Solved! Use CLIPSRV.VIR (Virus Expiro) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

CLIPSRV.VIR – Virus Expiro removal

File MD5 Virus Alias
CLIPSRV.VIR 36cbc82c94b408b25d00a84e6686ecdc Virus Expiro
CLIPSRV.VIR 36cbc82c94b408b25d00a84e6686ecdc Trojan XPACK
CLIPSRV.VIR 36cbc82c94b408b25d00a84e6686ecdc Trojan Vilsel
CLIPSRV.VIR 36cbc82c94b408b25d00a84e6686ecdc Trojan Crypt

CLIPSRV.VIR size: 229888 bytes
CLIPSRV.VIR hash: 36CBC82C94B408B25D00A84E6686ECDC

Created files:

C:\windows\system32\cisvc.vir
C:\windows\system32\clipsrv.vir
C:\windows\system32\dllhost.exe
C:\windows\system32\dmadmin.vir
C:\windows\system32\imapi.vir
C:\windows\system32\mnmsrvc.vir
C:\windows\system32\msdtc.exe
C:\windows\system32\msiexec.vir
C:\windows\system32\svchost.vir
%Temp%\1FAF3B.dmp

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\msiserver\Type: 20010000
HKLM\System\CurrentControlSet\Services\msiserver\Start: 02000000

Detected by UnHackMe:

CLIPSRV.VIR
Default location: %SYSDIR%\CLIPSRV.VIR

Dropper information:
MD5: 3592223a4d9b55b37ed52aaa95df9a26
File size: 221696 bytes

Leave a Reply