1. #1

    Starcraft 2/Recovering from a Virus help please.

    Hi, Im posting this here in case i dont get any help on the other forum... My problem is the same as this guy had
    http://us.battle.net/wow/en/forum/topic/2416115591 i dont know if any of you checked that post before or not or if you dont want to read it...
    long story, short... im on a laptop and i run windows vista... about 3 months ago i had ''instability'' virus that said blah blah your hard is failing so purchase our product and it will be fine... and their product site took u to a malware and so on... anyways i recovered from that virus but now i believe my files/folders on my laptop are ''Hidden'' and read only.. i cant seem to uncheck and keep the files/folders unchecked from read only.. and some of the files/folders are also hidden... main example is from my starcraft 2 folder my ''Banks'' folder is gone.. which means when i play certain maps.. it cannot track my progress so i always have to start from scratch.

    So yes its a VERY big problem.. and i dont know how to get passed it.. i cannot ''restore'' my system because i never backed it up unfortunately... im wondering if there are other solutions and what they are.. help would be GREATLY GREATLY appreciated.
    Last edited by Slizardxoxo; 2011-08-06 at 07:52 AM.

  2. #2
    oh I remember several PCs with scareware like this. I keep recommending a new OS installation but if thats impossible there are several things to check to recover most of the problems...
    I dont know what kind of scareware you got but from my experience I expect the following behaviour...

    1. theres probably a process with a cryptic name running .. hard to describe since many proper system processes have kinda cryptic names.. tho names mixing letters and numbers arent normal.. so try to kill that process via task manager. if it block task manager you can start a command line [WIN] + [R], type cmd and ok. there you can use tasklist command to get a list of all processes and their process ID (PID), then use taskkill /F /PID xxx to kill that process

    2. then you have to prevent that process from autostarting everytime. you can run msconfig [WIN] + [R], type msconfig and ok. in the system start tab (dunno what its named in english) is a list of all programs starting with the system automatically. find that suspicious process and uncheck it.

    3. then you should be able to uncheck the read only and hidden options from your files. if they keep getting checked then you probably got the wrong process.


    it can be tonz of work to recovery a system from changes made by scareware and you never can be sure if you got rid of every change and hidden thingies.. thats why i prefer a restore of the system. lot of scareware do changes to the local group policies.. that might cause unusual behaviours of the system... like blocking task manager etc. in that case you have to run gpedit.msc and browse all the policies to figure changes that might've been made.

    Please be careful when doing stuff like that above. depending on your skills things might also get worse. im just trying to give some ideas in bad english from my experience

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •