Malicious file
winserv.exe: what it is, whether it is a virus and how to remove it
winserv.exe is most often a malicious file. The old report tied it to the AudioHD.exe XMRig cryptocurrency miner, and Microsoft lists a second malicious use. A harmless Winserv service tool exists too. Judge your copy by its folder, its service and its signature, not by the name.
Prefer to do it yourself? The manual steps follow.
A winserv.exe that you did not install on purpose should be treated as malware. The old report called it the file behind a cryptocurrency miner that runs under the name WindowsHub next to AudioHD.exe, and a process that uses a large share of the processor all the time fits that description.
The name alone is not proof. A genuine utility called Winserv turns a program into a Windows service, so a copy that you or your administrator installed, in a folder you know, is not a miner. Check the folder and the service before you delete anything.
- Type
- Executable (.exe). In the old report: the file of a cryptocurrency miner (Trojan class) that works with AudioHD.exe
- Process description
- WindowsHub in Task Manager; the companion AudioHD.exe is described as XMRig, a Monero miner
- Folders reported for the miner
- %UserProfile%\AppData\Roaming\AudioHDriver\winserv.exe and AudioHD.exe, a startup shortcut AudioHD.url in the user's Startup folder, and C:\Program Files (x86)\wise\ with an uninstall entry named Wise
- Other malicious use
- Microsoft lists winserv.exe among the files dropped by Trojan:Win32/RemoteAdmin!bit, a legitimate remote administration tool turned into a backdoor, in user application data folders
- Folder in a 2023 user report
- A folder named Windows Tasks Service under ProgramData on Windows 11, where the file restarted within seconds of being stopped
- Legitimate use
- Winserv is a utility that creates a Windows service that runs any application. It is installed by an administrator, not hidden in a user data folder
- Also looked up as
- winserv, winserv exe, winserv.exe system, WindowsHub
What winserv.exe is
The old report described winserv.exe as the executable responsible for cryptocurrency mining. It runs next to a second file, AudioHD.exe, which Task Manager shows with the description XMRig, the name of a Monero miner. Winserv.exe itself shows the description WindowsHub. Both processes are visible in Task Manager.
XMRig is a genuine open-source miner and looks like legitimate software, which is what makes the infection hard to spot. Attackers install it without the owner's knowledge and take the processor time and the electricity. MITRE ATT&CK classifies this as Resource Hijacking (technique T1496): using a co-opted system to mine cryptocurrency, which can make the system and its services slow or unavailable.
A miner that works well gives itself away by load. The old report said it drains over 70% of the processor, and a 2017 removal guide said it uses the whole processor indefinitely, which keeps the CPU hot for long periods and can shorten its life. Other signs listed there: windows that minimize and maximize slowly, slower games, stuttering video and general slowness.
The name winserv.exe has more than one owner, and only the first matches the old page. First, the miner companion above (2017). Second, Microsoft's description of Trojan:Win32/RemoteAdmin!bit, which says the malware drops files such as ClassicSvc.exe or winserv.exe in user application data folders. It installs a real remote administration tool as a backdoor, with system services, registry keys and connections on TCP ports 5650 and 5655. A 2014 write-up of point-of-sale malware also listed %APPDATA%\winserv.exe among the files it wrote. Third, the Winserv utility, a tool that creates an NT service running any application.
A user report from 2023 on Windows 11 described a winserv.exe in a ProgramData folder named Windows Tasks Service. The folder opened for a moment and closed, Microsoft Defender did not detect the file, and the process restarted within about 10 seconds after it was stopped. That report did not identify the family, so treat it as a persistent copy that needs the checks below.
About .exe files. An .exe file is a program. It runs as a process you can see in Task Manager, so its name, folder and publisher are what to check.
How it arrives
The 2017 removal guide said the miner is installed through adware bundles or by trojans that download it. The old report added that crooks push miners into apps and browser extensions, and that Google Play was a popular place to hide them.
The old report also said the app that carried the miner is hard to find, because developers give the apps random names. The examples it listed were SafeBrowse, Recitiamo Santo Rosario Free, SafetyNet Wireless App and Car Wallpaper HD. Finding the source by hand is often not practical.
For the remote administration variant, Microsoft describes a spear-phishing email with a malicious Office document whose script silently installs the remote tool.
If you remember an app that you installed just before the slowdown began, uninstall it first.
How to find it
Check where the file runs from, what starts it and whether it is signed. Do these in order.
- Look at the processes Press Ctrl+Shift+Esc, open the Processes tab and sort by CPU. Look for winserv.exe (description WindowsHub) and AudioHD.exe (description XMRig). On the Details tab, right-click the process and choose Open file location to see the folder.
- Read the folder A copy in %AppData%\AudioHDriver, in a ProgramData folder named Windows Tasks Service, or in %AppData%\Remote Utilities Agent is malicious. A copy in a program folder that an administrator created on purpose, run by a service you recognize, is the harmless Winserv tool.
dir /s /b C:\*winserv.exe - Check the services Press Win+R, type services.msc and look for a service whose Path to executable ends in winserv.exe. Windows 11 and Windows 10 show the path in the service's Properties window. A service you did not create is a warning sign. Microsoft names ClassicSSvc and USBPrintManagerGrp for the remote administration variant.
sc query state= all | findstr /i "SERVICE_NAME" - Check what starts at sign-in In Task Manager open the Startup apps tab. Open the Startup folder with Win+R and shell:startup and look for AudioHD.url. In Task Scheduler (taskschd.msc) look for tasks that run winserv.exe or AudioHD.exe.
reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run - Check the signature Right-click the file, open Properties > Digital Signatures. No signature, or a signer you cannot trace to a tool you installed, is a warning sign.
Get-AuthenticodeSignature "C:\path\to\winserv.exe" | Format-List Status, SignerCertificate - Check installed apps Open Settings > Apps > Installed apps on Windows 11, or Settings > Apps > Apps & features on Windows 10. The 2017 guide listed an entry named Wise that belonged to the miner.
Task Manager shows the process but not why it exists. A copy that stops and returns within seconds is being restarted by a service, a scheduled task or a second process, so look for the second file too.
How to remove winserv.exe
Remove the miner and the things that restart it together, then scan. These steps apply to Windows 11 and Windows 10. Skip them if the check showed the harmless Winserv tool that you installed on purpose.
- Note the folders first In Task Manager, Details tab, right-click winserv.exe and AudioHD.exe, choose Open file location and write down the folders. Then choose End task on both. If they come back within seconds, continue anyway: something is restarting them.
- Uninstall the program that carried it Open Settings > Apps > Installed apps (Windows 11) or Apps & features (Windows 10). Uninstall any app you did not choose, especially an entry named Wise or the app you installed just before the slowdown. If you remember which app the miner came with, delete it right away.
- Stop and remove the service Press Win+R, type services.msc, find the service whose Path to executable is winserv.exe, open Properties, press Stop and set Startup type to Disabled. To delete it, run the command in an administrator Command Prompt, replacing the name.
sc stop ServiceName sc delete ServiceName - Remove the startup entries and tasks Delete AudioHD.url from the Startup folder (Win+R, shell:startup). In Task Manager > Startup apps disable the entry. In Task Scheduler (taskschd.msc) delete tasks that run winserv.exe or AudioHD.exe, and clear Run and RunOnce values that point to them.
schtasks /query /fo LIST /v | findstr /i "winserv AudioHD" - Delete the folders Delete %AppData%\AudioHDriver, C:\Program Files (x86)\wise, the ProgramData\Windows Tasks Service folder if present, and %AppData%\Remote Utilities Agent. If a folder will not delete or the file returns after a restart, start Safe Mode (Settings > System > Recovery > Advanced startup > Restart now > Troubleshoot > Advanced options > Startup Settings > Restart > 4) and delete it there.
rmdir /s /q "%AppData%\AudioHDriver" - Run a full Microsoft Defender scan Open Windows Security > Virus & threat protection > Scan options, select Full scan and choose Scan now. Remove what it finds. A user in 2023 reported that Defender did not flag the file, so do the manual steps above even if the scan is clean.
- Run Microsoft Defender Offline scan In the same Scan options list choose Microsoft Defender Offline scan and Scan now. The PC restarts and scans before Windows loads, which catches threats that hide from a normal scan.
- Restart and check again Restart and run the scan once more to confirm the removal worked. Then check that CPU use is normal in Task Manager, and repair system files if Windows behaves oddly.
sfc /scannow DISM /Online /Cleanup-Image /RestoreHealth - If the remote administration variant was present Microsoft advises disconnecting the PC from the network, removing the dropped files and registry keys, deleting the services, and checking for unknown user accounts such as supportaccount. From a clean device change the passwords of everyone who signed in to the PC, administrators first.
net user
Warning signs
| What you see | What it means |
|---|---|
| A process with the description WindowsHub next to AudioHD.exe (XMRig) | The pair the old report tied to the cryptocurrency miner. |
| High CPU use that does not stop when you close your programs | Mining uses the processor continuously; the old report said over 70%. |
| winserv.exe in AppData\Roaming, Remote Utilities Agent or a ProgramData folder named Windows Tasks Service | A genuine service tool is installed in a folder an administrator chose, not hidden in user data. |
| A service or scheduled task that runs winserv.exe and that you did not create | Something restarts the file on purpose, so ending the process once does not help. |
| The process returns within seconds after End task | A second process, service or task is restarting it. |
| An app you do not remember, or an uninstall entry named Wise | The 2017 guide listed it as part of the miner's install. |
| A fan that runs hard, a hot laptop, slow windows and stuttering video | Symptoms of a processor that is working for someone else. |
Questions people ask
Is winserv.exe a virus?
In most cases yes. The old report described it as the file behind a cryptocurrency miner that runs as WindowsHub next to AudioHD.exe (XMRig), and Microsoft lists a winserv.exe dropped by a remote-access trojan. A harmless Winserv tool also exists, so check the folder, the service and the signature before you decide.
How do I tell a real winserv.exe from the malicious one?
Look at the folder first. The harmless Winserv utility is installed by an administrator in a program folder and runs as a service you named. The malicious copies reported sit in AppData\Roaming, a Remote Utilities Agent folder or a ProgramData folder named Windows Tasks Service. Then check the service name in services.msc and the digital signature on the file.
Why does winserv.exe run as SYSTEM?
Because a Windows service runs under the SYSTEM account by default. A winserv.exe that shows SYSTEM as the user was started by a service, which is how the harmless Winserv tool works and also how Microsoft describes the remote-access trojan keeping itself alive. Open services.msc, find the service that points to the file and read its folder.
Why does winserv.exe use so much CPU?
Because the miner companion works out cryptocurrency blocks for the attacker, which keeps the processor busy all the time. The old report said it drains over 70% of the processor. Slow windows, slower games and stuttering video are the usual signs. Closing your programs does not lower the load, because the miner is not one of them.
I cannot delete winserv.exe, it comes back. What do I do?
Something restarts it, so deleting the file is not enough. Stop and delete the service in services.msc, remove the scheduled task and startup entries, and delete the parent folder. If it still returns, do this in Safe Mode, then run a full and an offline Microsoft Defender scan. A user in 2023 reported it restarting within about 10 seconds.
What is brhosthelper and is it related to winserv.exe?
We found no source that links brhosthelper to winserv.exe. People search for the two names together, but nothing we read connects them. If a file called brhosthelper runs on your PC, check its folder, its service and its signature in the same way as above, and scan it with Microsoft Defender.
How did the miner get on my PC?
The 2017 removal guide said such miners arrive through adware bundles or trojans that download them. The old report added that miners hide in apps and browser extensions under random names. If you remember an app you installed just before the slowdown, uninstall it, and install apps only from the publisher's own site or a store you trust.
How do I stop miners coming back?
Remove the app that carried the miner, keep Microsoft Defender and Windows updated, and install browser extensions only from known publishers. The old report warned that ratings in an extension store can be faked, so read independent reviews, and that a copy of a genuine tool can be a malicious clone. Restart after the scan and scan again to confirm.
Sources
- Winserv.exe and AudioHD.exe CPU miner (XMRig) removal guide, 17 October 2017
- Microsoft Security Intelligence: Trojan:Win32/RemoteAdmin!bit
- MITRE ATT&CK: Resource Hijacking (T1496)
- Microsoft Q&A: Removal of winserv.exe file (November 2023)
- Winserv, a utility that creates an NT service running any application
- Backoff point-of-sale malware indicators, including %APPDATA%\winserv.exe (2014)
Version data read on Oct 10, 2026.
Questions and experiences
Ask about this page: members and our editors answer. Reading is open; writing needs a free account.
…