Malware

W64/Moiva-B removal

Malware Removal

The W64/Moiva-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W64/Moiva-B virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine W64/Moiva-B?


File Info:

name: 3906E856B08C12ADB9AC.mlw
path: /opt/CAPEv2/storage/binaries/53932d212903dc98e9b4a50c7212c36c9806d67c3a1a6eaf82931908d0bd3aa7
crc32: 9BD5B576
md5: 3906e856b08c12adb9ac805a13eaa15b
sha1: d4f327071589a553866eef77ad2cb9aed7fcd443
sha256: 53932d212903dc98e9b4a50c7212c36c9806d67c3a1a6eaf82931908d0bd3aa7
sha512: 119f47ba5e7a5588cf1677606ca059b8b2c4ab596281d9d3c5e12556825f51d6b123381377cf051958f89295be36cae20b69938d36ff67fce379293dcfa2cf0b
ssdeep: 24576:NVW9VNxXDOKArpSNflxEQhcKZrocmvpftlhvAtOkzQi/:NVWRx6KAraEuc6ocepfDhvAtxzQ
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T17575F119F2B414F8E5B78238CD62894AE3F1BC9607B1D69F13E847561F376618C2EB21
sha3_384: 0a47f0f5cb6eef36fa11617c66dacb1883a38f9099e1a4dd512ab1a3022791fe48e299de1e17368e43d89cc4fab5c1d8
ep_bytes: 4883ec28e84b0500004883c428e97afe
timestamp: 2021-04-13 02:36:12

Version Info:

CompanyName: Google LLC
FileDescription: Google Crash Handler
FileVersion: 1.3.36.81
InternalName: Google Update
LegalCopyright: Copyright 2018 Google LLC
OriginalFilename: GoogleUpdate.exe
ProductName: Google Update
ProductVersion: 1.3.36.81
Translation: 0x0409 0x04b0

W64/Moiva-B also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin64.Expiro.Gen.7
FireEyeGeneric.mg.3906e856b08c12ad
CAT-QuickHealW32.Expiro.R3
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWVirus ( 00592e701 )
K7AntiVirusVirus ( 00592e701 )
CyrenW64/Expiro.AR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/Expiro.CV
CynetMalicious (score: 100)
KasperskyVirus.Win64.Moiva.a
BitDefenderWin64.Expiro.Gen.7
AvastWin64:Expiro-AJ [Inf]
TencentVirus.Win64.VirMoiva.a
EmsisoftWin64.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.153
VIPREWin64.Expiro.Gen.7
McAfee-GW-EditionBehavesLike.Win64.Dropper.tm
SophosW64/Moiva-B
IkarusTrojan-Ransom.FileCrypter
AviraW32/Infector.Gen
Antiy-AVLVirus/Win64.Expiro.ce
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitWin64.Expiro.Gen.7
ZoneAlarmVirus.Win64.Moiva.a
GDataWin64.Expiro.Gen.7
GoogleDetected
AhnLab-V3Malware/Win.Generic.R558504
ALYacWin64.Expiro.Gen.7
MAXmalware (ai score=84)
PandaW64/Moyv.A
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW64/Expiro.CU
AVGWin64:Expiro-AJ [Inf]
DeepInstinctMALICIOUS

How to remove W64/Moiva-B?

W64/Moiva-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment