Hi All,

FTP, was recomended to come to this forum after unsuccessfullying trying to log a job with microsoft support.

Please describe the issue in 2-3 sentences. Include what you’re trying to accomplish when the issue occurs.
High CPU usage on terminal server hosting published application. Makes pubapp unusable for end users.

When did it begin and how often does it occur?
Not sure exactly when this began, this seems to be resolved by a restart but within about 5 or so mins, the CPU usage gets stuck at ~99%

What errors do you see?
High CPU usage (~99%), Sluggish response via console and pubapp almost unusable for end users.

In task manager high CPU usage seems to be caused by
dcom server process launcher
service host local system network restricted
service host

What’s the environment and are there recent changes?
Virtual server on vsphere nutanix, nil recent changes - ongoing issue

What have you tried to troubleshoot this?
Restarting server - seems to resolve issue for around 5mins or so
Clearing user profiles - nil inprovement
sfc scan now
dsim reg check
Attempted to run Windows performance log to get a file for you but I get the attached error when trying to save the log and it won’t let me proceed further.

Capture.png

7 Spice ups

Have you got AV exceptions in place? Terminal Server AV Exceptions

Also I’d run all Windows Updates and see if there is any improvement from there?

1 Spice up

There are a few questions like :

  • What is the OS ?

  • What are the applications installed ? Were they installed with Terminal server mode enable (change user /install & change user /execute)

  • What is the AV or security installed ? Are they for use with Terminal servers ?

  • Does the issue happen with or without users ? Eg. If you reboot the server at 1am, does the CPU increase significantly till 8am ? Or if you reboot at 1am, the issue starts after 9am when users start to login ?

  • What are the specs of the server ?

  • Are there mapped drives ?

  • When the issue occurs, what are the applications that use the most CPU & RAM resources. How much RAM is free, available & cached ?

I’d also recommend booting the server without networking to see if it’s network related in some way, could be a misbehaving client connection. Might explain the startup delay.

Edit: Welcome to Spiceworks :slight_smile:

Event Viewer? What happens at around the 5 minute mark?

In Task Manager under Details, for each of the high-CPU service hosts, right-click and Go to service(s); this will highlight all the services running under that service host.

Note those down and google / list them here.

e.g. if “wuauserv” (Windows Update) is among them then it’s pretty likely that’s the culprit.

This could my my paranoia or just my job, but the first thing I think of when I hear this is crypto mining. I would look to isolate the server, restart in Safe mode and run a full AV scan.

1 Spice up

We use cisco umbrella, given I haven’t seen any cryptomining blocks I would doubt it. But thanks for your insight.

Thanks @bengreen2 ​, services are as follows:
SystemEventsBroker
Power
PlugPlay
LSM
DcomLaunch
BrokerInfrastructure

Worked it out in the end. Was Duo MFA that was auto installed that was causing high CPU usage

1 Spice up