VGA working 100% load when computer was left idle

Codehawx

Reputable
Dec 30, 2014
10
0
4,510
==========================================
PROBLEM IS SOLVED

It was a malware infection with the detection name of TR/Dropper.MSIL.tixlc with the file name of 'taskhost.exe'. As how the malware works, after i left the computer idle for 10-15 minutes then it ordered my GPU to be basically its slave to work hard computing something i don't know.

I scanned my whole system with Avirafree and it found that SOB as an Active Malware, quarantined it, and now the GPU is free from its chains.

Now the GPU's mine again.
==========================================


Oh hello.

I have a MSI GTX 970 Gaming 4G VGA, with triple monitor setup.

So basically when i left my PC for a couple of hours, the PC still turned on, i just left it in idle state.
However what funny here is the VGA suddenly working while there shouldn't be any processes. I don't know what the VGA's working so hard for. I don't know how to detect which program the VGA is working on (unlike CPU, i could easily trace it in task manager).

I can see that when i was working with the computer, the core clock of the VGA stays at 135 MHz, but when i left it, probably after minutes or hours of inactivity, my VGA fan starts spinning with recorded core clock of 1316 MHz, it's the same for the heat, memory clock, memory usage, everything that involves VGA increases. The GPU usage did increase to 100%.


SPEC:
Windows 8.1
i7-6700k, no overclock
ASUS Z170i Pro Gaming
RAM patriot viper 8GBx2 @2400MHz
MSI GTX 970 Gaming 4G VGA, factory overclock/boost.
Triple monitor setup with three 1920x1080 monitors
VGA driver is the latest one

Any suggestions?
Thanks in advance!
(english isn't my native lang, so excuse me)

 

Codehawx

Reputable
Dec 30, 2014
10
0
4,510


I should correct my post above. it's not power save mode, it's actually automatic monitor turn off (the setting the windows has, had set it to 10 mins).

Now it becomes weirder. I actually turned the automatic turn off monitor feature to off (so the monitor will stay on when i left the computer).

It actually worked pretty hard (100% gpu usage) when i left it. I'm not sure when it exactly started to work. But i have MSI afterburner that records my GPU activity, and it does tell me that my GPU was working really hard while i was away with the computer left idle.

gpuusage_zpsjeao6ugu.jpg

 

Codehawx

Reputable
Dec 30, 2014
10
0
4,510
alright, i found the culprit and i'm still looking at how to solve it. Probably it's a malware.... a bitcoin mining process or something that uses my GPU after it was left idle for like 10-15 minutes.

What a damned thing, it actually vanished when i pressed the printscreen button. So this thing ain't a joke.

vdsdotexeGotcha_zpsjifqcr3t.png


the process is called "vds.exe", with no description or company name. It ate 600MB of my GPU RAM, that's for sure. It also has detected I/O read activity, but with almost no I/O write activity.

searched it on google, some said it is bitcoin mining malware, but i also found that it's a just a windows's task, like in this url

http://batcmd.com/windows/8/services/vds/
 

Codehawx

Reputable
Dec 30, 2014
10
0
4,510


what do you mean by 'clear everything out'?
 

Codehawx

Reputable
Dec 30, 2014
10
0
4,510


if that means by using regular antivirus to scan and clean the virus, then i'll try to do some virus scanning then (i'll use Avira Free). It'll take hours if not days to complete i think. I'll update it when it's done.

Thank you.
 

Codehawx

Reputable
Dec 30, 2014
10
0
4,510


Hello, so i've scanned my computer with Avirafree, and actually found an "Active Malware". I hope this is a bingo, and it is.

malwarefound_zpswh3bpl92.jpg


Moved to quaratine just for test purpose.

I've left my computer for 1 hour and see no spikes nor VGA working by mysterious manner again. So i guess it's now solved. It's confirmed as malware infection.
Thank you. I'll update the first post for the record and i'll pick your post as the answer as for thanks making sure it is a malware/virus attack.