Worm

Worm:Win32/Moonlight!pz removal guide

Malware Removal

The Worm:Win32/Moonlight!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Moonlight!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Moonlight!pz?


File Info:

name: 8AFB4932E05773B23237.mlw
path: /opt/CAPEv2/storage/binaries/00abfb96ea09b88d5fe521c747f187a6d6677c292539be3c68b5c8f10f941add
crc32: 0D06221B
md5: 8afb4932e05773b2323712be30cb768c
sha1: 1487913888ecf8be5b53e8d45c8b687bfe92e5ea
sha256: 00abfb96ea09b88d5fe521c747f187a6d6677c292539be3c68b5c8f10f941add
sha512: ab70a46dfcfce8f3adaac66927cd65f10fb42262f7d69065ea5e102517bcc22709a7b727b65a7a45f3ab2ee6efa6fa3fcc2766358dbbcb371d0e87bcb17a46fe
ssdeep: 1536:i3C8wUcw1dwm8qlwn4iEv72oIY6bGkPwTufpXeTVZR3AWgCuNjC2WL2Rou:o0UXEfhEYbzPCTVZR3AWijGLMou
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1392501A2E7F04E1BD1E25538F2378229123A7E4A1176FDE906D2D00788367C65B798B6
sha3_384: 895b48aefe539f3a3d3f5b70f51c4475c04956f5c7ad2eea804fd1d950be1c85317937b0dfb8e034ee993e97f15f0714
ep_bytes: 807c2408010f859101000060be004006
timestamp: 1999-12-09 19:19:48

Version Info:

CompanyName: dEvil.Inc
FileDescription: LunALight Zipper
FileVersion:
InternalName:
LegalCopyright:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Worm:Win32/Moonlight!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Genome.leFd
MicroWorld-eScanGen:Variant.Zusy.440663
FireEyeGeneric.mg.8afb4932e05773b2
SkyhighBehavesLike.Win32.Trojan.dz
ALYacGen:Variant.Zusy.440663
Cylanceunsafe
ZillyaWorm.NoonLight.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0001140e1 )
AlibabaWorm:Win32/Moonlight.2c1a203e
K7GWTrojan ( 0001140e1 )
BitDefenderThetaGen:NN.ZedlaF.36744.9mVfaKx6H0fi
VirITWorm.Win32.Generic.AGSF
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/NoonLight.AA
APEXMalicious
ClamAVWin.Trojan.Moonlight-9881795-0
KasperskyHEUR:Trojan.Win32.Moonlight.gen
BitDefenderGen:Variant.Zusy.440663
AvastWin32:Trojan-gen
TencentEmail-Worm.Win32.VB.ha
F-SecureTrojan.TR/Moonlight.DLL.Dam
DrWebTrojan.DownLoader6.64360
VIPREGen:Variant.Zusy.440663
EmsisoftGen:Variant.Zusy.440663 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE1.VP3X0H
JiangminI-Worm/VB.bj.a
GoogleDetected
AviraTR/Moonlight.DLL.Dam
VaristW32/Noon.K.gen!Eldorado
Antiy-AVLTrojan/Win32.Genome
ArcabitTrojan.Zusy.D6B957 [many]
ZoneAlarmHEUR:Trojan.Win32.Moonlight.gen
MicrosoftWorm:Win32/Moonlight!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Damaged.R95983
McAfeeArtemis!8AFB4932E057
MAXmalware (ai score=81)
VBA32Worm.VB
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Win32.Damaged.a (CLASSIC)
YandexWorm.NoonLight!yraM5LGj/Aw
IkarusTrojan.Moonlight
MaxSecureTrojan.Malware.711133.susgen
FortinetW32/Moonlight.DAM!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Worm:Win32/Moonlight!pz?

Worm:Win32/Moonlight!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment