What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Smominru is a Windows botnet that attackers used to mine Monero with computing resources from infected computers. Proofpoint estimated more than 526,000 infected Windows hosts in a January 2018 investigation; that is a historical estimate, not a count of infected PCs today. A 2021 report said the related MyKings botnet was still active then, but the sources cited here do not establish its status or prevalence in 2026.
What is the Smominru botnet?
Smominru is a cryptomining botnet: a network of compromised computers whose processing power attackers use to mine cryptocurrency. Proofpoint’s January 2018 investigation focused on Monero mining. It estimated that more than 526,000 Windows hosts were infected, most of them believed to be servers, and observed the largest numbers in Russia, India, and Taiwan. These figures describe Proofpoint’s historical sinkholing investigation, not a current global infection count. Proofpoint’s 2018 investigation also reported that the botnet mined roughly 24 Monero per day during the week it described; that rate is historical and should not be read as a present-day figure.
Proofpoint worked with abuse.ch and the Shadowserver Foundation to sinkhole infrastructure and estimate the botnet’s size and location. After MineXMR acted on a request to ban an associated address, Proofpoint reported that the operators registered new domains and mined to a new address on the same pool; it then observed the botnet returning to about two-thirds of its earlier hash rate. This account describes events in the 2018 investigation, not the botnet’s current condition.
In 2021, BleepingComputer reported that MyKings—also referred to in some reporting as Smominru or DarkCloud—remained active at that time. That dated report does not establish activity in 2026. BleepingComputer’s 2021 report is evidence of activity reported then, not a live status check.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How does Smominru infect Windows PCs?
An archived NHS England Digital alert describes Smominru and WannaMine as closely related in their operation. It says the malware used the EternalBlue SMB exploit for delivery and propagation, and WMI-based persistence to survive reboots. The alert also warns that its content may be outdated or inaccurate, so these details should be understood as its account of the threats at the time—not as a description guaranteed to apply to every Smominru variant or a current infection. Read the NHS England Digital alert, published February 8, 2018 and last edited February 17, 2020.
The relevant historical patch context is Microsoft’s MS17-010 security bulletin, published March 14, 2017, which addressed remote-code-execution vulnerabilities in Windows SMBv1. Microsoft wrote: “This security update resolves vulnerabilities in Microsoft Windows.” The bulletin listed disabling SMBv1 as a possible workaround. That bulletin is not a complete modern cleanup procedure; administrators should follow Microsoft’s current, version-specific security guidance for the Windows systems they actually run. Microsoft Security Bulletin MS17-010.
Rank #2
- Certified to Microsoft’s highest fingerprint security standards (ESS & SDCP) for robust, hardware-isolated authentication. Supports next-gen Windows features, including Copilot Recall and Windows Hello with ESS support.
- Windows Hello ready for fast, password free fingerprint login to Windows and Microsoft 365 accounts
- On device fingerprint storage keeps biometric data securely within the key. Supports privacy regulations (GDPR, BIPA, CCPA) through on device biometric processing; TAA compliant.
- Reliable wired USB fingerprint authentication with USB C and USB A compatibility for desktop PCs.
- Consistent, all condition 360° fingerprint recognition.
How can I tell if my PC is being used for cryptocurrency mining?
Heavy or unexplained processor use can be a warning sign, but it does not identify Smominru by itself. The archived NHS alert said the malware could consume substantial system resources and potentially crash systems. High CPU use can also have unrelated causes, so treat it as a reason to investigate rather than proof of infection.
- Look for sustained, unexplained CPU activity, especially when you are not running demanding applications.
- Check for unusual processes and unexpected system slowdowns or crashes.
- Have an organization’s IT or security team review relevant network, proxy, and firewall logs if the computer is managed.
Cryptomining malware is not always unauthorized: Microsoft’s 2018 overview distinguishes miners used legitimately with permission from trojanized miners that steal computing resources. Its reported average of 644,000 unique computers encountering coin-mining malware per month from September 2017 through January 2018 covered coin-mining malware broadly, not Smominru specifically. Microsoft Defender Security Research Team’s 2018 overview.
Rank #3
- Protect accounts with USB-C & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
- FIDO2 Level 2 certified Security Key. Works with Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Compatible with Chrome, Safari & Edge on all major OS.
- Plug & play USB-C Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
- Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication & identity protection.
- IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise & daily use.
What should you do if you suspect an infection?
Use up-to-date security and incident-response guidance for your Windows version and situation. The NHS alert’s recommendations are historical and its page warns that the content may be outdated or inaccurate; consider them in that context, alongside current advice from your security provider or organizational response team.
- Contact your organization’s IT or security team if the computer is work-managed. Avoid treating a suspected compromised server like an ordinary home PC: follow the organization’s incident-response process.
- Update Windows and security software using guidance applicable to the installed Windows version. MS17-010 addresses a particular set of historical SMBv1 vulnerabilities; installing that bulletin alone should not be treated as a full assessment or cleanup.
- Investigate resource use and logs. The archived NHS alert recommends monitoring processes and CPU use, as well as network, proxy, and firewall logs. On a managed device, leave log collection and containment decisions to the responsible team.
- Reset potentially exposed accounts from a clean computer. The NHS alert recommends resetting accounts accessed from an infected computer, using a device believed to be clean. Follow current organizational guidance on which credentials to rotate and when.
- Use a non-administrative account for routine work where practical, as the NHS alert recommends. This is a general risk-reduction measure, not a substitute for patching or incident response.
What the historical numbers do—and do not—show
Smominru’s reported scale was substantial in Proofpoint’s 2018 investigation, but historical botnet estimates are not current prevalence measurements. Likewise, Proofpoint’s mining rate describes a particular week in 2018; it cannot be converted into a reliable present-day production rate or dollar value. Microsoft’s separate monthly figure counts computers encountering coin-mining malware across families, not Smominru infections. Keeping those scopes and dates separate avoids treating distinct measurements as if they described the same thing.
Quick Recap
Best Value
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
Rank #4
- Windows Hello for Windows 10/11 - Only works with Windows Hello on Windows 10/11 PCs and laptops. Plug the USB fingerprint reader into your computer and sign in with one touch. Not compatible with Mac, macOS, Linux or Chrome OS.
- Plug-and-Play Fingerprint Login - No extra app is needed on most genuine Windows systems. Insert the USB fingerprint scanner, set up fingerprint sign-in through Windows Hello, and unlock your PC without typing long passwords every time.
- Fast 0.5s 360° Recognition - Capacitive fingerprint technology supports quick authentication in about 0.5 seconds. 360° touch recognition helps read your fingerprint from different angles for faster, smoother daily login.
- Compact Scanner for PC & Laptop + Multi-User Support - Small, lightweight USB design works well for desktops, laptops, office PCs and shared home computers without built-in fingerprint sensors. Supports multiple Windows accounts and up to 10 fingerprints per user account. Smart-ID security helps protect saved passwords and encrypted folders with fingerprint access.
- Important Notes — Please Read Before Purchase - Support for Win10/11 32/64 bit original system. Not fit for the streamlined version. The Lite version has trimmed the biometric component, the fingerprint login device will not be able to recognize the Hello fingerprint option.It merely supports Windows Hello, does not fit for encrypting USB drives/files, and can merely support Windows system.It is recommended to prioritize plugging into the USB 2.0 interface of the motherboard. USB 3.0 docking stations are prone to power supply/interference and unstable recognition.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

