Solved! Potential java.exe malware

iLLMATICxKiNG

Honorable
Oct 8, 2013
5
0
10,510
Hello everyone!

I am on Windows 10 and have been noticing some weird programs running in my task manager that have been killing my CPU and it's starting to worry me. The program is called Zeallsoft Super Webcam Recorder Setup but I have never downloaded this. It sounds super fishy, I know.

- Here is a screenshot for what I am referencing: http://i.imgur.com/UvOYsju.png

- Here is a screenshot from the Details tab: http://i.imgur.com/1eo8Bbk.png

- On the resource monitor, it's called java.exe, so that's scary.

The program eats a lot of my CPU (~30%) when I am idle, so when I'm gaming, it's even more apparent that something is going on.

I have killed the task so many times but it just keeps coming back. I tried to Google what it was and I am having no luck at all (it just brings me to the Zeallsoft software). When I right click and open the file location, it opens up my Windows folder in my C: drive so that's worrisome in itself.

This EXACT thing was happening to me last week, and weeks before that, but the program was called 7z setup sfx and also had a Java icon and was named java.exe. So my suspicion is that whatever it is, it's changing names. I tried googling that too because it also killed my CPU and acted exactly like Zeallsoft Super Webcam Recorder Setup, but had a different name.

Does anyone have any idea what this is and how I could resolve it? It seems that the commonality is that they're both a java.exe that, when I open the file location, it takes me to my "Windows" folder.

What I've Tried in Both Instances I've Seen the Issue:

- Full scan with Panda Antivirus (I even ran this to scan processes running while the process was running; no luck)

- Full scan with Malwarebytes

Thank you for any assistance! I can provide more details if necessary.

EDIT: So I was messing around in my Windows folder and I see java.exe. When I open the properties, I see this http://i.imgur.com/A7aGhyR.png.

Should I delete this or will there be repercussions?

2nd Edit: Formatting/spelling
 
Solution
there is clearly somekind of malware on your system.
As far as said java.exe in windows directory goes, feel free to delete it.
Even if you have Java installed, it should be in program files, not c:\windows
Even if it was microsofts own toys, it'd be in system32 or syswow64 folder.
Even if it was real java (it isn't) it's description should NOT be Zeallsoft something.

The downside is, it's origins are still a mystery and it might only run, it might not be the original browser extension/other thing that downloads them to your computer.

On better removal directions, I cannot sadly tell much more.

little_me

Estimable
May 9, 2015
151
3
4,910
there is clearly somekind of malware on your system.
As far as said java.exe in windows directory goes, feel free to delete it.
Even if you have Java installed, it should be in program files, not c:\windows
Even if it was microsofts own toys, it'd be in system32 or syswow64 folder.
Even if it was real java (it isn't) it's description should NOT be Zeallsoft something.

The downside is, it's origins are still a mystery and it might only run, it might not be the original browser extension/other thing that downloads them to your computer.

On better removal directions, I cannot sadly tell much more.
 
Solution

iLLMATICxKiNG

Honorable
Oct 8, 2013
5
0
10,510


Thanks for your input. I would assume if it returns, I would need to perform a fresh installation of Windows?

 

Username_NNN

Prominent
Apr 5, 2017
1
0
510
Hey.

I wanted to tell you that you are not alone in this issue with crazy-CPU-eating 'Zeallsoft Super
Webcam Recorder Setup' process, though this is literally the only page I was able to find (and in Bing, no less - 0 results in Google).

Apart from the java.exe application, I also had lsa.exe in the same windows folder, with approx. same time of modification as java.exe, so you might wanna doublecheck your system folder.
 

iLLMATICxKiNG

Honorable
Oct 8, 2013
5
0
10,510


It's good to hear I'm not alone, but I'm sorry.

Did you fix it for good? Does it come back after you remove it? I Googled everything and lost hope until I noticed it was disguised as java.exe, probably to dodge scanners.

Has anything worked for you?

 

iLLMATICxKiNG

Honorable
Oct 8, 2013
5
0
10,510


Thanks for the suggestion. I'll do this.

But if I did download something free and it acts like this it raises more questions:

1. Why did it change names from 7z setup sfx to Zeallsoft Super Webcam Recorder Setup

2. Why is it labeled as java.exe with the official Java icon?

3. Why would a setup kill my CPU speed randomly?

4. Why is it installed in my C: drive Windows folder?

I don't expect you to answer any of those questions, and I will try your suggestion, but I have a feeling that isn't exactly what you mentioned and suspect that it's malware.
 

little_me

Estimable
May 9, 2015
151
3
4,910


Yes, unless you manage to find out how it appears back, fresh install of windows would likely be needed to get rid of it.

You could likely check startup tab of task manager to see if it simply runs it's own installer from somewhere on each reboot.

As side note to lsa.exe in windows folder, I believe that is just an attempt to not get deleted also since such exe should not exist there. (or anywhere in windows and it's subfolders)
windows\system32\lsass.exe, yes.. this is microsofts own
windows\system32\lsaiso.exe, yes.. this is microsofts own
 

iLLMATICxKiNG

Honorable
Oct 8, 2013
5
0
10,510


Hey man. I found it and deleted it but it came back.

Alas, I found out what it was. I opened the file location to view the command line and it was called sgminer.

Yep. A bitcoin mining type of Malware that absolutely kills CPU power. I ran Malwarebytes, Panda Security, Adwcleaner, and those didn't work.

I got a trial of Hitman Pro and it detected everything and deleted it, so hopefully it doesn't come back. I'm currently running adwcleaner and then a full scan to be safe.

But yeah - It was definitely a bitcoin miner disguised as java.exe in my Windows folder.