Worm

Worm:Win32/Lightmoon.G information

Malware Removal

The Worm:Win32/Lightmoon.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Lightmoon.G virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Lightmoon.G?


File Info:

name: 950A9FD3E7C5567CB182.mlw
path: /opt/CAPEv2/storage/binaries/ca0947b326bfeac06147e9a77e6c2730947c7160aa288ba977809aa4ac14ce9e
crc32: A2EE006C
md5: 950a9fd3e7c5567cb1827a5a02f8c4f3
sha1: d2c684005ba2175c379e77cf9dfdec926d6bbab8
sha256: ca0947b326bfeac06147e9a77e6c2730947c7160aa288ba977809aa4ac14ce9e
sha512: f68b6c0e9a40b5cde9a2ab3880f79e3d875e03a397c6d3049f253104af7b9343dd1fbe3b884eb73a040117fd3bb15ad0725472dfda4df4d26ce299a0ea099da3
ssdeep: 1536:SNepuouRpu45hU/IEqNYTYOY01BU6iWuudDm+m8x8orIREi0m6:fQBpu45+/IlN8p1DiWFmb08odm6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DC83F150170CE9EFC5783A39036620A13BE58C264A55E6C98C91FE23FDF2E534EC5497
sha3_384: 9e4f2ae3e171a94a4b20823a66f06d18fa711a542be5e3bf85626a24bb246d782aad5ef2741ceeb9da2bccda9363eff0
ep_bytes: 60be00c041008dbe0050feff5783cdff
timestamp: 2008-12-07 04:12:59

Version Info:

0: [No Data]

Worm:Win32/Lightmoon.G also known as:

BkavW32.AIDetectMalware
AVGWin32:Moonl@UPX [Wrm]
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.Heur.fmW@rbXSkVoib
FireEyeGeneric.mg.950a9fd3e7c5567c
SkyhighBehavesLike.Win32.Generic.mc
McAfeeW32/MoonLight.worm.c
MalwarebytesMoonlight.Worm.Autorun.DDS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.E103CBF71D
VirITWorm.Win32.VB.CZ
SymantecW32.Rontokbro@mm
ESET-NOD32a variant of Win32/Kryptik.FMNH
CynetMalicious (score: 100)
APEXMalicious
ClamAVLegacy.Trojan.Agent-1388589
KasperskyVirus.Win32.Virut.q
BitDefenderGen:Trojan.Heur.fmW@rbXSkVoib
AvastWin32:Moonl@UPX [Wrm]
EmsisoftGen:Trojan.Heur.fmW@rbXSkVoib (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
VIPREGen:Trojan.Heur.fmW@rbXSkVoib
TrendMicroTROJ_GEN.R011C0CC924
Trapminemalicious.high.ml.score
SophosMal/Behav-043
IkarusVirus.Win32.Virut
VaristW32/Virut.CA.gen!Eldorado
AviraTR/Crypt.ULPM.Gen
Antiy-AVLWorm/Win32.VB.cz
Kingsoftmalware.kb.b.979
MicrosoftWorm:Win32/Lightmoon.G
ArcabitTrojan.Heur.ED1243A
ZoneAlarmVirus.Win32.Virut.q
GDataGen:Trojan.Heur.fmW@rbXSkVoib
GoogleDetected
ALYacGen:Trojan.Heur.fmW@rbXSkVoib
MAXmalware (ai score=87)
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_GEN.R011C0CC924
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
SentinelOneStatic AI – Malicious PE
Cybereasonmalicious.3e7c55
DeepInstinctMALICIOUS

How to remove Worm:Win32/Lightmoon.G?

Worm:Win32/Lightmoon.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment