0

as the title suggests, after I login to default/main account which has administration privileges, after desktop loads almost instantly CMD opens and shuts down the computer, only way I found to stop it temporary was to login to my other account question is can you recognize this virus ?

I have been wandering shady russian sites lately could it be due to that ?

I have no antivirus installed other than windows defender.

  • Reboot in safe mode, see if that helps. If it does, look for login autorun scripts in the admin account. You probably do have a virus – Natanael Feb 17 '19 at 17:41
  • Hello, I was able to pinpoint the virus, called "7king hacker suck" it simply puts itself into tasks folder in sys32, and runs cmd with shutdown command after boot, however what I found interesting was that none of the antiviruses were able to detect it, https://www.virustotal.com/#/file/27e26e77578466a1f93f1a33332893393e176960a5f9fd4295d4515d473a0195/detection it seems to have russian origin – Thesnake123 Feb 17 '19 at 20:34
  • I'm voting to close this question as off-topic because although we deal with malware and infection concepts, we are not a malware removal site. – schroeder Aug 02 '19 at 08:07

2 Answers2

2

Since it's not detected by antivirus software:

https://www.virustotal.com/#/file/27e26e77578466a1f93f1a33332893393e176960a5f9fd4295d4515d473a0195/detectionthe

The script runs the command shutdown -s -t 0, this is the usual command to shut down the computer after 0 seconds.

In order to remove, remove the following if found:

 User Startup: `
C:\Users\(username)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk`
C:\Users\(username)\AppData\Roaming\Tempo\DOC001.exe

HKLM\..\ShellIconOverlayIdentifiers\00asw: (no name) - {472083B0-C522-11CF-8763-00608CC02F24} - (no file)

Task: 7king hacker suck - C:\Windows\system32\cmd.exe /c shutdown -s -t 0
schroeder
  • 123,438
  • 55
  • 284
  • 319
2

So, I've had the same problem all day and i've been trying to find out how to remove whats happening. I logged into a spare account that I previously made that had Administrator Privileges and I got into safe mode. By the looks of it, in safe mode the latest version of Malwarebytes (Version 3.8.3 Free) picked the virus up. This has allowed me to log into my Computer normally. So what I can suggest is to somehow get into safe mode and run the latest version of Malwarebytes to remove the virus. I hoped this helped even though a little late.