• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 15:24
CEST 21:24
KST 04:24
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Team Liquid Map Contest #22 - The Finalists14[ASL21] Ro16 Preview Pt1: Fresh Flow9[ASL21] Ro24 Preview Pt2: News Flash10[ASL21] Ro24 Preview Pt1: New Chaos0Team Liquid Map Contest #22 - Presented by Monster Energy21
Community News
2026 GSL Season 1 Qualifiers11Maestros of the Game 2 announced32026 GSL Tour plans announced10Weekly Cups (April 6-12): herO doubles, "Villains" prevail1MaNa leaves Team Liquid20
StarCraft 2
General
Team Liquid Map Contest #22 - The Finalists Weekly Cups (April 6-12): herO doubles, "Villains" prevail MaNa leaves Team Liquid Oliveira Would Have Returned If EWC Continued 2026 GSL Tour plans announced
Tourneys
2026 GSL Season 1 Qualifiers Sparkling Tuna Cup - Weekly Open Tournament Master Swan Open (Global Bronze-Master 2) SEL Doubles (SC Evo Bimonthly) $5,000 WardiTV TLMC tournament - Presented by Monster Energy
Strategy
Custom Maps
[D]RTS in all its shapes and glory <3 [A] Nemrods 1/4 players [M] (2) Frigid Storage
External Content
Mutation # 521 Memorable Boss The PondCast: SC2 News & Results Mutation # 520 Moving Fees Mutation # 519 Inner Power
Brood War
General
ASL21 General Discussion BGH Auto Balance -> http://bghmmr.eu/ Pros React To: Tulbo in Ro.16 Group A RepMastered™: replay sharing and analyzer site BW General Discussion
Tourneys
Escore Tournament StarCraft Season 2 [ASL21] Ro16 Group A [ASL21] Ro16 Group B [Megathread] Daily Proleagues
Strategy
Simple Questions, Simple Answers What's the deal with APM & what's its true value Any training maps people recommend? Fighting Spirit mining rates
Other Games
General Games
General RTS Discussion Thread Nintendo Switch Thread Battle Aces/David Kim RTS Megathread Stormgate/Frost Giant Megathread Starcraft Tabletop Miniature Game
Dota 2
The Story of Wings Gaming Official 'what is Dota anymore' discussion
League of Legends
G2 just beat GenG in First stand
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia Mafia Game Mode Feedback/Ideas TL Mafia Community Thread Five o'clock TL Mafia
Community
General
Things Aren’t Peaceful in Palestine US Politics Mega-thread Russo-Ukrainian War Thread YouTube Thread Canadian Politics Mega-thread
Fan Clubs
The IdrA Fan Club
Media & Entertainment
Anime Discussion Thread [Req][Books] Good Fantasy/SciFi books [Manga] One Piece Movie Discussion!
Sports
McBoner: A hockey love story 2024 - 2026 Football Thread Formula 1 Discussion Cricket [SPORT]
World Cup 2022
Tech Support
[G] How to Block Livestream Ads
TL Community
The Automated Ban List
Blogs
Reappraising The Situation T…
TrAiDoS
lurker extra damage testi…
StaticNine
Broowar part 2
qwaykee
Funny Nicknames
LUCKY_NOOB
Iranian anarchists: organize…
XenOsky
ASL S21 English Commentary…
namkraft
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1662 users

Computer got hacked, help pl0x! - Page 2

Blogs > TuElite
Post a Reply
Prev 1 2 3 Next All
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
August 05 2011 15:47 GMT
#21
On August 06 2011 00:36 Darkdeath3 wrote:
Have you tried the system resotore or can u still not start any programs?


Just tried System Restore.

Same as any other program, can't access it.
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
mucker
Profile Blog Joined May 2009
United States1120 Posts
August 05 2011 15:50 GMT
#22
Try using the exe association fix from here
It's supposed to be automatic but actually you have to press this button.
iamperfection
Profile Blog Joined February 2011
United States9645 Posts
August 05 2011 15:51 GMT
#23
Microsoft has an article to this problem and links to this page to solve it.
http://www.bleepingcomputer.com/virus-removal/remove-win-7-antispyware-2012
http://www.teamliquid.net/forum/viewmessage.php?topic_id=406168&currentpage=78#1551
Marcus420
Profile Joined January 2011
Canada1923 Posts
Last Edited: 2011-08-05 15:56:17
August 05 2011 15:53 GMT
#24
On August 06 2011 00:47 TuElite wrote:
Show nested quote +
On August 06 2011 00:36 Darkdeath3 wrote:
Have you tried the system resotore or can u still not start any programs?


Just tried System Restore.

Same as any other program, can't access it.

you can boot off the installation dvd, and choose the “Repair your computer” option on the lower left hand side. If you don’t have an installation/repair disc, you can make one with these instructions. http://www.howtogeek.com/howto/windows-vista/how-to-make-a-windows-vista-repair-disk-if-you-dont-have-one/

Click next on the next screen, and then choose System Restore from the System Recovery dialog. It will take a few seconds to come up, and you will see the same screen that you would see in windows.

Click next, and on the next screen select the drive that your copy of Windows 7 or Vista is installed on.

Click Finish, and Windows will roll back to the previous restore point. Really pretty simple stuff.
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
Last Edited: 2011-08-05 16:09:47
August 05 2011 16:02 GMT
#25
GOOD NEWS UPON ME

By using Task Manager and holding CTRL + File(Run) I managed to access the DOS or whatever (the black screen where u can get shit done). I can now access regedit and the registry from there.

Now I'm going to try and delete the following files in the registry
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'


As well as these files

%AllUsersProfile%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\ppn.exe %Temp%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\U3F7PNVFNCSJK2E86ABFBJ5H %AppData%\TEMPLATES\U3F7PNVFNCSJK2E86ABFBJ5H

And that should get rid of the virus....

Hoppefully my .exe files comeback after that too but I have a feeling that I'll need to do more shit...
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
h3r1n6
Profile Blog Joined September 2007
Iceland2039 Posts
August 05 2011 16:17 GMT
#26
On August 06 2011 01:02 TuElite wrote:
GOOD NEWS UPON ME

By using Task Manager and holding CTRL + File(Run) I managed to access the DOS or whatever (the black screen where u can get shit done). I can now access regedit and the registry from there.

Now I'm going to try and delete the following files in the registry
Show nested quote +
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'


As well as these files

%AllUsersProfile%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\ppn.exe %Temp%\U3F7PNVFNCSJK2E86ABFBJ5H %LocalAppData%\U3F7PNVFNCSJK2E86ABFBJ5H %AppData%\TEMPLATES\U3F7PNVFNCSJK2E86ABFBJ5H

And that should get rid of the virus....

Hoppefully my .exe files comeback after that too but I have a feeling that I'll need to do more shit...



On August 06 2011 00:27 h3r1n6 wrote:
Try a rescue cd, most anti virus companies have them. I suggest the Kaspersky rescue disk.



Just try a rescue disk, way easier and more efficient.
Wordpad
Profile Blog Joined November 2010
Denmark154 Posts
Last Edited: 2011-08-05 16:38:14
August 05 2011 16:34 GMT
#27
My best advice is to re-install Windows. This type of Malware is designed to be profitable at the expense of the victim, and trust me when I say the creators are relentless. Whether that means tricking you to pay for their crap, or stealing credit card information. Due to that fact, and the nature of how operating systems function (you can never be 100% sure the given malware is completely removed if it has root-kit functionalities), I will personally always recommend a reinstall.
enigmaticcam
Profile Blog Joined October 2010
United States280 Posts
Last Edited: 2011-08-05 16:40:35
August 05 2011 16:40 GMT
#28
On August 06 2011 00:50 mucker wrote:
Try using the exe association fix from here

This is your answer.

I had this exact same virus on my machine just a couple months ago. Ended up accidentally removing the association to exe files in an attempt to get rid of it. I did a google search and found the reg keys you can download to re-associate exe files.

You don't need to reinstall windows.
ZeromuS
Profile Blog Joined October 2010
Canada13407 Posts
August 05 2011 16:56 GMT
#29
Ive only ever gotten rid of this by reinstalling windows.
StrategyRTS forever | @ZeromuS_plays | www.twitch.tv/Zeromus_
Frigo
Profile Joined August 2009
Hungary1023 Posts
August 05 2011 17:18 GMT
#30
Try with full path, c:\windows\system32\regedit.exe?
http://www.fimfiction.net/user/Treasure_Chest
Probe1
Profile Blog Joined August 2010
United States17920 Posts
August 05 2011 17:19 GMT
#31
After it's done you might want to think about buying a backup external drive. After years of clicking on stupid things I learned it's best ot just reformat and start fresh with my media secured on a unconnected drive

Sorry.
우정호 KT_VIOLET 1988 - 2012 While we are postponing, life speeds by
Dance.
Profile Blog Joined July 2010
United States389 Posts
August 05 2011 18:19 GMT
#32
Anyone who uses "pl0x" any where other than 4chan deserves to be hacked.
It is what it is...
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-05 22:55:17
August 05 2011 22:54 GMT
#33
I would use the association fix now, and then run combofix (transfer from USB to desktop) to get rid of the virus.

What are rescue disks? I might make one soon. Also, this thread should be under tech support, you'd get less replies but better replies there.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
h3r1n6
Profile Blog Joined September 2007
Iceland2039 Posts
August 05 2011 23:07 GMT
#34
On August 06 2011 07:54 obesechicken13 wrote:
I would use the association fix now, and then run combofix (transfer from USB to desktop) to get rid of the virus.

What are rescue disks? I might make one soon. Also, this thread should be under tech support, you'd get less replies but better replies there.


A bootable cd image, that will scan and remove infections from your pc. So it's basically an anti virus that you can run without booting your os Trying to disinfect a pc by booting it first and then trying to remove the infection is a losing battle.
Sad[Panda]
Profile Blog Joined January 2009
United States458 Posts
August 05 2011 23:20 GMT
#35
I got rid of this for a friend recently I just used SuperAntiSpyware's Mobile version its named differently so the virus doesn't block the EXE of it. gl I would just follow the bleepingcomputers link others have posted its what I used as a reference also
( O.O) ("\(t.t )/") ~ I'm just looking for someone to hug
iSometric
Profile Blog Joined February 2011
2221 Posts
Last Edited: 2011-08-05 23:36:40
August 05 2011 23:36 GMT
#36
Not to derail the thread (idk how to make my own thread) but, I have a similar problem where I can't open FB/Youtube sometimes. I think its a virus and its like sometimes I can access certain websties and sometimes I can't. (internet works for e.g. yahoo.com though) PM me if u can help!
strava.com/athletes/zhaodynasty
Kipsate
Profile Blog Joined July 2010
Netherlands45349 Posts
August 05 2011 23:41 GMT
#37
Well fuck your KARA collection better not be in danger.

Good luck!

Also, perhaps you should make a seperate thread in the Tech Support section?There are some really smart guys there too who don't read blogs.
WriterXiao8~~
obesechicken13
Profile Blog Joined July 2008
United States10467 Posts
Last Edited: 2011-08-06 01:48:23
August 06 2011 01:36 GMT
#38
On August 06 2011 08:36 iSometric wrote:
Not to derail the thread (idk how to make my own thread) but, I have a similar problem where I can't open FB/Youtube sometimes. I think its a virus and its like sometimes I can access certain websties and sometimes I can't. (internet works for e.g. yahoo.com though) PM me if u can help!

Make a new thread. If you speak binary, post it in tech support.

Otherwise post it in blogs or say "use a code to english translator" before hitting post.

Derailing a thread only serves to lose focus on the original intention.
I think in our modern age technology has evolved to become more addictive. The things that don't give us pleasure aren't used as much. Work was never meant to be fun, but doing it makes us happier in the long run.
TuElite
Profile Blog Joined March 2010
Canada2123 Posts
Last Edited: 2011-08-06 03:22:49
August 06 2011 03:22 GMT
#39
On August 06 2011 08:41 Kipsate wrote:
Well fuck your KARA collection better not be in danger.

Good luck!

Also, perhaps you should make a seperate thread in the Tech Support section?There are some really smart guys there too who don't read blogs.


Number 1 reason why I didn't just reinstall obv obv.

I haven't tried to fix my registry yet, I will try tomorrow morning and if I can't get it to work I'll consider posting in Tech Support (lol did not even know that section existed). Thanks!

And then I'm backing up the collection on external hard drive. This work of art must be preserved.
Always Smile - Jung Nicole - Follow Nicole on Twitter @_911007 and me @TuElite
mizU
Profile Blog Joined April 2010
United States12125 Posts
August 06 2011 21:58 GMT
#40
You didn't get hacked, you just got malware.

Try to get a better anti-virus/malware so it doesn't happen again.

There's almost never a need to re-install windows, or run msconfig, cuz if you don't know what you're doing you can EFF up big time.

Regedit is pretty confusing, but once you get down the file tree and layout as well as the data entry, you should be fine. Make sure you only change what you need to, cuz if you mess certain things up... gg. Just follow the guide on the site you got and it should be fine.

Regedit should help you take care of most of the virus triggers, but make sure you search your C drive for hidden folders or newly created files+folders. (Sort by date modified)
Also use MalwareBytes to makes sure everything is gone.

GL!
if happy ever afters did exist <3 @watamizu_
Prev 1 2 3 Next All
Please log in or register to reply.
Live Events Refresh
Big Brain Bouts
16:00
#112
Serral vs herO
RotterdaM1750
IndyStarCraft 294
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
RotterdaM 1750
IndyStarCraft 294
UpATreeSC 80
StarCraft: Brood War
Dewaltoss 107
Aegong 84
Sexy 64
ggaemo 38
Rock 33
Dota 2
febbydoto4
Counter-Strike
fl0m7749
olofmeister3856
Super Smash Bros
Mew2King52
Heroes of the Storm
Liquid`Hasu359
Other Games
Grubby3034
FrodaN1479
qojqva738
Beastyqt540
Mlord341
KnowMe225
Pyrionflax180
ArmadaUGS169
Trikslyr168
summit1g105
QueenE61
MindelVK19
Organizations
Other Games
BasetradeTV339
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 19 non-featured ]
StarCraft 2
• StrangeGG 101
• IndyKCrew
• sooper7s
• AfreecaTV YouTube
• Migwel
• intothetv
• LaughNgamezSOOP
• Kozan
StarCraft: Brood War
• 80smullet 18
• HerbMon 16
• FirePhoenix10
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• WagamamaTV657
League of Legends
• Nemesis2689
• TFBlade1425
Other Games
• imaqtpie1068
• Shiphtur223
Upcoming Events
Korean StarCraft League
7h 36m
CranKy Ducklings
14h 36m
WardiTV Map Contest Tou…
15h 36m
IPSL
20h 36m
WolFix vs nOmaD
dxtr13 vs Razz
BSL
23h 36m
UltrA vs KwarK
Gosudark vs cavapoo
dxtr13 vs HBO
Doodle vs Razz
Patches Events
1d 2h
CranKy Ducklings
1d 4h
Sparkling Tuna Cup
1d 14h
WardiTV Map Contest Tou…
1d 15h
Ladder Legends
1d 19h
[ Show More ]
BSL
1d 23h
StRyKeR vs rasowy
Artosis vs Aether
JDConan vs OyAji
Hawk vs izu
IPSL
1d 23h
JDConan vs TBD
Aegong vs rasowy
Replay Cast
2 days
Wardi Open
2 days
Afreeca Starleague
2 days
Bisu vs Ample
Jaedong vs Flash
Monday Night Weeklies
2 days
RSL Revival
3 days
Afreeca Starleague
3 days
Barracks vs Leta
Royal vs Light
WardiTV Map Contest Tou…
3 days
RSL Revival
4 days
Replay Cast
5 days
The PondCast
5 days
WardiTV Map Contest Tou…
5 days
Replay Cast
6 days
RSL Revival
6 days
Liquipedia Results

Completed

Proleague 2026-04-16
RSL Revival: Season 4
NationLESS Cup

Ongoing

BSL Season 22
ASL Season 21
CSL 2026 SPRING (S20)
IPSL Spring 2026
KCM Race Survival 2026 Season 2
Escore Tournament S2: W3
StarCraft2 Community Team League 2026 Spring
WardiTV TLMC #16
Nations Cup 2026
IEM Rio 2026
PGL Bucharest 2026
Stake Ranked Episode 1
BLAST Open Spring 2026
ESL Pro League S23 Finals
ESL Pro League S23 Stage 1&2
PGL Cluj-Napoca 2026
IEM Kraków 2026

Upcoming

Escore Tournament S2: W4
Acropolis #4
BSL 22 Non-Korean Championship
CSLAN 4
Kung Fu Cup 2026 Grand Finals
HSC XXIX
uThermal 2v2 2026 Main Event
2026 GSL S2
RSL Revival: Season 5
2026 GSL S1
XSE Pro League 2026
IEM Cologne Major 2026
Stake Ranked Episode 2
CS Asia Championships 2026
IEM Atlanta 2026
Asian Champions League 2026
PGL Astana 2026
BLAST Rivals Spring 2026
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.