Trojan

About “Dropped:Trojan.PrivilegeEscalation.C” infection

Malware Removal

The Dropped:Trojan.PrivilegeEscalation.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.PrivilegeEscalation.C virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Dropped:Trojan.PrivilegeEscalation.C?


File Info:

name: 88496F2919BCAEA7DFDD.mlw
path: /opt/CAPEv2/storage/binaries/669070477eeb05b4c88ab6525dfac83ed3cc6634c7de475d8a557b83a84bb400
crc32: 1746A6D7
md5: 88496f2919bcaea7dfdd281fc0012c90
sha1: 56bdcc70c7074a232e78272f8215e097a5b98fc9
sha256: 669070477eeb05b4c88ab6525dfac83ed3cc6634c7de475d8a557b83a84bb400
sha512: 384fb174b892afee59049d41849ea55d28d5ddb43ebb77710ee947c505f5de2d1e95753496914d4432834382023f3409ac11dbf15572824c2b7ac0ed5c6e9189
ssdeep: 1536:sEiBwAw/cGYQi1y2QNAx1FcLD12Qs7yGVd7U7TtRt7D5nouy82O:uB9wUGYQN2XD6Udsvt9out
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AC63F12BFA458DA5C811D0740E86B116882CD2559FE9CA12BDED32772FD1B30D89E7E8
sha3_384: e2cf631ba1a6b7b64e346900abc1993f390814e8070ef962624405ecfb5e82c211499b6614998541fe801369a3281b99
ep_bytes: 60be151041008dbeebfffeff5789e58d
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Dropped:Trojan.PrivilegeEscalation.C also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.PrivilegeEscalation.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.88496f2919bcaea7
McAfeeArtemis!88496F2919BC
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Generic.b55cf0f9
K7GWTrojan ( 0051918e1 )
K7AntiVirusTrojan ( 0051918e1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Agen-7532797-0
BitDefenderDropped:Trojan.PrivilegeEscalation.C
MicroWorld-eScanDropped:Trojan.PrivilegeEscalation.C
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10ce5381
Ad-AwareDropped:Trojan.PrivilegeEscalation.C
EmsisoftDropped:Trojan.PrivilegeEscalation.C (B)
TrendMicroTROJ_GEN.R049C0PLE21
McAfee-GW-EditionBehavesLike.Win32.Backdoor.kc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataDropped:Trojan.PrivilegeEscalation.C
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1115821
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Occamy
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.PrivilegeEscalation.C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win.Generic.R421843
BitDefenderThetaGen:NN.ZexaF.34114.emGfamZ0ogf
ALYacDropped:Trojan.PrivilegeEscalation.C
MalwarebytesMalware.AI.1984473966
TrendMicro-HouseCallTROJ_GEN.R049C0PLE21
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazr0gD0SbVcprEDie8seDBW3)
eGambitUnsafe.AI_Score_97%
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.919bca

How to remove Dropped:Trojan.PrivilegeEscalation.C?

Dropped:Trojan.PrivilegeEscalation.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment