Virus

Should I remove “Virus:Win32/Expiro.AL”?

Malware Removal

The Virus:Win32/Expiro.AL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.AL virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Expiro.AL?


File Info:

name: 5F51F112E2E6EEBC9DEC.mlw
path: /opt/CAPEv2/storage/binaries/fc872681bd3063ac364486f859d4814695c58a718e925d4b4855cb43e9fe42bd
crc32: CD4ECAE3
md5: 5f51f112e2e6eebc9decef4354af382d
sha1: a7583bb4754b73195fc5b26ba13e18a094e5bdef
sha256: fc872681bd3063ac364486f859d4814695c58a718e925d4b4855cb43e9fe42bd
sha512: 9d03673e961b5cce1e2116c7f298bdd7f6bab673df3d8430a424220e137b7a61c1a3fee8307a1f4e4fae8f9ea35194891e6663984a54c46517616093d1273715
ssdeep: 3072:Ujc2+9O+URgs6vwjzwTm3hMuKPmm5h7pMJn8FMvnix6RklDBhFF:Hb9lDvssTyfyfpMN8ykX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T120049D01F7E17C67FEC9917017F499D80228E150BAF9289EB7432EA59463FE19CBC219
sha3_384: 64c0f7395fdb6f997cf2d3e1e19676d365597e6f0732e4a0253c3033de29e35b0006eed3d06fcf1e924a52ac2813d131
ep_bytes: 50515253545556575589e583ec605356
timestamp: 2008-04-13 18:36:59

Version Info:

CompanyName: Microsoft Corporation
FileDescription: NetMeeting Remote Desktop Sharing
FileVersion: 5.1.2600.5512
InternalName: mnmsrvc
LegalCopyright: Copyright © Microsoft Corporation 1996-2001
LegalTrademarks: Microsoft® is a registered trademark of Microsoft Corporation. Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: mnmsrvc.dll
ProductName: Windows® NetMeeting®
ProductVersion: 3.01
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.AL also known as:

BkavW32.Expiro2NHc.PE
LionicVirus.Win32.Expiro.mvQU
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.2
ClamAVWin.Trojan.Expiro-17
FireEyeGeneric.mg.5f51f112e2e6eebc
CAT-QuickHealW32.Expiro.D
SkyhighBehavesLike.Win32.Expiro.ch
McAfeeW32/Expiro.gen.a
Cylanceunsafe
SangforVirus.Win32.Expiro.wb
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Expiro.ec2a7baf
K7GWVirus ( 0040f4dc1 )
K7AntiVirusVirus ( 0040f4dc1 )
BitDefenderThetaAI:FileInfector.1BB980DD12
VirITWin32.Expiro.V
SymantecW32.Xpiro.E
ESET-NOD32Win32/Expiro.X
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Expiro.w
BitDefenderWin32.Expiro.Gen.2
NANO-AntivirusVirus.Win32.Expiro.jcukc
AvastWin32:Expiro-AC
TencentVirus.Win32.Expiro.b
TACHYONVirus/W32.Expiro.B
EmsisoftWin32.Expiro.Gen.2 (B)
BaiduWin32.Virus.Expiro.d
F-SecureMalware.W32/Expiro.X
DrWebWin32.Expiro.40
ZillyaVirus.Expiro.Win32.21
TrendMicroPE_EXPIRO.RAP
SophosW32/Expiro-H
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.2
JiangminWin32/Expiro.m
WebrootW32.Virus.AL
VaristW32/Expiro.T
AviraW32/Expiro.X
Antiy-AVLVirus/Win32.Expiro.w
KingsoftWin32.Expiro.pj.192000
XcitiumVirus.Win32.Expiro.ew@4jygz8
ArcabitWin32.Expiro.Gen.2
ZoneAlarmVirus.Win32.Expiro.w
MicrosoftVirus:Win32/Expiro.AL
GoogleDetected
AhnLab-V3Win32/Expiro.Gen
Acronissuspicious
ALYacWin32.Expiro.Gen.2
MAXmalware (ai score=100)
VBA32Virus.Expiro.317
PandaW32/Expiro.gen
TrendMicro-HouseCallPE_EXPIRO.RAP
RisingVirus.Expiro!1.A140 (CLASSIC)
IkarusTrojan.Win32.Spy
MaxSecureVirus.Expiro.W
FortinetW32/Expiro.W
AVGWin32:Expiro-AC
Cybereasonmalicious.4754b7
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.AL?

Virus:Win32/Expiro.AL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment