Trojan

Trojan:Win32/Leonem removal guide

Malware Removal

The Trojan:Win32/Leonem is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Leonem virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:Win32/Leonem?


File Info:

name: 862AB45F1971154697E1.mlw
path: /opt/CAPEv2/storage/binaries/93ad84ccbfa42d17d6690e0e7f6babe73ab64a672f2a1b1ab68004830efc6c6d
crc32: 2A4C419B
md5: 862ab45f1971154697e151522f778224
sha1: cea83f06f9742fdbc5c93b5702d7e1fa7cee17c3
sha256: 93ad84ccbfa42d17d6690e0e7f6babe73ab64a672f2a1b1ab68004830efc6c6d
sha512: da5554337b72473079d482000eb7d5b099fd5675d510e794e0717f983cc72f95aa226bdd30ffe68bca1999507dbeeca6d726d8c21eccd6c56b8b2b97471a98ac
ssdeep: 24576:Y0AFsxBjlY9S10EZxg+CUqIxWU7nQFDPXfU6xWp+B9n7ClGG:Yjsnl5RrgMDQtt2E9UGG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119355B983650B59FC45BCE36CA645C20EB60BC67530BE307A49732AD9D2E69BCF150F2
sha3_384: f1f351dd4449919696f8d76f9ce2dfd910eb886c5c79884b3e25c58ce44f4f9f7a54c6dac8dd471d62c9958760590e5f
ep_bytes: ff250020400000000000000000000000
timestamp: 2100-07-04 04:08:03

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Weifen Luo
FileDescription: Panel Suite
FileVersion: 1.0.0.0
InternalName: Ass.exe
LegalCopyright: Copyright © Weifen Luo 2007
LegalTrademarks:
OriginalFilename: Ass.exe
ProductName: Panel Suite
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:Win32/Leonem also known as:

BkavW32.AIDetectNet.01
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.61079908
FireEyeGeneric.mg.862ab45f19711546
McAfeeArtemis!862AB45F1971
MalwarebytesMalware.AI.3466631963
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005964d71 )
BitDefenderTrojan.GenericKD.61079908
K7GWTrojan ( 005964d71 )
BitDefenderThetaGen:NN.ZemsilF.34806.hn0@ayqdYHn
CyrenW32/Trojan.IDF.gen!Eldorado
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/GenKryptik.FYDE
TrendMicro-HouseCallTrojanSpy.Win32.AZORULT.YXCG3Z
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/GenKryptik.ab39bdb9
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:jomMXyL7W0Tw+OvZX4rsww)
Ad-AwareTrojan.GenericKD.61079908
SophosML/PE-A
DrWebTrojan.PackedNET.1464
VIPRETrojan.GenericKD.61079908
TrendMicroTrojanSpy.Win32.AZORULT.YXCG3Z
McAfee-GW-EditionBehavesLike.Win32.Fareit.tc
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.GenericKD.61079908 (B)
APEXMalicious
AviraHEUR/AGEN.1202701
Antiy-AVLTrojan/Generic.ASMalwS.720E
MicrosoftTrojan:Win32/Leonem
GDataTrojan.GenericKD.61079908
CynetMalicious (score: 100)
VBA32CIL.HeapOverride.Heur
ALYacTrojan.GenericKD.61079908
CylanceUnsafe
PandaTrj/Chgt.AD
TencentWin32.Trojan.Sdum.Dyqc
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.FVXS!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Leonem?

Trojan:Win32/Leonem removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment