Virus

Virus:Win32/Expiro.BJ removal instruction

Malware Removal

The Virus:Win32/Expiro.BJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.BJ virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Expiro.BJ?


File Info:

name: 3697CECBAA38D59131FD.mlw
path: /opt/CAPEv2/storage/binaries/bbb118355397e06dee3aaad7b8601933691cb1d64d87869c838bd2d3736d2a7b
crc32: 488813CC
md5: 3697cecbaa38d59131fde8bdf2e9df9a
sha1: baf59e56fd642b3754c5148214abe0adbad533d3
sha256: bbb118355397e06dee3aaad7b8601933691cb1d64d87869c838bd2d3736d2a7b
sha512: 4818ad1eca245fc8cefef0623e3bde1910d96fa9b06a34b080907e7e7917e9a1f6359c10b23f7ebd66d880840bfc9584e3d9bec45b5d8b451fde13bedfd5f47a
ssdeep: 3072:BbSG8qwlwqz5iMUFXdVp/hC2ckLcI40uJQIgNhVKafpZzBSNO7/12e5GaOWLOPSG:Bb78bz5iRFoI+CIUKaFVxoqhmsFCLxRd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A547C5C648C5BBDEAE3B7708EF882B38077BC549B20568E8B13F5EE24A45013F55396
sha3_384: d56f364708384c9beabc99d34edb608afdb837d09b6e12346af5e002d2e63a51384362d6d686d433fae84e8fc4d7830c
ep_bytes: 50519052905390545556575589e581ec
timestamp: 2004-08-04 06:07:31

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Telnet
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: tlntsvr.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: tlntsvr.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.2180
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.BJ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.BE
FireEyeGeneric.mg.3697cecbaa38d591
SkyhighBehavesLike.Win32.Expiro.dh
Cylanceunsafe
ZillyaVirus.Expiro.Win32.93
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Expiro.b5590f2a
K7GWVirus ( 0040f4dc1 )
K7AntiVirusVirus ( 0040f4dc1 )
BitDefenderThetaAI:FileInfector.975171A10F
VirITWin32.Expiro.AA
SymantecW32.Xpiro.D
ESET-NOD32Win32/Expiro.NAU
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderWin32.Expiro.BE
NANO-AntivirusVirus.Win32.Expiro.cboywd
AvastWin32:Expiro-BS
RisingVirus.Expiro!1.A140 (CLASSIC)
EmsisoftWin32.Expiro.BE (B)
DrWebWin32.Expiro.53
VIPREWin32.Expiro.BE
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusVirus.Win32.Expiro
GDataWin32.Expiro.BE
GoogleDetected
Antiy-AVLVirus/Win32.Expiro.ai
Kingsoftmalware.kb.a.999
XcitiumVirus.Win32.Expiro.isn@4z1wg0
ArcabitWin32.Expiro.BE
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirus:Win32/Expiro.BJ
VaristW32/Expiro.AI
VBA32Virus.Expiro.311
ALYacWin32.Expiro.BE
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware.AI.DDS
TencentWin32.Virus.Expiro.Osmw
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Expiro.W
FortinetW32/Expiro.fam
AVGWin32:Expiro-BS
Cybereasonmalicious.6fd642
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.BJ?

Virus:Win32/Expiro.BJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment