Skip to main content

Virus:W32/Expiro.A

Classification

Category:

Malware

Type:

Virus

Aliases:

  • W32/Expiro
  • PE_EXPIRO.A
  • Expiro.A
  • W32.Kakavex
  • Virus.Win32.Expiro.a
  • W32/Expiro.A

Summary

Expiro.A is a Windows executable file infecting virus. It is also capable of stealing credit card information gathered from the affected machine.

Removal

Technical Details

Expiro.A is a Windows executable file infecting virus. It is also capable of stealing credit card information gathered from the affected machine. Upon execution, this virus recursively looks for link files (.LNK) inside drives C: to Z: starting from the root directory and subdirectories and tries to infect the link's target Windows executable. Infected files grow in size and four additional sections are appended at the end of each file. The following describes the appended section details which includes the name, virtual size and physical size, respectively.

  • .data 00020000 0000EA00
  • .text 0000AD40 0000AD40
  • .bss 00005BD8 00000000
  • .data 00001A00 00001A00

Expiro.A creates a duplicate file alongside of infected files named with an .IVR extension. This identifies files it has already infected. Example:

  • %windir%\system32\notepad.exe %windir%\system32\notepad.ivr

This virus steals credit card information via a keylogger scheme. While the virus is active in memory, it monitors and logs credit card information and steals user input data that may be triggered when browsing one of these sites:

  • 53bank.com
  • banking.halifax-online.co.uk
  • barclays.com
  • chechenpress.info
  • crutop.nu
  • ebay.com
  • goldpoll.com
  • goldpoll.com
  • goldpoll.com
  • intgold.com
  • kavkazcenter.com
  • kgbrelaxclub.ru
  • kidos-bank.ru
  • master-x.com
  • myonlineaccounts2.abbeynational.co.uk
  • new.egg.com
  • olb2.nationet.com
  • online-business.lloydstsb.co.uk
  • openbank.com
  • paypal.com
  • seclab.ru
  • securitylab.ru
  • stormpay.com
  • tat-neftbank.ru
  • totallyfreebanking.com
  • welcome3.smile.co.uk
  • www.allahabadbank.com
  • www.b2b-trust.com
  • www.bank-banque-canada.ca
  • www.bankofindia.com
  • www.bankofmadura.com
  • www.bbin.ru
  • www.bmo.com
  • www.candidateverifier.com
  • www.cbr.ru
  • www.cibc.com
  • www.cwbank.com
  • www.icbank.ru
  • www.kmb.ru
  • www.lbcdirect.laurentianbank.ca
  • www.mmbank.ru
  • www.nbc.ca
  • www.netmagister.com
  • www.ponziscams.com
  • www.ponziscams.com
  • www.ponziscams.com
  • www.ponziscams.com
  • www.ponziscams.com
  • www.ponziscams.com
  • www.ponziscams.com
  • www.rbc.com
  • www.socks.ac
  • www.uniastrum.ru
  • www.vendorsname.ws
  • www.vendorsname.ws
  • www.vendorsname.ws
  • www.vendorsname.ws
  • www.vtb.ru
  • www.worldbank.org
  • www1.hsbc.ca
  • yambo.biz

Expiro.A creates the following mutex when it is running and active in memory:

  • kkq-vx_mtx1

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.