Characteristics of computers being mined: 1. The computer becomes extremely slow, frequently unresponsive, network lags, fan noise, repeated restarts and other problems. After troubleshooting the system and program itself, restarting still cannot recover. , you need to consider whether you are infected with a "mining" Trojan virus; 2. If you are infected with a mining Trojan, because the mining program will run in the system, the computer will become very laggy under normal operation, and the CPU usage will be very high. The rate will become very high, even reaching 100%; 3. The network traffic will increase; 4. The power consumption will increase sharply.
The operating environment of this tutorial: Windows 10 system, Dell G3 computer.
If a computer is mined, it means it has been hit by a "mining" Trojan.
What is a "mining" Trojan?
The "mining" Trojan is an attacker who uses various means to implant the "mining" Trojan program into the victim's computer and uses its computer resources without the victim's knowledge. To obtain virtual currency, this type of Trojan program is a "mining" Trojan virus. After the computer is infected with the "mining" Trojan virus, the system will slow down, network traffic will increase, power consumption will increase sharply, and performance will be significantly reduced.
Characteristics of a computer being mined
1. The computer becomes extremely slow , Abnormal crash/stuck
You can see the high CPU usage of the "PowerShell" process in the task manager. Note that this phenomenon is the core manifestation of mining viruses.
2. CPU usage is very high
I was hit by a mining Trojan because it will be in the system Running the mining program in the middle will cause the computer to become very stuck during normal operation, and the CPU usage will become very high, even reaching 100%.
#3. The network is slow and a large number of network requests occur (the network traffic becomes larger)
4. Power consumption Sharp Rise
Mining is a very power-consuming and environmentally unfriendly process. A single Bitcoin transaction consumes about 2,165 kilowatt-hours of electricity, which is equivalent to more than two months of electricity consumption by an American household. This amount of electricity can be used by a household in India for an entire year.
"Mining" Trojan self-examination guide
1. Preliminary hardware inspection
Computer If problems such as frequent unresponsiveness, network lags, abnormal fan noises, and repeated restarts occur. If the problem still cannot be recovered after restarting after troubleshooting the system and program itself, you need to consider whether it is infected with a "mining" Trojan virus.
2. CPU usage troubleshooting
Check CPU usage
Open the task manager (Ctrl Alt Delete or right-click the taskbar and select Task Manager) - Select "Performance" to view the CPU usage. If the CPU usage is higher than the normal value or reaches 100%, it is necessary to further confirm whether there is a "mining" Trojan virus.
View Resource Monitor
Open the "Resource Monitor", find the process with obviously high CPU usage, and check whether there is "" in the "Description" of the process XMRig CPU miner" information. "Mining" Trojans typically contain this information.
View the file location
Open the Task Manager, select "Details", find the process in question in the Resource Monitor, right-click and select Open the location of the file, view relevant information, and further confirm.
End the process and delete the files
After confirmation, end the process in time, delete the relevant files, and restart the computer.
3. Use anti-virus software for troubleshooting
Use anti-virus software and perform regular full scans. Mining Trojans can also be found. Miner or Eternal Blue vulnerabilities are usually scanned. Files using toolkits appear to contain the characters "ShadowBrokers" and "EternalBlue". They should be checked and killed immediately after discovery.
For more related knowledge, please visit the FAQ column!
The above is the detailed content of What are the characteristics of a computer being mined?. For more information, please follow other related articles on the PHP Chinese website!