Malware

W32/Expiro-S (file analysis)

Malware Removal

The W32/Expiro-S is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Expiro-S virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine W32/Expiro-S?


File Info:

name: 0771FA541C2A17E4BDFE.mlw
path: /opt/CAPEv2/storage/binaries/9f68b39d0f32b99189a31a2556c1dc6110b40432e8736f1c76a272ce2581364f
crc32: C7C9A774
md5: 0771fa541c2a17e4bdfe36414a534ba6
sha1: df9da8ffdee907901cc084baec07b3b405e7ed97
sha256: 9f68b39d0f32b99189a31a2556c1dc6110b40432e8736f1c76a272ce2581364f
sha512: 2b2ff6b564607e77243916c9136f475be662fb6928180adff525341e8d79910d4ad44f640988513d15a3526dd032a402fe9f183c22196ed422b42d3ac95c345a
ssdeep: 98304:gxC3ud6MOIvysigCQKzo5qphIHVruP3WpF3UdE1hZHEdLFG2RAB:LGQVMkhgJuP32+dmhZk/JRA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C676BF2E6BD20032CE535179AA4F9504E234E0136315CAE77ADCC3985FF1AE29676FE4
sha3_384: fb35521b3e06c7d574c187beee98d0de45c4e16c70bd4ffd81331438210e4458611d59793e4b8c5a78791eb6973cc30f
ep_bytes: 605589e581ec08010000c745f40a0000
timestamp: 2021-02-24 21:22:24

Version Info:

0: [No Data]

W32/Expiro-S also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.3
FireEyeGeneric.mg.0771fa541c2a17e4
CAT-QuickHealW32.Expiro.L4
McAfeeW32/Expiro.gen.p
CylanceUnsafe
ZillyaVirus.Expiro.Win32.41
K7AntiVirusVirus ( 0040f4dc1 )
K7GWVirus ( 0040f4dc1 )
Cybereasonmalicious.41c2a1
BitDefenderThetaAI:FileInfector.6CBEB04B12
CyrenW32/Expiro.BJ
SymantecW32.Xpiro.F
ESET-NOD32a variant of Win32/Expiro.NBZ
BaiduWin32.Virus.Expiro.c
TrendMicro-HouseCallPE_EXPIRO.AR
ClamAVWin.Virus.Expiro-7139558-0
KasperskyVirus.Win32.Expiro.ar
BitDefenderWin32.Expiro.Gen.3
NANO-AntivirusVirus.Win32.Expiro.clnvwd
AvastWin32:Xpirat [Inf]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareWin32.Expiro.Gen.3
EmsisoftWin32.Expiro.Gen.3 (B)
ComodoVirus.Win32.Expiro.SR@564eat
DrWebWin32.Expiro.80
VIPREVirus.Win32.Expiro.p (v)
TrendMicroPE_EXPIRO.AR
McAfee-GW-EditionW32/Expiro.gen.p
SentinelOneStatic AI – Malicious PE
SophosW32/Expiro-S
APEXMalicious
GDataWin32.Expiro.Gen.3
AviraW32/Expiro.NS
Antiy-AVLTrojan/Generic.ASVirus.C5
MicrosoftVirus:Win32/Expiro.CI
CynetMalicious (score: 100)
AhnLab-V3Win32/Expiro5.Gen
Acronissuspicious
VBA32BScope.Trojan.Vilsel
ALYacWin32.Expiro.Gen.3
MAXmalware (ai score=86)
MalwarebytesMalware.AI.4244314689
RisingVirus.Expiro!1.A140 (CLASSIC)
FortinetW32/Expiro.W
AVGWin32:Xpirat [Inf]
PandaW32/Expiro.O

How to remove W32/Expiro-S?

W32/Expiro-S removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment