Z.exe takes 99% of CPU

sorter123

New member
hello. my computer was lagging lately so i checked task manager and i found that file named Z.exe is taking like 100% of cpu
i googled it and found the program Malwarebytes, downloaded, installed and scanned it found the Z.exe and like 50 more malwares i deleted all of em but this one stays... i tried deleting it and scanning several times but no effect.
can anyone help me ?
 

My Computer

OS
windows 7

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Hi Sorter,

Can you post the log from Malwarebytes Anti-Malware please?

Please download DDS by sUBs from one of these locations:

Link 1
Link 2

Link 3


Double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt
Save both reports to your Desktop. Post them back here for review.
 

My Computer

Computer Manufacturer/Model Number
Dell XPS 8300
OS
Windows 7 Ultimate x64
CPU
Intel Core i&-2600 3.40 Ghz
Motherboard
Dell 0Y2MRG
Memory
12GB DDR3
Graphics Card(s)
AMD Radeon HD 6600
Sound Card
Sound Blaster X-Fi Titanium
Monitor(s) Displays
24" Dell and 22" Dell
Screen Resolution
1920x1080
Hard Drives
2.0TB Seagate
Keyboard
Dell OEM
Mouse
Dell OEM
Firstly, you should google that, then check if it's a virus or a application thats taking up your cpu usage. I suggest you to do a complete scan with your anti spyware/virus software, to check if there's any virus running in your system.
 

My Computer

Computer Manufacturer/Model Number
Compaq
OS
Windows 7 Home Premium 32bit
CPU
AMD Athlon 64 Processor 3400+
Motherboard
Asus Nagami
Memory
1.5 GB
Graphics Card(s)
Nvidia GeForce 6150 LE
Sound Card
Realtek High Definition Audio
Try scanning with hitman pro and see what it comes up with.
 

My Computer

OS
Windows 7 Home Premium x64 SP1
CPU
Intel Core i7 2720QM @ 2.20GHz
Memory
8.00 GB Dual-Channel DDR3 @ 665MHz
heres the first scan with malwarebytes

Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: 8041

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

10/29/2011 8:30:44 PM
mbam-log-2011-10-29 (20-30-44).txt

Scan type: Full scan (C:\|D:\|G:\|)
Objects scanned: 313176
Time elapsed: 37 minute(s), 1 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 52

Memory Processes Infected:
c:\Users\z. lama\AppData\Roaming\regsrv64.exe (Trojan.Agent) -> 3584 -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft DLL Registration (Trojan.Agent) -> Value: Microsoft DLL Registration -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\\AppData\Roaming\regsrv64.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\1174.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\136F.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\188.exe (Trojan.Taskupdate) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\1966.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\1984.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\1AE0.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\2DD.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\3257.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\39EE.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\4351.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\462C.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\4846.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\49CF.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\4A07.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\4BCF.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\50A3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\5A07.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\5C6D.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\5CFD.exe (Trojan.Taskupdate) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\65EA.exe (Trojan.Taskupdate) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\67C6.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\6C2D.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\6CBD.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\6FC7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\7D35.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\85C4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\886D.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\8A54.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\8C21.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\904F.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\9137.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\E757.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\EE48.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\F55.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\F90B.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\F95D.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\9B71.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\9F80.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\A270.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\A668.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\AA17.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\B33B.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\B435.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\B6DE.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\B81A.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\BB6D.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\BF1E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\C37A.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\D75A.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\DF27.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

and the second
Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: 8041

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

10/29/2011 11:24:04 PM
mbam-log-2011-10-29 (23-24-04).txt

Scan type: Full scan (C:\|D:\|G:\|)
Objects scanned: 314145
Time elapsed: 41 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\\AppData\Local\Temp\acd\z.exe (Trojan.Agent) -> Delete on reboot.
c:\Users\\Desktop\removewat.exe (HackTool.Wpakill) -> Quarantined and deleted successfully.
c:\Users\\AppData\Roaming\microsoft\Windows\start menu\Programs\Startup\dat.exe (Backdoor.Agent) -> Quarantined and deleted successfully.

with avast6 it found the Z.exe . deleted successfully but it started up again. so i scanned again and it finds nothing now.

thanks everyone ill start trying those right now. gonna post the results


also. i googled it but only advertising sites come up. nothing usefull
 
Last edited:

My Computer

OS
windows 7
Hi,

I think you might need to consider scanning from outisde the Windows environement with this:

http://www.sevenforums.com/tutorials/166445-microsoft-standalone-system-sweeper.html

Be careful what you download with torrents - this is arguably the greatest source of malware infection.

Regards,
Golden

i used this. found nothing


okay, so i used Hitman pro 3.5 it found like 15+ viruses Z.exe too .. also theres this Dat.exe which is located in Startup that can be related to Z.exe . so after the scan it just deleted all those viruses, i rebooted but Z.exe is still here.

any suggestion ?
 

My Computer

OS
windows 7

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
okay thanks ill try scanning it in safe mode.
but i think after that i will just reinstall windows... its way easy to just reinstall than all this stuff.
 

My Computer

OS
windows 7
Code:
c:\Users\\Desktop\removewat.exe (HackTool.Wpakill)

Removewat is a hack designed to circumvent Windows activation. Lets confirm the status of your Windows OS : run this tool, then post the results back here:

http://go.microsoft.com/fwlink/?linkid=52012

If you have the original installation disks, you might want to completely reinstall Windows from scratch.

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
I have not seen that many Trojans on one computer for a while!
Any ideas what site it was on?
Porno usually but it could have been the Teletubbies website I suppose.
Remove WAT!
 

My Computer

OS
Stools
Lol, these guys makes the pros in this forum run in circles because of the shitty stuff loaded with their pirated versions of windows 7.....
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 10 Professional / Windows 7 Professional
CPU
Intel i5-3570
Motherboard
Lenovo Mahobay
Memory
16GB DDR3
Graphics Card(s)
AMD Radeon HD 7850 2GB
Sound Card
(1) Realtek HD Audio (2) AMD HD Audio
Monitor(s) Displays
LG LS192WS
Screen Resolution
1440 x 900 @ 32bit color
Hard Drives
(1) SUV300S37A/120G (2) ST3500413AS SATA Disk Device AHCI mode enabled.
PSU
Corsair HX620
Case
Thermaltake V4 Black Edition
Cooling
Cooler Master Hyper 212 + Artic Silver 5 on CPU/GPU
Keyboard
Dell SK-8115
Mouse
Razer Copperhead with MAPED mat (awesome!)
Internet Speed
100 Mbps up/down
Browser
Chrome
Back
Top