Persistent GPU-Using Malware After Reinstalling Windows

0
3
Asked By MellowCedar42 On

I downloaded a file from someone on Discord after disabling Windows Defender. The next day, my GPU started reaching 100% utilization whenever the computer sat idle for about 15–20 minutes. Moving the mouse causes a blank window to briefly appear and disappear, and Task Manager shows a suspicious process called "Diniizz jpeg" running from AppDataRoamingMicrosoft. I reinstalled Windows from a USB drive and deleted everything, but the behavior still seems to be present. When the computer becomes active again, several suspicious files also disappear from that folder. Could this be a crypto miner or other malware, and what should I do to make sure the system is actually clean?

4 Answers

Answered By PixelHarbor7 On

The symptoms are consistent with a crypto-mining trojan that activates when the computer is idle. Disconnect the machine from the internet, and don’t use it for banking, email, or other sensitive accounts until it has been cleaned. From a separate, trusted device, change your important passwords and enable multifactor authentication where possible.

Answered By AmberVale55 On

If the problem survives a correctly performed clean install from freshly created media, check whether the suspicious behavior is actually coming from another drive, a restored backup, or a scheduled device utility. Disconnect secondary drives during installation and reconnect them one at a time. If it still persists with a bare, updated Windows installation, have a reputable professional examine the hardware and firmware rather than assuming the motherboard must be replaced.

Answered By KernelKite19 On

Before reinstalling, unplug the computer from the network and back up only personal documents that you can verify are safe. Avoid copying programs, installers, scripts, or unknown files. After reinstalling, fully update Windows, enable Defender again, install updates for your browser and other software, and check Task Manager and startup entries before restoring anything.

Answered By QuietMaple_83 On

A genuine clean installation should remove malware stored on the Windows drive, so the installation method matters. Create the Windows installer using another known-clean computer, boot directly from it, delete every partition on the target drive during setup, and install to the unallocated space. Don’t reuse an installer USB that may have been created or modified on the infected machine, and scan any backups before restoring them.

MellowCedar42 -

I used a USB and deleted everything, but I’m going to recreate the installer on another computer and carefully remove all the existing partitions in case I missed one.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.