Malware

What is “Troj/AutoG-KG”?

Malware Removal

The Troj/AutoG-KG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/AutoG-KG virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Leivion malware family

How to determine Troj/AutoG-KG?


File Info:

name: 067471A2592927D12548.mlw
path: /opt/CAPEv2/storage/binaries/da4fcf0e83a81e6c979540c3af40cd7c3dc39c153f17d5daa627fa0aa7157d3a
crc32: 2380F05C
md5: 067471a2592927d125482b334611a207
sha1: 0dacd95ce5a1c7f17758dafe5dff9941f82b4a43
sha256: da4fcf0e83a81e6c979540c3af40cd7c3dc39c153f17d5daa627fa0aa7157d3a
sha512: 00cea5707d3230a5ff577a93bc36793f4d5169024ea8b107d18b744a8880d366b538c5e03dc3dfce61e1aecafcf67ecd70085d30a6564c168c7d6e691c545bd9
ssdeep: 49152:PS10mfGs4EDkFAT9OsrUYeMPd+DfS0vnW9xmrQd+aa8m+VxA/TB6Eoi+4l8WxW:PS10mfGs4EDkFAT9OsrUYeMPd+DfS0vn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181D508C0F9DB40F6E50B8E7248F6522FAB30160893B4CAC7DF685E59EC1B6E1197B215
sha3_384: 11057e6d638417eb662e0c26bb5e91814715a5c1d9a9dea89416ff058cb76c9e9f1dff52dc1daf6207793d79fc29aba2
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Troj/AutoG-KG also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Trojan.Liev.9
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050f7371 )
K7GWTrojan ( 0050f7371 )
Cybereasonmalicious.259292
BitDefenderThetaGen:NN.ZexaF.36250.VsW@aWKKpWd
VirITBackdoor.Win32.Meterpreter.T
CyrenW32/S-a0eadfad!Eldorado
SymantecHacktool.Veil!g3
ESET-NOD32a variant of Win32/Agent.YXS
APEXMalicious
ClamAVWin.Malware.Liev-9638375-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Trojan.Liev.9
NANO-AntivirusTrojan.Win32.Agent.eqpvom
MicroWorld-eScanGen:Variant.Trojan.Liev.9
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Agent.hf
EmsisoftGen:Variant.Trojan.Liev.9 (B)
F-SecureHeuristic.HEUR/AGEN.1314221
DrWebBackDoor.Meterpreter.19
VIPREGen:Variant.Trojan.Liev.9
McAfee-GW-EditionBehavesLike.Win32.TrojanVeil.vh
FireEyeGeneric.mg.067471a2592927d1
SophosTroj/AutoG-KG
IkarusTrojan.Win32.Leivion
JiangminBackdoor.Agent.bay
AviraHEUR/AGEN.1314221
MicrosoftTrojan:Win32/Leivion.S
ArcabitTrojan.Trojan.Liev.9
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Trojan.Liev.9
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R266227
McAfeeTrojan-Veil-FLRK!067471A25929
MAXmalware (ai score=82)
VBA32BScope.Trojan.Leivion
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Agent!1.E34D (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.YXS!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/AutoG-KG?

Troj/AutoG-KG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment