W32/Lightmoon-A exhibits the following characteristics:
File Information
- Size
- 119K
- SHA-1
- c963c58671f4b1541d3562b6f4c45b1e553d2e12
- MD5
- 081bc5750966a27250a1ae56477adbb2
- CRC-32
- 1ea94cff
- File type
- Windows executable
- First seen
- 2012-08-03
Other vendor detection
- Avira
- Worm/VB.CZ.14.A
- Kaspersky
- HEUR:Worm.Win32.Generic
Runtime Analysis
Copies Itself To
- C:\WINDOWS\M24627\EmangEloh.exe
- C:\WINDOWS\M24627\Ja745710bLay.com
- C:\WINDOWS\M24627\smss.exe
- C:\WINDOWS\Ti434852ta.exe
- C:\WINDOWS\sa-644166.exe
- C:\WINDOWS\system32\016276434852l.exe
- C:\WINDOWS\system32\X40223go\Z016276cie.cmd
- c:\Documents and Settings\test user\Templates\O52525Z\service.exe
- c:\Documents and Settings\test user\Templates\O52525Z\winlogon.exe
Dropped Files
- C:\WINDOWS\system\msvbvm60.dll
Modified Files
- %SYSTEM%\msvbvm60.dll
- Set the readonly, hidden, system and archive flags
Registry Keys Created
- HKCU\Software\VB and VBA Program Settings\untukmu\version
- me
- 4
- HKLM\SOFTWARE\Microsoft\TUX\biang
- 5
- 0x00002028
- HKLM\SOFTWARE\Microsoft\TUX\Path
- 3
- X40223go