Worm

Worm:Win32/Lightmoon!pz removal

Malware Removal

The Worm:Win32/Lightmoon!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Lightmoon!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Lightmoon!pz?


File Info:

name: 8D7C1F91C9914F9F08CC.mlw
path: /opt/CAPEv2/storage/binaries/871b5d451cc585431135b1534f2b5e4427e668310877ea36e50db48d3e043f82
crc32: 8C36FFBB
md5: 8d7c1f91c9914f9f08cc12e7ddae2c39
sha1: de118b9e1d85caec5fa12c0d2d35b362e5a4d75e
sha256: 871b5d451cc585431135b1534f2b5e4427e668310877ea36e50db48d3e043f82
sha512: bed82adeac477c971dd89d9e89f1777659f2806c7375a078bf5664b9ba59691247e51530d5a7a129c001f07aee10444816eb302f7359ad6212bc9645c3d70f89
ssdeep: 6144:3BlY+32WWluqvHpVmXWEjFJRWci+WUd20rUU5EYCTvaBju4z2G2b2Sx:3UnWwvHpVmXpjJIUd2cUusvalxzBY9x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12DA42A3AEB10B126FA578C7A78294E1A15283C3522119E4BB3926B4D34767C3F9F474F
sha3_384: a29c3ff7db0e94a4b9033337df0f32003a3ed7b1a4c0e2c0ba8622a9769d3233e5b11fce695f5e29381f917532c9c6d3
ep_bytes: 680c4d4000e8eeffffff000000000000
timestamp: 2007-01-12 10:04:58

Version Info:

Translation: 0x0409 0x04b0
Comments: Microsoft Corporation
CompanyName: File Folder
ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName: FILE FOLDER
OriginalFilename: FILE FOLDER.exe

Worm:Win32/Lightmoon!pz also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanDeepScan:Generic.Malware.LMV3!prn!g.C051BF71
SkyhighBehavesLike.Win32.Generic.gm
McAfeeW32/MoonLight.worm.b
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.VB.Win32.63717
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderDeepScan:Generic.Malware.LMV3!prn!g.C051BF71
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.VB.a
VirITTrojan.Win32.VB_Heur
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/NoonLight.Y
APEXMalicious
ClamAVWin.Worm.Moonlight-9775620-0
KasperskyEmail-Worm.Win32.VB.co
NANO-AntivirusTrojan.Win32.VB.foifdq
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
SophosW32/Bobandy-I
F-SecureTrojan.TR/Moonlight.DLL.yiila
DrWebTrojan.DownLoader6.64360
VIPREDeepScan:Generic.Malware.LMV3!prn!g.C051BF71
TrendMicroWORM_MOONLIGHT.F
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8d7c1f91c9914f9f
EmsisoftDeepScan:Generic.Malware.LMV3!prn!g.C051BF71 (B)
IkarusTrojan.Win32.Patched
JiangminWorm/VB.a
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Moonlight.DLL.yiila
VaristW32/Noon.K.gen!Eldorado
Antiy-AVLTrojan/Win32.NoonLight
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Lightmoon!pz
XcitiumTrojWare.Win32.Regrun.Q@1gs3xh
ArcabitDeepScan:Generic.Malware.LMV3!prn!g.C051BF71
ZoneAlarmEmail-Worm.Win32.VB.co
GDataDeepScan:Generic.Malware.LMV3!prn!g.C051BF71
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R243850
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacDeepScan:Generic.Malware.LMV3!prn!g.C051BF71
MAXmalware (ai score=86)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaW32/Moonlight.P.worm
ZonerTrojan.Win32.77489
TrendMicro-HouseCallWORM_MOONLIGHT.F
TencentEmail-Worm.Win32.Vb.c
YandexI-Worm.VB.ZUF
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Moonlight.B!worm
BitDefenderThetaAI:Packer.18D87A541D
AVGWin32:Trojan-gen
Cybereasonmalicious.e1d85c
AvastWin32:Trojan-gen

How to remove Worm:Win32/Lightmoon!pz?

Worm:Win32/Lightmoon!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment