• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 21:08
CEST 03:08
KST 10:08
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
BGE Stara Zagora 2025: Info & Preview27Code S RO12 Preview: GuMiho, Bunny, SHIN, ByuN3The Memories We Share - Facing the Final(?) GSL47Code S RO12 Preview: Cure, Zoun, Solar, Creator4[ASL19] Finals Preview: Daunting Task30
Community News
Weekly Cups (June 2-8): herO doubles down1[BSL20] ProLeague: Bracket Stage & Dates9GSL Ro4 and Finals moved to Sunday June 15th13Weekly Cups (May 27-June 1): ByuN goes back-to-back0EWC 2025 Regional Qualifier Results26
StarCraft 2
General
Jim claims he and Firefly were involved in match-fixing The SCII GOAT: A statistical Evaluation RECLAIM YOUR SCAMMED CRYPTOCURRENCY WITH SLAYER CO Best Crypto Asset Recovery Service Providers CN community: Firefly accused of suspicious activities
Tourneys
Bellum Gens Elite: Stara Zagora 2025 $3,500 WardiTV European League 2025 Sparkling Tuna Cup - Weekly Open Tournament SOOPer7s Showmatches 2025 Master Swan Open (Global Bronze-Master 2)
Strategy
[G] Darkgrid Layout Simple Questions Simple Answers [G] PvT Cheese: 13 Gate Proxy Robo
Custom Maps
[UMS] Zillion Zerglings
External Content
Mutation # 477 Slow and Steady Mutation # 476 Charnel House Mutation # 475 Hard Target Mutation # 474 Futile Resistance
Brood War
General
StarCraft & BroodWar Campaign Speedrun Quest BGH auto balance -> http://bghmmr.eu/ Will foreigners ever be able to challenge Koreans? Mihu vs Korea Players Statistics BW General Discussion
Tourneys
[ASL19] Grand Finals NA Team League 6/8/2025 [Megathread] Daily Proleagues [BSL20] ProLeague Bracket Stage - Day 2
Strategy
I am doing this better than progamers do. [G] How to get started on ladder as a new Z player
Other Games
General Games
Stormgate/Frost Giant Megathread What do you want from future RTS games? Armies of Exigo - YesYes? Nintendo Switch Thread Path of Exile
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
LiquidLegends to reintegrate into TL.net
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread Vape Nation Thread European Politico-economics QA Mega-thread
Fan Clubs
Maru Fan Club Serral Fan Club
Media & Entertainment
Korean Music Discussion [Manga] One Piece
Sports
2024 - 2025 Football Thread Formula 1 Discussion NHL Playoffs 2024
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Cognitive styles x game perf…
TrAiDoS
StarCraft improvement
iopq
Heero Yuy & the Tax…
KrillinFromwales
I was completely wrong ab…
jameswatts
Need Your Help/Advice
Glider
Trip to the Zoo
micronesia
Poker
Nebuchad
Customize Sidebar...

Website Feedback

Closed Threads



Active: 22084 users

Lurking in TL saved my PC

Blogs > JieXian
Post a Reply
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
Last Edited: 2011-07-14 06:43:42
July 14 2011 05:52 GMT
#1
Referring to this post, sorry if it's pure common sense to some of you but it certainly wasn't for me. I haven't encountered this ever since I was using a win95 PC. Also I hope this might be of use to someone.

I was lurking around reading posts about 1 month ago when today my father was clicking on some link he claims he does everyday from a blog to some "UK newspaper" site about "How to buy gold" <--- my spider sense detects inconsistency at this point. But no point arguing with him.

----------------------------------------------------------------------------------------------------------------------------
EDIT: Later he came back and offered to show me what he did earlier and it was a life feed link from a blog and looking legit, I clicked it (knowing how to solve the problem) and got here (just in case you're worried, it really is): http://www.telegraph.co.uk/finance/personalfinance/investing/gold/8635523/How-to-invest-in-gold.html . Showing him the article, he said he didn't see this page earlier. Based on how he spoke and knowing his .. routines, I have some confidence that that's what happened. If it's true than it's really scary.

On second thought, it could be due to some link he clicked earlier since programs take some time to finish installing. That makes more sense.
----------------------------------------------------------------------------------------------------------------------------


The program "Security protection" had all the pictures used by Win7, the firewall and the shield thing and for moment I thought it was from windows, until I saw the shortcut icon on the desktop which meant that a program was installed. Moreover I couldn't close it and any program I execute just dies after 2 seconds so I can't use the task manager to kill the process or restore it to and earlier state.

And it scanned my pc automatically and detected some win32Gen-Child-Porn which made me panic a while. This was before I saw the shortcut icon on my desktop.

So at first I tried to out maneuver it by trying to kill the process with the task manager faster than it could kill the task manager.

Didn't work.

Next, after trying to alt f4 and right click it from the task bar in vain, I went to the 'settings' tab and saw options to "Start Security Protection on startup" and "Scan PC on startup". Seeing a glimmer of hope, I pounced on both the checkboxes and promtly restarted my computer.

Only to be greeted by the the same scareware again.

After staring and thinking for a few minutes, I suddenly recalled reading something about safe mode and hoped that it will allow me to restore my backup. Sure enough, in safe mode, the "Security Protection" scareware didn't startup and neither did MsnMessenger or anything else. Without anything stopping me, I was able to restore my computer to an earlier state.

And sure it did :D

After restoring, I quickly loaded the thread I bookmarked and couldn't be more grateful.

Download Combofix ( http://www.bleepingcomputer.com/combofix/how-to-use-combofix )

Also download hijackthis ( http://free.antivirus.com/hijackthis/ )

What you want to do is boot into safe-mode and run hijackthis first, after that run combofix. Once combofix finishes its going to reboot your computer. Running both of them should do quite the trick to speed up your computer.

After that I would run malwarebytes ( http://www.malwarebytes.org/ )

I used to work at a PC repair shop and those 3 programs solved 95+% of our issues.



Thank you so very very much Halfwarr!!!!!

*****
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
Alabasern
Profile Blog Joined September 2010
United States4005 Posts
July 14 2011 06:12 GMT
#2
TeamLiquid is a splendid resource indeed.
Support your esport!
Mickey
Profile Blog Joined July 2005
United States2606 Posts
July 14 2011 06:17 GMT
#3
Combofix is an amazing utility that has saved me so many times.
Z3kk
Profile Blog Joined December 2009
4099 Posts
July 14 2011 06:22 GMT
#4
Wait, how were you able to download those two things and run then successfully if everything you opened got closed? :o

Thanks for this; good to know for future reference
Failure is not falling down over and over again. Failure is refusing to get back up.
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
Last Edited: 2011-07-14 06:40:49
July 14 2011 06:34 GMT
#5
Opps I forgot to describe the most important part. Added it to the OP

Basically when I start up in safe mode (keep mashing F8 during booting). None of the programs will launch at startup, and that includes the scareware.

So I was able to safely restore my computer to an earlier state. Program files -->Accessories --> {something about restoring backup or System restore} (currently using a Spanish interface to learn the language)

I didn't download the programs because this was easier and I didn't have any work that will be lost if I were to restore to the state it was 2 days ago. Anyways I'm going to download those 2 programs right now just in case this happens again.
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
Kyuukyuu
Profile Blog Joined January 2009
Canada6263 Posts
July 14 2011 06:40 GMT
#6
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?
Cr4zyH0r5e
Profile Blog Joined November 2007
Peru1308 Posts
Last Edited: 2011-07-14 06:42:04
July 14 2011 06:41 GMT
#7
you could have also googled how to get rid of the scareware and you would have found out that you can start your computer in safe mode, locate the installed file and delete it from your computer, then find it on your registry, and delete its entrance as well. You wouldnt' have had to restore your computer to an earlier state assuming there was something that you would have rather not deleted. Nonetheless, I'm glad you managed to get rid of it. =]

Edit: You ninja'd me with your edit 2 posts above.
Diamond 4 Jungle/Support - http://www.twitch.tv/cr4zyh0r5e/c/3051057 Zyra support 101
Dakk
Profile Blog Joined June 2010
Sweden572 Posts
July 14 2011 06:44 GMT
#8
On July 14 2011 15:22 Z3kk wrote:
Wait, how were you able to download those two things and run then successfully if everything you opened got closed? :o

Thanks for this; good to know for future reference

He opened windows in safe mode when he restarted the PC. This prevents stuff to execute themselves somewhat and it makes you able to do stuff you otherwise cannot do.
I will not fear, Fear is the mindkiller. Fear is the little death.
Z3kk
Profile Blog Joined December 2009
4099 Posts
July 14 2011 06:45 GMT
#9
On July 14 2011 15:40 Kyuukyuu wrote:
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?


Yeah, I was like "wait a minute..." when I read that post :o
Failure is not falling down over and over again. Failure is refusing to get back up.
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
Last Edited: 2011-07-14 06:53:15
July 14 2011 06:46 GMT
#10
On July 14 2011 15:41 Cr4zyH0r5e wrote:
you could have also googled how to get rid of the scareware and you would have found out that you can start your computer in safe mode, locate the installed file and delete it from your computer, then find it on your registry, and delete its entrance as well. You wouldnt' have had to restore your computer to an earlier state assuming there was something that you would have rather not deleted. Nonetheless, I'm glad you managed to get rid of it. =]

Edit: You ninja'd me with your edit 2 posts above.


Thanks, that is actually simpler...
EDIT: if I don't have anything to lose wouldn't restoring be safer since I may not be able to completely remove everything manually?

On July 14 2011 15:40 Kyuukyuu wrote:
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?


Actually what I learnt from the post was to run in safe mode :D I just wanted to quickly solve the problem.
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
JieXian
Profile Blog Joined August 2008
Malaysia4677 Posts
July 14 2011 06:48 GMT
#11
On July 14 2011 15:45 Z3kk wrote:
Show nested quote +
On July 14 2011 15:40 Kyuukyuu wrote:
Wait so you just system restored and didn't actually use the things in the post you quoted o_O?


Yeah, I was like "wait a minute..." when I read that post :o


After staring and thinking for a few minutes, I suddenly recalled reading something about safe mode and hoped that it will allow me to restore my backup.




Didn't mean to mislead. I only remembered the "safe mode" part of the post.
Please send me a PM of any song you like that I most probably never heard of! I am looking for people to chat about writing and producing music | https://www.youtube.com/watch?v=noD-bsOcxuU |
MiraKul
Profile Blog Joined November 2010
Malaysia498 Posts
July 14 2011 08:44 GMT
#12
ehh bleepingcomputer.com is down? The link is dead.
ovrpwrd
FlaminGinjaNinja
Profile Blog Joined January 2011
United Kingdom879 Posts
July 14 2011 11:41 GMT
#13
On July 14 2011 15:22 Z3kk wrote:
Wait, how were you able to download those two things and run then successfully if everything you opened got closed? :o

Thanks for this; good to know for future reference


When booting in safe mode only critical drivers are loaded, the absolute minimum to still allow the PC to run. That means that no start-up programs and no specialised drivers will start. Because of this the program cloing everything that installed itself does not start and therefore can not close down the things you open.

It's important to note that if you need to download programs from the internet to solve your issue you will need to boot in safe-mode with networking, because normal safe-mode does not load the drivers nessasary to connect to a network

Also, malwarebytes rocks!
GinjaNinja.661 EU I'd like to thank my sh*t keyyboard for always messing up my 'Y's
Please log in or register to reply.
Live Events Refresh
Replay Cast
00:00
2025 KFC #10: SC Evolution
CranKy Ducklings129
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
PiGStarcraft433
Nina 137
Livibee 89
-ZergGirl 44
Ketroc 24
StarCraft: Brood War
Horang2 1054
Artosis 786
NaDa 6
Icarus 4
Dota 2
monkeys_forever503
NeuroSwarm65
Counter-Strike
Stewie2K1111
Super Smash Bros
Mew2King60
Other Games
summit1g9857
shahzam1654
JimRising 355
Maynarde118
RuFF_SC215
Organizations
Other Games
gamesdonequick851
BasetradeTV81
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 17 non-featured ]
StarCraft 2
• Berry_CruncH91
• davetesta19
• Mapu4
• Kozan
• AfreecaTV YouTube
• intothetv
• sooper7s
• IndyKCrew
• LaughNgamezSOOP
• Migwel
StarCraft: Brood War
• RayReign 31
• Azhi_Dahaki29
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
League of Legends
• Doublelift5439
Other Games
• Scarra1157
Upcoming Events
Replay Cast
8h 52m
WardiTV Invitational
9h 52m
WardiTV Invitational
9h 52m
PiGosaur Monday
22h 52m
GSL Code S
1d 8h
Rogue vs GuMiho
Maru vs Solar
Online Event
1d 22h
Replay Cast
2 days
GSL Code S
2 days
herO vs Zoun
Classic vs Bunny
The PondCast
2 days
Replay Cast
2 days
[ Show More ]
WardiTV Invitational
3 days
OSC
3 days
Korean StarCraft League
4 days
CranKy Ducklings
4 days
WardiTV Invitational
4 days
Cheesadelphia
4 days
GSL Code S
5 days
Sparkling Tuna Cup
5 days
Replay Cast
5 days
Replay Cast
6 days
Liquipedia Results

Completed

CSL Season 17: Qualifier 2
BGE Stara Zagora 2025
Heroes 10 EU

Ongoing

JPL Season 2
BSL 2v2 Season 3
BSL Season 20
KCM Race Survival 2025 Season 2
NPSL S3
Rose Open S1
CSL 17: 2025 SUMMER
2025 GSL S2
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
PGL Astana 2025
Asian Champions League '25
BLAST Rivals Spring 2025
MESA Nomadic Masters
CCT Season 2 Global Finals
IEM Melbourne 2025
YaLLa Compass Qatar 2025
PGL Bucharest 2025
BLAST Open Spring 2025

Upcoming

Copa Latinoamericana 4
CSLPRO Last Chance 2025
CSLPRO Chat StarLAN 3
K-Championship
SEL Season 2 Championship
Esports World Cup 2025
HSC XXVII
Championship of Russia 2025
Murky Cup #2
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.