Trojan

Should I remove “Trojan:Win32/Leivion!pz”?

Malware Removal

The Trojan:Win32/Leivion!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Leivion!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Leivion malware family

How to determine Trojan:Win32/Leivion!pz?


File Info:

name: 751F23626D4D2F001B79.mlw
path: /opt/CAPEv2/storage/binaries/0e7933389889be87e5379143166453dc705b3fca5e31d1b5956adaf1f73083ca
crc32: 1EA13DA3
md5: 751f23626d4d2f001b794362dbc3a344
sha1: 281b844f92c5c5f7c828102d817994e5ddc6d9dc
sha256: 0e7933389889be87e5379143166453dc705b3fca5e31d1b5956adaf1f73083ca
sha512: e0d690f2035204cbe43b8e0c41a633e895a352c7ba675677558d9ae1b130158b93dcc405033e668e3d9963a50b182c4ce5b6369d13764d146cc6cbecb87a3ac1
ssdeep: 49152:UtZNSttv2Pd2Pa6IMvYweQ5iZUe0f2NkTFdCsGjmuWe+wKy4oiHTxmnJe+ano8Ww:uZNG+b6I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125D507C0F9DB45F6D5078EB288E6922FAA30460883B1CAC7DF681E59EC5B7D1057B724
sha3_384: c2549493fe599a66545ddb1ac966393fa96098ab8278be963c579dfe81a78162178d8fd1447e1ff5b9f30f4576d7ca35
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Leivion!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.14613
MicroWorld-eScanGen:Variant.Trojan.Liev.9
FireEyeGeneric.mg.751f23626d4d2f00
CAT-QuickHealTrojan.GenericPMF.S17662776
SkyhighBehavesLike.Win32.TrojanVeil.vh
McAfeeTrojan-Veil-FLRK!751F23626D4D
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Trojan.Liev.9
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050f7371 )
K7GWTrojan ( 0050f7371 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36744.XsW@a8jZkkk
SymantecHacktool.Veil!g3
ESET-NOD32a variant of Win32/Agent.YXS
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R014C0DC324
ClamAVWin.Malware.Liev-9646116-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Trojan.Liev.9
NANO-AntivirusTrojan.Win32.Cobalt.evgfoi
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Agent.zq
EmsisoftGen:Variant.Trojan.Liev.9 (B)
F-SecureHeuristic.HEUR/AGEN.1314221
TrendMicroTROJ_GEN.R014C0DC324
SophosATK/Veil-AZ
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
JiangminHackTool.Cobalt.ax
WebrootW32.Trojan.Ransom
GoogleDetected
AviraHEUR/AGEN.1314221
VaristW32/S-a0eadfad!Eldorado
Antiy-AVLTrojan/Win32.Leivion
Kingsoftmalware.kb.a.995
MicrosoftTrojan:Win32/Leivion!pz
ArcabitTrojan.Trojan.Liev.9
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.15VG02W
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R286547
VBA32Trojan.Leivion
ALYacGen:Variant.Trojan.Liev.9
Cylanceunsafe
RisingTrojan.Agent!1.E34D (CLASSIC)
YandexTrojan.Agent!kqQdev3oNGg
IkarusTrojan.Win32.Leivion
MaxSecureTrojan.Malware.11902157.susgen
FortinetW32/Agent.YXS!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.f92c5c
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Leivion!pz?

Trojan:Win32/Leivion!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment