Malware

About “Win32/Expiro.DL” infection

Malware Removal

The Win32/Expiro.DL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Expiro.DL virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Win32/Expiro.DL?


File Info:

name: 1A1BB16CF260F55F7FF9.mlw
path: /opt/CAPEv2/storage/binaries/7739b40252daa9775b0753af04fcc13c92fd67f542310cfdb3a91371cc684371
crc32: 3BEF6008
md5: 1a1bb16cf260f55f7ff9405eb66b34c3
sha1: b3e5658e58dfb589fa392b480d5cd5dbf128397d
sha256: 7739b40252daa9775b0753af04fcc13c92fd67f542310cfdb3a91371cc684371
sha512: 3a703d965e69483659b769f3bdeb8f9876a024acfdbce73181e1114411cc9ca3aae7d742e1fd92108828b3edb76f2b711e79ccdc64976eed2b8fcf898fcb6c27
ssdeep: 24576:R7Vjptf3FzayY/JcSokzkAHCuC9oX3f4OSTR3YE:dVbfVzayY/qSPkAHCuC9439St3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F6501213BA2C035E55702368E798B6A562DBF200F6741C7B7E43A2E8EB46D25F34357
sha3_384: defdd5990c8c68d1fa59534aeb70f4e127de0d40d6b5076a00ea8b08d9e383c0113c6d12c6fb07d1eddf59daea882d58
ep_bytes: e8ff6d0000e989feffff8bff558bec8b
timestamp: 2013-02-08 20:26:19

Version Info:

CompanyName: Intel Corporation
FileDescription: IntelCpHeciSvc Executable
InternalName: IntelCpHeciSvc
LegalCopyright: Copyright (C) 2011 Intel Corporation
LegalTrademarks: Intel Corporation
OriginalFilename: IntelCpHeciSvc.exe
ProductName: IntelCpHeciSvc Executable
ProductVersion: 9.0.0.1340
Translation: 0x0409 0x04b0

Win32/Expiro.DL also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.H5
ALYacWin32.Expiro.Gen.7
CylanceUnsafe
K7AntiVirusVirus ( 00594aea1 )
K7GWVirus ( 00594aea1 )
CyrenW32/Expiro.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Expiro.DL
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
APEXMalicious
TencentVirus.Win32.VirMoiva.a
Ad-AwareWin32.Expiro.Gen.7
EmsisoftWin32.Expiro.Gen.7 (B)
DrWebWin32.Expiro.153
VIPREWin32.Expiro.Gen.7
FireEyeGeneric.mg.1a1bb16cf260f55f
SophosGeneric ML PUA (PUA)
GDataWin32.Expiro.Gen.7
AviraW32/Infector.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASVirus.316
ArcabitWin32.Expiro.Gen.7
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.IH.C4949384
MalwarebytesMalware.Heuristic.1001
AvastWin32:Malware-gen
RisingTrojan.Generic@AI.79 (RDMK:cmRtazrW4WgV/ZxI1NLgG3E+37Kd)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Malware-gen
PandaW32/Moyv.A

How to remove Win32/Expiro.DL?

Win32/Expiro.DL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment