Trojan

Trojan.Leivion removal tips

Malware Removal

The Trojan.Leivion is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Leivion virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Leivion malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Leivion?


File Info:

name: EBB872AE26554F0F0D23.mlw
path: /opt/CAPEv2/storage/binaries/6700c9cd0562ac36353e54fd65843ff48d98bd618d98ecdceeb48d5cfa6e6e07
crc32: 083DBB78
md5: ebb872ae26554f0f0d232fda40997c41
sha1: f6fb931849d5c65fa3113c4f412b5651ca54cacc
sha256: 6700c9cd0562ac36353e54fd65843ff48d98bd618d98ecdceeb48d5cfa6e6e07
sha512: b1efad3b023b01eb976c51682652568f3b6125c1dda58e9c74684fc7ffb46f0af47f7b0b4fc2599e1f10e048f29a26fdb87d32f914cda41550a189c8ec252436
ssdeep: 49152:dtZNSttv2Pd2Pa6IMvYweQ5iZUe0f2NkTFdCsGjmuWe+wKy4oiHTxmoJv+anp8Ww:PZNG+b6I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1D507C0F9DB45F6D5078EB288E6922FAA30460883B1CAC7DF681E59EC5B7D1057B724
sha3_384: 148c5e2977f08d118e98c67337c36e837ca90b49b64f88d13e8065cd4c5de5aec1c04b976166b03ab22b3974249ecfb5
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Leivion also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S17662776
ALYacGen:Variant.Trojan.Liev.9
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050f7371 )
K7GWTrojan ( 0050f7371 )
Cybereasonmalicious.e26554
BitDefenderThetaGen:NN.ZexaF.36250.XsW@a8jZkkk
CyrenW32/S-a0eadfad!Eldorado
SymantecHacktool.Veil!g3
ESET-NOD32a variant of Win32/Agent.YXS
APEXMalicious
ClamAVWin.Malware.Liev-9646116-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Trojan.Liev.9
NANO-AntivirusTrojan.Win32.Cobalt.evgfoi
MicroWorld-eScanGen:Variant.Trojan.Liev.9
AvastWin32:Evo-gen [Trj]
Ad-AwareGen:Variant.Trojan.Liev.9
EmsisoftGen:Variant.Trojan.Liev.9 (B)
F-SecureHeuristic.HEUR/AGEN.1314221
DrWebTrojan.Siggen9.14613
VIPREGen:Variant.Trojan.Liev.9
McAfee-GW-EditionBehavesLike.Win32.TrojanVeil.vh
FireEyeGeneric.mg.ebb872ae26554f0f
SophosATK/Veil-AZ
IkarusTrojan.Win32.Leivion
JiangminHackTool.Cobalt.ax
AviraHEUR/AGEN.1314221
MicrosoftTrojan:Win32/Leivion.S
ArcabitTrojan.Trojan.Liev.9
GDataWin32.Trojan.PSE.S4M0C2
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R286547
McAfeeTrojan-Veil-FLRK!EBB872AE2655
MAXmalware (ai score=89)
VBA32Trojan.Leivion
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Agent!1.E34D (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.11902157.susgen
FortinetW32/Agent.YXS!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Leivion?

Trojan.Leivion removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment