Worm

Worm:Win32/Lightmoon!pz removal instruction

Malware Removal

The Worm:Win32/Lightmoon!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Lightmoon!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Lightmoon!pz?


File Info:

name: F71A0A6E94FEBD274D5B.mlw
path: /opt/CAPEv2/storage/binaries/b0dca6d8f2853cc00cc7e7da5d6521028d817254f3aa8fb136509336d99a2163
crc32: CAFD4170
md5: f71a0a6e94febd274d5bc014f3c65d36
sha1: 84710dba63e8e55101a05294d9c83c7aee2ecd0a
sha256: b0dca6d8f2853cc00cc7e7da5d6521028d817254f3aa8fb136509336d99a2163
sha512: 5977968cf39d993e4754e223fa106362b170f30832ce9033a9fa1d272d6686b920440b9bbe9e399ea1f87f910e0114b93b1508138fd12bd6afa80fd869ff21da
ssdeep: 6144:yY+32WWluqvHpVmXWEjFJRWci+WUd20hUU5EYCTvaBju4zk9Op:hnWwvHpVmXpjJIUd2OUusvalxzk9Op
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BBA42A3AEB10B126FA578C7A782A4E1615243C3522119E4BB3926B4D38767C3F9F474F
sha3_384: fcd6bf08b8842a7283a394598bd7ae1a8245de2c52dd1b1544dd576078a466781315af86f3c86bda70cf9f664caae443
ep_bytes: 680c4d4000e8eeffffff000000000000
timestamp: 2007-01-12 10:04:58

Version Info:

Translation: 0x0409 0x04b0
Comments: Microsoft Corporation
CompanyName: File Folder
ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName: FILE FOLDER
OriginalFilename: FILE FOLDER.exe

Worm:Win32/Lightmoon!pz also known as:

BkavW32.AIDetectMalware
DrWebTrojan.DownLoader6.64360
MicroWorld-eScanDeepScan:Generic.Malware.LMV3!prn!g.EE1407F1
FireEyeGeneric.mg.f71a0a6e94febd27
SkyhighBehavesLike.Win32.Ramnit.gt
McAfeeW32/MoonLight.worm.b
MalwarebytesGeneric.Malware.AI.DDS
VIPREDeepScan:Generic.Malware.LMV3!prn!g.EE1407F1
SangforTrojan.Win32.Save.ShadowBrokersC
K7AntiVirusTrojan ( 0040f6141 )
BitDefenderDeepScan:Generic.Malware.LMV3!prn!g.EE1407F1
K7GWTrojan ( 0040f6141 )
Cybereasonmalicious.a63e8e
BitDefenderThetaAI:Packer.764ED5571D
VirITWorm.Win32.MoonLight.A
SymantecW32.Lunalight@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/NoonLight.Y
APEXMalicious
ClamAVWin.Worm.Moonlight-9775620-0
KasperskyEmail-Worm.Win32.VB.co
NANO-AntivirusTrojan.Win32.VB.foifdq
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
EmsisoftDeepScan:Generic.Malware.LMV3!prn!g.EE1407F1 (B)
GoogleDetected
F-SecureTrojan.TR/Moonlight.DLL.yiila
BaiduWin32.Worm.VB.a
ZillyaWorm.VB.Win32.67990
Trapminemalicious.high.ml.score
SophosW32/Bobandy-I
SentinelOneStatic AI – Malicious PE
JiangminWorm/VB.a
WebrootW32.Malware.Gen
VaristW32/Noon.K.gen!Eldorado
AviraTR/Moonlight.DLL.yiila
MAXmalware (ai score=80)
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Lightmoon!pz
XcitiumTrojWare.Win32.Regrun.Q@1gs3xh
ArcabitDeepScan:Generic.Malware.LMV3!prn!g.EE1407F1
ZoneAlarmEmail-Worm.Win32.VB.co
GDataDeepScan:Generic.Malware.LMV3!prn!g.EE1407F1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.VBKrypt.R526323
Acronissuspicious
ALYacDeepScan:Generic.Malware.LMV3!prn!g.EE1407F1
DeepInstinctMALICIOUS
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaW32/Moonlight.P.worm
ZonerTrojan.Win32.77489
TencentWorm.Win32.Vb.wao
YandexWorm.NoonLight!yraM5LGj/Aw
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Moonlight.B!worm
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Lightmoon!pz?

Worm:Win32/Lightmoon!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment