Worm

Should I remove “Worm.ExpiroViru.S28494482”?

Malware Removal

The Worm.ExpiroViru.S28494482 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.ExpiroViru.S28494482 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Worm.ExpiroViru.S28494482?


File Info:

name: 5726046C55BFC46237B0.mlw
path: /opt/CAPEv2/storage/binaries/1fac7aa2001a3b68cf03ddb4f286488ac03c145dc7c90c08c4269acb77d33ad4
crc32: 21ED7CFB
md5: 5726046c55bfc46237b0371bcb8adfad
sha1: fd4519c819a7152da93c88ccc9daa96b67a76500
sha256: 1fac7aa2001a3b68cf03ddb4f286488ac03c145dc7c90c08c4269acb77d33ad4
sha512: 832aabd0b604f97b84568376d9ee44d668e3580c6d197fdda929af08e10d2c5e7d29f647daa14261e3c88308fa22dd9fc6067b756887cc643f2faae41a58b88f
ssdeep: 12288:B8/VvF5T5TRpwMDVp0l29OoteEblA1Sh6+VTB0l4swfasRRBc3xCItKSnhd:2vFj1C/l2zdO0QM0l4lfasdc3gM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F55120235E090B5D4B3123486349B506E3EFD768EA5EA4BF7E4598D5A7C0C0BA3A773
sha3_384: 1ee341359484ea5e3737711206207a2b0f7a41dd8bd6ad937542830d76d33ab01877ad7bb96db7e381a2009d332f2cce
ep_bytes: e8fd2f0000e979feffff3b0d50104200
timestamp: 2015-03-27 03:43:48

Version Info:

Comments:
LegalCopyright: License: MPL 2
CompanyName: Mozilla Foundation
FileDescription:
FileVersion: 37.0
ProductVersion: 37.0
InternalName:
LegalTrademarks: Mozilla
OriginalFilename: maintenanceservice.exe
ProductName: Firefox
BuildID: 20150326190726
Translation: 0x0000 0x04b0

Worm.ExpiroViru.S28494482 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.5726046c55bfc462
CAT-QuickHealWorm.ExpiroViru.S28494482
ALYacWin32.Expiro.Gen.7
VIPREWin32.Expiro.Gen.7
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00594aea1 )
K7GWVirus ( 00594aea1 )
Cybereasonmalicious.819a71
CyrenW32/Expiro.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Expiro.CU
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
Ad-AwareWin32.Expiro.Gen.7
EmsisoftWin32.Expiro.Gen.7 (B)
DrWebWin32.Expiro.153
McAfee-GW-EditionBehavesLike.Win32.BadFile.tt
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLTrojan/Generic.ASVirus.317
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!5726046C55BF
MAXmalware (ai score=88)
VBA32Trojan.Sabsik.TE
MalwarebytesMalware.Heuristic.1001
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
PandaW32/Moyv.A

How to remove Worm.ExpiroViru.S28494482?

Worm.ExpiroViru.S28494482 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment