204
2 Computer Viruses, Malicious Logic, and Spyware
be implemented “on paper” but can be realized using special software and, of course,
state-of-the-art high-performance computing devices.
As of now, the authors only know of two methods of such malicious mining. In the
first case, a Trojan miner covertly penetrates the user’s PC and starts constantly using
its calculating resource and hardware means (mainly the graphic card and the central
processor). In the second case, however (this information is communicated by the
popular antivirus company ESET in its newsletter), the mining process only occurs
when an uninformed user (the one who hasn’t read this book) visits an infected site.
This category of digital theft is known among cybersecurity specialists as browser
mining.
It is obvious that the first method of cybertheft is safer and more convenient for
intruders, even if more complex in terms of implementation—the user’s attacking
computer first needs to be properly infected; on the other hand, the second attack
method is much simpler from economical and technical point of view: the intruders
compensate for the lack of computing power required to achieve the goal by means
of simply increasing (attracting) various users who visit a specific site on the Internet
deliberately or accidentally.
How can a naive average user realize that something is wrong with their favorite
computer?
Computer security specialists believe that the very first sign of such parasite
mining is lagging in absolutely usual situations or freezing when the computer only
runs the browser with several tabs open. Of course, such symptoms are typical not
only of attacking mining situations—a regular process of software update can be
running on the computer.
This is an example of so-called heavy background process for a user computer.
However, if such computer constantly works in such loaded mode, it is a dangerous
symptom already. Unfortunately, according to Chap. 3 of the encyclopedia, it is not
recommended to rely on various standard programs in this case. In order to understand
gravity of the situation, we should cite here opinions of such authoritative experts
as, say, Kaspersky Lab.
Let us cite an extract from the statement of the Kaspersky Lab: miners are not
essentially malicious. Therefore, they are included in the category of Riskware—
such software that can be absolutely legally used for malicious ends. Therefore,
the software complex Kasper Internet Security known to specialists never blocks or
removes such programs since the user could have installed them consciously! This
means that the antivirus does not perform its designated function in a specific case of
hidden browser mining, and this is very sad. However, a question emerges: how can
an average user in such case detect such hidden mining, let alone a hidden miner?
Clearly, the most convenient way of detecting such parasite eating up all the
resources of your computer is using the embedded block “Task Manager” (to call it
in Windows, the user only needs to press the combination of keys Ctrl + Shift +
Es). If the users see that an unknown (unauthorized) computing process loads the
processor by dozens of extra percents, this process can very well be a mining one.
There’s no reason to be proud of drawing its attention; however, you as a responsible user of your computer, absolutely have to interrupt solving of the current task
2 Computer Viruses, Malicious Logic, and Spyware
be implemented “on paper” but can be realized using special software and, of course,
state-of-the-art high-performance computing devices.
As of now, the authors only know of two methods of such malicious mining. In the
first case, a Trojan miner covertly penetrates the user’s PC and starts constantly using
its calculating resource and hardware means (mainly the graphic card and the central
processor). In the second case, however (this information is communicated by the
popular antivirus company ESET in its newsletter), the mining process only occurs
when an uninformed user (the one who hasn’t read this book) visits an infected site.
This category of digital theft is known among cybersecurity specialists as browser
mining.
It is obvious that the first method of cybertheft is safer and more convenient for
intruders, even if more complex in terms of implementation—the user’s attacking
computer first needs to be properly infected; on the other hand, the second attack
method is much simpler from economical and technical point of view: the intruders
compensate for the lack of computing power required to achieve the goal by means
of simply increasing (attracting) various users who visit a specific site on the Internet
deliberately or accidentally.
How can a naive average user realize that something is wrong with their favorite
computer?
Computer security specialists believe that the very first sign of such parasite
mining is lagging in absolutely usual situations or freezing when the computer only
runs the browser with several tabs open. Of course, such symptoms are typical not
only of attacking mining situations—a regular process of software update can be
running on the computer.
This is an example of so-called heavy background process for a user computer.
However, if such computer constantly works in such loaded mode, it is a dangerous
symptom already. Unfortunately, according to Chap. 3 of the encyclopedia, it is not
recommended to rely on various standard programs in this case. In order to understand
gravity of the situation, we should cite here opinions of such authoritative experts
as, say, Kaspersky Lab.
Let us cite an extract from the statement of the Kaspersky Lab: miners are not
essentially malicious. Therefore, they are included in the category of Riskware—
such software that can be absolutely legally used for malicious ends. Therefore,
the software complex Kasper Internet Security known to specialists never blocks or
removes such programs since the user could have installed them consciously! This
means that the antivirus does not perform its designated function in a specific case of
hidden browser mining, and this is very sad. However, a question emerges: how can
an average user in such case detect such hidden mining, let alone a hidden miner?
Clearly, the most convenient way of detecting such parasite eating up all the
resources of your computer is using the embedded block “Task Manager” (to call it
in Windows, the user only needs to press the combination of keys Ctrl + Shift +
Es). If the users see that an unknown (unauthorized) computing process loads the
processor by dozens of extra percents, this process can very well be a mining one.
There’s no reason to be proud of drawing its attention; however, you as a responsible user of your computer, absolutely have to interrupt solving of the current task
