Malware

Win64/Expiro.CU removal tips

Malware Removal

The Win64/Expiro.CU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Expiro.CU virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Win64/Expiro.CU?


File Info:

name: 7B1C31990500C0EEBFF2.mlw
path: /opt/CAPEv2/storage/binaries/9337914b21dd6fb4be02fbbecb3b894ce915f96f9a89ba39c4cdb92513bff805
crc32: E0403B79
md5: 7b1c31990500c0eebff23b81c7ed8495
sha1: 3003d7c6eb79270fd34ec65495b87ba1e1cabc63
sha256: 9337914b21dd6fb4be02fbbecb3b894ce915f96f9a89ba39c4cdb92513bff805
sha512: e3acef8c4faa0be96c3d7491249af5e7d0415f377d80e0eae7b9e5c95d52dcfc83e0a38b216302c539470a2a36dfbb0e71899708db497a0fc22be7588fee651b
ssdeep: 24576:2ZtfgEMwZCfuhFkOWsZ4PL4N6j4/Pm/g:2ZtfTTZiIJZ4cQj4Xm/g
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1DD55F16ABBAD8062D077C23DDAC2C789E2B2B4915F115BC762118B7E0E33AF59D35311
sha3_384: 98de1aa2a5cdd9c14f049bb33b60e25a119721bb17467bfbc06089e29b303c9cf5c78079f5a61a8fc35b45d19104cee6
ep_bytes: 4883ec28e8bfdc12004883c428e9dafc
timestamp: 2009-07-13 23:47:44

Version Info:

CompanyName: Microsoft Corporation
FileDescription: WMI Performance Reverse Adapter
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: WmiApSrv.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WmiApSrv.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Win64/Expiro.CU also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin64.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9956501-0
FireEyeGeneric.mg.7b1c31990500c0ee
VIPREWin64.Expiro.Gen.7
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWVirus ( 00592e701 )
K7AntiVirusVirus ( 00592e701 )
CyrenW64/Expiro.AR.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win64/Expiro.CU
CynetMalicious (score: 100)
KasperskyVirus.Win64.Moiva.a
BitDefenderWin64.Expiro.Gen.7
NANO-AntivirusVirus.Win64.Virut-Gen.bwpxnc
AvastWin64:Expiro-AJ [Inf]
TencentVirus.Win64.VirMoiva.a
Ad-AwareWin64.Expiro.Gen.7
TACHYONVirus/W64.Movia
DrWebWin32.Expiro.153
EmsisoftWin64.Expiro.Gen.7 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin64.Expiro.Gen.7
AviraW32/Infector.Gen
Antiy-AVLTrojan/Generic.ASVirus.317
ArcabitWin64.Expiro.Gen.7
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
ALYacWin64.Expiro.Gen.7
MAXmalware (ai score=87)
RisingVirus.Expiro!1.A140 (CLASSIC)
IkarusVirus.Win64.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW64/Expiro.CP!tr
AVGWin64:Expiro-AJ [Inf]
Cybereasonmalicious.6eb792
PandaW64/Moyv.A

How to remove Win64/Expiro.CU?

Win64/Expiro.CU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment