Virus

Virus:Win32/Expiro.L removal instruction

Malware Removal

The Virus:Win32/Expiro.L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.L virus can do?

  • Unconventionial language used in binary resources: Japanese
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Virus:Win32/Expiro.L?


File Info:

name: DEA79C193EE50EC3475A.mlw
path: /opt/CAPEv2/storage/binaries/8caa184142badf50166a91c15a1aec3c91370620d7cee1420ed1d328e96c4a28
crc32: BF65E1CE
md5: dea79c193ee50ec3475a5c5af244b765
sha1: 9ae41ad522e65807b1e1b1578357922393cf70ff
sha256: 8caa184142badf50166a91c15a1aec3c91370620d7cee1420ed1d328e96c4a28
sha512: 76e64fb6771094b3abcd47f8c48abd2ddd4048699edda46bb20f6febbe7fda418ff8c08baa4b1d4022c18e16d3c48cffc89b33e7b3992121b6249ea0cce1dc80
ssdeep: 12288:8Uwqt8pg8e+63/JQCOCFhGVrjp123E1U9zepnfLN:8vqH8eb/JQCOWhKpE3TMpnfLN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D515187272A2C0E1F826863149BF5EEE3EF5DC4716790A6322E0F96EEDB35427D11211
sha3_384: e6753d399e92f5cf1660bee4e431011f7c0322a2cebafc9da2f90c23a732eb0f39b63a302b5d9a820b08ba9ec18c79f0
ep_bytes: 605589e583ec60535657c745e8060000
timestamp: 2003-11-21 12:49:45

Version Info:

CompanyName: CANON INC.
FileDescription: Canon PageComposer Queue Manager
FileVersion: 4.40.008
InternalName: CPC10Q
LegalCopyright: Copyright CANON INC. 1997-2003 All Rights Reserved
OriginalFilename: CPC10Q.EXE
ProductName: Canon PageComposer
ProductVersion: 4.40.008
Translation: 0x0411 0x04b0

Virus:Win32/Expiro.L also known as:

LionicVirus.Win32.Expiro.lo0C
Elasticmalicious (high confidence)
DrWebWin32.Expiro.22
MicroWorld-eScanWin32.Expiro.Gen.2
ClamAVWin.Virus.Expiro-9824284-0
FireEyeGeneric.mg.dea79c193ee50ec3
CAT-QuickHealW32.Expiro.D
SkyhighBehavesLike.Win32.Infected.dm
ALYacWin32.Expiro.Gen.2
MalwarebytesGeneric.Malware/Suspicious
ZillyaVirus.Expiro.Win32.75
SangforTrojan.Win32.Agent.nil
K7AntiVirusVirus ( 0040f4dc1 )
AlibabaVirus:Win32/Expiro.f73a52c3
K7GWVirus ( 0040f4dc1 )
Cybereasonmalicious.522e65
BitDefenderThetaAI:FileInfector.1BB980DD12
VirITWin32.Expiro.U
SymantecW32.Xpiro.D
ESET-NOD32Win32/Expiro.R
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Expiro.w
BitDefenderWin32.Expiro.Gen.2
NANO-AntivirusVirus.Win32.Expiro.josia
AvastWin32:Xpiro [Inf]
TencentVirus.Win32.Expiro.c
EmsisoftWin32.Expiro.Gen.2 (B)
F-SecureMalware.W32/Expiro.N
BaiduWin32.Virus.Expiro.d
VIPREWin32.Expiro.Gen.2
TrendMicroPE_EXPIRO.RAP
SophosW32/Expiro-H
IkarusVirus.Win32.Expiro
JiangminWin32/Expiro.h
WebrootW32.Malware.Gen
GoogleDetected
AviraW32/Expiro.N
MAXmalware (ai score=100)
Antiy-AVLVirus/Win32.Expiro.w
KingsoftWin32.Expiro.pj.192000
MicrosoftVirus:Win32/Expiro.L
XcitiumMalCrypt.Indus!@1qrzi1
ArcabitWin32.Expiro.Gen.2
ViRobotWin32.Expiro.Gen.B
ZoneAlarmVirus.Win32.Expiro.w
GDataWin32.Expiro.Gen.2
VaristW32/Expiro.O
AhnLab-V3Win32/Expiro2.Gen
McAfeeW32/Expiro.gen.a
VBA32Virus.Win32.Expiro.SEP.1
Cylanceunsafe
PandaW32/Expiro.gen
TrendMicro-HouseCallPE_EXPIRO.RAP
RisingVirus.Expiro!1.A140 (CLASSIC)
YandexWin32.Expiro.O
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.Expiro.W
FortinetW32/Expiro.fam
AVGWin32:Xpiro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.L?

Virus:Win32/Expiro.L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment