Worm

Worm:Win32/Lightmoon!pz removal tips

Malware Removal

The Worm:Win32/Lightmoon!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Lightmoon!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Worm:Win32/Lightmoon!pz?


File Info:

name: 305E1473C5FF0E25E1E0.mlw
path: /opt/CAPEv2/storage/binaries/f4541f8b6343f6924c41034aab0af47267665ce0ab55791a616eabfa11d899ba
crc32: 160D4A17
md5: 305e1473c5ff0e25e1e0beb14cfb02b1
sha1: 412367f2de9346affdd8a37c86ce46e5a9b05aa8
sha256: f4541f8b6343f6924c41034aab0af47267665ce0ab55791a616eabfa11d899ba
sha512: 2e8d29e9116a2e0460d97eb3201839e2a56603099f5445344267300c89a8cbdd9c4137a77a3836b09fbec3cea13de185e6de1690d3d99b846555e9f522c216cb
ssdeep: 6144:vY+32WWluqvHpVmXWEjFJRWci+WUd20rUU5EYCTvaBju4:QnWwvHpVmXpjJIUd2cUusvalx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F64293AEB10B12AFA538C7A78394E1615283C3162519E4BB3926B4930767C3F9F475F
sha3_384: efb481c994451870be56759e4764a19355592a2a97c60ab66250ddf7fa1b0548b8a3ee01e7436b7d264079968e55afc7
ep_bytes: 680c4d4000e8eeffffff000000000000
timestamp: 2007-01-12 10:04:58

Version Info:

0: [No Data]

Worm:Win32/Lightmoon!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Ulise.84101
SkyhighBehavesLike.Win32.PWSZbot.fm
McAfeeW32/MoonLight.worm.b
VIPREGen:Variant.Ulise.84101
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
BitDefenderGen:Variant.Ulise.84101
K7GWNetWorm ( 700000151 )
CrowdStrikewin/malicious_confidence_90% (D)
VirITWorm.Win32.MoonLight.A
Elasticmalicious (high confidence)
ESET-NOD32Win32/NoonLight.Y
APEXMalicious
ClamAVWin.Worm.Moonlight-9775620-0
KasperskyEmail-Worm.Win32.VB.co
NANO-AntivirusTrojan.Win32.VB.foifdq
RisingWorm.NoonLight!8.4EF (TFE:3:gaeiTKQY09L)
SophosW32/Bobandy-I
BaiduWin32.Worm.VB.a
DrWebTrojan.DownLoader6.64360
ZillyaWorm.VB.Win32.63914
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.305e1473c5ff0e25
EmsisoftGen:Variant.Ulise.84101 (B)
IkarusTrojan.AgentMB.VB
MAXmalware (ai score=88)
JiangminWorm/VB.a
WebrootW32.Malware.Gen
GoogleDetected
VaristW32/Backdoor.J.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.b.1000
MicrosoftWorm:Win32/Lightmoon!pz
XcitiumTrojWare.Win32.Regrun.Q@1gs3xh
ArcabitTrojan.Ulise.D14885
ZoneAlarmEmail-Worm.Win32.VB.co
GDataGen:Variant.Ulise.84101
CynetMalicious (score: 100)
Acronissuspicious
VBA32Worm.VB
ALYacGen:Variant.Ulise.84101
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moonlight.P.worm
ZonerTrojan.Win32.77489
TencentWorm.Win32.Vb.wao
YandexI-Worm.VB!rsRZYoOxulI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Moonlight.B!worm
AVGWin32:VB-DHR [Wrm]
Cybereasonmalicious.2de934
AvastWin32:VB-DHR [Wrm]

How to remove Worm:Win32/Lightmoon!pz?

Worm:Win32/Lightmoon!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment