Events
WardiTV Korean Royale
57m
BSL: GosuLeague
9h 57m
PiGosaur Cup
13h 57m
The PondCast
22h 57m
Replay Cast
1d 11h
RSL Revival
1d 22h
herO vs Zoun
Classic vs Reynor
Maru vs SHIN
MaxPax vs TriGGeR
BSL: GosuLeague
2 days
RSL Revival
2 days
WardiTV Korean Royale
3 days
RSL Revival
3 days
[ Show More ]
WardiTV Korean Royale
4 days
IPSL
4 days
Julia vs Artosis
JDConan vs DragOn
RSL Revival
4 days
Wardi Open
5 days
IPSL
5 days
StRyKeR vs OldBoy
Sziky vs Tarson
Replay Cast
5 days
Replay Cast
6 days
Liquipedia Results

Completed

Proleague 2025-11-14
Stellar Fest: Constellation Cup
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
BSL Season 21
CSCL: Masked Kings S3
SLON Tour Season 2
RSL Revival: Season 3
META Madness #9
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025

Upcoming

BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.