Jump to content

"7king hacker suck" task in Task Scheduler

Guiltyxz

A few days ago my pc shutdown randomly, and would after a minute of being logged in, eventually I booted into safe mode and found that a task by the name of "7king hacker suck" had been created 1 min before my PC shutdown. I removed it and when I booted up again I googled and I could only find one forum thread with no replys about it. Does anyone know what causes it? I have had it happen before but then I never found it in Task Scheduler and just did a system refresh or whatever (where it takes your system back in time idk)

 

The code from the XML document are

Spoiler

<?xml version="1.0" encoding="UTF-16"?>
<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
  <RegistrationInfo>
    <Date>2020-10-25T13:57:17</Date>
    <Author>JOSEPHS-PC\heygu</Author>
    <URI>\7king hacker suck</URI>
  </RegistrationInfo>
  <Triggers>
    <TimeTrigger>
      <Repetition>
        <Interval>PT1M</Interval>
        <StopAtDurationEnd>false</StopAtDurationEnd>
      </Repetition>
      <StartBoundary>2020-10-25T13:57:00</StartBoundary>
      <Enabled>true</Enabled>
    </TimeTrigger>
  </Triggers>
  <Principals>
    <Principal id="Author">
      <UserId>S-1-5-21-1038655758-2430040986-4280083883-1001</UserId>
      <LogonType>InteractiveToken</LogonType>
      <RunLevel>LeastPrivilege</RunLevel>
    </Principal>
  </Principals>
  <Settings>
    <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
    <DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries>
    <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries>
    <AllowHardTerminate>true</AllowHardTerminate>
    <StartWhenAvailable>false</StartWhenAvailable>
    <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
    <IdleSettings>
      <Duration>PT10M</Duration>
      <WaitTimeout>PT1H</WaitTimeout>
      <StopOnIdleEnd>true</StopOnIdleEnd>
      <RestartOnIdle>false</RestartOnIdle>
    </IdleSettings>
    <AllowStartOnDemand>true</AllowStartOnDemand>
    <Enabled>false</Enabled>
    <Hidden>false</Hidden>
    <RunOnlyIfIdle>false</RunOnlyIfIdle>
    <WakeToRun>false</WakeToRun>
    <ExecutionTimeLimit>PT72H</ExecutionTimeLimit>
    <Priority>7</Priority>
  </Settings>
  <Actions Context="Author">
    <Exec>
      <Command>cmd.exe</Command>
      <Arguments>/c shutdown -s -t 0</Arguments>
    </Exec>
  </Actions>
</Task>

 

PC: Ryzen 7 2700 | RX 5700 XT | Asus Prime B450-PLUS | CoolerMaster Masterwatt 600W | 32GB Corsair Vengeance 3200MHz RAM | 512GB NVME SSD & 7TB combined HDD | macOS Monterey 12.6.6, Windows 7 Ultimate x64 and WIndows 10 Pro x64

Laptop: MacBook Pro 15" 2015 | i7-4870HQ | R9 M370X | 16gb | 1tb SSD

iPhone 13 Pro Max | 256GB | iOS 15.7

 

My Folding Stats | #MuricaParrotGang

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, Orange1 said:

Looks like a virus, do a scan and wipe it out.

Do you have any antivirus to recommend? 

PC: Ryzen 7 2700 | RX 5700 XT | Asus Prime B450-PLUS | CoolerMaster Masterwatt 600W | 32GB Corsair Vengeance 3200MHz RAM | 512GB NVME SSD & 7TB combined HDD | macOS Monterey 12.6.6, Windows 7 Ultimate x64 and WIndows 10 Pro x64

Laptop: MacBook Pro 15" 2015 | i7-4870HQ | R9 M370X | 16gb | 1tb SSD

iPhone 13 Pro Max | 256GB | iOS 15.7

 

My Folding Stats | #MuricaParrotGang

Link to comment
Share on other sites

Link to post
Share on other sites

The safest and easiest thing to do is wipe your entire system and start from scratch. Once you've been compromised you can never be certain that you've got rid of it.

Link to comment
Share on other sites

Link to post
Share on other sites

that is slightly scary. i would have had a heart attack by now

13 minutes ago, WY6 said:

Do you have any antivirus to recommend? 

I think people like malwarebytes and ltt once promoted bitdefender

PC specs:

Ryzen 9 3900X overclocked to 4.3-4.4 GHz

Corsair H100i platinum

32 GB Trident Z RGB 3200 MHz 14-14-14-34

RTX 2060

MSI MPG X570 Gaming Edge wifi

NZXT H510

Samsung 860 EVO 500GB

2 TB WD hard drive

Corsair RM 750 Watt

ASUS ROG PG248Q 

Razer Ornata Chroma

Razer Firefly 

Razer Deathadder 2013

Logitech G935 Wireless

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, WY6 said:

Do you have any antivirus to recommend? 

Malwarebytes Anti-Malware is pretty good. Also Windows Security should be one of the best free ones out there. I would recommend a full scan of the system as well as any attached drives to make sure nothing is left.

CPU Cooler Tier List  || Motherboard VRMs Tier List || Motherboard Beep & POST Codes || Graphics Card Tier List || PSU Tier List 

 

Main System Specifications: 

 

CPU: AMD Ryzen 9 5950X ||  CPU Cooler: Noctua NH-D15 Air Cooler ||  RAM: Corsair Vengeance LPX 32GB(4x8GB) DDR4-3600 CL18  ||  Mobo: ASUS ROG Crosshair VIII Dark Hero X570  ||  SSD: Samsung 970 EVO 1TB M.2-2280 Boot Drive/Some Games)  ||  HDD: 2X Western Digital Caviar Blue 1TB(Game Drive)  ||  GPU: ASUS TUF Gaming RX 6900XT  ||  PSU: EVGA P2 1600W  ||  Case: Corsair 5000D Airflow  ||  Mouse: Logitech G502 Hero SE RGB  ||  Keyboard: Logitech G513 Carbon RGB with GX Blue Clicky Switches  ||  Mouse Pad: MAINGEAR ASSIST XL ||  Monitor: ASUS TUF Gaming VG34VQL1B 34" 

 

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, dilpickle said:

The safest and easiest thing to do is wipe your entire system and start from scratch. Once you've been compromised you can never be certain that you've got rid of it.

Only on the most extreme cases of a virus would you re install from fresh the o/s.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Orange1 said:

Only on the most extreme cases of a virus would you re install from fresh the o/s.

There is no such thing as a non-extreme virus. A compromised system is a compromised system. If you have a virus that means you are being unsafe online and there is no telling what else could be on your system. With rampant ransomware this is not something to be taken lightly.

 

Anti-virus software is far from foolproof. None of them can keep up with all the threats out there. I thought this was common knowledge at least among tech savvy folks but it seems like everyone is living in blissful ignorance.

Link to comment
Share on other sites

Link to post
Share on other sites

  • 5 months later...

its a virus ,

A Trojan Virus but idk what type of is but (mine is named as Trojan.Shutdown)

 

this &king hacker suckvirus thing can disguise it self as a taskeng and shutdown completely my pc.

theres a folder to it. tho my trojen viruses downloader without me noticing it idk how it got downloaded.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×