2.8 Specifics of Organization of Data Protection …
205
(“heavy” computer game, video editing, etc.). Unfortunately for “basic” Internet
users, standard administrator (task manager) not always proves effective in such
situations. Modern miners, for example, have learned to pause their operation and
hide into usual standard processes, such as svchost, exe, chrome, stream.exe, etc.
Many information system security specialists recommend using additional software protection means, such as AnVir Task Manager, in this case; however, these
recommendations are purely theoretical. Some of the practical pieces of advice from
security specialists can be helpful during different stages of attacks. For example, if
mining is implemented with the help of an infected site, the user only needs to open
a relevant tab in the browser. Of course, the situation is much worse if such miner
has ended up on your computer. For starters, the user can try to close the detected
malicious process in the task manager and try to quickly delete it from the so-called
autostart, which is not so easily implemented in practice.
All such miners usually employ absolutely non-standard methods of activation
(launch) implemented by professional developers, which have not been previously
described in open publications, as well as at least two redundant launch processes:
if one process of Trojan launching is detected, the following one after a short period
of the mining operation implementation shall undertake the second attack attempt.
Moreover, computer rebooting process can be automatically launched in case of an
attempt to access the miner files or to delete them from the autostart.
The main protection method in this case is provided by special antivirus software.
Moreover, if the antivirus selected by the user cannot detect the virus in normal mode,
it is recommended to save a free portable scanner like Kaspersky Virus Removal Tool
or Web Cureit on a flash drive and boot the computer in safe mode.
Here, we should cite the opinion of Natalya Kaspersakya, a reputable cybersecurity specialist and the CEO of InfoWatch and the co-founder of the world-famous
Kaspersky Lab, on this problem. Kasperskaya called bitcoin the result of development of a special project by American special services within the framework of the
information war. Kasperskaya called Satoshi Nakamoto, who is officially believed to
be the creator of Bitcoin, “a group of American cryptographers.” As for the currency
exchange rates, she believes that these rates are controlled by stock market owners.
It should also be noted that antiviruses don’t always count miners as malware—
after all, you can be mining for your personal gain. For example, Kaspersky Antivirus
automatically classifies them as riskware (software with security issues). In order
to identify an object and delete it from this category, go to the security solution
settings, find the section “Threats and Detection”, and tick the “Other Programs”
item. Similar solution is provided by ESET: in order to identify miners (including the
ones on visited sites), the user needs to switch on detection of potentially undesirable
programs in settings. If the mining process continues after performance of all these
manipulations, the only extreme solution left is reinstalling the operating system. Let
us also say several words about other methods of protection from mining.
Protection from browser mining, in addition to various antivirus solutions identifying malicious Java scripts on sites, is ensured by browser extensions capable of
detecting miners, which have already appeared on the marked by the time of publication of this book; such extensions include No Coin, Mining Blocker, and so on. If the
205
(“heavy” computer game, video editing, etc.). Unfortunately for “basic” Internet
users, standard administrator (task manager) not always proves effective in such
situations. Modern miners, for example, have learned to pause their operation and
hide into usual standard processes, such as svchost, exe, chrome, stream.exe, etc.
Many information system security specialists recommend using additional software protection means, such as AnVir Task Manager, in this case; however, these
recommendations are purely theoretical. Some of the practical pieces of advice from
security specialists can be helpful during different stages of attacks. For example, if
mining is implemented with the help of an infected site, the user only needs to open
a relevant tab in the browser. Of course, the situation is much worse if such miner
has ended up on your computer. For starters, the user can try to close the detected
malicious process in the task manager and try to quickly delete it from the so-called
autostart, which is not so easily implemented in practice.
All such miners usually employ absolutely non-standard methods of activation
(launch) implemented by professional developers, which have not been previously
described in open publications, as well as at least two redundant launch processes:
if one process of Trojan launching is detected, the following one after a short period
of the mining operation implementation shall undertake the second attack attempt.
Moreover, computer rebooting process can be automatically launched in case of an
attempt to access the miner files or to delete them from the autostart.
The main protection method in this case is provided by special antivirus software.
Moreover, if the antivirus selected by the user cannot detect the virus in normal mode,
it is recommended to save a free portable scanner like Kaspersky Virus Removal Tool
or Web Cureit on a flash drive and boot the computer in safe mode.
Here, we should cite the opinion of Natalya Kaspersakya, a reputable cybersecurity specialist and the CEO of InfoWatch and the co-founder of the world-famous
Kaspersky Lab, on this problem. Kasperskaya called bitcoin the result of development of a special project by American special services within the framework of the
information war. Kasperskaya called Satoshi Nakamoto, who is officially believed to
be the creator of Bitcoin, “a group of American cryptographers.” As for the currency
exchange rates, she believes that these rates are controlled by stock market owners.
It should also be noted that antiviruses don’t always count miners as malware—
after all, you can be mining for your personal gain. For example, Kaspersky Antivirus
automatically classifies them as riskware (software with security issues). In order
to identify an object and delete it from this category, go to the security solution
settings, find the section “Threats and Detection”, and tick the “Other Programs”
item. Similar solution is provided by ESET: in order to identify miners (including the
ones on visited sites), the user needs to switch on detection of potentially undesirable
programs in settings. If the mining process continues after performance of all these
manipulations, the only extreme solution left is reinstalling the operating system. Let
us also say several words about other methods of protection from mining.
Protection from browser mining, in addition to various antivirus solutions identifying malicious Java scripts on sites, is ensured by browser extensions capable of
detecting miners, which have already appeared on the marked by the time of publication of this book; such extensions include No Coin, Mining Blocker, and so on. If the
