Search:  In

 Lunalight - Description


 Browse by name

 
 | misc | a | b | c | d | e | f | g | h | i | j | k | l | m | n | o | p | q | r | s | t | u | v | w | x | y | z |

Description:
Lunalight is a sophisticated Internet worm that spreads by e-mail through messages with archived attachments containing infected executables. Once the user opens such an attachment and runs the file in it, the parasite secretly installs itself to the system and runs a spreading routine. It uses an integrated mail engine to send malicious letters to e-mail addresses it gathers from local files. It may also attempt to propagate through floppy disks and via file sharing networks if any peer-to-peer applications are installed to the infected system. Then Lunalight runs a payload. It creates multiple copies of itself, disables the Task Manager and the Registry Editor, modifies some system settings and deletes files and registry keys related to certain parasites as well as some legitimate programs. Some essential system components might also be deleted. Lunalight can prevent some software and system tools from running. It may also log user keystrokes and perform Denial of Service (DoS) attacks. Furthermore, the parasite is able to update itself via the Internet.


Alias:

Category:
Worms

Automatic Removal: Most effective removal tool is: Easy SpyRemover

Manual Removal:



Stop Runnin Processes:
data [X1].exe
foto [X1].exe
l.exe
smss.exe
system.exe
winlogon.exe
5.exe
[X2].exe



Unregister DLLs:



Clean Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\[X2]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[X2]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell=[X2].exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\AlternateShell=[X2].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe, C:\Documents and Settings\[Current User]\Templates\[X2]\[X2].exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\titta
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\untukmu2



Remove Files:
data [X1].exe
foto [X1].exe
l.exe
smss.exe
system.exe
winlogon.exe
5.exe
[X2].exe
crtsys.dll
l.com
adodb.cmd
lsass.exe0.cmd
moonlight.scr

   


Latest Spyware Threats
    Comodo Trust Toolbar
    XP Antispyware 2009
    Antivirus 2010
    Freview
    RegistryGreat
    XPAntivirus
    Windows Antivirus 2008
    IE AntiVirus
    SpywareQuake 4
    Antivirus XP
    SecurePCCleaner
    Trojan.FakeAlert



Copyright © PcRepairCentral, 2005.