Cryptominers on Windows: signs, hiding tricks and removal

•Malware•Ugnius Kiguolis

A hidden cryptominer uses your PC's processor or graphics card to mine cryptocurrency for someone else, so the PC runs slow, hot and loud even when you are not using it. Many miners stop as soon as you open Task Manager, so the most reliable checks are idle usage over time, scheduled tasks and Windows Security exclusions, followed by an offline scan.

What a cryptominer is and why criminals use your PC

Mining is the computing work that some cryptocurrencies pay for. Anyone can do it with the right software; the reward is small compared with the cost of electricity and hardware. Cryptojacking removes the cost for the attacker: the software runs on thousands of other people's PCs, and the coins go to the attacker's wallet.

The currency is usually Monero, because it can be mined efficiently on ordinary processors and its transactions are hard to trace. Many malicious miners are built from open-source mining software, frequently XMRig, with the settings changed to hide it and point it at the attacker's wallet.

Microsoft makes a useful distinction. A mining program you installed on purpose is not malware; Defender may still flag it as a potentially unwanted application (PUA or PUAMiner) because it uses so many resources. A miner that arrived without your consent, hides and restarts itself is malware, detected under names such as Trojan:Win32/CoinMiner.

Miners are listed under the Malware rubric on this site.

How miners get onto a PC

  • Cracked games, repacks, cheats and activators. The most common route on home PCs, and gaming PCs are attractive because of their graphics cards. See cracked software and keygens.
  • Loaders. A trojan already on the PC installs a miner because it pays steadily. A miner is often a sign that something else got in first. See trojans and loaders.
  • E-mail attachments and malicious documents that run scripts and download a miner, as Microsoft describes in its coin miner overview.
  • Fake software downloads and bundles from unofficial download sites.
  • Worms on USB drives or networks, some of which carry miners. See worms and file infectors.
  • Websites that mine in the browser. A script on a page uses your processor while the tab is open. It stops when you close the tab and installs nothing, but a browser extension can do the same on every site.

Signs of a hidden miner on Windows

  • Fans spin loudly and the case or laptop gets hot when nothing is open, especially a few minutes after you stop using the PC.
  • The PC feels slow, games stutter or drop frames, and video calls lag, without a clear reason.
  • A laptop's battery drains much faster than it used to.
  • Task Manager > Performance shows CPU or GPU use staying high (tens of percent) when the PC is idle.
  • A process with a Windows-like name (svchost.exe, conhost.exe, explorer.exe, dllhost.exe) or a vague one (Runtime Broker, System Host, Windows Update Service) uses a lot of CPU or GPU and runs from an unusual folder.
  • Fans calm down the moment you open Task Manager, then speed up again after you close it.
  • Windows Security shows exclusions you did not add, or detections of CoinMiner or PUAMiner in Protection history.
  • The electricity bill rises, or a desktop PC never goes to sleep any more.

None of these signs alone proves a miner. Windows Update, indexing, antivirus scans and cloud sync also use the processor for a while, especially after startup. A miner's use is long, steady and returns every time the PC is idle.

How miners hide from you

Miners only pay while they run unnoticed, so most of the code that is not mining is about hiding.

  • Stopping when Task Manager opens. The miner watches for Taskmgr.exe, Resource Monitor, Process Explorer and similar tools, and pauses or exits when one starts. It resumes a minute after the tool closes.
  • Working only when you are away. It checks for mouse and keyboard activity and mines only after a few minutes of idle time, or when the screen is locked.
  • Pausing for games. Some stop when a full-screen game runs, so that you do not notice frame drops.
  • Limiting itself. It uses only part of the processor so that the fans do not give it away.
  • Borrowing names and folders. It names itself after a Windows process, or injects into a genuine one such as explorer.exe or svchost.exe, so the busy process looks legitimate. How to tell a real one from a fake: is a Windows process genuine?
  • Restarting itself. A scheduled task, a service or a startup entry starts it again after every reboot and every time you end it; a watchdog process may restart it within seconds.
  • Blinding the antivirus. It adds its folder to Defender exclusions, blocks security sites in the hosts file, or turns protection off where it can.
  • Changing power settings so that the PC does not sleep and keeps mining overnight.

How to check whether a miner is running

These checks use only tools built into Windows 11 and Windows 10.

  1. Listen first. Leave the PC idle with nothing open for ten minutes. If the fans spin up, open Task Manager (Ctrl + Shift + Esc) straight away and look at Performance: a miner that pauses needs a few seconds to stop, so you may still see a peak.
  2. Look at the graph, not the number. In Performance, the CPU and GPU graphs show the last minute. A sudden drop at the moment you opened Task Manager is suspicious.
  3. Find the busy process. In Processes, sort by CPU or GPU. Right-click anything unknown and choose Open file location. Windows processes live in C:\Windows and C:\Windows\System32, not in %AppData%, %Temp% or C:\ProgramData with a random folder name.
  4. Check Windows Security exclusions. Open Windows Security > Virus & threat protection > Manage settings > Add or remove exclusions. An exclusion for a folder you never added is a strong sign of malware.
  5. Check Protection history in the same app for CoinMiner, Miner or PUAMiner detections, especially ones that come back.
  6. Check scheduled tasks. Open Task Scheduler and look in Task Scheduler Library for tasks with random names, tasks that run at every logon or every few minutes, and actions that start powershell, cmd, wscript or a program in %AppData% or C:\ProgramData.
  7. Check startup entries in Task Manager > Startup apps (on Windows 10, the Startup tab).

Do not delete Windows files or system tasks you are unsure about. Write down the name and path, and let the scans below decide.

How to remove a cryptominer

  1. Turn protection back on. In Windows Security > Virus & threat protection > Manage settings, switch on Real-time protection, Cloud-delivered protection and Tamper Protection, and remove exclusions you did not add.
  2. Uninstall the program that brought the miner, such as a cracked game, a repack or a "free" tool, sorting Installed apps by date: Uninstall a program or app in Windows On uGetFix.
  3. Run a full scan, then an offline scan. The offline scan starts before Windows, so a miner that hides from running tools cannot interfere: Run a Microsoft Defender Offline scan.
  4. Remove leftovers: the scheduled task, service or startup entry that restarted the miner. Startup entries: Stop apps from opening at startup On uGetFix. If the miner changed the hosts file to block security sites: Restore the hosts file.
  5. Check the browser. A mining or ad-injecting extension needs removing separately: Remove a browser extension.
  6. Check the result. After a restart, leave the PC idle for ten minutes. CPU use should settle at a few percent and the fans should be quiet.

If you cannot remove it because it restarts instantly, start Windows in Safe Mode, which loads only basic drivers and services, and run the scan from there: Start Windows or a Mac in Safe Mode On uGetFix.

What else to check after a miner

A miner on its own steals electricity and hardware time, not data. The problem is how it arrived. The cracks, loaders and worms that deliver miners also deliver information stealers, and some miner packages include a stealer or a remote access component.

If the miner came with a crack or you do not know how it got in, change your important passwords from another device and sign out of all sessions: securing your accounts after malware. If other PCs on the same network or USB drives are involved, scan them too.

Heavy mining runs components hot for long periods. Once the miner is gone, check that fans and temperatures are back to normal; a laptop that ran hot for months may also need its vents cleaned.

If scans keep finding miners again after each clean-up, something else on the PC is reinstalling them. That is the point where resetting Windows is faster than chasing them.

How to keep miners off your PC

  • Download games and programs only from official stores and developers' sites. Avoid repacks, cracks, cheats and "free full version" downloads.
  • Keep Potentially unwanted app blocking on in Windows Security > App & browser control > Reputation-based protection settings. It catches unwanted miners and the bundles that carry them.
  • Leave Tamper Protection on, so that malware cannot quietly switch Defender off or add exclusions.
  • Keep Windows, browsers and graphics drivers up to date.
  • Use a standard account for everyday use, so that programs need approval before they install services and tasks.
  • Install browser extensions only from the official Chrome Web Store, Edge Add-ons or Firefox Add-ons, and only ones you need.
  • Never run a command that a website asks you to paste into Windows: fake CAPTCHA and ClickFix pages.

Common myths about miners

  • "Task Manager shows nothing, so there is no miner." Many miners stop when Task Manager opens. Watch idle behaviour and check scheduled tasks and exclusions instead.
  • "A miner is harmless because it does not steal data." The miner may not, but the thing that installed it often does.
  • "High CPU means a virus." Updates, indexing, scans and sync use the CPU too, for a while. A miner's load is long and returns whenever the PC is idle.
  • "My PC is too old to be worth mining on." Attackers do not pay for the hardware, so every PC adds a little. Old and slow PCs are infected too.
  • "The website that mined in my browser infected the PC." Browser mining stops when the tab closes. Only an extension or a program keeps it going.

Frequently asked questions

How do I know if a crypto miner is on my PC?

Leave the PC idle with nothing open for ten minutes and listen. Fans that spin up, a hot case and a battery that drains fast are typical signs. Then open Task Manager and look at Performance: CPU or GPU use that stays high when idle, or a graph that drops sharply the moment you open Task Manager, is suspicious. Check Windows Security for exclusions you did not add and for CoinMiner detections in Protection history, and look in Task Scheduler for tasks with random names that start PowerShell or a program in AppData. A Microsoft Defender offline scan usually finds the miner itself.

Why does the high CPU usage disappear when I open Task Manager?

Because many miners are written to do exactly that. They watch for Task Manager, Resource Monitor, Process Explorer and similar tools, and pause or close as soon as one starts, then resume a minute after you close it. Some also mine only when the mouse and keyboard have been idle for a while. This behaviour is a strong sign of malware, since legitimate programs have no reason to hide from Task Manager. Check scheduled tasks and Windows Security exclusions, then run a Microsoft Defender offline scan, which works before Windows starts so that the miner cannot react.

Is it a miner or just Windows doing updates?

Windows Update, search indexing, Defender scans, OneDrive sync and driver installs all use the processor, mostly in the first minutes after startup or after an update. That load drops within a while and is shown under names you can trace to Windows or a known program. A miner's load is long and steady, comes back every time the PC is idle, and often belongs to a process in an odd folder or vanishes when you look. If the busy process opens to C:\Windows\System32 and has a valid Microsoft signature, it is Windows; if it opens to AppData or ProgramData with a random name, scan the PC.

Can a crypto miner damage my computer?

It does not destroy hardware directly, but it runs the processor and graphics card hot for long periods, which shortens fan life, adds dust and wear, and raises your electricity use. Laptops suffer most, because their cooling is limited and batteries age faster when hot. The larger risk is what came with the miner: cracks and loaders that install miners often install information stealers and remote access tools too. After removing a miner, check that temperatures return to normal and change important passwords if you do not know how the miner got in.

Will Microsoft Defender remove a crypto miner?

Usually, yes. Defender detects many malicious miners as Trojan:Win32/CoinMiner and unwanted ones as PUA or PUAMiner, provided real-time and cloud-delivered protection are on and the miner has not added an exclusion for itself. Check exclusions first, then run a full scan and an offline scan, which catches miners that hide while Windows runs. Afterwards, look in Task Scheduler for a leftover task, because a task that downloads the miner again can survive a clean-up. If idle CPU use is back to a few percent after a restart, the miner is gone.

Can a website mine cryptocurrency on my computer?

Yes, while the page is open. A mining script on a website uses your processor in the browser tab; Microsoft describes this browser-based mining in its coin miner overview. It installs nothing and stops when you close the tab. If high CPU use continues with every tab closed, or the browser is busy on every site you visit, the cause is an extension or a program instead. Remove extensions you do not recognise and keep SmartScreen or Safe Browsing on, which blocks many known mining and malicious sites.

About the author

Ugnius Kiguolis, Owner and editor of 2-spyware.com. Ugnius Kiguolis owns and edits 2-spyware.com and is responsible for its Windows security guides. Every page he signs is checked against current vendor, law-enforcement and Microsoft sources before it is published and again when the facts change.

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year