
Scammers have turned Steam’s discussion forums into a trap for gamers. Fake accounts are posting “helpful” replies to people asking about game crashes or bugs — but instead of a real fix, the posts tell you to open PowerShell as an administrator and paste in a command. That command silently downloads and installs an XMRig cryptominer on your PC, then sets it up to run every time Windows starts with full system privileges.
XMRig is software that uses your computer’s processor to mine the cryptocurrency Monero for the attacker. If you ran one of these commands, your computer may feel significantly slower than usual and your CPU fans will likely be spinning at full speed even when you are not playing a game. The malware creates a Windows scheduled task named “XMRig-[your computer’s name]” that keeps it running automatically in the background after every restart.
How to check if you’re affected
Affected devices are Windows computers running Windows 10 or Windows 11. If you recently followed instructions from a Steam forum post that asked you to paste something into PowerShell or Command Prompt, check for the miner now:
- Press Win + R, type
taskschd.msc, and press Enter to open Task Scheduler. - Look for any task named “XMRig-” followed by your computer’s name. If you find one, your computer has been infected.
- Run a full scan with your antivirus — Windows Defender can detect and remove XMRig.
- Going forward, never paste commands from forum posts into PowerShell or Command Prompt, no matter how official the “fix” looks. Game companies do not deliver updates this way.
