Malware

What is “W32/Moiva-C”?

Malware Removal

The W32/Moiva-C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Moiva-C virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine W32/Moiva-C?


File Info:

name: A2F24B64E48C934A5D46.mlw
path: /opt/CAPEv2/storage/binaries/04fc59063e964f2d160bfdea16044d67a84c5c9fbadc623447d712ffb726a1d3
crc32: CE3A5262
md5: a2f24b64e48c934a5d469e6afc8cfc9b
sha1: 8b79e5926a437971865e68ee83d5de39522388b2
sha256: 04fc59063e964f2d160bfdea16044d67a84c5c9fbadc623447d712ffb726a1d3
sha512: 120310e46ebd928f5c82a325232dd45fe9c0e8672de69c7c2b44c17f9c351908f37f0af9d6f96a8833eb2886436d8f2cc1839938ae1341c8f6ec8ae02eee0a14
ssdeep: 12288:I/OVMFCqIoLjjDZcTf+Reg00VPv5YEZx:IWVMFHDZcTfcep0VPvpx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD752313B2D8B451F9D345F00AEF8240A51AEC328B185AC363C17ADF96B9BD6453D72B
sha3_384: c08ad3b3fa9b5547033b996fe578fcc3ff3526c365e242bdca8a0fd01b353ca0dec4aef375af523720484288c3b2a309
ep_bytes: e84b610900e905000000cccccccccc6a
timestamp: 2015-10-30 02:35:10

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows® installer
FileVersion: 5.0.10586.0 (th2_release.151029-1700)
InternalName: msiexec
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: msiexec.exe
ProductName: Windows Installer - Unicode
ProductVersion: 5.0.10586.0
Translation: 0x0409 0x04b0

W32/Moiva-C also known as:

BkavW32.AIDetectNet.01
LionicVirus.Win32.Moiva.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a2f24b64e48c934a
CAT-QuickHealW32.Expiro.H5
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Moiva.5e7b6357
K7GWVirus ( 0059041f1 )
K7AntiVirusVirus ( 0059041f1 )
CyrenW32/Expiro.AU.gen!Eldorado
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
Paloaltogeneric.ml
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
Trapminesuspicious.low.ml.score
SophosW32/Moiva-C
IkarusVirus.Win64.Expiro
GDataWin32.Expiro.Gen.7
AviraW32/Infector.Gen
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=88)
VBA32BScope.TrojanDownloader.Zenlod
MalwarebytesMalware.Heuristic.1001
PandaW32/Moyv.A
RisingTrojan.Generic@AI.95 (RDMK:cmRtazosIicpHSkfeyEClgJcibtp)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove W32/Moiva-C?

W32/Moiva-C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment