Here is one article from Malwarebytes about Bitcoin miners that can now be picked up via a "drive-by". You visit a website, and if it's infected, you get infected by the program. All it does is do the calculations for mining Bitcoins, but it can cause high resource use and overheating in some computers.
If you can't afford the full version, I highly recommend the free version of Malwarebytes, which will still manually find and remove the "nasties" which I have found that AVG, Avira, etc., won't. The full version of MWB is now a full security suite, but costs $40/year per license, or less in a bundle package.
https://blog.malwarebytes.com/detection ... coinminer/
Partial text:
RiskWare.BitCoinMiner is Malwarebytes generic detection name for crypto-currency miners that may be active on a system without user consent. These do not necessarily mine for Bitcoins, it could be mining for a different crypto-currency. Crypto-currency miners use a lot of resources to optimize the earning of the virtual currency. For this reason, threat actors try to use other peoples machines to do the mining for them. This detection warns you that a bitcoin miner is active on your system, but it has no way of checking whether it is working for you or for someone else. That is why these bitcoin miners are detected as riskware.
Riskware, in general, is a detection for items that are not strictly malicious, but pose some sort of risk for the user in another way.
Symptoms
Users may notice a very slow computer as most of the CPU cycles will be used up by the miner. The process-names may vary but NsCpuCNMiner32.exe and NsCpuCNMiner64.exe are very common ones, which are not necessarily malicious.
You can also get Malwarebytes ADWCleaner from the MWB people as well. I highly recommend it. No, I do not get paid by the MWB people!
Bitcoin Miners via "Drive-by"
-
Eunuchorn (imported)
- Articles: 0
- Posts: 267
- Joined: Fri Nov 30, 2001 4:39 am
-
Posting Rank
Re: Bitcoin Miners via "Drive-by"
Even with the free version, I think you will be surprised by what MWB comes up with. I was.