简体   繁体   中英

Antimalware Service Executable uses High CPU and blocks running IIS .Net Core App

I have a.Net Core API on Windows server 2019 VPS, its been two days now as and when request comes to API 'Antimalware Service Executable' kicks in to scan the app, this leads to high CPU use as well as API is not able to respond to any request, every request gets failed until the scan is over and the scan takes hours to finish.

have tried re-deploying the app after emptying the directory and still the issue exists. There are other small console apps that exist on the same server has no issue at all. can anyone help me with what could be wrong here that suddenly changed the behavior of the Antimalware?

任务管理器

Update: This issue is not specific to.Net Core but i have deployed.Net Framework API on the same server for testing and as soon sends a request to the new API Antimalware kicks in and IIS Worker Process takes about 34% CPU and 66% by Antimalware, this seems not specific to API instead related to IIS process, has anyone had similar situation with Windows Defender on Win Server 2019? Further i have scanned entire server with 'Microsoft Safety Scanner' and found 0 infected file also tried SFC /Scannow have completed without finding any issue.

See if this fix helps you:

https://www.kapilarya.com/fix-antimalware-service-executable-msmpeng-exe-high-cpu-usage

I see that someone has solved this issue, unfortunately no sources online tell you this incredibly common sense tool given by Windows Defender. When you enter Windows Defender you will see a long list of malware that the system has detected. If you read where this malware leads to/what the program is named you'll find the source of the issue.

Finally, the issue has been resolved by restoring Firewalls settings to default. not sure what magic was but did a restore and Antimalware CPU usage has reduced to 3% and that is also occasionally. yes, obviously I had to do all the required firewall custom settings once again, I did not export and import the policy as that might bring those wrong config again in.

在此处输入图像描述

The technical post webpages of this site follow the CC BY-SA 4.0 protocol. If you need to reprint, please indicate the site URL or the original address.Any question please contact:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM