• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 15:38
CET 21:38
KST 05:38
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Revival - 2025 Season Finals Preview8RSL Season 3 - Playoffs Preview0RSL Season 3 - RO16 Groups C & D Preview0RSL Season 3 - RO16 Groups A & B Preview2TL.net Map Contest #21: Winners12
Community News
$21,000 Rongyi Cup Season 3 announced (Jan 22-Feb 7)4Weekly Cups (Dec 29-Jan 4): Protoss rolls, 2v2 returns6[BSL21] Non-Korean Championship - Starts Jan 103SC2 All-Star Invitational: Jan 17-1822Weekly Cups (Dec 22-28): Classic & MaxPax win, Percival surprises3
StarCraft 2
General
Weekly Cups (Dec 29-Jan 4): Protoss rolls, 2v2 returns SC2 All-Star Invitational: Jan 17-18 Weekly Cups (Dec 22-28): Classic & MaxPax win, Percival surprises Chinese SC2 server to reopen; live all-star event in Hangzhou Starcraft 2 Zerg Coach
Tourneys
$21,000 Rongyi Cup Season 3 announced (Jan 22-Feb 7) WardiTV Winter Cup WardiTV Mondays SC2 AI Tournament 2026 OSC Season 13 World Championship
Strategy
Simple Questions Simple Answers
Custom Maps
Map Editor closed ?
External Content
Mutation # 507 Well Trained Mutation # 506 Warp Zone Mutation # 505 Rise From Ashes Mutation # 504 Retribution
Brood War
General
BGH Auto Balance -> http://bghmmr.eu/ I would like to say something about StarCraft BW General Discussion StarCraft & BroodWar Campaign Speedrun Quest Data analysis on 70 million replays
Tourneys
[Megathread] Daily Proleagues [BSL21] Grand Finals - Sunday 21:00 CET [BSL21] Non-Korean Championship - Starts Jan 10 SLON Grand Finals – Season 2
Strategy
Game Theory for Starcraft Simple Questions, Simple Answers Current Meta [G] How to get started on ladder as a new Z player
Other Games
General Games
Awesome Games Done Quick 2026! General RTS Discussion Thread Nintendo Switch Thread Stormgate/Frost Giant Megathread Should offensive tower rushing be viable in RTS games?
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia Mafia Game Mode Feedback/Ideas
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine Trading/Investing Thread The Big Programming Thread
Fan Clubs
White-Ra Fan Club
Media & Entertainment
Anime Discussion Thread
Sports
2024 - 2026 Football Thread Formula 1 Discussion
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List TL+ Announced
Blogs
Life Update and thoughts.
FuDDx
How do archons sleep?
8882
Psychological Factors That D…
TrAiDoS
James Bond movies ranking - pa…
Topin
StarCraft improvement
iopq
Customize Sidebar...

Website Feedback

Closed Threads



Active: 2690 users

Computer got hacked, help pl0x! - Page 2

Blogs > TuElite
Post a Reply
Prev 1 2 3 Next All
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
August 05 2011 15:47 GMT
#21
On August 06 2011 00:36 Darkdeath3 wrote:
Have you tried the system resotore or can u still not start any programs?


Just tried System Restore.

Same as any other program, can't access it.
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
mucker
Profile Blog Joined May 2009
United States1120 Posts
August 05 2011 15:50 GMT
#22
Try using the exe association fix from here
It's supposed to be automatic but actually you have to press this button.
iamperfection
Profile Blog Joined February 2011
United States9645 Posts
August 05 2011 15:51 GMT
#23
Microsoft has an article to this problem and links to this page to solve it.
http://www.bleepingcomputer.com/virus-removal/remove-win-7-antispyware-2012
http://www.teamliquid.net/forum/viewmessage.php?topic_id=406168&currentpage=78#1551
Marcus420
Profile Joined January 2011
Canada1923 Posts
Last Edited: 2011-08-05 15:56:17
August 05 2011 15:53 GMT
#24
On August 06 2011 00:47 TuElite wrote:
Show nested quote +
On August 06 2011 00:36 Darkdeath3 wrote:
Have you tried the system resotore or can u still not start any programs?


Just tried System Restore.

Same as any other program, can't access it.

you can boot off the installation dvd, and choose the “Repair your computer” option on the lower left hand side. If you don’t have an installation/repair disc, you can make one with these instructions. http://www.howtogeek.com/howto/windows-vista/how-to-make-a-windows-vista-repair-disk-if-you-dont-have-one/

Click next on the next screen, and then choose System Restore from the System Recovery dialog. It will take a few seconds to come up, and you will see the same screen that you would see in windows.

Click next, and on the next screen select the drive that your copy of Windows 7 or Vista is installed on.

Click Finish, and Windows will roll back to the previous restore point. Really pretty simple stuff.
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
Last Edited: 2011-08-05 16:09:47
August 05 2011 16:02 GMT
#25
GOOD NEWS UPON ME

By using Task Manager and holding CTRL + File(Run) I managed to access the DOS or whatever (the black screen where u can get shit done). I can now access regedit and the registry from there.

Now I'm going to try and delete the following files in the registry
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'


As well as these files

%AllUsersProfile%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\ppn.exe %Temp%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\U3F7PNVFNCSJK2E86ABFBJ5H %AppData%\TEMPLATES\U3F7PNVFNCSJK2E86ABFBJ5H

And that should get rid of the virus....

Hoppefully my .exe files comeback after that too but I have a feeling that I'll need to do more shit...
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
h3r1n6
Profile Blog Joined September 2007
Iceland2039 Posts
August 05 2011 16:17 GMT
#26
On August 06 2011 01:02 TuElite wrote:
GOOD NEWS UPON ME

By using Task Manager and holding CTRL + File(Run) I managed to access the DOS or whatever (the black screen where u can get shit done). I can now access regedit and the registry from there.

Now I'm going to try and delete the following files in the registry
Show nested quote +
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'


As well as these files

%AllUsersProfile%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\ppn.exe %Temp%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\U3F7PNVFNCSJK2E86ABFBJ5H %AppData%\TEMPLATES\U3F7PNVFNCSJK2E86ABFBJ5H

And that should get rid of the virus....

Hoppefully my .exe files comeback after that too but I have a feeling that I'll need to do more shit...



On August 06 2011 00:27 h3r1n6 wrote:
Try a rescue cd, most anti virus companies have them. I suggest the Kaspersky rescue disk.



Just try a rescue disk, way easier and more efficient.
Wordpad
Profile Blog Joined November 2010
Denmark154 Posts
Last Edited: 2011-08-05 16:38:14
August 05 2011 16:34 GMT
#27
My best advice is to re-install Windows. This type of Malware is designed to be profitable at the expense of the victim, and trust me when I say the creators are relentless. Whether that means tricking you to pay for their crap, or stealing credit card information. Due to that fact, and the nature of how operating systems function (you can never be 100% sure the given malware is completely removed if it has root-kit functionalities), I will personally always recommend a reinstall.
enigmaticcam
Profile Blog Joined October 2010
United States280 Posts
Last Edited: 2011-08-05 16:40:35
August 05 2011 16:40 GMT
#28
On August 06 2011 00:50 mucker wrote:
Try using the exe association fix from here

This is your answer.

I had this exact same virus on my machine just a couple months ago. Ended up accidentally removing the association to exe files in an attempt to get rid of it. I did a google search and found the reg keys you can download to re-associate exe files.

You don't need to reinstall windows.
ZeromuS
Profile Blog Joined October 2010
Canada13389 Posts
August 05 2011 16:56 GMT
#29
Ive only ever gotten rid of this by reinstalling windows.
StrategyRTS forever | @ZeromuS_plays | www.twitch.tv/Zeromus_
Frigo
Profile Joined August 2009
Hungary1023 Posts
August 05 2011 17:18 GMT
#30
Try with full path, c:\windows\system32\regedit.exe?
http://www.fimfiction.net/user/Treasure_Chest
Probe1
Profile Blog Joined August 2010
United States17920 Posts
August 05 2011 17:19 GMT
#31
After it's done you might want to think about buying a backup external drive. After years of clicking on stupid things I learned it's best ot just reformat and start fresh with my media secured on a unconnected drive

Sorry.
우정호 KT_VIOLET 1988 - 2012 While we are postponing, life speeds by
Dance.
Profile Blog Joined July 2010
United States389 Posts
August 05 2011 18:19 GMT
#32
Anyone who uses "pl0x" any where other than 4chan deserves to be hacked.
It is what it is...
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-05 22:55:17
August 05 2011 22:54 GMT
#33
I would use the association fix now, and then run combofix (transfer from USB to desktop) to get rid of the virus.

What are rescue disks? I might make one soon. Also, this thread should be under tech support, you'd get less replies but better replies there.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
h3r1n6
Profile Blog Joined September 2007
Iceland2039 Posts
August 05 2011 23:07 GMT
#34
On August 06 2011 07:54 obesechicken13 wrote:
I would use the association fix now, and then run combofix (transfer from USB to desktop) to get rid of the virus.

What are rescue disks? I might make one soon. Also, this thread should be under tech support, you'd get less replies but better replies there.


A bootable cd image, that will scan and remove infections from your pc. So it's basically an anti virus that you can run without booting your os Trying to disinfect a pc by booting it first and then trying to remove the infection is a losing battle.
Sad[Panda]
Profile Blog Joined January 2009
United States458 Posts
August 05 2011 23:20 GMT
#35
I got rid of this for a friend recently I just used SuperAntiSpyware's Mobile version its named differently so the virus doesn't block the EXE of it. gl I would just follow the bleepingcomputers link others have posted its what I used as a reference also
( O.O) ("\(t.t )/") ~ I'm just looking for someone to hug
iSometric
Profile Blog Joined February 2011
2221 Posts
Last Edited: 2011-08-05 23:36:40
August 05 2011 23:36 GMT
#36
Not to derail the thread (idk how to make my own thread) but, I have a similar problem where I can't open FB/Youtube sometimes. I think its a virus and its like sometimes I can access certain websties and sometimes I can't. (internet works for e.g. yahoo.com though) PM me if u can help!
strava.com/athletes/zhaodynasty
Kipsate
Profile Blog Joined July 2010
Netherlands45349 Posts
August 05 2011 23:41 GMT
#37
Well fuck your KARA collection better not be in danger.

Good luck!

Also, perhaps you should make a seperate thread in the Tech Support section?There are some really smart guys there too who don't read blogs.
WriterXiao8~~
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-06 01:48:23
August 06 2011 01:36 GMT
#38
On August 06 2011 08:36 iSometric wrote:
Not to derail the thread (idk how to make my own thread) but, I have a similar problem where I can't open FB/Youtube sometimes. I think its a virus and its like sometimes I can access certain websties and sometimes I can't. (internet works for e.g. yahoo.com though) PM me if u can help!

Make a new thread. If you speak binary, post it in tech support.

Otherwise post it in blogs or say "use a code to english translator" before hitting post.

Derailing a thread only serves to lose focus on the original intention.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
Last Edited: 2011-08-06 03:22:49
August 06 2011 03:22 GMT
#39
On August 06 2011 08:41 Kipsate wrote:
Well fuck your KARA collection better not be in danger.

Good luck!

Also, perhaps you should make a seperate thread in the Tech Support section?There are some really smart guys there too who don't read blogs.


Number 1 reason why I didn't just reinstall obv obv.

I haven't tried to fix my registry yet, I will try tomorrow morning and if I can't get it to work I'll consider posting in Tech Support (lol did not even know that section existed). Thanks!

And then I'm backing up the collection on external hard drive. This work of art must be preserved.
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
mizU
Profile Blog Joined April 2010
United States12125 Posts
August 06 2011 21:58 GMT
#40
You didn't get hacked, you just got malware.

Try to get a better anti-virus/malware so it doesn't happen again.

There's almost never a need to re-install windows, or run msconfig, cuz if you don't know what you're doing you can EFF up big time.

Regedit is pretty confusing, but once you get down the file tree and layout as well as the data entry, you should be fine. Make sure you only change what you need to, cuz if you mess certain things up... gg. Just follow the guide on the site you got and it should be fine.

Regedit should help you take care of most of the virus triggers, but make sure you search your C drive for hidden folders or newly created files+folders. (Sort by date modified)
Also use MalwareBytes to makes sure everything is gone.

GL!
if happy ever afters did exist <3 @watamizu_
Prev 1 2 3 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 7h 22m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
SpeCial 188
IndyStarCraft 173
JuggernautJason131
BRAT_OK 105
UpATreeSC 86
SteadfastSC 85
EmSc Tv 20
StarCraft: Brood War
Britney 16117
EffOrt 292
Shuttle 167
Larva 67
Killer 38
Rock 38
Dota 2
Gorgc5492
Counter-Strike
adren_tv89
Other Games
Grubby5205
FrodaN2784
Liquid`RaSZi2246
tarik_tv2094
Beastyqt907
Harstem469
Liquid`Hasu418
Mlord390
mouzStarbuck371
B2W.Neo252
Pyrionflax245
KnowMe214
XaKoH 168
ArmadaUGS160
TKL 73
QueenE60
Dewaltoss57
ZombieGrub23
DeMusliM0
Organizations
Other Games
gamesdonequick48215
StarCraft 2
EmSc Tv 20
EmSc2Tv 20
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 19 non-featured ]
StarCraft 2
• Hupsaiya 55
• Adnapsc2 14
• intothetv
• sooper7s
• Migwel
• AfreecaTV YouTube
• LaughNgamezSOOP
• IndyKCrew
• Kozan
StarCraft: Brood War
• 80smullet 23
• FirePhoenix11
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
League of Legends
• Doublelift3655
• Nemesis3166
Other Games
• imaqtpie1656
• Shiphtur344
• WagamamaTV250
Upcoming Events
SOOP
7h 22m
SHIN vs GuMiho
Cure vs Creator
The PondCast
13h 22m
Wardi Open
15h 22m
Big Gabe XPERIONCRAFT
16h 22m
AI Arena Tournament
23h 22m
Sparkling Tuna Cup
1d 13h
WardiTV Invitational
1d 16h
IPSL
1d 23h
DragOn vs Sziky
Replay Cast
2 days
Wardi Open
2 days
[ Show More ]
Monday Night Weeklies
2 days
WardiTV Invitational
3 days
WardiTV Invitational
4 days
The PondCast
5 days
Liquipedia Results

Completed

Proleague 2026-01-08
WardiTV 2025
META Madness #9

Ongoing

C-Race Season 1
IPSL Winter 2025-26
OSC Championship Season 13
eXTREMESLAND 2025
SL Budapest Major 2025
ESL Impact League Season 8
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025

Upcoming

BSL 21 Non-Korean Championship
CSL 2025 WINTER (S19)
Escore Tournament S1: W4
Acropolis #4
IPSL Spring 2026
Bellum Gens Elite Stara Zagora 2026
HSC XXVIII
Rongyi Cup S3
Thunderfire SC2 All-star 2025
Big Gabe Cup #3
Nations Cup 2026
Underdog Cup #3
NA Kuram Kup
BLAST Open Spring 2026
ESL Pro League Season 23
ESL Pro League Season 23
PGL Cluj-Napoca 2026
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter Qual
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.