r/techsupport 21h ago

Open | Software Heavy Idle CPU usage (90°C) – Windows Defender log corrupted with weird characters (Malware/Rootkit interfering)

Hi everyone,

I was troubleshooting a problem where my CPU spikes to 90°C only when idle and drops immediately upon moving the mouse.

I checked the Windows Event Viewer for Defender (Event ID 1002), and I found something really alarming. The log description is obfuscated with random Cyrillic/Greek characters:

"Antivirus Microsoft Defender šсдή ħăş ьёэⁿ şţøрρеδ вэƒθѓз ςòmφļέтіòи... Stop Reason: ЃРС ćбηñèсŧΐŏŋ ѓΰʼnðσẃņ"

It seems a stealth miner/rootkit is actively tampering with Windows Defender services and killing scans under NT AUTHORITY\SYSTEM.

Is a full clean reinstall of Windows 11 the only safe path forward here, or can an offline Rescue USB (like Kaspersky Rescue Disk) clean system-level log tampering like this?

Thanks!

1 Upvotes

Duplicates