Malware

How to remove “Win32/Expiro.AY”?

Malware Removal

The Win32/Expiro.AY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Expiro.AY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics

How to determine Win32/Expiro.AY?


File Info:

name: 04803FFA54D473FC070D.mlw
path: /opt/CAPEv2/storage/binaries/040f35e44c3b24fa75af5f2c194ce2f2c12ff1d19fcaed5deecc277fa1c0f774
crc32: 909EBF97
md5: 04803ffa54d473fc070d8b719ead4671
sha1: 278600d6b3a3ba8a227a5aef91f9c8730020abb4
sha256: 040f35e44c3b24fa75af5f2c194ce2f2c12ff1d19fcaed5deecc277fa1c0f774
sha512: c93633c71d61346ef0f48e243c8bb4ecd1b0aae3b085d32953e8bde24299bbdb4995fc50b07b016d37e7f0e34962dcbbb7227c6fd58fd11fe19b01f617aa32ca
ssdeep: 24576:oE6Ehg7mM+M6RkMkIM7gE6Eh672FA4gxK7P5+MGXKZ+FP:w0g7mM+M6RkMkIM7I0672FAbxK0MGXi2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11745AF83F9D1BCA5D254993055FFAE7102E7ACBE2D0402AF7199BA2F38786C15871F06
sha3_384: 2d2df7a7cd006b33da388d31f69d28cad152a1b48b365b4bcff06e3dda6ba86eca94dd0afc5b2e4040cdbf4723ef4a9f
ep_bytes: 605589e581ec08010000c745f8010000
timestamp: 2010-11-20 09:46:56

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Internet Explorer
FileVersion: 8.00.7601.17514
InternalName: iexplore
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: IEXPLORE.EXE
ProductName: Windows® Internet Explorer
ProductVersion: 8.00.7601.17514
Translation: 0x0409 0x04b0

Win32/Expiro.AY also known as:

BkavW32.Expiro2NHc.PE
LionicVirus.Win32.Expiro.m4FI
MicroWorld-eScanWin32.Expiro.Gen.3
SkyhighBehavesLike.Win32.Expiro.tc
McAfeeW32/Expiro.gen.p
MalwarebytesGeneric.Malware/Suspicious
VIPREWin32.Expiro.Gen.3
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Expiro.c5e3ad4d
K7GWVirus ( 0040f4dc1 )
K7AntiVirusVirus ( 0040f4dc1 )
BaiduWin32.Virus.Expiro.c
VirITWin32.Expiro.AL
SymantecW32.Xpiro.F
Elasticmalicious (high confidence)
ESET-NOD32Win32/Expiro.AY
APEXMalicious
TrendMicro-HouseCallPE_EXPIRO.AR
ClamAVWin.Trojan.Expiro-34
KasperskyVirus.Win32.Expiro.ar
BitDefenderWin32.Expiro.Gen.3
NANO-AntivirusVirus.Win32.Expiro.clnvwd
AvastWin32:Xpirat [Inf]
TencentVirus.Win32.Expiro.aab
EmsisoftWin32.Expiro.Gen.3 (B)
F-SecureMalware.W32/Expiro.NU
DrWebWin32.Expiro.80
ZillyaVirus.Expiro.Win32.42
TrendMicroPE_EXPIRO.AR
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.04803ffa54d473fc
SophosW32/Expiro-S
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=89)
GoogleDetected
AviraW32/Expiro.NU
VaristW32/Expiro.BG
Antiy-AVLVirus/Win32.Expiro.nr
MicrosoftVirus:Win32/Expiro.CD
XcitiumVirus.Win32.Expiro.SR@564eat
ArcabitWin32.Expiro.Gen.3
ZoneAlarmVirus.Win32.Expiro.ar
GDataWin32.Expiro.Gen.3
CynetMalicious (score: 100)
AhnLab-V3Win32/Expiro5.Gen
BitDefenderThetaAI:FileInfector.6CBEB04B12
ALYacWin32.Expiro.Gen.3
VBA32Virus.Expiro.2414
Cylanceunsafe
PandaW32/Expiro.O
RisingVirus.Expiro!1.A140 (CLASSIC)
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.W
AVGWin32:Xpirat [Inf]
Cybereasonmalicious.a54d47
DeepInstinctMALICIOUS
alibabacloudVirus:Win/Expiro.QPUNLJHDDWOINBUN

How to remove Win32/Expiro.AY?

Win32/Expiro.AY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment