Virus

About “Virus:Win32/Expiro.AL” infection

Malware Removal

The Virus:Win32/Expiro.AL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.AL virus can do?

  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Expiro.AL?


File Info:

name: B7E6CDCEC25D98BC67E5.mlw
path: /opt/CAPEv2/storage/binaries/696775c317cc7a69f816f261ab09e4f6cba63466d5767058aab5651b592ac152
crc32: CC7D231A
md5: b7e6cdcec25d98bc67e5060e9a3dd830
sha1: 6f73ff721e5313593a391be36b336c9f75eb7748
sha256: 696775c317cc7a69f816f261ab09e4f6cba63466d5767058aab5651b592ac152
sha512: d29f8405bed399a1d5d55e5d605b4ec335782878ea2f733ff26a2838db741669b1c6268437f1d050f30ff411b5c8408e62c12af827652548f6db6dcb4bcf212d
ssdeep: 6144:bgvo5luxSrwwEAVQptNfaPnSxSrkdA0mRnMGhr9ISjdSVox5QdwID4t/pV:cvqlqSrzEAupLiPuSrN0oMapIHq/3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F742846A385F018E967047CF652D7F01295BCB3EBE187973A487F2FBA3019D0A31A46
sha3_384: 0265ab27567827b3cd88f03486544f85626c048b18e8945c449a9c281cedfd5a4497d6044cf3fac067a3ef1bed139cde
ep_bytes: 50515253545556575589e583ec605356
timestamp: 2004-08-04 06:07:11

Version Info:

CompanyName: Microsoft Corporation
FileDescription: On-Screen Keyboard
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: osk
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: osk.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.2180
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.AL also known as:

BkavW32.Expiro2NHc.PE
tehtrisGeneric.Malware
MicroWorld-eScanWin32.Expiro.Gen.2
FireEyeGeneric.mg.b7e6cdcec25d98bc
CAT-QuickHealW32.Expiro.D
SkyhighBehavesLike.Win32.PWSZbot.fh
ALYacWin32.Expiro.Gen.2
Cylanceunsafe
VIPREWin32.Expiro.Gen.2
SangforVirus.Win32.Expiro.wb
K7AntiVirusVirus ( 0040f4dc1 )
AlibabaVirus:Win32/Expiro.fda48c48
K7GWVirus ( 0040f4dc1 )
Cybereasonmalicious.21e531
BitDefenderThetaAI:FileInfector.1BB980DD12
VirITWin32.Expiro.V
SymantecW32.Xpiro.E
Elasticmalicious (high confidence)
ESET-NOD32Win32/Expiro.X
APEXMalicious
ClamAVWin.Trojan.Expiro-17
KasperskyVirus.Win32.Expiro.w
BitDefenderWin32.Expiro.Gen.2
NANO-AntivirusVirus.Win32.Expiro.jcukc
AvastWin32:Xpiro [Inf]
TencentVirus.Win32.Expiro.b
EmsisoftWin32.Expiro.Gen.2 (B)
BaiduWin32.Virus.Expiro.d
F-SecureTrojan.TR/Kazy.JC
DrWebWin32.Expiro.40
TrendMicroPE_EXPIRO.RAP
Trapminemalicious.high.ml.score
SophosW32/Expiro-H
IkarusTrojan.Win32.Spy
MAXmalware (ai score=100)
GDataWin32.Expiro.Gen.2
JiangminWin32/Expiro.m
GoogleDetected
AviraTR/Kazy.JC
VaristW32/Expiro.T
Antiy-AVLVirus/Win32.Expiro.w
KingsoftWin32.Expiro.pj.192000
XcitiumVirus.Win32.Expiro.ew@4jygz8
ArcabitWin32.Expiro.Gen.2
ZoneAlarmVirus.Win32.Expiro.w
MicrosoftVirus:Win32/Expiro.AL
CynetMalicious (score: 100)
AhnLab-V3Win32/Expiro.Gen
Acronissuspicious
McAfeeW32/Expiro.gen.a
TACHYONVirus/W32.Expiro.B
VBA32Virus.Expiro.317
PandaW32/Expiro.gen
TrendMicro-HouseCallPE_EXPIRO.RAP
RisingVirus.Expiro!1.A140 (CLASSIC)
YandexWin32.Expiro.Gen.4
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Expiro.W
FortinetW32/Expiro.W
AVGWin32:Xpiro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.AL?

Virus:Win32/Expiro.AL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment