Virus

Should I remove “Virus.Win32.Expiro.ob”?

Malware Removal

The Virus.Win32.Expiro.ob is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Win32.Expiro.ob virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus.Win32.Expiro.ob?


File Info:

name: 59FDE0D6A147EC2A4BA0.mlw
path: /opt/CAPEv2/storage/binaries/d89806676981b2c4b108e6fba487080750788952b10c27411b67c68368987e53
crc32: 4B97AA9F
md5: 59fde0d6a147ec2a4ba03036e2ae098a
sha1: 8e05135f030b9aeffe80ea49c006cef3b0573549
sha256: d89806676981b2c4b108e6fba487080750788952b10c27411b67c68368987e53
sha512: 2246ce2e2ef21ac021399beba117d230c084f0a47d872bb88c61c62c852f7b3dcb05ec316b26c47b776798eca2e208c42064e1af91a0beb1438d7f3f5bb2be0e
ssdeep: 12288:WxLVMsCpn5K6hqL7JtLFIv/8YPRsK14ZzYjnxUKU8:WxLYi6huwUPKeIn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11CA4B0303550B23DF8D661F08D4EB231F5AE99746B2483C773B45AEDA864BC19A3429F
sha3_384: c4fe2f465aedf44b3de48ffb425d094403324c5f38e3bdfbb0bbf489b1ea5b3c40b44979eb275982370ce2cc9d9b635f
ep_bytes: 5253562bd283c218648b1a01d201da8b
timestamp: 2004-12-22 06:19:53

Version Info:

CompanyName: Microsoft Corp., Veritas Software
FileDescription: Logical Disk Manager service process
FileVersion: 2600.2180.503.0
InternalName: dmadmin
LegalCopyright: Copyright © 1985-2000 Microsoft Corporation. All rights reserved. Portions Copyright © 1997-2000 Veritas Software. All rights reserved.
OriginalFilename: dmadmin.exe
ProductName: Logical Disk Manager for Windows NT
ProductVersion: 1.0
Translation: 0x0409 0x04e4

Virus.Win32.Expiro.ob also known as:

BkavW32.Expiro2NHc.PE
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.59fde0d6a147ec2a
ALYacWin32.Expiro.Gen.6
CylanceUnsafe
K7AntiVirusVirus ( 00580a951 )
AlibabaVirus:Win32/Expiro.2df6c1d6
K7GWVirus ( 0052ed0c1 )
Cybereasonmalicious.6a147e
CyrenW32/Expiro.CC
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NCW
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Virus.Expiro-6963725-0
KasperskyVirus.Win32.Expiro.ob
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
TencentWin32.Virus.Expiro.Szvx
Ad-AwareWin32.Expiro.Gen.6
TACHYONVirus/W32.Expiro.D
EmsisoftWin32.Expiro.Gen.6 (B)
ComodoVirus.Win32.Expiro.NCW@89m86e
DrWebWin32.Expiro.144
VIPREVirus.Win32.Expiro.dp (v)
McAfee-GW-EditionBehavesLike.Win32.Fareit.gc
SophosMal/Generic-R + W32/Expiro-AV
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.6
AviraW32/Infector.Gen8
Antiy-AVLTrojan/Generic.ASVirus.2F9
ArcabitWin32.Expiro.Gen.6
ZoneAlarmVirus.Win32.Expiro.rd
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!59FDE0D6A147
VBA32BScope.Trojan.Packed
RisingVirus.Expiro!8.375 (CLOUD)
IkarusExpiro.Win32
FortinetW32/Expiro.NCW
BitDefenderThetaAI:FileInfector.1CD444C412
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus.Win32.Expiro.ob?

Virus.Win32.Expiro.ob removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment