Malware

About “Win32/Expiro.CY” infection

Malware Removal

The Win32/Expiro.CY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Expiro.CY virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Expiro.CY?


File Info:

name: B8AEFE6413584D0104B4.mlw
path: /opt/CAPEv2/storage/binaries/f9612cd6b0aba2c6187270da36bb4668242cfff9957ec81f50242d2a147369da
crc32: 116CC082
md5: b8aefe6413584d0104b4ad5a98a1e86b
sha1: d0a270b22c0a0099e78fb453e8cecce01550af7b
sha256: f9612cd6b0aba2c6187270da36bb4668242cfff9957ec81f50242d2a147369da
sha512: a41789ff8c6625504eff88f45e76a7c5d4aae1b22e94526052eea7150a0336826cc49872c4e7e3bf6d9cea8be6b9932f76d1c307a55810c6c1d7ef5cec677e10
ssdeep: 12288:PKyXc3ajG+hjQKymY8efKCpD7Gj9G6GlqT8nQkCu83L3Wl/np9DBDt3kbE:PKysqjnhMgeiCl7G0XehbGZpbD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13645237FA60C91A7D95248BA83E8F01D581B7F569B1004C3AE977CBEE2F54E44F38066
sha3_384: 4333f3a7e987894f10213f13dab961a05e93396d9ec7943c245604c4eb4290435302733a43ada06431ba1df1e9f22ebc
ep_bytes: e90a280000e9991e0000e9441d0000e9
timestamp: 2016-08-08 19:09:27

Version Info:

0: [No Data]

Win32/Expiro.CY also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.b8aefe6413584d01
ALYacWin32.Expiro.Gen.7
CylanceUnsafe
K7AntiVirusVirus ( 0058c9f71 )
K7GWVirus ( 0058c9f71 )
CyrenW32/Expiro.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.CY
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Evo-gen [Susp]
Ad-AwareWin32.Expiro.Gen.7
SophosML/PE-A
DrWebWin32.Expiro.153
EmsisoftWin32.Expiro.Gen.7 (B)
GDataWin32.Expiro.Gen.7
JiangminTrojan.Generic.herau
AviraW32/Infector.Gen
Antiy-AVLTrojan/Generic.ASVirus.316
MicrosoftTrojan:Script/Phonzy.C!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R482093
MAXmalware (ai score=80)
VBA32SScope.Trojan.Zbot.gen
RisingTrojan.Generic@AI.77 (RDMK:cmRtazpvGb1dKof2x2btWbzffz+X)
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDO!tr
AVGWin32:Evo-gen [Susp]
PandaW32/Moyv.A

How to remove Win32/Expiro.CY?

Win32/Expiro.CY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment