>And how many samples are just trivial keyloggers, screen grabbers, enablers for fishing attacks, etc. that don't even need anything more than user-level privileges?
They need more privileges for hiding itself from antivirus software, SmartScreen and MMSRT.
That's true. Unfortunately that assumes the user 1. has an antivirus installed 2. his interaction with it isn't limited to closing the "license expired" window as quickly as possible at startup. That's still a very typical pattern.
They need more privileges for hiding itself from antivirus software, SmartScreen and MMSRT.