Worm

What is “Worm:Win32/Lightmoon!pz”?

Malware Removal

The Worm:Win32/Lightmoon!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Lightmoon!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Worm:Win32/Lightmoon!pz?


File Info:

name: EF238F18A0B2003A95C4.mlw
path: /opt/CAPEv2/storage/binaries/cf2947ff2c22a6ad42d03baa65024cb24ba0a34216396d0b5b8dd06bfb2ead4e
crc32: 286596B0
md5: ef238f18a0b2003a95c4c1d2eb9dc366
sha1: 30f9b0317c9dbae479d341ea46ed27e25e4a490d
sha256: cf2947ff2c22a6ad42d03baa65024cb24ba0a34216396d0b5b8dd06bfb2ead4e
sha512: 27aa39a64cc194a5d200ff04d0208074475af66070b4870696473174544d3045b2977cd29e21a1fa84c97781837f40ed7259d28172567d9de44643ec6cb064c1
ssdeep: 6144:dY+32WWluqvHpVmXWEjFJRWci+WUd201r+UU5EYCTvaBju4z:anWwvHpVmXpjJIUd2fUusvalxz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DFA4293AEB20B116FA578C7A78394E1A15283C3562119E4BB3926B4934727C3F9F474F
sha3_384: 4d49656bb92a922a229751f062bb9a30121d9ffd96b08ad9c7f3a907297e0c68790b03c394a594225815a5b93ddb0f5d
ep_bytes: 680c4d4000e8eeffffff000000000000
timestamp: 2007-01-12 10:04:58

Version Info:

Translation: 0x0409 0x04b0
Comments: Microsoft Corporation
CompanyName: File Folder
ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName: FILE FOLDER
OriginalFilename: FILE FOLDER.exe

Worm:Win32/Lightmoon!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Heur.Cq1@rHElvAfib
FireEyeGeneric.mg.ef238f18a0b2003a
SkyhighBehavesLike.Win32.MoonLight.gt
ALYacGen:Trojan.Heur.Cq1@rHElvAfib
Cylanceunsafe
VIPREGen:Trojan.Heur.Cq1@rHElvAfib
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Trojan.Heur.Cq1@rHElvAfib
K7GWNetWorm ( 700000151 )
K7AntiVirusNetWorm ( 700000151 )
BaiduWin32.Worm.VB.a
VirITTrojan.Win32.VB_Heur
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/NoonLight.Y
APEXMalicious
ClamAVWin.Worm.Moonlight-9775620-0
KasperskyEmail-Worm.Win32.VB.co
NANO-AntivirusTrojan.Win32.VB.foifdq
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
EmsisoftGen:Trojan.Heur.Cq1@rHElvAfib (B)
F-SecureTrojan.TR/Moonlight.DLL.yiila
DrWebTrojan.DownLoader6.64360
ZillyaWorm.VB.Win32.66382
TrendMicroWORM_MOONLIGHT.F
Trapminemalicious.high.ml.score
SophosW32/Bobandy-I
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=84)
JiangminWorm/VB.a
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Moonlight.DLL.yiila
VaristW32/Backdoor.J.gen!Eldorado
Antiy-AVLTrojan/Win32.Genome
Kingsoftmalware.kb.b.999
MicrosoftWorm:Win32/Lightmoon!pz
XcitiumTrojWare.Win32.Regrun.Q@1gs3xh
ArcabitTrojan.Heur.ED1B7BD
ZoneAlarmEmail-Worm.Win32.VB.co
GDataGen:Trojan.Heur.Cq1@rHElvAfib
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R243850
Acronissuspicious
McAfeeW32/MoonLight.worm.b
DeepInstinctMALICIOUS
VBA32Worm.VB
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moonlight.P.worm
ZonerTrojan.Win32.77489
TrendMicro-HouseCallWORM_MOONLIGHT.F
TencentEmail-Worm.Win32.Vb.c
YandexI-Worm.VB.ZUF
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Moonlight.B!worm
BitDefenderThetaAI:Packer.3FDDFE651D
AVGWin32:Trojan-gen
Cybereasonmalicious.17c9db
AvastWin32:Trojan-gen

How to remove Worm:Win32/Lightmoon!pz?

Worm:Win32/Lightmoon!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment