Virus

Virus:Win32/Expiro.AL removal guide

Malware Removal

The Virus:Win32/Expiro.AL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.AL virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Expiro.AL?


File Info:

name: DFA2193096DD2C214B55.mlw
path: /opt/CAPEv2/storage/binaries/7b35ab265fad79b484f4647f99de699b7bd3f88088ca9be328c9fb2efb953a2c
crc32: C7AFF616
md5: dfa2193096dd2c214b558677fea51000
sha1: 92c11d92d8f58ff538a7ffdc5ab1f353f25c1f8e
sha256: 7b35ab265fad79b484f4647f99de699b7bd3f88088ca9be328c9fb2efb953a2c
sha512: 13e2ac37eed74ed3edfc3e847f0e7f940907647db2f593f3f55fd9da92023b8124ffe36427ea8f4f587a7ed827aecaa9fa881876d9b148e9be6975e8a049e6ba
ssdeep: 6144:XDQ1VY7yScIRouWgirLDZToKe+wcE4IPL77CgExRhYz0RAHZ:XDQ1nScI+uWdrLDNEJL77CgsrWHZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EC548D0170F0903FE4AF25717A9DB15595294132F3283FDB2ACC2FAAEA60DAD7634356
sha3_384: b13f1d4885fe35eed34d7b320bac8a8c0cb49b1901e4079f7698cdf6352ad0355125b41e6776ca064d98411c81f698dd
ep_bytes: 50515253545556575589e583ec605356
timestamp: 2004-08-04 06:02:48

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Image Mastering API
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: imapi
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: imapi.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.2180
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.AL also known as:

BkavW32.Expiro2NHc.PE
LionicVirus.Win32.Expiro.lrDN
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.dfa2193096dd2c21
CAT-QuickHealW32.Expiro.D
SkyhighBehavesLike.Win32.Expiro.dc
McAfeeW32/Expiro.gen.a
VIPREWin32.Expiro.Gen.2
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 0040f4dc1 )
AlibabaVirus:Win32/Expiro.c56b4bd6
K7GWVirus ( 0040f4dc1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:FileInfector.1BB980DD12
VirITWin32.Expiro.V
SymantecW32.Xpiro.E
tehtrisGeneric.Malware
ESET-NOD32Win32/Expiro.X
APEXMalicious
ClamAVWin.Trojan.Expiro-17
KasperskyVirus.Win32.Expiro.w
BitDefenderWin32.Expiro.Gen.2
NANO-AntivirusVirus.Win32.Expiro.jcukc
MicroWorld-eScanWin32.Expiro.Gen.2
AvastWin32:Xpiro [Inf]
TACHYONVirus/W32.Expiro.B
EmsisoftWin32.Expiro.Gen.2 (B)
BaiduWin32.Virus.Expiro.d
F-SecureTrojan.TR/Kazy.IO
DrWebWin32.Expiro.40
ZillyaVirus.Expiro.Win32.21
TrendMicroPE_EXPIRO.RAP
Trapminemalicious.high.ml.score
SophosW32/Expiro-H
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.2
JiangminWin32/Expiro.m
AviraTR/Kazy.IO
Antiy-AVLVirus/Win32.Expiro.w
KingsoftWin32.Expiro.pj.192000
XcitiumVirus.Win32.Expiro.ew@4jygz8
ArcabitWin32.Expiro.Gen.2
ZoneAlarmVirus.Win32.Expiro.w
MicrosoftVirus:Win32/Expiro.AL
VaristW32/Expiro.T
AhnLab-V3Win32/Expiro.Gen
Acronissuspicious
VBA32Virus.Expiro.317
ALYacWin32.Expiro.Gen.2
MAXmalware (ai score=100)
Cylanceunsafe
PandaW32/Expiro.gen
TrendMicro-HouseCallPE_EXPIRO.RAP
RisingVirus.Expiro!1.A140 (CLASSIC)
IkarusTrojan.Win32.Spy
MaxSecureVirus.Expiro.W
FortinetW32/Expiro.W
AVGWin32:Xpiro [Inf]
Cybereasonmalicious.096dd2
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.AL?

Virus:Win32/Expiro.AL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment