Malware

What is “W32/Expiro-AC”?

Malware Removal

The W32/Expiro-AC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Expiro-AC virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine W32/Expiro-AC?


File Info:

name: 8C76E9F33E2C0F5D661E.mlw
path: /opt/CAPEv2/storage/binaries/5158467bccdb4a1e8497bf1e023f17d2a41fb13ff8957e944e594f97ccb12699
crc32: 1353A945
md5: 8c76e9f33e2c0f5d661eb9a5254ac8be
sha1: 6e2466c2b49875a7da4a1eba55912f89c22b5e8f
sha256: 5158467bccdb4a1e8497bf1e023f17d2a41fb13ff8957e944e594f97ccb12699
sha512: 30eb7db3971c769dc518b49ccdd783ed1fdc25a3382faa2917f5379c909f86cd5b1eaff025c3dc1438a1471e6ce6dc0496c1db320113c1754833af002a84cfd1
ssdeep: 98304:l0nsR2Q3V1nANHRr9kDiwcc8326ZPahzwS08KfDlNuS3:lAb2V1yH59Y9ccb6ZPah+DlNuC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19136CF43AACD41E9D5972530A22AB321A2BFAF709B6544C75360E78DB13D7C38D36633
sha3_384: 5aecca04a6f83223019d96dc861e4bd67a3d785018f13c87580bf35b243b2d3c0af8b583b82c144c1f2c86b726b9c251
ep_bytes: 56505129f683c630648b06528b50088b
timestamp: 2076-02-19 18:16:24

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Software Protection Platform Service
FileVersion: 10.0.18362.815 (WinBuild.160101.0800)
InternalName: sppsvc
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: sppsvc.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.18362.815
Translation: 0x0409 0x04b0

W32/Expiro-AC also known as:

BkavW32.Expiro2NHc.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.5
FireEyeGeneric.mg.8c76e9f33e2c0f5d
CAT-QuickHealW32.Vilsel.C4
McAfeeW32/Expiro.gen.rc
CylanceUnsafe
K7AntiVirusVirus ( 00550a661 )
K7GWVirus ( 00550a661 )
Cybereasonmalicious.33e2c0
CyrenW32/Expiro.A!Generic
SymantecW32.Xpiro.I
ESET-NOD32a variant of Win32/Expiro.CG
APEXMalicious
KasperskyVirus.Win32.Expiro.rc
BitDefenderWin32.Expiro.Gen.5
NANO-AntivirusVirus.Win32.Expiro.eowduk
AvastWin32:Expiro-GG [Inf]
TencentVirus.Win32.Expiro.ae
EmsisoftWin32.Expiro.Gen.5 (B)
ComodoVirus.Win32.Expiro.CG@79ayaa
DrWebWin32.Expiro.133
McAfee-GW-EditionW32/Expiro.gen.rc
SophosW32/Expiro-AC
IkarusVirus.Win32.Expiro
GDataWin32.Expiro.Gen.5
JiangminTrojan.Vilsel.avt
AviraW32/Infector.Gen8
Antiy-AVLTrojan/Generic.ASVirus.2EC
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Win32/Expiro5.Gen
Acronissuspicious
VBA32BScope.Trojan.Vilsel
MAXmalware (ai score=84)
RisingVirus.Expiro!1.A140 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Expiro.CG
BitDefenderThetaAI:FileInfector.85DD157E12
AVGWin32:Expiro-GG [Inf]
PandaW32/Expiro.AD
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureVirus.W32.Expiro.NS

How to remove W32/Expiro-AC?

W32/Expiro-AC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment