Is Your PC Secretly Mining Crypto? Signs & Removal (2026)

Logeshwaran
—

Is your PC secretly mining cryptocurrency for someone else? It is a real and surprisingly common condition, and the check takes two minutes: press Ctrl + Shift + Esc for Task Manager, click the CPU column to sort, and watch with everything closed — an idle PC should idle. Sustained high CPU or GPU load from a process you don't recognize, fans roaring at a desktop doing nothing, is the signature of cryptojacking: malware that mines coins on your hardware and your electricity bill. It is also a sign of how the malware business changed — modern intruders often steal nothing from your disk at all; they steal your power and your PC's lifespan instead, quietly, for months. Your fans are the alarm most people ignore.

⚡ Quick Answer

• Check → Task Manager → sort by CPU and GPU → an idle PC pinned high by an unknown process = suspect.

• Remove → full Defender scan, then an offline scan — miners often travel with friends.

• #1 way they get in → cracked software and fake installers. The "free" game pays for itself with your power bill.

Loud fans alone prove nothing — the honest differential is here (dust is innocent until proven guilty).

Jake met his favorite specimen in a gaming PC that had "aged overnight." The customer's story: games stuttering, fans screaming even at the desktop, the room noticeably warmer — and, mentioned as an afterthought, an electricity bill that had crept up enough for his dad to comment on it. The machine's story, via Task Manager: GPU parked at full load around the clock, working for a process with a name like a keyboard sneeze, which had arrived — the timeline matched perfectly — inside a cracked game installer a few weeks earlier. The PC wasn't aging. It was moonlighting.

Ethan: "Someone moved a small factory into your garage. They don't touch the car, they don't enter the house — they just run their machines off your power meter, day and night, and let your equipment absorb the wear. It is the politest burglary ever invented, and the giveaway was never a broken lock. It was the humming."

Cryptojacking: the theft with nothing missing

Mining cryptocurrency is, mechanically, paying electricity to run computations for coin rewards — profitable only when someone else pays the power bill. That economic fact created cryptojacking: infect thousands of ordinary PCs, point their CPUs and GPUs at mining, collect the coins centrally. From the attacker's chair it is the ideal crime — no ransom negotiation, no stolen-card fencing, just a silent revenue stream — and the victim's losses are real but diffuse: a fatter power bill month after month, a hotter and slower machine, fans and thermal paste aging years in months. Nothing is "missing," so nothing gets reported. Which is exactly why knowing the signs matters more here than for any louder kind of malware.

The 2019 story this page grew from (and its embarrassing lesson)

The original version of this page reported Plurox, a backdoor-plus-worm researchers caught spreading that year: it picked the most profitable miner for each infected machine's hardware and hopped across local networks using EternalBlue — the same leaked exploit behind 2017's WannaCry catastrophe. Sit with the timeline: by the time Plurox was crawling through networks in 2019, the patch for EternalBlue had existed for over two years. Every machine it claimed was a machine somebody had left unpatched through the loudest possible warning. That is the evergreen lesson hiding in the dead news, and it is why the prevention section below starts with the least glamorous advice in security — the one delivered monthly in our Patch Tuesday coverage.

The five signs of a moonlighting PC

One: fans running hard while the machine is idle — the classic. Two: everything feels slower, because your programs are competing with a miner for the same processor. Three: heat — a hot case, a hot room, a laptop that cooks knees at the login screen. Four: on laptops, battery life falling off a cliff, since mining drinks watts. Five: the slow one nobody connects — the electricity bill, which on a mining GPU can quietly grow by real money every month. No single sign convicts (heat has innocent causes; see the differential below) — but two or more together, appearing after some download you half-remember, is a pattern worth two minutes of Task Manager.

The Task Manager check, done properly

  1. Close everything you opened. Press Ctrl + Shift + Esc, and click More details if the compact view appears.
  2. On the Processes tab, click the CPU column header to sort heaviest-first. Watch for a minute: an idle PC should sit in the low single digits with only familiar names on top.
  3. Repeat with the GPU column — miners love graphics cards; sustained high GPU load on an idle desktop is deeply suspicious.
  4. Know the trick smarter miners play: some pause the moment Task Manager opens and resume when it closes. So also use the sneak test — a silent room and an ear for fans that spin down suspiciously fast when you start looking, plus the signs above over days, not seconds.
  5. Found a mystery process pinning the machine? Note its exact name (right-click → open file location tells you more), and move to removal — do not just End Task and call it cured; miners reinstall themselves at reboot.

Removal: evict the factory, then change the locks

  1. Full scan first: Windows Security → Virus & threat protection → Scan options → Full scan. (App won't open? The command-line routes drive the same engine.)
  2. Then the offline scan: same Scan options → Microsoft Defender Offline scan — the PC reboots into a clean environment where hiding malware can't hide. Miners like Plurox arrive as backdoors with company; this pass catches the shy ones. (Full offline-scan guide here.)
  3. Check the startup list: Task Manager → Startup apps → disable anything you cannot name. Miners persist by riding your boot.
  4. Delete the source — the crack, the "installer," the too-good download the timeline points at. Removing the miner while keeping its delivery vehicle is evicting the tenant and leaving the key under the mat.
  5. Change important passwords from a clean device if the infection came via a backdoor-style package — miners are often one payload among several, and assuming the polite burglar came alone is optimism, not analysis.

The honest differential: loud fans have innocent explanations

SymptomMining looks likeInnocent twin
Loud fansRoaring at idle, CPU/GPU pinned in Task ManagerDust-clogged cooling — loud even at LOW usage numbers
Sudden slownessConstant, with the mystery process on topUpdates installing, browser with 60 tabs, aging drive
High CPU brieflySustained for hours, every dayIndexing, antivirus scans, update work — bursts that end
Hot laptopHot while "doing nothing"Blocked vents, soft-surface use, summer
Fat power billPC-shaped: started when symptoms didA/C season, rate changes, the new appliance

The deciding witness in every row is Task Manager's numbers, not the noise. Loud fans with low usage numbers is a cleaning problem — a can of compressed air, not a malware scan. Loud fans with pinned usage and a stranger's name on top is this page's business.

How miners get in

Four doors, in order of traffic. Cracked software and keygens — overwhelmingly the champion; a miner bundled with a popular crack monetizes every "free" download, and the installer's instructions to disable your antivirus first are the miner clearing its own path (the same confession we flagged in the Mac malware guide — the trick is cross-platform). Fake installers and fake updates from ad-ranked download pages. Worms on unpatched machines — the Plurox route: no click required, just a missing two-year-old patch. And rogue browser extensions, mining while the browser lives — worth remembering that in-browser mining's industrial era actually ended back in 2019 when Coinhive, the service that powered it, shut down; today's browser-side offenders are stragglers, and modern browsers block most of them outright.

Prevention: three boring habits beat one dramatic cleanup

Patch — Plurox's whole career ran on a fix people skipped for two years; staying current amputates the worm route entirely. Don't run cracks — the arithmetic never works: the $60 you saved funds a stranger's coin wallet off your power bill, at roughly the cost of the software per year in electricity for a worked GPU. Leave Defender running — it recognizes commodity miners on sight, and its real-time protection kills most of these infections at the download stage; if that shield is off and you don't remember turning it off, start here. Three habits, zero products to buy — cryptojacking is close to a solved problem for people who practice them, which is precisely why it concentrates among people who don't.

Every check, one table

QuestionWhere to look
Is something eating my CPU/GPU right now?Task Manager → Processes → sort CPU, then GPU
What is this process, really?Right-click → Open file location; a "system" process living in a temp folder is a costume
Does it survive reboots?Task Manager → Startup apps
Deep cleanFull scan, then Microsoft Defender Offline scan
Is my protection even on?Get-MpComputerStatus in a terminal
Browser-only suspicion?Extensions list — remove anything you didn't choose; usage drops when the browser closes = browser-side culprit

FAQ — cryptojacking and secret mining

How do I know if my PC is mining cryptocurrency?

Task Manager with everything closed: sustained high CPU or GPU use from an unfamiliar process on an idle machine is the core sign, backed by loud fans, heat, and slowness that arrived together.

What is cryptojacking?

Malware that mines cryptocurrency on your hardware for someone else's wallet — stealing electricity and machine lifespan instead of files. Profitable for them precisely because you pay the power bill.

Does mining malware damage my computer?

It ages it: months of full-load heat wear fans, thermal paste, and batteries years ahead of schedule. Nothing explodes; everything erodes — plus the electricity you funded along the way.

What was Plurox?

A 2019 backdoor-worm that picked the most profitable miner for each infected machine and spread across networks using EternalBlue — an exploit whose patch had existed for over two years. Its victims were, definitionally, the unpatched.

My fans are loud. Do I have a miner?

Not necessarily — check the numbers. Loud fans with LOW usage in Task Manager is dust and dying cooling: a cleaning job. Loud fans with pinned usage and a stranger process is the mining pattern.

Why does the suspicious process disappear when I open Task Manager?

Smarter miners pause when monitoring tools open and resume after. Judge over days — heat, fans, battery, bill — not over the seconds Task Manager is on screen, and run the offline scan regardless.

How do I remove a crypto miner?

Full Defender scan, then a Microsoft Defender Offline scan (the reboot is the point), then prune unknown startup apps and delete the download that brought it. End Task alone is not removal — they return at boot.

How did I get infected in the first place?

Odds-on: a crack, keygen, or fake installer — especially one whose instructions said to disable antivirus first. Runners-up: fake update pages, unpatched-machine worms, rogue browser extensions.

Can websites mine through my browser?

The industrial era of that ended in 2019 when Coinhive shut down, and modern browsers block the stragglers. If usage drops the moment you close the browser, audit your extensions — that is the remaining browser-side route.

How much does a hidden miner cost me in electricity?

A worked GPU draws real wattage around the clock — enough to show as a noticeable monthly increase, which is why an unexplained bill bump that started alongside the other symptoms belongs on the evidence list.

Is Defender enough to catch miners?

Commodity miners, yes — on sight, usually at download time, if real-time protection is on. The infections that stick almost always involve the shield being off or deliberately disabled "to install something."

The crack told me to disable antivirus first. Is that normal?

It is normal for malware. That instruction is the payload clearing its own path, and following it converts your PC into the attacker's hardware with your consent on record. No legitimate software asks for it.

Do Macs and phones get cryptojacked too?

Yes — the economics are platform-agnostic, though Windows PCs with strong GPUs are the prize targets. The entry routes rhyme everywhere: fake installers, cracked apps, and users escorted past their own protections.

Should I reinstall Windows after finding a miner?

Usually the two-scan cleanup suffices for commodity miners. Reinstall when the infection came bundled in a backdoor package, keeps returning, or you simply want certainty — a fair call after any breach of trust this size.

Should I change my passwords after a miner infection?

If it arrived via a backdoor-style bundle — and cracks usually are bundles — yes, from a clean device, starting with email. Assume the polite burglar brought a colleague who wasn't polite.

Is mining on my OWN PC, on purpose, harmful?

Legal and yours to choose — the same wear-and-electricity math just lands on you voluntarily, and for consumer hardware the arithmetic rarely favors it. This page's objection is to strangers running the numbers on your meter.

Revision note. Originally published June 2019, reporting the Plurox worm the week researchers named it. Rewritten August 18, 2026: Plurox is history, but the crime it ran — strangers mining coins off your electricity and your hardware's lifespan — never went away, so this page grew into the standing guide: the signs, the honest fan-noise differential, the two-scan removal, and the three boring habits that end the whole category. If your PC has felt mysteriously old and your power bill mysteriously bold, spend the two minutes in Task Manager — the humming was always the clue. Spotted something wrong or something missing? Tell me through the contact page and I will fix it. Keep your watts.

Related