Author Topic: Win32:expiro-u  (Read 13473 times)

0 Members and 1 Guest are viewing this topic.

popo13

  • Guest
Win32:expiro-u
« on: February 19, 2011, 10:38:45 PM »
I have this virus on my network and the virus is in all the .exe files the problem is that avast only can delete or move the files to chest, so the system will not be usable

My question is posible to disinfect this files without deleting, maybe when avast check at the system start up.

I really need your anwers.

Sorry for my terrible english

« Last Edit: February 19, 2011, 10:57:56 PM by popo13 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37596
  • Not a avast user
Re: Win32:expiro-u
« Reply #1 on: February 19, 2011, 11:00:16 PM »
you are infected with a file-infector and that is usually bad news, it often ends with a format and reinstall. I do not know if this one is cleanable but you need Essexboy on this

i send him a PM..


Follow this guide from our expert malware remover Essexboy
http://forum.avast.com/index.php?topic=53253.0
(post the logs here in this topic and not in the guide)


To avoid using multiple post with copy and paste you have to attach the log`s

Lower left corner: Additional Options > Attach ( OTL.Txt. / Extras.Txt )




popo13

  • Guest
Re: Win32:expiro-u
« Reply #2 on: February 19, 2011, 11:06:00 PM »
Thank you pondus i really need a solution i work on a big company (100 pc 4 servers) and
if i have to format all the computer it will be .....RIP

I wait for your news

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76034
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Win32:expiro-u
« Reply #3 on: February 19, 2011, 11:12:02 PM »
Doesn't sound good, but let's wait what Essexboy says.
Good luck,
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:expiro-u
« Reply #4 on: February 19, 2011, 11:14:26 PM »
Hi what infector is Avast reporting ?


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37596
  • Not a avast user
Re: Win32:expiro-u
« Reply #5 on: February 19, 2011, 11:16:36 PM »

popo13

  • Guest
Re: Win32:expiro-u
« Reply #6 on: February 19, 2011, 11:21:33 PM »
it sais win32:expiro-u please help essexboy
« Last Edit: February 19, 2011, 11:29:42 PM by popo13 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:expiro-u
« Reply #7 on: February 19, 2011, 11:33:24 PM »
OK first thing is - if any of the computers access banking sites on line their passwords may be compromised

If all 100 computers are infected you would be better of reinstalling the latest image that you took

For 1 computer I will try this, although this is my first exposure to this one

 Download AVPTool from Here to your desktop

Run the programme you have just downloaded to your desktop (it will be randomly named )

First we will run a virus scan

On the first tab select all elements down to Computer and then select start scan
Once it has finished select report and post that.



Do not close AVPTool or it will self uninstall, if it does uninstall - then just rerun the setup file on your desktop

Now an analysis scan

Select the Manual Disinfection tab
Press the Gather System Information button
Once done Open the last report saved folder  then attach the zip file to your next post zip
The file is located at C:\Users\your name\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip



popo13

  • Guest
Re: Win32:expiro-u
« Reply #8 on: February 19, 2011, 11:35:26 PM »
Essexboy
with comodo says malcrypt.indus!@105441913
with avg says win32/exprio.O
and with avast says win32:expiro-u

please tell me something that is possible to clean the system... without deleting the files

waiting.....

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:expiro-u
« Reply #9 on: February 19, 2011, 11:42:55 PM »
I will need to try on one first to see if there is any hope

popo13

  • Guest
Re: Win32:expiro-u
« Reply #10 on: February 19, 2011, 11:46:37 PM »
give me one second and i post the results

popo13

  • Guest
Re: Win32:expiro-u
« Reply #11 on: February 19, 2011, 11:47:44 PM »
If you want to conect to one of my computers... via some remote program....

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:expiro-u
« Reply #12 on: February 20, 2011, 12:05:29 AM »
Sorry do not do remote work

popo13

  • Guest
Re: Win32:expiro-u
« Reply #13 on: February 20, 2011, 01:12:04 AM »
kaspersky removal tool  doesnt find nothing.
I attach one jpg with a caputre from avast anlyce
I really thing that its impossible to clean all files
there are 1300 files infected.
I apreciate your help but Im starting to prepare to
format all the computers...
Thank you very much to all.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Win32:expiro-u
« Reply #14 on: February 20, 2011, 01:37:30 AM »
Hi popo13,

Infections were found to come from users playing games like RuneScape....
Read the description of what this type of virus is up to here: http://www.f-secure.com/v-descs/virus_w32_expiro_a.shtml
After a reformat, be careful when you have to visit any site mentioned in the description that the virus monitors and logs, before a reformat you can do an additional scan with: http://download.avg.com/filedir/util/avg_rem_sup.dir/rmexpiro.exe
If the infected computers are connected via a LAN, disconnect and reconnect only when all computers have been scanned to be clean after cleansing or after the "total-recall" e.g. reformat,

polonus
« Last Edit: February 20, 2011, 01:44:54 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!