I downloaded a file from someone on Discord after disabling Windows Defender. The next day, my GPU started reaching 100% utilization whenever the computer sat idle for about 15–20 minutes. Moving the mouse causes a blank window to briefly appear and disappear, and Task Manager shows a suspicious process called "Diniizz jpeg" running from AppDataRoamingMicrosoft. I reinstalled Windows from a USB drive and deleted everything, but the behavior still seems to be present. When the computer becomes active again, several suspicious files also disappear from that folder. Could this be a crypto miner or other malware, and what should I do to make sure the system is actually clean?
4 Answers
The symptoms are consistent with a crypto-mining trojan that activates when the computer is idle. Disconnect the machine from the internet, and don’t use it for banking, email, or other sensitive accounts until it has been cleaned. From a separate, trusted device, change your important passwords and enable multifactor authentication where possible.
If the problem survives a correctly performed clean install from freshly created media, check whether the suspicious behavior is actually coming from another drive, a restored backup, or a scheduled device utility. Disconnect secondary drives during installation and reconnect them one at a time. If it still persists with a bare, updated Windows installation, have a reputable professional examine the hardware and firmware rather than assuming the motherboard must be replaced.
Before reinstalling, unplug the computer from the network and back up only personal documents that you can verify are safe. Avoid copying programs, installers, scripts, or unknown files. After reinstalling, fully update Windows, enable Defender again, install updates for your browser and other software, and check Task Manager and startup entries before restoring anything.
A genuine clean installation should remove malware stored on the Windows drive, so the installation method matters. Create the Windows installer using another known-clean computer, boot directly from it, delete every partition on the target drive during setup, and install to the unallocated space. Don’t reuse an installer USB that may have been created or modified on the infected machine, and scan any backups before restoring them.

I used a USB and deleted everything, but I’m going to recreate the installer on another computer and carefully remove all the existing partitions in case I missed one.