• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 17:50
CEST 23:50
KST 06:50
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL22] Ro8 Preview: In A Tizzy7[ASL22] Ro16 Preview: Holy Diver5[ASL22] Ro16 Preview: Rough Waters10[ASL22] Ro24 Preview: Siren's Call8[ASL22] Ro24 Preview: Summer's End9
Community News
Weekly Cups (Sep 13-20): herO scores triple1BSL Season 235Weekly Cups (Sep 7-12): SHIN, ByuN, MaxPax double down1StarCraft open world shooter announced at BlizzCon101Weekly Cups (Aug 30-Sep 7): herO thrives amid growing schism10
StarCraft 2
General
Blizzard Classic Cup @ BlizzCon 2026 - $100k prize pool The Death of Cheese: From a Professional Cheeser Weekly Cups (Sep 13-20): herO scores triple Balance hotfix patch 5.0.16b (July 16) StarCraft open world shooter announced at BlizzCon
Tourneys
2026 GSTL Announcement Sparkling Tuna Cup - Weekly Open Tournament RSL Revival: Season 6 - Qualifiers and Main Event RSL goes to London! 2026 Offline Finals Nov 21-22 SC2 AI Tournament 2026 Fall
Strategy
[H] ZvP Mid-Late Game: Stalkers Collossi HT
Custom Maps
Nexus Wars 2021 GUIDE [M] (2) Industrial Park
External Content
Mutation # 544 Double Trouble The PondCast: SC2 News & Results Mutation # 543 Enhanced Defenses Mutation # 542 The Ascended
Brood War
General
Bot on ladder New 3v3 BGH Ladder (and more) on ShieldBattery! [ASL22] Ro8 Preview: In A Tizzy an AI researcher's take on the ladder bot Recent recommended BW games
Tourneys
[ASL22] Ro8 Day 1 [IPSL] IPSL is Back With Winter 26-27! [BSL23] SM: Ret vs TerrOr -> DragOn vs StRyKeR [Megathread] Daily Proleagues
Strategy
Cliff Jump Revisited (1 in a 1000 strategy) Replay Review Process - What do you do? Simple Questions, Simple Answers Odyssey Mineral Stack Saturation
Other Games
General Games
Warcraft III: The Frozen Throne Nintendo Switch Thread Stormgate/Frost Giant Megathread EVE Corporation Diablo IV
Dota 2
Dota 2 Champions League Season 3 Begins April 25! Official 'what is Dota anymore' discussion
League of Legends
[TL LoL EUW IHs] Teemo shall perish
Heroes of the Storm
Heroes of the Storm 2.0
Hearthstone
Deck construction bug
TL Mafia
TL Mafia Community Thread
Community
General
US Politics Mega-thread Artificial Intelligence Thread Things Aren’t Peaceful in Palestine All you football fans (soccer)! Russo-Ukrainian War Thread
Fan Clubs
MarineLorD Fan Club The Creator Fan Club The ShoWTimE Fan Club
Media & Entertainment
Movie Discussion! [Manga] One Piece Diablo Animated Series on Netflix
Sports
Football (Soccer) Thread TeamLiquid Health and Fitness Initiative For 2023 MLB/Baseball 2023
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
Recent Gifted Posts
Blogs
Gaming Intensity, Problemati…
TrAiDoS
38 yo Retired SWE loo…
PurE)Rabbit-SF
Can Bots Beat Pros?? Starcr…
namkraft
[meme] I finally understa…
LUCKY_NOOB
Regacy Esports:Our Goa…
regacyesports
Dreaming of BW patches (mod…
c3rberUs
Customize Sidebar...

Website Feedback

Closed Threads



Active: 8098 users

Computer got hacked, help pl0x! - Page 2

Blogs > TuElite
Post a Reply
Prev 1 2 3 Next All
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
August 05 2011 15:47 GMT
#21
On August 06 2011 00:36 Darkdeath3 wrote:
Have you tried the system resotore or can u still not start any programs?


Just tried System Restore.

Same as any other program, can't access it.
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
mucker
Profile Blog Joined May 2009
United States1120 Posts
August 05 2011 15:50 GMT
#22
Try using the exe association fix from here
It's supposed to be automatic but actually you have to press this button.
iamperfection
Profile Blog Joined February 2011
United States9648 Posts
August 05 2011 15:51 GMT
#23
Microsoft has an article to this problem and links to this page to solve it.
http://www.bleepingcomputer.com/virus-removal/remove-win-7-antispyware-2012
http://www.teamliquid.net/forum/viewmessage.php?topic_id=406168&currentpage=78#1551
Marcus420
Profile Joined January 2011
Canada1923 Posts
Last Edited: 2011-08-05 15:56:17
August 05 2011 15:53 GMT
#24
On August 06 2011 00:47 TuElite wrote:
Show nested quote +
On August 06 2011 00:36 Darkdeath3 wrote:
Have you tried the system resotore or can u still not start any programs?


Just tried System Restore.

Same as any other program, can't access it.

you can boot off the installation dvd, and choose the “Repair your computer” option on the lower left hand side. If you don’t have an installation/repair disc, you can make one with these instructions. http://www.howtogeek.com/howto/windows-vista/how-to-make-a-windows-vista-repair-disk-if-you-dont-have-one/

Click next on the next screen, and then choose System Restore from the System Recovery dialog. It will take a few seconds to come up, and you will see the same screen that you would see in windows.

Click next, and on the next screen select the drive that your copy of Windows 7 or Vista is installed on.

Click Finish, and Windows will roll back to the previous restore point. Really pretty simple stuff.
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
Last Edited: 2011-08-05 16:09:47
August 05 2011 16:02 GMT
#25
GOOD NEWS UPON ME

By using Task Manager and holding CTRL + File(Run) I managed to access the DOS or whatever (the black screen where u can get shit done). I can now access regedit and the registry from there.

Now I'm going to try and delete the following files in the registry
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'


As well as these files

%AllUsersProfile%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\ppn.exe %Temp%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\U3F7PNVFNCSJK2E86ABFBJ5H %AppData%\TEMPLATES\U3F7PNVFNCSJK2E86ABFBJ5H

And that should get rid of the virus....

Hoppefully my .exe files comeback after that too but I have a feeling that I'll need to do more shit...
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
h3r1n6
Profile Blog Joined September 2007
Iceland2039 Posts
August 05 2011 16:17 GMT
#26
On August 06 2011 01:02 TuElite wrote:
GOOD NEWS UPON ME

By using Task Manager and holding CTRL + File(Run) I managed to access the DOS or whatever (the black screen where u can get shit done). I can now access regedit and the registry from there.

Now I'm going to try and delete the following files in the registry
Show nested quote +
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'


As well as these files

%AllUsersProfile%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\ppn.exe %Temp%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\U3F7PNVFNCSJK2E86ABFBJ5H %AppData%\TEMPLATES\U3F7PNVFNCSJK2E86ABFBJ5H

And that should get rid of the virus....

Hoppefully my .exe files comeback after that too but I have a feeling that I'll need to do more shit...



On August 06 2011 00:27 h3r1n6 wrote:
Try a rescue cd, most anti virus companies have them. I suggest the Kaspersky rescue disk.



Just try a rescue disk, way easier and more efficient.
Wordpad
Profile Blog Joined November 2010
Denmark154 Posts
Last Edited: 2011-08-05 16:38:14
August 05 2011 16:34 GMT
#27
My best advice is to re-install Windows. This type of Malware is designed to be profitable at the expense of the victim, and trust me when I say the creators are relentless. Whether that means tricking you to pay for their crap, or stealing credit card information. Due to that fact, and the nature of how operating systems function (you can never be 100% sure the given malware is completely removed if it has root-kit functionalities), I will personally always recommend a reinstall.
enigmaticcam
Profile Blog Joined October 2010
United States280 Posts
Last Edited: 2011-08-05 16:40:35
August 05 2011 16:40 GMT
#28
On August 06 2011 00:50 mucker wrote:
Try using the exe association fix from here

This is your answer.

I had this exact same virus on my machine just a couple months ago. Ended up accidentally removing the association to exe files in an attempt to get rid of it. I did a google search and found the reg keys you can download to re-associate exe files.

You don't need to reinstall windows.
ZeromuS
Profile Blog Joined October 2010
Canada13422 Posts
August 05 2011 16:56 GMT
#29
Ive only ever gotten rid of this by reinstalling windows.
StrategyRTS forever | @ZeromuS_plays | www.twitch.tv/Zeromus_
Frigo
Profile Joined August 2009
Hungary1023 Posts
August 05 2011 17:18 GMT
#30
Try with full path, c:\windows\system32\regedit.exe?
http://www.fimfiction.net/user/Treasure_Chest
Probe1
Profile Blog Joined August 2010
United States17920 Posts
August 05 2011 17:19 GMT
#31
After it's done you might want to think about buying a backup external drive. After years of clicking on stupid things I learned it's best ot just reformat and start fresh with my media secured on a unconnected drive

Sorry.
우정호 KT_VIOLET 1988 - 2012 While we are postponing, life speeds by
Dance.
Profile Blog Joined July 2010
United States389 Posts
August 05 2011 18:19 GMT
#32
Anyone who uses "pl0x" any where other than 4chan deserves to be hacked.
It is what it is...
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-05 22:55:17
August 05 2011 22:54 GMT
#33
I would use the association fix now, and then run combofix (transfer from USB to desktop) to get rid of the virus.

What are rescue disks? I might make one soon. Also, this thread should be under tech support, you'd get less replies but better replies there.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
h3r1n6
Profile Blog Joined September 2007
Iceland2039 Posts
August 05 2011 23:07 GMT
#34
On August 06 2011 07:54 obesechicken13 wrote:
I would use the association fix now, and then run combofix (transfer from USB to desktop) to get rid of the virus.

What are rescue disks? I might make one soon. Also, this thread should be under tech support, you'd get less replies but better replies there.


A bootable cd image, that will scan and remove infections from your pc. So it's basically an anti virus that you can run without booting your os Trying to disinfect a pc by booting it first and then trying to remove the infection is a losing battle.
Sad[Panda]
Profile Blog Joined January 2009
United States458 Posts
August 05 2011 23:20 GMT
#35
I got rid of this for a friend recently I just used SuperAntiSpyware's Mobile version its named differently so the virus doesn't block the EXE of it. gl I would just follow the bleepingcomputers link others have posted its what I used as a reference also
( O.O) ("\(t.t )/") ~ I'm just looking for someone to hug
iSometric
Profile Blog Joined February 2011
2221 Posts
Last Edited: 2011-08-05 23:36:40
August 05 2011 23:36 GMT
#36
Not to derail the thread (idk how to make my own thread) but, I have a similar problem where I can't open FB/Youtube sometimes. I think its a virus and its like sometimes I can access certain websties and sometimes I can't. (internet works for e.g. yahoo.com though) PM me if u can help!
strava.com/athletes/zhaodynasty
Kipsate
Profile Blog Joined July 2010
Netherlands45349 Posts
August 05 2011 23:41 GMT
#37
Well fuck your KARA collection better not be in danger.

Good luck!

Also, perhaps you should make a seperate thread in the Tech Support section?There are some really smart guys there too who don't read blogs.
WriterXiao8~~
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-06 01:48:23
August 06 2011 01:36 GMT
#38
On August 06 2011 08:36 iSometric wrote:
Not to derail the thread (idk how to make my own thread) but, I have a similar problem where I can't open FB/Youtube sometimes. I think its a virus and its like sometimes I can access certain websties and sometimes I can't. (internet works for e.g. yahoo.com though) PM me if u can help!

Make a new thread. If you speak binary, post it in tech support.

Otherwise post it in blogs or say "use a code to english translator" before hitting post.

Derailing a thread only serves to lose focus on the original intention.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
Last Edited: 2011-08-06 03:22:49
August 06 2011 03:22 GMT
#39
On August 06 2011 08:41 Kipsate wrote:
Well fuck your KARA collection better not be in danger.

Good luck!

Also, perhaps you should make a seperate thread in the Tech Support section?There are some really smart guys there too who don't read blogs.


Number 1 reason why I didn't just reinstall obv obv.

I haven't tried to fix my registry yet, I will try tomorrow morning and if I can't get it to work I'll consider posting in Tech Support (lol did not even know that section existed). Thanks!

And then I'm backing up the collection on external hard drive. This work of art must be preserved.
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
mizU
Profile Blog Joined April 2010
United States12125 Posts
August 06 2011 21:58 GMT
#40
You didn't get hacked, you just got malware.

Try to get a better anti-virus/malware so it doesn't happen again.

There's almost never a need to re-install windows, or run msconfig, cuz if you don't know what you're doing you can EFF up big time.

Regedit is pretty confusing, but once you get down the file tree and layout as well as the data entry, you should be fine. Make sure you only change what you need to, cuz if you mess certain things up... gg. Just follow the guide on the site you got and it should be fine.

Regedit should help you take care of most of the virus triggers, but make sure you search your C drive for hidden folders or newly created files+folders. (Sort by date modified)
Also use MalwareBytes to makes sure everything is gone.

GL!
if happy ever afters did exist <3 @watamizu_
Prev 1 2 3 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 12h 10m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
SpeCial 64
EnDerr 11
StarCraft: Brood War
firebathero 77
910 25
yabsab 15
Dota 2
monkeys_forever307
capcasts66
Counter-Strike
pashabiceps1381
Super Smash Bros
PPMD17
Heroes of the Storm
Liquid`Hasu579
Other Games
summit1g6767
Liquid`RaSZi3909
Grubby3772
FrodaN1634
JimRising 366
B2W.Neo266
ToD226
shahzam202
C9.Mang0152
ZombieGrub144
Mew2King72
Trikslyr70
SteadfastSC60
Organizations
Other Games
BasetradeTV58
[ Show 15 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• Migwel
StarCraft: Brood War
• Eskiya23 41
• FirePhoenix13
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• masondota22156
League of Legends
• TFBlade942
• Scarra889
Other Games
• imaqtpie683
• Shiphtur173
Upcoming Events
Sparkling Tuna Cup
12h 10m
Afreeca Starleague
12h 10m
Light vs EffOrt
OSC
14h 10m
PiGosaur Cup
1d 2h
Kung Fu Cup
1d 13h
The PondCast
2 days
Replay Cast
3 days
Korean StarCraft League
4 days
CranKy Ducklings
4 days
GSL
5 days
[ Show More ]
Yamato Cup
5 days
Replay Cast
6 days
Afreeca Starleague
6 days
WardiTV Weekly
6 days
Liquipedia Results

Completed

Super Anchor Qualifying S3
Blizzard Classic Cup 2026
Big Dog Cup 2026 Div 1

Ongoing

ASL Season 22
CSL 2026 AUTUMN (S22)
Acropolis #5
Acropolis #5 - GSA
Calamity Invitational
Logitech G Play Connect 2026
SL StarSeries Fall 2026
FISSURE Playground #3
BLAST Open Fall 2026
Esports World Cup 2026
BLAST Bounty Summer 2026
BLAST Bounty Summer Qual
Stake Ranked Episode 3
XSE Pro League 2026

Upcoming

Acropolis #5 - GSB
Acropolis #5 - GSC
BSL Season 23
SC4ALL II: Brood War
BSL 23: Non-Korean Championship
HSC XXX
Stellar Fest 2: Lunar Cup
SC4ALL II: StarCraft II
Kung Fu Cup 2026 Grand Finals
RSL Offline Finals
Copium Cup
PGL Major Singapore 2026
Stake Ranked Episode 6
BLAST Rivals Fall 2026
IEM Beijing 2026
Stake Ranked Episode 5
PGL Masters Bucharest 2026
1win Private Club #2
Thunderpick World Champ. '26
ESL Pro League Season 24
Stake Ranked Episode 4
1win Private Club #1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.