Trojan

TrojanDownloader:Win32/Leodon.D removal guide

Malware Removal

The TrojanDownloader:Win32/Leodon.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Leodon.D virus can do?

  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Leodon.D?


File Info:

name: 33D326F7A79494B5CA3E.mlw
path: /opt/CAPEv2/storage/binaries/37548aea431722f23b2af50c6aad316008dc26cc23ad8912f0879daea00790c9
crc32: C7840C58
md5: 33d326f7a79494b5ca3e39bed9fb8bd5
sha1: e3bced71094926669f1ad0c3ba83d7f2c3f61ba1
sha256: 37548aea431722f23b2af50c6aad316008dc26cc23ad8912f0879daea00790c9
sha512: b68814d15ff4c26e3d06327a4b3a527b109ce665a759be2ab872216a83864a35fa1276444202e1359e1a966d43148b872440ddf730872ea2b21a4043d957d71e
ssdeep: 768:oCyiql0mQoxYlFanSl+Ym+g9iFxEG1tx37S0wPtyoNIUCjejt1P8FFbK4Ntc:Iiql0mQoxpnDYzDWEth+PtyVUCjeEO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D283D0AEFAE089B3C136DDBD8E24C255DB377A200E2D0645F99E1DDCDE673A1181C206
sha3_384: 570c00db30f474847c4b7af111e0cc5958b077c7b11712d9be9370e9491662c816f120b15570d0266222e4ad3635dead
ep_bytes: 558bec83c4f053b8dc484000e8b3f1ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

TrojanDownloader:Win32/Leodon.D also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Viking.l3Va
MicroWorld-eScanGen:Variant.Doina.20805
FireEyeGeneric.mg.33d326f7a79494b5
SkyhighBehavesLike.Win32.Sytro.lm
McAfeePolyPatch-UPX
MalwarebytesMalware.Heuristic.2047
ZillyaTrojan.Delf.Win32.81294
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanDownloader:Win32/Cosmu.8728a641
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.7a7949
BaiduWin32.Trojan.Delf.it
VirITTrojan.Win32.Delf.QIP
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Delf.PGB
APEXMalicious
TrendMicro-HouseCallMal_Otorun9
ClamAVWin.Trojan.Agent-899155
KasperskyTrojan.Win32.Cosmu.xet
BitDefenderGen:Variant.Doina.20805
NANO-AntivirusTrojan.Win32.Nilage.croxoi
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.13b03a0e
SophosW32/Autorun-BGT
F-SecureTrojan.TR/Delf.V.1
DrWebTrojan.MulDrop1.16843
VIPREGen:Variant.Doina.20805
TrendMicroMal_Otorun9
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Doina.20805 (B)
IkarusWorm.Win32.AutoRun
JiangminTrojan/Cosmu.dkj
GoogleDetected
AviraTR/Delf.V.1
VaristW32/Autorun.DVQD-1997
Antiy-AVLWorm/Win32.AutoRun
KingsoftWin32.HeurC.KVM003.a
MicrosoftTrojanDownloader:Win32/Leodon.D
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Doina.D5145
ZoneAlarmTrojan.Win32.Cosmu.xet
GDataGen:Variant.Doina.20805
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cosmu.C99609
VBA32Trojan-Dropper.Delf.Bps
ALYacGen:Variant.Doina.20805
MAXmalware (ai score=99)
Cylanceunsafe
PandaTrj/CI.A
RisingDownloader.Leodon!8.EA2 (TFE:4:Uc2UGAQ0zfS)
YandexTrojan.GenAsa!athc83fE8WU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1751547.susgen
FortinetW32/Cosmu.XET!tr
BitDefenderThetaAI:Packer.1701B46A20
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm:Win/Delf.PGB

How to remove TrojanDownloader:Win32/Leodon.D?

TrojanDownloader:Win32/Leodon.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment