Backdoor

Backdoor.MSIL.LightStone.egq removal tips

Malware Removal

The Backdoor.MSIL.LightStone.egq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.LightStone.egq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Anomalous binary characteristics

How to determine Backdoor.MSIL.LightStone.egq?


File Info:

name: 985E15CC244BD6E59D8F.mlw
path: /opt/CAPEv2/storage/binaries/3f395080b15cb30633f0efa3875b90428cf3866ac456e3c27a3e82b78edafdf1
crc32: 02D916C1
md5: 985e15cc244bd6e59d8fe752d579b034
sha1: 411f595117b80325d55d4a2c1ea92dd268439dd9
sha256: 3f395080b15cb30633f0efa3875b90428cf3866ac456e3c27a3e82b78edafdf1
sha512: d22cf70396347924f11ada22f652e3bbca0d5db09e6fc753e6d22c13165e7b2624ba9b32ef97af99f6e87889f30080df519ddd3939a195ebe26ece7319576def
ssdeep: 24576:ldmrjSFqJkfBYfz0rOKKts62Uxg7SlAq8IyXHUCb19iyTJkbst+ySUtY:ldmr2mygykAe8PlJSvCY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A55335C4D3353A9DE5F567A625223D6AAEA6C3A5E001CDD1EBFCD00F470EA839C4509
sha3_384: 1fdaf82adafaef03872cb2cef0db1bb1c82f76b1713b1d9483ab0fdcd734ea3827a0e2bae29e1e164ea076a537790853
ep_bytes: 558bec83c4f0b800104000e801000000
timestamp: 2021-10-10 14:18:44

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.132.56703
InternalName: telescop
LegalCopyright: Please find more information
OriginalFilename: telescop.exe
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04b0

Backdoor.MSIL.LightStone.egq also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Symmi.4!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.985e15cc244bd6e5
McAfeeArtemis!985E15CC244B
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:MSIL/LightStone.48d13955
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c244bd
BitDefenderThetaGen:NN.ZexaF.34726.qz0@aGY6ESii
CyrenW32/Trojan.FFG.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.J suspicious
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.MSIL.LightStone.egq
NANO-AntivirusTrojan.Win32.LightStone.jmnysm
AvastWin32:Malware-gen
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraHEUR/AGEN.1215880
Antiy-AVLTrojan/Generic.ASBOL.C669
MicrosoftBackdoor:MSIL/DCRat.GA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Sabsik.R446654
Acronissuspicious
VBA32Trojan.Zpevdo
MalwarebytesTrojan.Injector
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
YandexBackdoor.LightStone!O36g8LunvKg
IkarusPUA.Packed.Enigma
FortinetRiskware/Application
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor.MSIL.LightStone.egq?

Backdoor.MSIL.LightStone.egq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment