Malware

Should I remove “W32/Moiva-A”?

Malware Removal

The W32/Moiva-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Moiva-A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine W32/Moiva-A?


File Info:

name: CA7D3F5EED5BED35A2A5.mlw
path: /opt/CAPEv2/storage/binaries/129ea78144cf6abd357527c2016aea4b457c4accbe91a3f3b4acab2e95c63d46
crc32: AC2452A9
md5: ca7d3f5eed5bed35a2a5092bbb47520f
sha1: 586c3fd1be0533f46495e6562c35b55e0bda86d2
sha256: 129ea78144cf6abd357527c2016aea4b457c4accbe91a3f3b4acab2e95c63d46
sha512: 52a1453a295f9515800127d00cef37da4d4f27d0d0dfb372d491ef862e4e7325603d81ee397827d3c29aec71f675ef0bc2603ac3646ee8817a7ff349fee5421a
ssdeep: 24576:GdeuhuxD05+2xsqjnhMgeiCl7G0nehbGZpbD:uHhp5+2FDmg27RnWGj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F75F1107680D072E87206348FB9D77A652EBD600F6546D7F3D82EBE5E742D12B31BA2
sha3_384: fae4b5baf3f5b1d64f11abd2956976e719ea8470384aab34c09e64b04b6c810d57e0816b2f2c5c7620e8c0eb5a2d7926
ep_bytes: e8c6050000e988feffffff2500f34300
timestamp: 2017-03-14 07:01:59

Version Info:

CompanyName: Intel Corporation
FileDescription: IntelCpHeciSvc Executable
InternalName: IntelCpHeciSvc
LegalCopyright: Copyright (C) 2011 Intel Corporation
LegalTrademarks: Intel Corporation
OriginalFilename: IntelCpHeciSvc.exe
ProductName: IntelCpHeciSvc Executable
ProductVersion: 9.0.14.0317
Translation: 0x0409 0x04b0

W32/Moiva-A also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.ca7d3f5eed5bed35
CAT-QuickHealW32.Expiro.R3
ALYacWin32.Expiro.Gen.7
MalwarebytesMalware.Heuristic.1001
K7AntiVirusVirus ( 00594aea1 )
K7GWVirus ( 00594aea1 )
CyrenW32/Expiro.AU.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32Win32/Expiro.NDO
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastFileRepMalware [Misc]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
DrWebWin32.Expiro.153
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
SentinelOneStatic AI – Suspicious PE
GDataWin32.Expiro.Gen.7
AviraW32/Infector.Gen
MAXmalware (ai score=86)
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
MicrosoftTrojan:Script/Phonzy.C!ml
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2165
McAfeeArtemis!CA7D3F5EED5B
TACHYONVirus/W32.Movia
VBA32Trojan.Sabsik.TE
Cylanceunsafe
RisingTrojan.Generic@AI.78 (RDMK:cmRtazpeDje2Rwqqkqn0ubMnmHBi)
IkarusVirus.Win32.Expiro
FortinetW32/FileInfector.C!tr
AVGFileRepMalware [Misc]
PandaW32/Moyv.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove W32/Moiva-A?

W32/Moiva-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment