Malware

Win32/Expiro.CT information

Malware Removal

The Win32/Expiro.CT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Expiro.CT virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Expiro.CT?


File Info:

name: A54D233AD89C249E3FC5.mlw
path: /opt/CAPEv2/storage/binaries/0a194aa7a246e1ae3365c58a4395c53370ecfbe93dc9d2a3c36119a2ea9b6238
crc32: 5A1EBEE4
md5: a54d233ad89c249e3fc5387dd953f678
sha1: 9fece1ac2a6c513ba50569d83160772eab0f53e0
sha256: 0a194aa7a246e1ae3365c58a4395c53370ecfbe93dc9d2a3c36119a2ea9b6238
sha512: 4f77bb6cc83f55b2de986514691af36f48b1c7e10030a5b38f0b84a7c81c5f73bf1c38e52c0d21695a692d51886c36266651617097b463b2b86bd820c106a591
ssdeep: 12288:DYqjokuvUA+RWV3MAqzJQCdP1kSe2Tub4xwgMgAdY8en5j0pELeTpa:Dmj+WV8ADCdP1HXqbAwgMmj0+LeQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T114759C5077F91019F2B3ABB27FFA99658AB7BDB25A36D11F2204420E0A31E40D971737
sha3_384: 38e7771e86fd43acdc79cccc0992ead9afd4b96e1e6cab4890a9ca05d376f9449304de4f70c92b7003a8ad3c0a336a37
ep_bytes: 558bec81ec1402000056578dbdecfdff
timestamp: 2021-02-15 03:01:38

Version Info:

Comments: Acrobat Installer Utility
CompanyName: Adobe Systems, Inc.
FileDescription: ADelRCP Dynamic Link Library
FileVersion: 21.1.20138.422477
InternalName: ADelRCP
LegalCopyright: Copyright © 1998-2011 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename: ADelRCP.dll
ProductName: ADelRCP Dynamic Link Library
ProductVersion: 21.1.20138.422477
Translation: 0x0409 0x04b0

Win32/Expiro.CT also known as:

BkavW32.AIDetect.malware1
DrWebWin32.Expiro.153
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.a54d233ad89c249e
ALYacWin32.Expiro.Gen.7
CylanceUnsafe
CyrenW32/Expiro.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.CT
APEXMalicious
ClamAVWin.Virus.Expiro-9973157-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-A [Heur]
TencentVirus.Win32.VirMoiva.a
Ad-AwareWin32.Expiro.Gen.7
EmsisoftWin32.Expiro.Gen.7 (B)
VIPREWin32.Expiro.Gen.7
Trapminesuspicious.low.ml.score
SophosML/PE-A
GoogleDetected
AviraTR/Patched.Gen
Antiy-AVLTrojan/Generic.ASVirus.317
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
CynetMalicious (score: 100)
MAXmalware (ai score=85)
MalwarebytesMalware.Heuristic.1001
RisingTrojan.Generic@AI.81 (RDML:FEHGNqtbRVm2tcIledzIvg)
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-A [Heur]
PandaW32/Moyv.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Expiro.CT?

Win32/Expiro.CT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment