• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

CPU usage high, stops when opening taskmgr, possible malware/miner?

Joined
May 7, 2023
Messages
670 (1.15/day)
Processor Ryzen 5700x
Motherboard Gigabyte Auros Elite AX V2
Cooling Thermalright Peerless Assassin SE White
Memory TeamGroup T-Force Delta RGB 32GB 3600Mhz
Video Card(s) PowerColor Red Dragon Rx 6800
Storage Fanxiang S660 1TB, Fanxiang S500 Pro 1TB, BraveEagle 240GB SSD, 2TB Seagate HDD
Case Corsair 4000D White
Power Supply Corsair RM750x SHIFT
Have noticed this happening tonight, my CPU usage will get to around 70-80% fans spin up and will stay like that until I open taskmgr then the CPU usage goes down and I can't seen any specifdic process that was using it before it disappears, also tried process explorer and get the same behaviour, have run multiple AV scans (defender, malware bytes and Sophos hitman pro) nothing has been picked up, have looked in startup and there's nothing there that shouldn't be, set to selective startup, deleted all unneccesary apps/programs, deleted downloaded files etc, 1 thing interesting I found some random file in my downloads that was supposedly created/downloaded a couple of weeks ago at 4am! and was a randomised file name ending in .DOC, I don't have office on my PC and didn't recognise the file, opened it up using a free DOC viewer website on edge and it was some kind of random african government meeting minutes file, obviusly that went to the recycle bin, have run the following CMD's "Open cmd.exe with Run as Administrator. (2) DISM.exe /Online /Cleanup-image /StartComponentCleanup (3) DISM.exe /Online /Cleanup-Image /Restorehealth (4) SFC /SCANNOW " all come back fine, and yet the problem remains, even formatted my 2nd NVME drives at it was just for game installs and my C: drive is down to 865Gb from 930Gb so I have very little installed/downloaded etc and the problem remains, basically only made aware of it as my fans spin up and I have them set to very quiet until the CPU reaches 60-65c, with Radeon overlay running I can see when this happens the CPU is hitting 70-80% usage and hitting 65c+ but as I have stated as soon as I open taskmgr or process explorer the CPU shoots back down to single digit use and there's nothing I can see that is causing the high usage
 
Last edited:
Joined
Feb 6, 2021
Messages
2,920 (2.08/day)
Location
Germany
Processor AMD Ryzen 7 7800X3D
Motherboard ASRock B650E Steel Legend Wifi
Cooling Arctic Liquid Freezer III 280
Memory 2x16GB Corsair Vengeance RGB 6000 CL30 (A-Die)
Video Card(s) RTX 4090 Gaming X Trio
Storage 1TB Samsung 990 PRO, 4TB Corsair MP600 PRO XT, 1TB WD SN850X, 4x4TB Crucial MX500
Display(s) Alienware AW2725DF, LG 27GR93U, LG 27GN950-B
Case Streacom BC1 V2 Black
Audio Device(s) Bose Companion Series 2 III, Sennheiser GSP600 and HD599 SE - Creative Soundblaster X4
Power Supply bequiet! Dark Power Pro 12 1500w Titanium
Mouse Razer Deathadder V3
Keyboard Razer Black Widow V3 TKL
VR HMD Oculus Rift S
Software ~2000 Video Games
Joined
May 7, 2023
Messages
670 (1.15/day)
Processor Ryzen 5700x
Motherboard Gigabyte Auros Elite AX V2
Cooling Thermalright Peerless Assassin SE White
Memory TeamGroup T-Force Delta RGB 32GB 3600Mhz
Video Card(s) PowerColor Red Dragon Rx 6800
Storage Fanxiang S660 1TB, Fanxiang S500 Pro 1TB, BraveEagle 240GB SSD, 2TB Seagate HDD
Case Corsair 4000D White
Power Supply Corsair RM750x SHIFT
Worth noting that when I open taskmgr/process explorer and the CPU usage returns to normal there seems to be a 20min wait from closing them before the CPU usage spikes up again I need to measure the time but always is around 20mins time before it happens again
download HitmanPro and run a "one time only" virus scan in the freeware.
Done that, nothing found.
 
Joined
Feb 6, 2021
Messages
2,920 (2.08/day)
Location
Germany
Processor AMD Ryzen 7 7800X3D
Motherboard ASRock B650E Steel Legend Wifi
Cooling Arctic Liquid Freezer III 280
Memory 2x16GB Corsair Vengeance RGB 6000 CL30 (A-Die)
Video Card(s) RTX 4090 Gaming X Trio
Storage 1TB Samsung 990 PRO, 4TB Corsair MP600 PRO XT, 1TB WD SN850X, 4x4TB Crucial MX500
Display(s) Alienware AW2725DF, LG 27GR93U, LG 27GN950-B
Case Streacom BC1 V2 Black
Audio Device(s) Bose Companion Series 2 III, Sennheiser GSP600 and HD599 SE - Creative Soundblaster X4
Power Supply bequiet! Dark Power Pro 12 1500w Titanium
Mouse Razer Deathadder V3
Keyboard Razer Black Widow V3 TKL
VR HMD Oculus Rift S
Software ~2000 Video Games
sounds maybe like a random idle task is kicking in like defragmenting your 2TB HDD.
did you ever ran "Rundll32.exe advapi32.dll,ProcessIdleTasks" (can take a while with that HDD but it will process every existing idle task that windows has scheduled)

1 thing interesting I found some random file in my downloads that was supposedly created/downloaded a couple of weeks ago at 4am! and was a randomised file name ending in .DOC, I don't have office on my PC and didn't recognise the file, opened it up using a free DOC viewer website on edge and it was some kind of random african government meeting minutes file,
well that sounds weird xD
 
Joined
May 7, 2023
Messages
670 (1.15/day)
Processor Ryzen 5700x
Motherboard Gigabyte Auros Elite AX V2
Cooling Thermalright Peerless Assassin SE White
Memory TeamGroup T-Force Delta RGB 32GB 3600Mhz
Video Card(s) PowerColor Red Dragon Rx 6800
Storage Fanxiang S660 1TB, Fanxiang S500 Pro 1TB, BraveEagle 240GB SSD, 2TB Seagate HDD
Case Corsair 4000D White
Power Supply Corsair RM750x SHIFT
Last happened at 22:50
sounds maybe like a random idle task is kicking in like defragmenting your 2TB HDD.
did you ever ran "Rundll32.exe advapi32.dll,ProcessIdleTasks" (can take a while with that HDD but it will process every existing idle task that windows has scheduled)
HDD is currently disconnected, only the 2 NVME drives are connected, also I am not completely idling when it happens, usually have FF open with 5-8 tabs including YT, I thought that was the culprit initially as it gradually eats up RAM and needs the tab refreshing though it has happened when FF has been closed and I have just been looking at the desktop lol
 
Joined
Feb 6, 2021
Messages
2,920 (2.08/day)
Location
Germany
Processor AMD Ryzen 7 7800X3D
Motherboard ASRock B650E Steel Legend Wifi
Cooling Arctic Liquid Freezer III 280
Memory 2x16GB Corsair Vengeance RGB 6000 CL30 (A-Die)
Video Card(s) RTX 4090 Gaming X Trio
Storage 1TB Samsung 990 PRO, 4TB Corsair MP600 PRO XT, 1TB WD SN850X, 4x4TB Crucial MX500
Display(s) Alienware AW2725DF, LG 27GR93U, LG 27GN950-B
Case Streacom BC1 V2 Black
Audio Device(s) Bose Companion Series 2 III, Sennheiser GSP600 and HD599 SE - Creative Soundblaster X4
Power Supply bequiet! Dark Power Pro 12 1500w Titanium
Mouse Razer Deathadder V3
Keyboard Razer Black Widow V3 TKL
VR HMD Oculus Rift S
Software ~2000 Video Games
if there is nothing in the eventviewer or anything scheduled i would consider wiping that drive and reinstalling windows.
 

Count von Schwalbe

Nocturnus Moderatus
Staff member
Joined
Nov 15, 2021
Messages
3,136 (2.79/day)
Location
Knoxville, TN, USA
System Name Work Computer | Unfinished Computer
Processor Core i7-6700 | Ryzen 5 5600X
Motherboard Dell Q170 | Gigabyte Aorus Elite Wi-Fi
Cooling A fan? | Truly Custom Loop
Memory 4x4GB Crucial 2133 C17 | 4x8GB Corsair Vengeance RGB 3600 C26
Video Card(s) Dell Radeon R7 450 | RTX 2080 Ti FE
Storage Crucial BX500 2TB | TBD
Display(s) 3x LG QHD 32" GSM5B96 | TBD
Case Dell | Heavily Modified Phanteks P400
Power Supply Dell TFX Non-standard | EVGA BQ 650W
Mouse Monster No-Name $7 Gaming Mouse| TBD
Process Lasso same thing?


I would try leaving Task Manager open in the background for a while, and seeing if the usage kicks up again.

Also, perhaps Glasswire would give you insight into unauthorized programs accessing the Internet.
 

Solaris17

Super Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
27,044 (3.83/day)
Location
Alabama
System Name RogueOne
Processor Xeon W9-3495x
Motherboard ASUS w790E Sage SE
Cooling SilverStone XE360-4677
Memory 128gb Gskill Zeta R5 DDR5 RDIMMs
Video Card(s) MSI SUPRIM Liquid X 4090
Storage 1x 2TB WD SN850X | 2x 8TB GAMMIX S70
Display(s) 49" Philips Evnia OLED (49M2C8900)
Case Thermaltake Core P3 Pro Snow
Audio Device(s) Moondrop S8's on schitt Gunnr
Power Supply Seasonic Prime TX-1600
Mouse Razer Viper mini signature edition (mercury white)
Keyboard Monsgeek M3 Lavender, Moondrop Luna lights
VR HMD Quest 3
Software Windows 11 Pro Workstation
Benchmark Scores I dont have time for that.
Not sure why wiping the game drive would be relevant. It seems this is more of a mind game than an actual virus at this point. I’d wipe it and just be done.
 
Joined
May 7, 2023
Messages
670 (1.15/day)
Processor Ryzen 5700x
Motherboard Gigabyte Auros Elite AX V2
Cooling Thermalright Peerless Assassin SE White
Memory TeamGroup T-Force Delta RGB 32GB 3600Mhz
Video Card(s) PowerColor Red Dragon Rx 6800
Storage Fanxiang S660 1TB, Fanxiang S500 Pro 1TB, BraveEagle 240GB SSD, 2TB Seagate HDD
Case Corsair 4000D White
Power Supply Corsair RM750x SHIFT
Process Lasso same thing?


I would try leaving Task Manager open in the background for a while, and seeing if the usage kicks up again.

Also, perhaps Glasswire would give you insight into unauthorized programs accessing the Internet.
It doesn't happen if TM is running, usually use process lasso tbh though it's a fairly new Win10 install maybe 2-3 weeks old? so haven't got it installed. May take a look at GW


Not sure why wiping the game drive would be relevant. It seems this is more of a mind game than an actual virus at this point. I’d wipe it and just be done.
What do you mean by mind game? I just uninstalled loads of things and decided to wipe the 1 drive to rule it out incase anything may have been downloaded/stored on that drive and only then have the C: drive as the culprit, not an issue with 1Gbps internet tbh just a minor annoyance, still one I could do without, at this point I have practically deleted everything from both drives and it's clear the issue still persists despite running various AV/MW scans, getting rid of a load of installed programs, downloads, temp files and directories, common CMD prompts, selective startup, looking through services etc and yes, I agree at this point I will likely just nuke the OS and start again but that's not the point really, I want to know what is causing the behaviour

When running process explorer in the systray it stops the CPU usage spiking just as when I run it or taskmgr on the desktop, as soon as I quit the PE systray, 20 mins later which seems to be the time after using task manager type apps it starts back up again, obviously nothing shows up in either taskmgr or process explorer to pinpoint the rogue process, though it is definitely timed to start up again at a set interval and to quit as soon as any monitoring app is opened
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
42,443 (6.66/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Start fresh would be safest solution
 
Joined
Oct 22, 2014
Messages
14,142 (3.82/day)
Location
Sunshine Coast
System Name H7 Flow 2024
Processor AMD 5800X3D
Motherboard Asus X570 Tough Gaming
Cooling Custom liquid
Memory 32 GB DDR4
Video Card(s) Intel ARC A750
Storage Crucial P5 Plus 2TB.
Display(s) AOC 24" Freesync 1m.s. 75Hz
Mouse Lenovo
Keyboard Eweadn Mechanical
Software W11 Pro 64 bit
Random Docs don't download themselves.
Either you visited a dodgy site or it was an email attachment with a virus.
 
Top