W32/Lightmoon-A

Category: Viruses and Spyware Protection available since:05 Feb 2013 17:29:25 (GMT)
Type: Win32 worm Last Updated:05 Feb 2013 17:29:25 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Lightmoon-A exhibits the following characteristics:

File Information

Size
119K
SHA-1
c963c58671f4b1541d3562b6f4c45b1e553d2e12
MD5
081bc5750966a27250a1ae56477adbb2
CRC-32
1ea94cff
File type
Windows executable
First seen
2012-08-03

Other vendor detection

Avira
Worm/VB.CZ.14.A
Kaspersky
HEUR:Worm.Win32.Generic

Runtime Analysis

Copies Itself To
  • C:\WINDOWS\M24627\EmangEloh.exe
  • C:\WINDOWS\M24627\Ja745710bLay.com
  • C:\WINDOWS\M24627\smss.exe
  • C:\WINDOWS\Ti434852ta.exe
  • C:\WINDOWS\sa-644166.exe
  • C:\WINDOWS\system32\016276434852l.exe
  • C:\WINDOWS\system32\X40223go\Z016276cie.cmd
  • c:\Documents and Settings\test user\Templates\O52525Z\service.exe
  • c:\Documents and Settings\test user\Templates\O52525Z\winlogon.exe
Dropped Files
  • C:\WINDOWS\system\msvbvm60.dll
Modified Files
  • %SYSTEM%\msvbvm60.dll
    • Set the readonly, hidden, system and archive flags
Registry Keys Created
  • HKCU\Software\VB and VBA Program Settings\untukmu\version
    me
    4
  • HKLM\SOFTWARE\Microsoft\TUX\biang
    5
    0x00002028
  • HKLM\SOFTWARE\Microsoft\TUX\Path
    3
    X40223go

download Try Sophos products for free
Download now