XMRig is a cryptocurrency miner that started as a legitimate, open-source tool for mining Monero but has become one of the most common pieces of malware we remove from infected computers in Roswell. Unlike ransomware that locks your files or spyware that steals passwords, this threat operates quietly in the background, consuming your computer's processing power to generate cryptocurrency for attackers. Many victims don't realize they're infected until their computer slows to a crawl or their electricity bill spikes unexpectedly.
The software itself isn't inherently malicious—miners use it legally every day. The problem arises when cybercriminals bundle it with free software downloads, hide it in pirated programs, or inject it through compromised websites without your knowledge or consent. Once installed, it hijacks your CPU resources, sometimes pushing utilization to 90-100%, which causes overheating, system instability, and premature hardware failure.
Threat Profile
| Threat Name | XMRig (cryptocurrency miner) |
| Threat Type | Cryptojacker / Potentially Unwanted Program (PUP) |
| Platform | Windows (PE executable) |
| File Type | Windows PE executable (.exe) |
| First Observed | 2017 (legitimate release); widespread malicious use since 2018 |
| Detection Names | Coin-Miner.Win32.XMRig, PUA:Win32/CoinMiner, Trojan.CryptoMiner, RiskWare.BitCoinMiner |
| Primary Payload | Monero (XMR) cryptocurrency mining using CPU resources |
| Typical Distribution | Software bundling, pirated applications, malvertising, exploit kits |
| CPU Impact | 50-100% sustained utilization (configurable by attacker) |
| Persistence Mechanism | Registry Run keys, scheduled tasks, Windows services |
| Network Behavior | Connects to Monero mining pools on ports 3333, 5555, 7777, 14444 |
| Severity for Home Users | Moderate to High (hardware damage risk, electricity costs, performance degradation) |
How It Spreads
XMRig infections rarely arrive through traditional email attachments or phishing links. Instead, attackers leverage software distribution channels where users actively seek out and install programs. The most common infection vector we see in Roswell is "bundling"—hiding the miner inside installers for legitimate-looking freeware, especially video converters, PDF tools, download managers, and game cheats. During installation, users click through setup screens too quickly and unknowingly agree to install "additional components" that include the miner.
Pirated software represents another major distribution method. Cracked versions of expensive programs like Adobe Creative Suite, AutoCAD, or Microsoft Office downloaded from torrent sites frequently contain XMRig or similar miners. The cracking groups themselves sometimes embed miners as a revenue source, or third parties inject them into popular torrents. We've also observed infections from fake software update prompts on compromised websites—pop-ups claiming your Flash Player, Java, or video codec is outdated.
Less commonly, XMRig spreads through:
- Exploit kits targeting unpatched browsers: Drive-by downloads from legitimate websites that have been compromised with malicious advertisements or code injection
- Remote Desktop Protocol (RDP) intrusions: Attackers scan for exposed RDP connections with weak passwords, then manually install miners on business computers and servers
- Infected USB drives: Particularly in workplace environments where employees share thumb drives containing infected autorun files
- Malicious browser extensions: Add-ons that promise ad-blocking or VPN services but include hidden mining scripts
- Supply chain attacks: Legitimate software update mechanisms compromised to distribute miners alongside real updates (rare but documented)
What It Does On Your Machine
Once executed, XMRig's primary function is converting your computer into a cryptocurrency mining rig without your consent. It immediately begins solving complex mathematical problems required to validate Monero blockchain transactions, with all profits directed to the attacker's wallet address. The software is designed for efficiency—it can detect how many CPU cores you have and utilize them at configurable intensity levels. Many attackers set it to 80-90% utilization to maximize profits while staying just below the threshold where average users might notice.
The performance impact is severe. Your computer will run hot, with CPU temperatures climbing 20-30 degrees above normal. Fans will spin constantly at maximum speed. Simple tasks like opening a web browser or typing in Word become sluggish. Gaming becomes impossible—frame rates drop to single digits. Video calls stutter and freeze. On older machines or laptops with limited cooling, prolonged mining can cause thermal throttling, shortened component lifespan, or permanent CPU damage. We've diagnosed multiple hard drive failures traced back to excessive heat from concurrent miner infections.
To ensure it continues generating revenue, XMRig employs multiple persistence techniques. The malware copies itself to hidden system folders, creates registry entries to launch at startup, establishes Windows services that restart the process if killed, and sometimes disables Windows Defender or adds exclusions for its own files. Some variants monitor for Task Manager and temporarily reduce CPU usage when it's open, making detection harder for non-technical users.
Beyond performance degradation, XMRig infections often arrive bundled with additional malware. Because the distribution method involves tricking users into running executables from untrusted sources, attackers frequently package miners alongside information stealers, adware, browser hijackers, and occasionally ransomware. We've encountered systems where XMRig was merely the most obvious symptom of a much broader infection involving credential theft and remote access trojans.
Manual Removal — Step by Step
Boot Into Safe Mode With Networking
Restart your computer and repeatedly press F8 during boot (or Shift+Restart on Windows 10/11, then Troubleshoot > Advanced Options > Startup Settings > Restart > press 5). Safe Mode loads only essential drivers, preventing most malware from starting automatically. You need networking enabled to download removal tools in later steps.
Open Task Manager and Identify Suspicious Processes
Press Ctrl+Shift+Esc and examine the Processes tab sorted by CPU usage. Look for unfamiliar executables consuming high percentages, especially those with random names, multiple instances of "svchost.exe" running under your username (legitimate ones run under SYSTEM), or processes located in AppData or Temp folders. Right-click suspicious processes, select "Open file location," then End Task.
Uninstall Suspicious Programs
Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11). Sort by install date and look for unfamiliar programs installed around the time symptoms started. Common miner-related names include anything with "Update," "Helper," "Service," or random character strings. Uninstall anything you don't recognize, but note that many miners don't appear here at all.
Delete Malware Files From Common Locations
Open File Explorer, enable "Show hidden files" in View options, and manually navigate to C:\Users\[YourName]\AppData\Roaming and C:\Users\[YourName]\AppData\Local\Temp. Delete any .exe files you don't recognize, especially "xmrig.exe," "config.json," or executables with random names. Also check C:\ProgramData and C:\Windows\Temp. Note the file paths before deletion—you'll need them for the next step.
Clean Registry Persistence Entries
Press Win+R, type "regedit," and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Look for entries pointing to the file paths you deleted in Step 4. Right-click and delete suspicious entries. Also check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services for unfamiliar service names. Export a backup before making changes.
Remove Scheduled Tasks
Open Task Scheduler (search in Start menu) and examine the Task Scheduler Library. Look for tasks with random names, tasks that run executables from AppData or Temp folders, or tasks set to run at every login. Right-click suspicious tasks and delete them. Miners often create multiple tasks as backup persistence mechanisms.
Run Malwarebytes Free
Download Malwarebytes from malwarebytes.com (verify you're on the real site—not a download portal), install it, update definitions, and run a full Threat Scan. This will catch miners that have rootkit components or remain hidden in system memory. Quarantine all detected items. The free version is sufficient for one-time removal.
Scan With AdwCleaner
Download AdwCleaner (also from Malwarebytes) and run a scan to catch bundled adware, browser hijackers, and potentially unwanted programs that likely accompanied the miner. These aren't always detected by standard antivirus. Clean all found items and allow the required reboot.
Reset Web Browsers
Some XMRig variants install browser-based miners as extensions. In Chrome, go to Settings > Reset and Clean Up > Restore settings to original defaults. In Firefox, type "about:support" in the address bar and click "Refresh Firefox." In Edge, go to Settings > Reset settings > Restore settings to their default values. This removes malicious extensions and homepage hijacks.
Verify Removal and Monitor Performance
Restart normally (exit Safe Mode) and open Task Manager immediately after login. Monitor CPU usage for 5-10 minutes with no programs open—it should stay under 10%. Check CPU temperature with HWMonitor (free download). Run one final scan with your primary antivirus. If CPU usage remains high or you see unfamiliar network connections, the infection may have deeper rootkit components requiring professional removal.
Prevention
- Download software only from official publisher websites. Avoid third-party download portals like Softonic, Download.com, or CNET Downloads, which frequently bundle installers with unwanted programs. For open-source tools, use GitHub releases or the project's official site.
- Never pirate software. Cracked programs are the number-one infection vector we see for miners. The money you "save" will cost you multiples in electricity, hardware damage, and repair fees. If cost is an issue, look for free alternatives rather than pirated commercial software.
- Read installation screens carefully and choose "Custom" installation. During software setup, never click "Express" or "Recommended"—always select "Custom" or "Advanced" and uncheck any offers for additional software, toolbars, browser changes, or "recommended" components.
- Keep Windows and all software updated. Enable automatic Windows Updates and keep browsers, Java, Adobe products, and other common targets patched. Miners often exploit known vulnerabilities in outdated software.
- Use a reputable antivirus with real-time protection. Windows Defender is acceptable for basic protection, but it misses many PUP/PUA variants of miners. Consider upgrading to Malwarebytes Premium, ESET, or Bitdefender, which have better detection of cryptocurrency mining malware.
- Enable Windows Firewall and review outbound connections. Consider using a firewall that prompts for permission when new programs attempt network connections. Miners must connect to mining pools—blocking unknown outbound connections can prevent them from functioning even if they execute.
- Install browser extensions carefully. Only install extensions from official browser stores, read reviews, and check the permissions requested. Avoid extensions that require "access to all websites" unless absolutely necessary for their function.
- Monitor your computer's performance. Get in the habit of occasionally opening Task Manager to see what's consuming resources. Unusual fan noise, heat, or slowdowns are early warning signs. The sooner you catch an infection, the less damage it causes.
Bring It In
XMRig removal is straightforward when you know what you're looking for, but the malware frequently travels with companions—adware, browser hijackers, information stealers, and sometimes backdoors that give attackers ongoing access to your system. Manual removal catches the obvious components but often misses rootkit-level persistence or secondary infections. If you've followed the steps above and still experience high CPU usage, unexpected network activity, or general sluggishness, you're likely dealing with a more complex infection that requires professional tools and experience.
Computer Repair Roswell has cleaned hundreds of miner infections from Roswell-area computers since this threat became widespread in 2018. We use enterprise-grade detection tools not available to consumers, perform deep scans of system memory and firmware, and verify removal with network traffic analysis. Most miner removals are completed same-day. Call us at (770) 637-1435 or stop by our shop at 1330 Hembree Road, Roswell, GA 30076. We're open Monday through Saturday, and we'll give you an honest assessment—if it's something you can handle yourself, we'll tell you. If it needs professional attention, we'll fix it right the first time.