Categories: Virus

Virus:Win64/Expiro.A malicious file

The Virus:Win64/Expiro.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win64/Expiro.A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win64/Expiro.A?


File Info:

name: 9E4702352AB1050BB450.mlwpath: /opt/CAPEv2/storage/binaries/9019a1a1994f06694d2110e6ccd2bea3d3f939e2c740c04ca97af7f2d8878b72crc32: 51FB3CDFmd5: 9e4702352ab1050bb450bac3308f7c09sha1: 0c13ac522a3d944e5f947686d76a6371680cdb17sha256: 9019a1a1994f06694d2110e6ccd2bea3d3f939e2c740c04ca97af7f2d8878b72sha512: 1e3a766d010575f93abbc987277ede95875c02fc4fe1b566dc8e8e61510badec02dec79afa99ed4a0f1b99728926ae5e41de05e744f76e6456ce2e5e251c4380ssdeep: 12288:NXItfaupmdQLvZRIwYyZBdyuYUj/s8zp7TDtFx0g:5ItfaEmdNpyhyxUlJDzxtype: PE32+ executable (console) x86-64, for MS Windowstlsh: T1D0B48D504A4A723BDB9CE331D1E9CB5A01597A36260B11F706C648D69BB2C5BB3C32FDsha3_384: 7d86c061c0ffb7d7e8aad6fb4e973f64a87978d95516b411300d8fb9ffd1f04c73b6f15d3278f652f6ae11c6c2e24893ep_bytes: 554889e5535641544155415641574881timestamp: 2008-11-08 16:22:40

Version Info:

CompanyName: Microsoft CorporationFileDescription: SNMP TrapFileVersion: 10.0.17134.1 (WinBuild.160101.0800)InternalName: snmptrap.exeLegalCopyright: © Microsoft Corporation. All rights reserved.OriginalFilename: snmptrap.exeProductName: Microsoft® Windows® Operating SystemProductVersion: 10.0.17134.1Translation: 0x0409 0x04b0

Virus:Win64/Expiro.A also known as:

Elastic malicious (high confidence)
MicroWorld-eScan Win64.Expiro.A
FireEye Generic.mg.9e4702352ab1050b
CAT-QuickHeal W64.Expiro.AY
ALYac Win64.Expiro.A
Cylance Unsafe
VIPRE Virus.Win64.Expiro.a (v)
K7AntiVirus Virus ( 0040f8071 )
K7GW Virus ( 0040f8071 )
CrowdStrike win/malicious_confidence_100% (D)
Baidu Win64.Virus.Expiro.e
Cyren W64/Expiro.AQ
Symantec W64.Xpiro
ESET-NOD32 Win64/Expiro.A
APEX Malicious
ClamAV Win.Virus.Sodinokibi-8015275-0
Kaspersky Virus.Win64.Expiro.c
BitDefender Win64.Expiro.A
NANO-Antivirus Virus.Win64.Expiro.byadzr
Avast Win64:Xpiro [Inf]
Tencent Virus.Win64.Expiro.Gen
Ad-Aware Win64.Expiro.A
TACHYON Virus/W64.Expiro.C
Emsisoft Win64.Expiro.A (B)
DrWeb Win64.Expiro.108
Zillya Virus.Expiro.Win64.1
TrendMicro PE64_EXPIRO.JX
McAfee-GW-Edition BehavesLike.Win64.Generic.hc
Sophos ML/PE-A + W64/Expiro-A
Ikarus Win32.Kryptik
Webroot W32.Virus.Win64.Expiro
Avira W64/Infector.Gen8
Antiy-AVL Trojan/Generic.ASVirus.1A7
Microsoft Virus:Win64/Expiro.A
GData Win64.Expiro.A
Cynet Malicious (score: 100)
AhnLab-V3 Win32/Expiro.Gen
McAfee W64/Expiro
MAX malware (ai score=88)
VBA32 Win64.Expiro.1
TrendMicro-HouseCall PE64_EXPIRO.JX
Rising Virus.Expiro!1.A140 (CLASSIC)
SentinelOne Static AI – Malicious PE
MaxSecure virus.win64.expiro.gen
Fortinet W64/Expiro.Q
AVG Win64:Xpiro [Inf]
Cybereason malicious.52ab10
Panda W32/Expiro.gen

How to remove Virus:Win64/Expiro.A?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Midie.100502 removal tips

The Midie.100502 is considered dangerous by lots of security experts. When this infection is active,…

36 mins ago

Malware.AI.3915743673 (file analysis)

The Malware.AI.3915743673 is considered dangerous by lots of security experts. When this infection is active,…

42 mins ago

Malware.AI.2034266737 removal

The Malware.AI.2034266737 is considered dangerous by lots of security experts. When this infection is active,…

42 mins ago

Trojan.Win32.Agent.xbmkmt removal tips

The Trojan.Win32.Agent.xbmkmt is considered dangerous by lots of security experts. When this infection is active,…

48 mins ago

About “MSIL/Kryptik.ALNP” infection

The MSIL/Kryptik.ALNP is considered dangerous by lots of security experts. When this infection is active,…

52 mins ago

How to remove “Malware.AI.4206534535”?

The Malware.AI.4206534535 is considered dangerous by lots of security experts. When this infection is active,…

58 mins ago