Virus

About “Virus:Win32/Expiro.AJ” infection

Malware Removal

The Virus:Win32/Expiro.AJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.AJ virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Expiro.AJ?


File Info:

name: D31C0D39141F6AC9D89F.mlw
path: /opt/CAPEv2/storage/binaries/3de2cc2cc83cd97ea5b4f67b3df2c68aa9e0ba30e18908edf9a72b127ff6d6df
crc32: C763FA13
md5: d31c0d39141f6ac9d89f903dea0c29a0
sha1: f36d76d9860f0c098d1f0ec6d208c25f706bf1d9
sha256: 3de2cc2cc83cd97ea5b4f67b3df2c68aa9e0ba30e18908edf9a72b127ff6d6df
sha512: 165e9decb08bf7461794520d22ee535b776c4b2b26e49bf5196a58fb621076e9be441370cbec279c14e50a890991e3d9109603f70678efdbe053f2f7eac60095
ssdeep: 6144:2gmIFuaxNO0JehQIQ4ZiBjRqlRPc0CoG4PrVuYaXP8:bFuau0J41De98RPQPyr8YaE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D034ADD2684BE228D6511EB0133B94D35234F9741B225F9FF3A03EF5A5656C3827B2CA
sha3_384: a53ff38be6b7a34479fc1008fb678125888f67b0bc0cb2d3c36bcae021b7fdf8270478e824f97a5174ea7fba5873eaa0
ep_bytes: 60e8d19d0100906190e9d873ffff720f
timestamp: 2010-11-20 08:45:43

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Takes ownership of a file
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
InternalName: takeown.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: takeown.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7601.17514
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.AJ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Kakavex.T
FireEyeGeneric.mg.d31c0d39141f6ac9
CAT-QuickHealW32.Expiro.Gen
SkyhighBehavesLike.Win32.Expiro.dc
McAfeeW32/Expiro.gen.k
ZillyaVirus.Expiro.Win32.58
SangforTrojan.Win32.Save.a
AlibabaVirus:Win32/Expiro.6f36cdc8
K7GWTrojan ( 0040f52d1 )
K7AntiVirusVirus ( 0040f52d1 )
BitDefenderThetaAI:FileInfector.E419DA950F
SymantecW32.Xpiro.C
ESET-NOD32a variant of Win32/Expiro.NBA
APEXMalicious
TrendMicro-HouseCallPE_EXPIRO.AE
ClamAVWin.Virus.Expiro-9961389-0
KasperskyVirus.Win32.Expiro.x
BitDefenderWin32.Kakavex.T
NANO-AntivirusVirus.Win32.Expiro.uukpy
AvastWin32:Expiro [Inf]
TencentVirus.Win32.Expiro.bb
EmsisoftWin32.Kakavex.T (B)
BaiduWin32.Virus.Expiro.b
F-SecureMalware.W32/Expiro.CC
DrWebWin32.Expiro.41
VIPREWin32.Kakavex.T
TrendMicroPE_EXPIRO.AE
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusVirus.Win32.Expiro
JiangminWin32/Expiro.m
GoogleDetected
AviraW32/Expiro.CC
VaristW32/Expiro.F.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.998
MicrosoftVirus:Win32/Expiro.AJ
XcitiumVirus.Win32.Expiro.nc@4rchke
ArcabitWin32.Kakavex.T
ZoneAlarmVirus.Win32.Expiro.x
GDataWin32.Kakavex.T
CynetMalicious (score: 100)
AhnLab-V3Win32/Expiro3.Gen
Acronissuspicious
VBA32Virus.Expiro.ab
ALYacWin32.Kakavex.T
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Chgt.AC
ZonerProbably Heur.ExeHeaderL
RisingVirus.Expiro!1.9B1D (CLASSIC)
YandexWin32.Expiro.P
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Expiro.Gen
FortinetW32/Expiro.NR
AVGWin32:Expiro [Inf]
DeepInstinctMALICIOUS
alibabacloudVirus:Win/Expiro.AIIPKLKAIOE

How to remove Virus:Win32/Expiro.AJ?

Virus:Win32/Expiro.AJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment