Trojan

Trojan:Win32/Leivion!pz removal tips

Malware Removal

The Trojan:Win32/Leivion!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Leivion!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Leivion malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Leivion!pz?


File Info:

name: F637A5A0338446163BED.mlw
path: /opt/CAPEv2/storage/binaries/a9eb474a70e54c1d85dc2c334abba902a4e444d778b89390b214e00a84878ecb
crc32: 295C43C3
md5: f637a5a0338446163bed85235c8288d7
sha1: cf94caabebb676789ea43b400c4c98d40ab1c3bc
sha256: a9eb474a70e54c1d85dc2c334abba902a4e444d778b89390b214e00a84878ecb
sha512: 9dab2e428c1ba47bf094711b34544a0f1e658da79a5bcc93b2e36992eabe5a9c44a2d2d158f199521bb4721d42e5b3ec5c1b8c962d846210b5bd1b2d1d355fbc
ssdeep: 49152:OekkMTSJMOnQhU63jIYweQ5iZUe0f1ekmZdCsGjmu9e+wKy4oiHOxmtk0nBCL8Ww:jkkxya63
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11AD507C0F9DB45F6D5078EB288E6922FAA30460883B1CAC7DF681E59EC5B7D1057B724
sha3_384: 2e29605dc6dbc5e74c9b7f03aa4611738a65c837ec331309c3058b95204f55be08ca178e7cbe7814c12d275e2af9b582
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Leivion!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Trojan.Liev.9
CAT-QuickHealTrojan.GenericPMF.S17662776
SkyhighBehavesLike.Win32.TrojanVeil.vh
ALYacGen:Variant.Trojan.Liev.9
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050f7371 )
K7GWTrojan ( 0050f7371 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Trojan.Liev.9
SymantecHacktool.Veil!g3
ESET-NOD32a variant of Win32/Agent.YXS
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Liev-9646116-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Trojan.Liev.9
NANO-AntivirusTrojan.Win32.Cobalt.evgfoi
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Agent.zq
EmsisoftGen:Variant.Trojan.Liev.9 (B)
F-SecureHeuristic.HEUR/AGEN.1314221
DrWebTrojan.Siggen9.14613
VIPREGen:Variant.Trojan.Liev.9
FireEyeGeneric.mg.f637a5a033844616
SophosATK/Veil-AZ
SentinelOneStatic AI – Malicious PE
JiangminHackTool.Cobalt.ax
WebrootW32.Trojan.Ransom
VaristW32/S-a0eadfad!Eldorado
AviraHEUR/AGEN.1314221
MicrosoftTrojan:Win32/Leivion!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.10OXN14
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R286547
McAfeeTrojan-Veil-FLRK!F637A5A03384
MAXmalware (ai score=84)
VBA32Trojan.Leivion
Cylanceunsafe
RisingTrojan.Agent!1.E34D (CLASSIC)
IkarusTrojan.Win32.Leivion
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.YXS!tr
BitDefenderThetaGen:NN.ZexaF.36802.XsW@aejDAIp
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Agent.8705d1a1

How to remove Trojan:Win32/Leivion!pz?

Trojan:Win32/Leivion!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment