• Happy holidays, folks! Thanks to each and every one of you for being part of the Tom's Hardware community!

Random 100% Disk Usage spikes and extremely slow boot up time

Ninety_1

Commendable
Sep 15, 2016
5
0
1,510
I am going to copy and paste with a few edits from another post from another site:


I am not sure what is happening besides the fact that when I checked Resource Monitor at the time in which this was happening, I noticed either svchost.exe or MsMpEng.exe was hogging my disk usage.

Here's all the events leading up to me writing this post:

Note: Everything prior to this was working fine so I assumed it was a virus. I am also on Windows 10. I initially had installed AVG Free Antivirus and was working fine while I had it. I am also on desktop.

While I was playing Rainbow Six: Siege (I was running the game fine with little problems) with my friend, and I noticed how the game just did not bother to load into another round during the session. My computer was not even responding and I could barely tab out. Everything on my computer was not responding and even my mouse froze every couple of seconds. However, the problem went away after let's say 10-30 minutes. So I assumed the game was giving me problems so I decided to stop playing it for the whole week.

Unfortunately, the game did not seem to be the underlying factor. At random times, even when I am merely moving the mouse on the desktop, I would get the same problem. At best it would last about 5-10 minutes. At worst it could have lasted a whole 30 minutes or more.

So I checked Task Manager. I see that the disk usage is at a 100%. Initially, when I first skimmed through the processes, nothing of significance was using the disk. However, one service caught my eye and that service was named Antimalware Executable. I uninstalled AVG to see if it did anything, but unfortunately, it did not. So I looked online, a forum post advised me to check Resource Monitor while the problem was occurring. It took a while, but once my computer slowly opened it up, it showed 2 things that seemed to have been the culprit. MsMpEng.exe and svchost.exe. They're both normal processes at surface value but this was not a normal situation because they were both hogging my disk and making my computer unusable at random and sometimes awful times. This was not normal because these same processes have been running in the background for very long without any problems, yet suddenly they decided to work together to slow down my computer.

I also noticed one more thing that might be related: My computer boots take about 30 minutes to an HOUR to even get to the desktop screen. I disabled many start up applications to alleviate this but I assume that due to whatever is beating on my computer is likely slowing the crap out of my boot times.

Please also note that I have considered to be a hardware problem. But, since my computer works perfectly at the times in which the disk is not being hogged, it likely should not be a hardware problem.

These are the several things that I have tried (bear with me because I might have missed some attempted solutions since I am recalling from the top of my head):

1. Turning off real-time protection on Windows Defender

2. I attempted disabling Windows Defender through regedit through no avail whatsoever.

3. I have tried fixing my registry

4. I have changed the Windows Defender's scheduling through Task Scheduler

5. I ran a full scan on Windows Defender because of a past subreddit post advised me to. Windows Defender had told me I had 2 threats after I woke up in the morning. Windows Defender removed the threats. Yet, this had no effect on the problem either.

6. I put MsMpEng.exe on the exclusions list

7. I have installed an antivirus program yesterday (Avast Free) to see if it can find anything that Windows Defender could not pick up. I ran a full scan and it did not find anything. However, I did notice that Antimalware Executable has been removed from the process list. I have not checked the resource monitor to see if MsMpEng.exe is still a problem, but I will assume (for now) that it's not the issue because it is only a component of Windows Defender.

8. I have tried MalwareBytes (found items that avast did not pick up), Rkill, KVRT, and Tronscript in safe mode. The last 3 did not find anything or delete the culprit.

EVEN WITH ALL of these attempts, they had no effect. It still sporadically slows down my computer and I have no clue what to do at this point.

But, I would like to point out the things that I have not done:

1. I have not tried any command prompt commands that involves the disk.

2. I have not tried resetting my PC (I want this to be the last resort and I am afraid that it might not work).

3. There are also several other methods that I could not remember and cannot find again.

One thing I noticed and found something else recently in the process list and it has no name. It's under Windows Processes and there are sometimes 2 or more of the process. When I try to end the task it shows up as (null) and I can't end this task because it's apparently a part of Windows. I went to details and it showed up as svchost.exe. This is weird because the "System" process is also taking up 100% disk usage which is also svchost.exe. I cannot delete this process and its PID changes each time. It also suspends itself before shutting down. I honestly think this is the culprit because it always shows up whenever the disk usage spikes.

I also have not seen any pattern in which this occurs, it can happen when I am merely browsing or it can happen when I am playing a game.

Your help will be greatly appreciated.


 
Solution
Right click on the blank process and select 'Open file location'
What's the name of the file and where is located?

Just in case, run a full malware scan using Malwarebytes free edition.
MsMpEng.exe is a component of Windows Defender, the anti-virus product from Microsoft. It calls a svchost.exe while running scanning your PC.
You should not turn it off or mess with it, unless you have a third-party antivirus installed ( e.g. Avira, AVG, Bitdefender, etc...), in that case, Windows Defender turns itself off automatically.
 


Yes, I'm aware that those processes are normal. However, this situation itself is not. There should not be a null process under windows processes at all. Again, the System process (svchost.exe) should not be taking up 100% of my disk usage as it never happened before, same with MsMpEng.exe.

Now I also noticed something different, since I installed a third-party antivirus, MsMpEng.exe no longer is being used. So whenever this problem occurs, it seems to make my antivirus ALSO use 100% disk usage.

Whatever this problem is, it's making it so that EITHER the System process or my Antivirus program take up 100% disk usage. This null process (named svchost.exe when I go to the null process's details) is ALWAYS up whenever this problem occurs. It's either a virus that's really good at making itself hidden or something else. I am not sure on how to fix this or just simply how to identify the exact problem, and that's why I need help.

EDIT: If you really need me to take screenshots, I will post it once it occurs again because that is the only time when the null process shows up.
 


I don't know what do you refer to, when you say "a null process".

Svchost.exe is not a "null process" and if you look at the Windows 10 processes you could have more than 50 running at any given time.
Some Windows services run from EXE files (e.g. MsMpEng.exe) but when a DLL functionality is needed by a program then an internal Windows services (e.g. Svchost.exe) DLL file start.

Open Task Manager, click the 'Processes' tab and when you see the Svchost.exe running at 100% right click it and select 'Expand'.
You will see the process running under 'Svchost.exe'
You could also use 'Process Explorer' (an advanced Windows Task Manager) so you can find out which files or DLLs have open and their location.
It's very usefull finding processes which are consuming a lot of system resources.

 


Sorry that it was not clear at first. I am talking about this: https://i.imgur.com/7o51cV5.png (the highlighted process). It's blank. When I try to end it, it says (null) process and it tells me it would shut down if i do end it. I could only make one screenshot because it's insanely hard to even do while this occurs so I will do the best I can to explain clearly as to what I saw.

The blank process does not use a significant about of disk usage, but the process shows up when the disk usage spikes. Not much information is shown about this specific process when I look it up on Process Explorer (I used the PID to find it).
 
If none of those others work, check your hard drive somewhere. If the drive is 5400RPM its gonna be a different problem.

EDIT: Has happened to me on a laptop with 5400RPM drive.