Trojan

Trojan:Win32/SystemHijack!C removal guide

Malware Removal

The Trojan:Win32/SystemHijack!C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SystemHijack!C virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Attempts to disable System Restore
  • The sample wrote data to the system hosts file.
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/SystemHijack!C?


File Info:

name: DD045104BA038E62377F.mlw
path: /opt/CAPEv2/storage/binaries/abd3fa468191f60175d62c5286c10aa643410f5d18e5e88f1d55572045c42426
crc32: 131CF470
md5: dd045104ba038e62377f3dedb6bd18f1
sha1: 0b1373e4c92ab461fcf57891c8e7ac4106687d66
sha256: abd3fa468191f60175d62c5286c10aa643410f5d18e5e88f1d55572045c42426
sha512: c0e79a90637ea633372338fce5fbe4935e3ea7037957fefdcb537c778ad8ae68d3ce4610fb47780ac459543f7ac379249875290259fdcd7de6d89d43fdd1cf73
ssdeep: 768:34Fg8+UAq4OwSRNFdv7QuhQ0KTM/0V6F0Et73cVkWReq6caN12Dt6QUAKE9XpCL6:IEbjDtCqdK/rjQiTZnQqN+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1132386760B4E69FCF1514271BB44722D41A3173C03FAE792ABE764E182218B646F2D7B
sha3_384: 74536305af8ab251036cc516505ff0cdf781e7fdabe75f47db158c67a0ceced3aeed13a4aabcb2f35e00ad44c10a5bd4
ep_bytes: 558bec81ec980700005356576a01ff15
timestamp: 2008-08-14 02:36:30

Version Info:

0: [No Data]

Trojan:Win32/SystemHijack!C also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.IRCBot.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Win32.Worm.Slenfbot.AI
FireEyeGeneric.mg.dd045104ba038e62
SkyhighBehavesLike.Win32.Generic.ph
McAfeePUP-XVQ-CY
Cylanceunsafe
SangforSuspicious.Win32.Save.a
AlibabaBackdoor:Win32/IRCBot.53630022
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.69DAB0C21E
VirITBackdoor.Win32.IRCBot.GTX
SymantecW32.IRCBot
ESET-NOD32a variant of Win32/AutoRun.Qhost.A
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT.ASZF
KasperskyBackdoor.Win32.IRCBot.gtx
BitDefenderDropped:Win32.Worm.Slenfbot.AI
NANO-AntivirusTrojan.Win32.IRCBot.bjnyuo
AvastWin32:Agent-WOW [Trj]
TencentWin32.Backdoor.Ircbot.Simw
EmsisoftDropped:Win32.Worm.Slenfbot.AI (B)
F-SecureTrojan.TR/Spy.Gen
DrWebWin32.HLLW.Autoruner.3733
VIPREDropped:Win32.Worm.Slenfbot.AI
TrendMicroTROJ_AGENT.ASZF
Trapminemalicious.high.ml.score
SophosMal/Behav-001
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminHeur:Backdoor/IRCBot
GoogleDetected
AviraTR/Spy.Gen
VaristW32/Bifrost.C.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.IRCBot
KingsoftWin32.HeurC.KVMH012.a
MicrosoftTrojan:Win32/SystemHijack.gen!C
XcitiumMalware@#w1oitt87873d
ArcabitWin32.Worm.Slenfbot.AI
ZoneAlarmBackdoor.Win32.IRCBot.gtx
GDataDropped:Win32.Worm.Slenfbot.AI
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.R581101
Acronissuspicious
VBA32BScope.Trojan-Dropper.1291
ALYacDropped:Win32.Worm.Slenfbot.AI
PandaGeneric Malware
RisingTrojan.SystemHijack!8.82E (TFE:5:ZXTzAiyT4n)
YandexTrojan.GenAsa!prHfpLFtpY4
IkarusWorm.Win32.Slenfbot.B
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Agent-WOW [Trj]
Cybereasonmalicious.4ba038
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Qhost.A

How to remove Trojan:Win32/SystemHijack!C?

Trojan:Win32/SystemHijack!C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment