Malware

W32.Expiro.R3 (file analysis)

Malware Removal

The W32.Expiro.R3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32.Expiro.R3 virus can do?

  • Authenticode signature is invalid

How to determine W32.Expiro.R3?


File Info:

name: BF29B3A8DA6F1567F436.mlw
path: /opt/CAPEv2/storage/binaries/516a5529af763fbf2ff8790bc2db4604affd6e7c86c80e8e7676639bb456f42a
crc32: 948D926B
md5: bf29b3a8da6f1567f4367953f6e292a0
sha1: 01f5ef2eb4489944871ea0427336c45263284f15
sha256: 516a5529af763fbf2ff8790bc2db4604affd6e7c86c80e8e7676639bb456f42a
sha512: ea47184837675b524b218fed54809a93ffcbeeadd04a2ae9af4d304284ce43822a7bdbcf034802bd4cb5ebd6c4d83e6ae3934b7aa183ed0d6382c241459c1d57
ssdeep: 12288:Xa+8ARfc+Jl/1PbY0DtKPxoVzElCgA7WPZxU2kLDNghY2B5Td/847t3:nnlVdDtKPxoVz6Cg0sZxA61l/8
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16A551212B38A49F2E15B12B6247993FA8B3DFA342B2091F3A3147979243D5D2DD3419F
sha3_384: 4fbc20cee48e5bec30dcd2ebf70fa39cecbd4bee067e8fd442fa4ba7c32ba8111e6a11e9ee43bc8ffc5adb86a30d7f94
ep_bytes: e84d040000e99ffdffffff2548664100
timestamp: 2011-03-19 00:58:20

Version Info:

CompanyName: Dassault Systemes
FileDescription: CORBAServerInfra
FileVersion: 5.21.0.11077
InternalName: GW0SRVMG.exe
LegalCopyright: Copyright Dassault Systemes 1999-2011
OriginalFilename: GW0SRVMG.exe
ProductName: Dassault Systemes Product
ProductVersion: 5.21.0.11077
Translation: 0x0409 0x04b0

W32.Expiro.R3 also known as:

LionicVirus.Win32.Moiva.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9993256-0
FireEyeGeneric.mg.bf29b3a8da6f1567
CAT-QuickHealW32.Expiro.R3
ALYacWin32.Expiro.Gen.7
MalwarebytesMalware.AI.1265375004
VIPREWin32.Expiro.Gen.7
SangforVirus.Win32.Expiro.V6ec
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Moiva.06ab55fb
K7GWVirus ( 00594aea1 )
K7AntiVirusVirus ( 00594aea1 )
CyrenW32/Expiro.AU.gen!Eldorado
SymantecW32.Xpiro.J!dam
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Vitro [Inf]
TencentVirus.Win32.VirMoiva.a
SophosW32/Moiva-A
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroTROJ_GEN.R002C0RBN23
McAfee-GW-EditionBehavesLike.Win32.Sality.tt
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Expiro.Gen.7
AviraW32/Infector.Gen
MAXmalware (ai score=88)
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftTrojan:Script/Phonzy.A!ml
GoogleDetected
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
TrendMicro-HouseCallTROJ_GEN.R002C0RBN23
RisingTrojan.Generic@AI.83 (RDML:Ewkp0MrhqEuzoJt9quen9Q)
IkarusExpiro.Win32
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS

How to remove W32.Expiro.R3?

W32.Expiro.R3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment