Virus

How to remove “Virus:Win32/Expiro.DW”?

Malware Removal

The Virus:Win32/Expiro.DW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.DW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus:Win32/Expiro.DW?


File Info:

name: 733354392F31EF071018.mlw
path: /opt/CAPEv2/storage/binaries/963cf88f4cfd86a657bfb30b74230ac73cf722cd5dd1376534a85a531df40cf4
crc32: 0427500C
md5: 733354392f31ef0710189ba098244d60
sha1: e8daab9a98479729b3bbc07a8fe0524336b975fb
sha256: 963cf88f4cfd86a657bfb30b74230ac73cf722cd5dd1376534a85a531df40cf4
sha512: bcd60e5ff3a986f18d153ecf045f3a63290ba122be352c8f633a08dfaec49f609a597968807b0dc4acf3db6af1834d82f87f64eb4bc76dfbf547815028ca5129
ssdeep: 6144:2DQFQYU0FAjeYQl3kawkewxprZ0M/RYlwCK46Rqg+kdtFncd5btNyie:DFhU0ijepND5xRZ0M/RYlwnBRrJ7cfi5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E74CF103940C135CCDD33F6405CB7E0969EB8A10B6682CB675B56E9EF6C6C29E786CB
sha3_384: 7a31db064f55cd568676b256db9b411dd9e0568bd85904ae5784d219af611ea43413970fb266b1dfc8f4cbcb96becffc
ep_bytes: 52565729d283c230648b328b7e0c8bd7
timestamp: 2006-12-08 01:48:18

Version Info:

CompanyName: SEIKO EPSON CORPORATION
FileDescription: EPSON Status Monitor 3
FileVersion: 4.02
InternalName: E_S40RP7
LegalCopyright: Copyright (C) SEIKO EPSON CORP. 2007
OriginalFilename: E_S40RP7.EXE
ProductName: EPSON Status Monitor 3
ProductVersion: 4.02
Translation: 0x0409 0x04e4

Virus:Win32/Expiro.DW also known as:

BkavW32.Expiro2NHc.PE
LionicVirus.Win32.Expiro.mzJk
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.4
FireEyeGeneric.mg.733354392f31ef07
CAT-QuickHealWorm.Expiro.S29486633
SkyhighW32/Expiro.gen.ra
McAfeeW32/Expiro.gen.ra
MalwarebytesGeneric.Malware/Suspicious
ZillyaVirus.Expiro.Win32.111
SangforVirus.Win32.Expiro.Vdef
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Expiro.5d026be6
K7GWVirus ( 0058face1 )
K7AntiVirusVirus ( 0058face1 )
BitDefenderThetaAI:FileInfector.F2DA25E812
VirITWin32.Expiro.CI
SymantecW32.Xpiro.F
ESET-NOD32Win32/Expiro.NCI
APEXMalicious
TrendMicro-HouseCallPE_EXPIRO.A7
AvastWin32:Expiro-FN [Trj]
ClamAVWin.Virus.Expiro-7401753-0
KasperskyVirus.Win32.Expiro.ns
BitDefenderWin32.Expiro.Gen.4
NANO-AntivirusVirus.Win32.Expiro.dtodst
RisingVirus.Expiro!1.A140 (CLASSIC)
EmsisoftWin32.Expiro.Gen.4 (B)
BaiduWin32.Virus.Expiro.s
F-SecureMalware.W32/Expiro.CH
DrWebWin32.Expiro.100
VIPREWin32.Expiro.Gen.4
TrendMicroPE_EXPIRO.A7
Trapminemalicious.moderate.ml.score
SophosW32/Expiro-AC
IkarusVirus.Win32.Expiro
MAXmalware (ai score=99)
JiangminVirus.Expiro.f
GoogleDetected
AviraW32/Expiro.CH
VaristW32/Expiro.CB
Antiy-AVLVirus/Win32.Expiro.ns
Kingsoftmalware.kb.a.877
MicrosoftVirus:Win32/Expiro.DW
XcitiumVirus.Win32.Expiro.CG@79ayaa
ArcabitWin32.Expiro.Gen.4
ZoneAlarmVirus.Win32.Expiro.ns
GDataWin32.Expiro.Gen.4
CynetMalicious (score: 100)
AhnLab-V3Win32/Expiro5.Gen
ALYacWin32.Expiro.Gen.4
TACHYONVirus/W32.Expiro
Cylanceunsafe
PandaW32/Expiro.Y
TencentVirus.Win32.Expiro.ns
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.W32.Expiro.NS
FortinetW32/Expiro.CG
AVGWin32:Expiro-FN [Trj]
Cybereasonmalicious.92f31e
DeepInstinctMALICIOUS
alibabacloudVirus:Win/Expiro.HHXBBNNPPJEGE

How to remove Virus:Win32/Expiro.DW?

Virus:Win32/Expiro.DW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment