Virus

How to remove “Virus:Win32/Expiro.MI!bit”?

Malware Removal

The Virus:Win32/Expiro.MI!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.MI!bit virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus:Win32/Expiro.MI!bit?


File Info:

name: 0B8DC187F49DB7103850.mlw
path: /opt/CAPEv2/storage/binaries/d457d74af8226c5f863a6bd903cf6711f8d1f114e722a27d219e2dca339b7e98
crc32: 7DB57B81
md5: 0b8dc187f49db7103850eaa3a87f2dd3
sha1: f21d744180eb1ee6e66ec5e0bbe4e4f505dea1b8
sha256: d457d74af8226c5f863a6bd903cf6711f8d1f114e722a27d219e2dca339b7e98
sha512: 828f7e4a3d5f65fa06383c41aaf4434f4079cfe0be07de95c0eb333fbd6b088820a20fddc2be5a596e255927d6460da8076d46c595b23938ac9e411cddc8f684
ssdeep: 12288:W68aJiPJGHvenKjNvZKCQbhSACBHuV4ONAsOGQzyGqlbq:W68asqvenKjNvZKCQbhrV4OKs6qle
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FDA4CF2333D4C832E2671575AC64A7B06F76B871B830AD0B23840BADCF79553DB6A746
sha3_384: 93bc62846b2b0f4e532e93f2e21f864d874d1d937921f2706838e65bcfb300626c8cafc7f8bf5ce762ab0406f9c8103b
ep_bytes: 5657532bf683c630648b3e518bf783c6
timestamp: 2013-02-05 16:37:53

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe® Flash® Player Update Service 11.7 r700
FileVersion: 11,7,700,169
LegalCopyright: Copyright © 1996 Adobe Systems Incorporated
LegalTrademarks: Adobe® Flash® Player
ProductName: Adobe® Flash® Player Update Service
ProductVersion: 11,7,700,169
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.MI!bit also known as:

BkavW32.Expiro2NHc.PE
MicroWorld-eScanWin32.Expiro.Gen.5
ClamAVWin.Packed.Sodinokibi-9822365-0
FireEyeGeneric.mg.0b8dc187f49db710
CAT-QuickHealW32.Xpiro.N1
ALYacWin32.Expiro.Gen.5
CylanceUnsafe
VIPREWin32.Expiro.Gen.5
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00550a661 )
K7GWVirus ( 00550a661 )
Cybereasonmalicious.7f49db
VirITWin32.Expiro.CS
CyrenW32/Expiro.CB
SymantecW32.Xpiro.I
Elasticmalicious (high confidence)
ESET-NOD32Win32/Expiro.CJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Expiro.nt
BitDefenderWin32.Expiro.Gen.5
NANO-AntivirusVirus.Win32.Gen.ccmw
TencentVirus.Win32.Expiro.ae
Ad-AwareWin32.Expiro.Gen.5
SophosML/PE-A + W32/Expiro-AC
ComodoVirus.Win32.Expiro.CG@79ayaa
DrWebWin32.Expiro.128
TrendMicroPE_EXPIRO.SJ
McAfee-GW-EditionBehavesLike.Win32.AdSnare.gc
Trapminemalicious.high.ml.score
EmsisoftWin32.Expiro.Gen.5 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.5
JiangminTrojan.Vilsel.auq
AviraW32/Infector.Gen8
Antiy-AVLTrojan/Generic.ASVirus.2D4
ArcabitWin32.Expiro.Gen.5
ZoneAlarmVirus.Win32.Expiro.nt
MicrosoftVirus:Win32/Expiro.MI!bit
GoogleDetected
AhnLab-V3Win32/Expiro5.Gen
McAfeeW32/Expiro.gen.rd
MAXmalware (ai score=83)
VBA32BScope.Trojan.Vilsel
TrendMicro-HouseCallPE_EXPIRO.SJ
RisingVirus.Expiro!1.A140 (CLASSIC)
IkarusVirus.Win32.Expiro
MaxSecureVirus.W32.Expiro.NS
FortinetW32/Expiro.CG
BitDefenderThetaAI:FileInfector.85DD157E12
PandaW32/Expiro.AI
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.MI!bit?

Virus:Win32/Expiro.MI!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment