• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 21:40
CET 03:40
KST 11:40
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
ByuL: The Forgotten Master of ZvT28Behind the Blue - Team Liquid History Book19Clem wins HomeStory Cup 289HomeStory Cup 28 - Info & Preview13Rongyi Cup S3 - Preview & Info8
Community News
Weekly Cups (Feb 16-22): MaxPax doubles0Weekly Cups (Feb 9-15): herO doubles up2ACS replaced by "ASL Season Open" - Starts 21/0243LiuLi Cup: 2025 Grand Finals (Feb 10-16)46Weekly Cups (Feb 2-8): Classic, Solar, MaxPax win2
StarCraft 2
General
ByuL: The Forgotten Master of ZvT How do you think the 5.0.15 balance patch (Oct 2025) for StarCraft II has affected the game? Oliveira Would Have Returned If EWC Continued Behind the Blue - Team Liquid History Book Weekly Cups (Feb 16-22): MaxPax doubles
Tourneys
StarCraft Evolution League (SC Evo Biweekly) Sea Duckling Open (Global, Bronze-Diamond) PIG STY FESTIVAL 7.0! (19 Feb - 1 Mar) Sparkling Tuna Cup - Weekly Open Tournament How do the "codes" work in GSL?
Strategy
Custom Maps
Map Editor closed ? [A] Starcraft Sound Mod
External Content
Mutation # 514 Ulnar New Year The PondCast: SC2 News & Results Mutation # 513 Attrition Warfare Mutation # 512 Overclocked
Brood War
General
BGH Auto Balance -> http://bghmmr.eu/ ACS replaced by "ASL Season Open" - Starts 21/02 TvZ is the most complete match up CasterMuse Youtube A cwal.gg Extension - Easily keep track of anyone
Tourneys
Escore Tournament StarCraft Season 1 [Megathread] Daily Proleagues [LIVE] [S:21] ASL Season Open Day 1 Small VOD Thread 2.0
Strategy
Fighting Spirit mining rates Simple Questions, Simple Answers Zealot bombing is no longer popular? Current Meta
Other Games
General Games
Path of Exile Nintendo Switch Thread Beyond All Reason Battle Aces/David Kim RTS Megathread New broswer game : STG-World
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia Mafia Game Mode Feedback/Ideas TL Mafia Community Thread
Community
General
US Politics Mega-thread Canadian Politics Mega-thread Mexico's Drug War Russo-Ukrainian War Thread Ask and answer stupid questions here!
Fan Clubs
The IdrA Fan Club The herO Fan Club!
Media & Entertainment
[Req][Books] Good Fantasy/SciFi books [Manga] One Piece Anime Discussion Thread
Sports
2024 - 2026 Football Thread Formula 1 Discussion TL MMA Pick'em Pool 2013
World Cup 2022
Tech Support
TL Community
The Automated Ban List
Blogs
ASL S21 English Commentary…
namkraft
Inside the Communication of …
TrAiDoS
My 2025 Magic: The Gathering…
DARKING
Life Update and thoughts.
FuDDx
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1495 users

Computer got hacked, help pl0x! - Page 2

Blogs > TuElite
Post a Reply
Prev 1 2 3 Next All
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
August 05 2011 15:47 GMT
#21
On August 06 2011 00:36 Darkdeath3 wrote:
Have you tried the system resotore or can u still not start any programs?


Just tried System Restore.

Same as any other program, can't access it.
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
mucker
Profile Blog Joined May 2009
United States1120 Posts
August 05 2011 15:50 GMT
#22
Try using the exe association fix from here
It's supposed to be automatic but actually you have to press this button.
iamperfection
Profile Blog Joined February 2011
United States9645 Posts
August 05 2011 15:51 GMT
#23
Microsoft has an article to this problem and links to this page to solve it.
http://www.bleepingcomputer.com/virus-removal/remove-win-7-antispyware-2012
http://www.teamliquid.net/forum/viewmessage.php?topic_id=406168&currentpage=78#1551
Marcus420
Profile Joined January 2011
Canada1923 Posts
Last Edited: 2011-08-05 15:56:17
August 05 2011 15:53 GMT
#24
On August 06 2011 00:47 TuElite wrote:
Show nested quote +
On August 06 2011 00:36 Darkdeath3 wrote:
Have you tried the system resotore or can u still not start any programs?


Just tried System Restore.

Same as any other program, can't access it.

you can boot off the installation dvd, and choose the “Repair your computer” option on the lower left hand side. If you don’t have an installation/repair disc, you can make one with these instructions. http://www.howtogeek.com/howto/windows-vista/how-to-make-a-windows-vista-repair-disk-if-you-dont-have-one/

Click next on the next screen, and then choose System Restore from the System Recovery dialog. It will take a few seconds to come up, and you will see the same screen that you would see in windows.

Click next, and on the next screen select the drive that your copy of Windows 7 or Vista is installed on.

Click Finish, and Windows will roll back to the previous restore point. Really pretty simple stuff.
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
Last Edited: 2011-08-05 16:09:47
August 05 2011 16:02 GMT
#25
GOOD NEWS UPON ME

By using Task Manager and holding CTRL + File(Run) I managed to access the DOS or whatever (the black screen where u can get shit done). I can now access regedit and the registry from there.

Now I'm going to try and delete the following files in the registry
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'


As well as these files

%AllUsersProfile%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\ppn.exe %Temp%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\U3F7PNVFNCSJK2E86ABFBJ5H %AppData%\TEMPLATES\U3F7PNVFNCSJK2E86ABFBJ5H

And that should get rid of the virus....

Hoppefully my .exe files comeback after that too but I have a feeling that I'll need to do more shit...
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
h3r1n6
Profile Blog Joined September 2007
Iceland2039 Posts
August 05 2011 16:17 GMT
#26
On August 06 2011 01:02 TuElite wrote:
GOOD NEWS UPON ME

By using Task Manager and holding CTRL + File(Run) I managed to access the DOS or whatever (the black screen where u can get shit done). I can now access regedit and the registry from there.

Now I'm going to try and delete the following files in the registry
Show nested quote +
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'


As well as these files

%AllUsersProfile%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\ppn.exe %Temp%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\U3F7PNVFNCSJK2E86ABFBJ5H %AppData%\TEMPLATES\U3F7PNVFNCSJK2E86ABFBJ5H

And that should get rid of the virus....

Hoppefully my .exe files comeback after that too but I have a feeling that I'll need to do more shit...



On August 06 2011 00:27 h3r1n6 wrote:
Try a rescue cd, most anti virus companies have them. I suggest the Kaspersky rescue disk.



Just try a rescue disk, way easier and more efficient.
Wordpad
Profile Blog Joined November 2010
Denmark154 Posts
Last Edited: 2011-08-05 16:38:14
August 05 2011 16:34 GMT
#27
My best advice is to re-install Windows. This type of Malware is designed to be profitable at the expense of the victim, and trust me when I say the creators are relentless. Whether that means tricking you to pay for their crap, or stealing credit card information. Due to that fact, and the nature of how operating systems function (you can never be 100% sure the given malware is completely removed if it has root-kit functionalities), I will personally always recommend a reinstall.
enigmaticcam
Profile Blog Joined October 2010
United States280 Posts
Last Edited: 2011-08-05 16:40:35
August 05 2011 16:40 GMT
#28
On August 06 2011 00:50 mucker wrote:
Try using the exe association fix from here

This is your answer.

I had this exact same virus on my machine just a couple months ago. Ended up accidentally removing the association to exe files in an attempt to get rid of it. I did a google search and found the reg keys you can download to re-associate exe files.

You don't need to reinstall windows.
ZeromuS
Profile Blog Joined October 2010
Canada13401 Posts
August 05 2011 16:56 GMT
#29
Ive only ever gotten rid of this by reinstalling windows.
StrategyRTS forever | @ZeromuS_plays | www.twitch.tv/Zeromus_
Frigo
Profile Joined August 2009
Hungary1023 Posts
August 05 2011 17:18 GMT
#30
Try with full path, c:\windows\system32\regedit.exe?
http://www.fimfiction.net/user/Treasure_Chest
Probe1
Profile Blog Joined August 2010
United States17920 Posts
August 05 2011 17:19 GMT
#31
After it's done you might want to think about buying a backup external drive. After years of clicking on stupid things I learned it's best ot just reformat and start fresh with my media secured on a unconnected drive

Sorry.
우정호 KT_VIOLET 1988 - 2012 While we are postponing, life speeds by
Dance.
Profile Blog Joined July 2010
United States389 Posts
August 05 2011 18:19 GMT
#32
Anyone who uses "pl0x" any where other than 4chan deserves to be hacked.
It is what it is...
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-05 22:55:17
August 05 2011 22:54 GMT
#33
I would use the association fix now, and then run combofix (transfer from USB to desktop) to get rid of the virus.

What are rescue disks? I might make one soon. Also, this thread should be under tech support, you'd get less replies but better replies there.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
h3r1n6
Profile Blog Joined September 2007
Iceland2039 Posts
August 05 2011 23:07 GMT
#34
On August 06 2011 07:54 obesechicken13 wrote:
I would use the association fix now, and then run combofix (transfer from USB to desktop) to get rid of the virus.

What are rescue disks? I might make one soon. Also, this thread should be under tech support, you'd get less replies but better replies there.


A bootable cd image, that will scan and remove infections from your pc. So it's basically an anti virus that you can run without booting your os Trying to disinfect a pc by booting it first and then trying to remove the infection is a losing battle.
Sad[Panda]
Profile Blog Joined January 2009
United States458 Posts
August 05 2011 23:20 GMT
#35
I got rid of this for a friend recently I just used SuperAntiSpyware's Mobile version its named differently so the virus doesn't block the EXE of it. gl I would just follow the bleepingcomputers link others have posted its what I used as a reference also
( O.O) ("\(t.t )/") ~ I'm just looking for someone to hug
iSometric
Profile Blog Joined February 2011
2221 Posts
Last Edited: 2011-08-05 23:36:40
August 05 2011 23:36 GMT
#36
Not to derail the thread (idk how to make my own thread) but, I have a similar problem where I can't open FB/Youtube sometimes. I think its a virus and its like sometimes I can access certain websties and sometimes I can't. (internet works for e.g. yahoo.com though) PM me if u can help!
strava.com/athletes/zhaodynasty
Kipsate
Profile Blog Joined July 2010
Netherlands45349 Posts
August 05 2011 23:41 GMT
#37
Well fuck your KARA collection better not be in danger.

Good luck!

Also, perhaps you should make a seperate thread in the Tech Support section?There are some really smart guys there too who don't read blogs.
WriterXiao8~~
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-06 01:48:23
August 06 2011 01:36 GMT
#38
On August 06 2011 08:36 iSometric wrote:
Not to derail the thread (idk how to make my own thread) but, I have a similar problem where I can't open FB/Youtube sometimes. I think its a virus and its like sometimes I can access certain websties and sometimes I can't. (internet works for e.g. yahoo.com though) PM me if u can help!

Make a new thread. If you speak binary, post it in tech support.

Otherwise post it in blogs or say "use a code to english translator" before hitting post.

Derailing a thread only serves to lose focus on the original intention.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
Last Edited: 2011-08-06 03:22:49
August 06 2011 03:22 GMT
#39
On August 06 2011 08:41 Kipsate wrote:
Well fuck your KARA collection better not be in danger.

Good luck!

Also, perhaps you should make a seperate thread in the Tech Support section?There are some really smart guys there too who don't read blogs.


Number 1 reason why I didn't just reinstall obv obv.

I haven't tried to fix my registry yet, I will try tomorrow morning and if I can't get it to work I'll consider posting in Tech Support (lol did not even know that section existed). Thanks!

And then I'm backing up the collection on external hard drive. This work of art must be preserved.
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
mizU
Profile Blog Joined April 2010
United States12125 Posts
August 06 2011 21:58 GMT
#40
You didn't get hacked, you just got malware.

Try to get a better anti-virus/malware so it doesn't happen again.

There's almost never a need to re-install windows, or run msconfig, cuz if you don't know what you're doing you can EFF up big time.

Regedit is pretty confusing, but once you get down the file tree and layout as well as the data entry, you should be fine. Make sure you only change what you need to, cuz if you mess certain things up... gg. Just follow the guide on the site you got and it should be fine.

Regedit should help you take care of most of the virus triggers, but make sure you search your C drive for hidden folders or newly created files+folders. (Sort by date modified)
Also use MalwareBytes to makes sure everything is gone.

GL!
if happy ever afters did exist <3 @watamizu_
Prev 1 2 3 Next All
Please log in or register to reply.
Live Events Refresh
PiGosaur Cup
01:00
#70
PiGStarcraft596
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
PiGStarcraft596
RuFF_SC2 204
StarCraft: Brood War
GuemChi 2100
Artosis 687
Noble 4
Dota 2
LuMiX1
Counter-Strike
FalleN 1970
taco 694
Super Smash Bros
hungrybox349
Other Games
summit1g12042
C9.Mang0294
Maynarde125
ViBE44
Mew2King36
minikerr8
Organizations
Other Games
gamesdonequick1090
Counter-Strike
PGL444
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 14 non-featured ]
StarCraft 2
• HeavenSC 12
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• RayReign 14
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• masondota2965
League of Legends
• Stunt193
Upcoming Events
CasterMuse Showmatch
6h 20m
Light vs Queen
WardiTV Winter Champion…
9h 20m
OSC
21h 20m
The PondCast
1d 7h
Replay Cast
1d 21h
Korean StarCraft League
3 days
CranKy Ducklings
3 days
SC Evo Complete
3 days
Replay Cast
3 days
Sparkling Tuna Cup
4 days
[ Show More ]
uThermal 2v2 Circuit
4 days
Replay Cast
5 days
Wardi Open
5 days
Replay Cast
5 days
Liquipedia Results

Completed

Proleague 2026-02-22
LiuLi Cup: 2025 Grand Finals
Underdog Cup #3

Ongoing

KCM Race Survival 2026 Season 1
Acropolis #4 - TS5
Jeongseon Sooper Cup
Spring Cup 2026
WardiTV Winter 2026
PiG Sty Festival 7.0
Nations Cup 2026
PGL Cluj-Napoca 2026
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter Qual
eXTREMESLAND 2025
SL Budapest Major 2025

Upcoming

[S:21] ASL SEASON OPEN 2nd Round
[S:21] ASL SEASON OPEN 2nd Round Qualifier
Acropolis #4 - TS6
Acropolis #4
IPSL Spring 2026
CSLAN 4
HSC XXIX
uThermal 2v2 2026 Main Event
Bellum Gens Elite Stara Zagora 2026
RSL Revival: Season 4
PGL Astana 2026
BLAST Rivals Spring 2026
CCT Season 3 Global Finals
FISSURE Playground #3
IEM Rio 2026
PGL Bucharest 2026
Stake Ranked Episode 1
BLAST Open Spring 2026
ESL Pro League S23 Finals
ESL Pro League S23 Stage 1&2
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.