Virus

How to remove “Virus:Win32/Expiro.CG”?

Malware Removal

The Virus:Win32/Expiro.CG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.CG virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Expiro.CG?


File Info:

name: C314D34525D17A1D68B8.mlw
path: /opt/CAPEv2/storage/binaries/465348ac22490e3db6a3ea3dc1f0700d3335da0ad34f51adfbd852fd767f3820
crc32: D82E1BBD
md5: c314d34525d17a1d68b8ee38388197e0
sha1: c5783c4cff01de25e83bdba989da098dcdfb5598
sha256: 465348ac22490e3db6a3ea3dc1f0700d3335da0ad34f51adfbd852fd767f3820
sha512: e42658783dd999d20308d3d6dca2ff39b74757db12c9cbe98426441af0bedaa9cab3c4b3bc64eb33da98687b98240800e3fa70d1f8079eaf3be8bee411c91644
ssdeep: 12288:7Dx0vwOEH0gUPkcwHUaumXbBkAyfwU6WKQp001IUoj7PEnUX44KPwYoO+wItBLFL:7Dx0vwOEH0gUPkd0aumXbBkAyft6a00u
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AAD48C7872542E09C4A23EB2E0D54D39E76546213E0E7FCEC9A6BE40315EF5EE4A8D0D
sha3_384: 92bb44ce954f93ab752380f968bd9ebec2179621094b935ac46156765a71243420dd50e59b5229ebb129182821ce2d23
ep_bytes: 605589e581ec08010000c745fc0e0000
timestamp: 2008-04-13 18:35:44

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows NT DDE Server
FileVersion: 5.1.2600.5512 (xpsp.080413-2105)
InternalName: CLIPSRV.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: CLIPSRV.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.5512
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.CG also known as:

BkavW32.Expiro2NHc.PE
LionicVirus.Win32.Expiro.mC50
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.3
ClamAVWin.Virus.Expiro-9461472-0
CAT-QuickHealW32.Expiro.L4
SkyhighBehavesLike.Win32.Virut.jc
McAfeeW32/Expiro.gen.p
MalwarebytesGeneric.Malware/Suspicious
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 0040f4dc1 )
AlibabaVirus:Win32/Expiro.262fbf62
K7GWVirus ( 0040f4dc1 )
Cybereasonmalicious.cff01d
BaiduWin32.Virus.Expiro.c
VirITWin32.Expiro.AN
SymantecW32.Xpiro.F
tehtrisGeneric.Malware
ESET-NOD32Win32/Expiro.NCB
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Expiro.ar
BitDefenderWin32.Expiro.Gen.3
NANO-AntivirusVirus.Win32.Expiro.clnvwd
AvastWin32:Xpirat [Inf]
TencentVirus.Win32.Expiro.nr
SophosW32/Expiro-S
F-SecureMalware.W32/Expiro.caia
DrWebWin32.Expiro.80
ZillyaVirus.Expiro.Win32.46
TrendMicroPE_EXPIRO.AR
FireEyeGeneric.mg.c314d34525d17a1d
EmsisoftWin32.Expiro.Gen.3 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.3
GoogleDetected
AviraW32/Expiro.caia
Antiy-AVLVirus/Win32.Expiro.nr
KingsoftWin32.Infected.AutoInfector.a
XcitiumPacked.Win32.Krap.AS@1pt1ia
ArcabitWin32.Expiro.Gen.3
ZoneAlarmVirus.Win32.Expiro.ar
MicrosoftVirus:Win32/Expiro.CG
VaristW32/Expiro.BL
AhnLab-V3Win32/Expiro5.Gen
Acronissuspicious
BitDefenderThetaAI:FileInfector.6CBEB04B12
ALYacWin32.Expiro.Gen.3
MAXmalware (ai score=100)
VBA32BScope.Trojan.Vilsel
Cylanceunsafe
PandaW32/Expiro.O
TrendMicro-HouseCallPE_EXPIRO.AR
RisingVirus.Expiro!1.A140 (CLASSIC)
IkarusVirus.Win32.Virut
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.W
AVGWin32:Xpirat [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.CG?

Virus:Win32/Expiro.CG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment