Malware

Win32/Expiro.NAN information

Malware Removal

The Win32/Expiro.NAN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Expiro.NAN virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Expiro.NAN?


File Info:

name: AF1E37B61A4C7A18AEC9.mlw
path: /opt/CAPEv2/storage/binaries/db3bc715bfba7ef9db7d444b3f8e04508449849627e3e2bd564d4c606b8fe02d
crc32: B8AB8D8B
md5: af1e37b61a4c7a18aec9c36ea0771ecc
sha1: 0212dfa5dea436642d47ceb3659613d5567cf4d4
sha256: db3bc715bfba7ef9db7d444b3f8e04508449849627e3e2bd564d4c606b8fe02d
sha512: 8aa45a0299f9f04395446ac04c49db8c00bbf67408f318942eee921601a7b158b5167bfcffef0504195c4fa364c9b1e1016f2b4fa0fcdc372463a63c05e847a3
ssdeep: 6144:1/auogvgA8rFhe8MU65iKbMUZeBr9PislEN:1D7vqPe8MU65iK9CP4N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12D44AF5210E0CF3BD4E9B63D59AD3B6FDB687CA4BD6322261C7E44E1D7E24C304252A9
sha3_384: a9aa010a5ef6176be2282627466f3dfca60ccd7e7c3ae84e0413e545366409e77eedc3bb0b6a9efbb37092f466be2450
ep_bytes: 50519052905390545556575589e583ec
timestamp: 2008-04-13 15:33:05

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 6.00.2900.5512 (xpsp.080413-2105)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.00.2900.5512
Translation: 0x0409 0x04b0

Win32/Expiro.NAN also known as:

BkavW32.Expiro1NHc.PE
AVGWin32:Xpiro [Inf]
Elasticmalicious (high confidence)
DrWebWin32.Expiro.47
MicroWorld-eScanWin32.Expiro.Gen.2
FireEyeGeneric.mg.af1e37b61a4c7a18
CAT-QuickHealW32.Expiro.AX
SkyhighBehavesLike.Win32.Expiro.dc
ALYacWin32.Expiro.Gen.2
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 0040f4dc1 )
K7GWVirus ( 0040f4dc1 )
Cybereasonmalicious.5dea43
BitDefenderThetaAI:FileInfector.1BB980DD12
VirITWin32.Expiro.AA
SymantecW32.Xpiro.D
ESET-NOD32Win32/Expiro.NAN
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Virus.Expiro-28
KasperskyVirus.Win32.Expiro.ao
BitDefenderWin32.Expiro.Gen.2
NANO-AntivirusVirus.Win32.Expiro.bfwzxr
AvastWin32:Xpiro [Inf]
TencentVirus.Win32.Expiro.f
TACHYONVirus/W32.Expiro.C
EmsisoftWin32.Expiro.Gen.2 (B)
F-SecureMalware.W32/Infector.Gen8
BaiduWin32.Virus.Expiro.a
ZillyaVirus.Expiro.Win32.24
TrendMicroPE_EXPIRO.JX
Trapminemalicious.high.ml.score
SophosW32/Expiro-H
IkarusTrojan.Win32.Vilsel
JiangminWin32/Expiro.r
AviraW32/Infector.Gen8
Antiy-AVLVirus/Win32.Expiro.ai
Kingsoftmalware.kb.a.998
XcitiumVirus.Win32.Expiro.isn@4z1wg0
ArcabitWin32.Expiro.Gen.2
ViRobotWin32.Expiro.Gen.C
ZoneAlarmVirus.Win32.Expiro.ao
GDataWin32.Expiro.Gen.2
VaristW32/Expiro.AF
AhnLab-V3Win32/Expiro4.Gen
McAfeeW32/Expiro.gen.d
MAXmalware (ai score=89)
VBA32Virus.Expiro.305
MalwarebytesGeneric.Malware/Suspicious
PandaW32/Expiro.gen
TrendMicro-HouseCallPE_EXPIRO.JX
RisingVirus.Expiro!1.A140 (CLASSIC)
YandexWin32.Expiro.Gen.7
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Expiro.W
FortinetW32/Expiro.fam
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Expiro.NAN?

Win32/Expiro.NAN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment