Virus

What is “Virus:Win32/Expiro.J”?

Malware Removal

The Virus:Win32/Expiro.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.J virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Expiro.J?


File Info:

name: CE713772100C7B07BE86.mlw
path: /opt/CAPEv2/storage/binaries/b479a88bd16ed750bbfcdab62e8ad6cba8894468a41c52fabaa0db51150d9d9d
crc32: A8585D71
md5: ce713772100c7b07be86241c83eca10c
sha1: 3b9508098e6a339f033c1ea7dccdcfe9ba2d875d
sha256: b479a88bd16ed750bbfcdab62e8ad6cba8894468a41c52fabaa0db51150d9d9d
sha512: 866e477602a8a734f6b57bc9bb33fbb6d36afebffee2483ff93f8705ac1d48e01a23c2605eaa3a7bbd22f10b8e9805c23708373aa1735968ec73a0637c484618
ssdeep: 3072:m1V6Cc49R/dMMMMMM2MMMMMZ12pZ9+ESg5bOvfJBFXcVZf8dPqH92o1wPDFensX8:m18CRRVMMMMMM2MMMMMCp+E6vPFFqD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130146C50B2404955EAB3283841222B6109EEFF6148725EB3FF603C4D2FFEFA1962575B
sha3_384: 67ac8ff87028cd84a7e1e77ebe445aaffdefe4d6f1b63a08b8cb0b42ed6ccbe1c569b5f18b9024fa6ab115b192da4a40
ep_bytes: 60e8e473020061e9c506ffff488d9505
timestamp: 2004-08-04 05:58:38

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Outlook Express
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: MSIMN
LegalCopyright: © 2004 Microsoft Corporation. All rights reserved.
OriginalFilename: MSIMN.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.00.2900.2180
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.J also known as:

BkavW32.ExpiroTN.PE
LionicVirus.Win32.Xorala.mp5D
Elasticmalicious (high confidence)
DrWebWin32.Expiro.8
MicroWorld-eScanWin32.Kakavex.L
FireEyeGeneric.mg.ce713772100c7b07
CAT-QuickHealW32.Expiro.Gen
SkyhighBehavesLike.Win32.Virut.ch
ALYacWin32.Kakavex.L
Cylanceunsafe
SangforVirus.Win32.Expiro.wc
K7AntiVirusVirus ( 0040f52d1 )
AlibabaVirus:Win32/Expiro.ee59f02b
K7GWTrojan ( 0040f52d1 )
BitDefenderThetaAI:FileInfector.F77542C30F
VirITWin32.Expiro.CB
SymantecW32.Xpiro
ESET-NOD32a variant of Win32/Expiro
APEXMalicious
ClamAVWin.Trojan.Expiro-8
KasperskyVirus.Win32.Expiro.i
BitDefenderWin32.Kakavex.L
NANO-AntivirusVirus.Win32.Expiro.gcih
AvastWin32:Expiro [Inf]
TencentVirus.Win32.Expiro.i
EmsisoftWin32.Kakavex.L (B)
F-SecureMalware.W32/Expiro.C
BaiduWin32.Virus.Expiro.b
ZillyaVirus.Expiro.Win32.10
TrendMicroPE_EXPIRO.GG
Trapminemalicious.high.ml.score
SophosW32/Expiro-D
SentinelOneStatic AI – Malicious PE
GDataWin32.Kakavex.L
JiangminWin32/Agent.e
WebrootW32.Malware.Gen
GoogleDetected
AviraW32/Expiro.C
VaristW32/Expiro.B.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.i
KingsoftWin32.Expiro.b.183808
XcitiumVirus.Win32.Expiro.10@u1b58
ArcabitWin32.Kakavex.L
ZoneAlarmVirus.Win32.Expiro.i
MicrosoftVirus:Win32/Expiro.J
CynetMalicious (score: 100)
AhnLab-V3Win32/Expiro3.Gen
McAfeeW32/Expiro.b
MAXmalware (ai score=100)
VBA32Virus.Expiro.108
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Expiro.gen
TrendMicro-HouseCallPE_EXPIRO.GG
RisingWorm.Win32.ExeKiller.m (CLASSIC)
YandexWin32.Expiro.Gen
IkarusVirus.Win32.Expiro
MaxSecureVirus.Expiro.Gen
FortinetW32/Expiro.NR
AVGWin32:Expiro [Inf]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.J?

Virus:Win32/Expiro.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment