I'm confused:
1) Wouldn't this show up as a process under task manager?
2) Wouldn't properly set security permissions require user assent for any downloads?
1. I think it did show up, but he needed to do further digging to find what it did, what it ran, etc.
2. No, as long as it doesn't need Administrative Access, it can do what it wants without a dialog. For most computers, downloading a file doesn't require UAC, so it can do it mostly undetected.
The process that showed up as named "Windows media sharing service" running on 2 cpus, which was just a copy of xptMiner running with some command line options, that was hidden and set to low priority, This was being run by a small DLL file that quit after starting the miner. Outside of that there was no other unusual process running that I could find or any strange open ports that I couldn't trace back too legitimate software.
exploits do just that, they bypass security by taking advantage of a bug or flaw in software to gain Administrator/root access without the OS/user knowing it happened, then executing what ever code/command they want. When its not detected, blocked or known, it's general referred to as a "0day exploit".
For now I'm going too assume it came in from a website that exploits browsers to get the miner on without much intervention from scans/resident anti-virus since the DLL is fairly basic it doesn't set off allot of red flags.