Virus

Virus:Win64/Expiro.DD!MTB removal tips

Malware Removal

The Virus:Win64/Expiro.DD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win64/Expiro.DD!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win64/Expiro.DD!MTB?


File Info:

name: 6104A50039C99EE311C1.mlw
path: /opt/CAPEv2/storage/binaries/9e46b5bbac19cb9879ad7096f054b89e1ac1a225eab9741c77f8d178e1e56591
crc32: 8CB47EFA
md5: 6104a50039c99ee311c14b01aac1bb2e
sha1: fd715df19f5c2e58b2ac49de81fe8aadbb517af0
sha256: 9e46b5bbac19cb9879ad7096f054b89e1ac1a225eab9741c77f8d178e1e56591
sha512: 2722c99d4266b4d6a23e90265d7ee42078d9c47c28cd692237e59fe2c1a364255117b37192622305f36b6cd6387c6f30c12cb3b82a3f8922224f0316a6708b06
ssdeep: 24576:aUozv/TaTot/sBlDqgZQd6XKtiMJYiPU:aUOnTT/snji6attJM
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T132850159B39048F5ED77863ACD519802E2B27C5D0B60D64F13E8366A5F333614C3EBAA
sha3_384: c651297e8009caae5d2c6bd14e3891420af049a948499f8b7c6a4fcd38a990da50f961efa9f93fd04355fdd1ed6b79cd
ep_bytes: 4883ec28e80b0600004883c428e97afe
timestamp: 2020-06-18 07:12:42

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java(TM) Platform SE binary
FileVersion: 8.0.2610.12
Full Version: 1.8.0_261-b12
InternalName: javaw
LegalCopyright: Copyright © 2020
OriginalFilename: javaw.exe
ProductName: Java(TM) Platform SE 8
ProductVersion: 8.0.2610.12
Translation: 0x0000 0x04b0

Virus:Win64/Expiro.DD!MTB also known as:

BkavW64.AIDetectMalware
MicroWorld-eScanWin64.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win64.Expiro.tt
MalwarebytesVirus.M0yv
VIPREWin64.Expiro.Gen.7
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a9e7d1 )
K7GWVirus ( 005a9e7d1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin64.Expiro.Gen.7
SymantecW64.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/Expiro.DP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win64.Moiva.a
BitDefenderWin64.Expiro.Gen.7
NANO-AntivirusVirus.Win64.Virut-Gen.bwpxnc
AvastWin64:Expiro-AJ [Inf]
TencentVirus.Win64.VirMoiva.a
SophosW64/Moiva-B
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroVirus.Win64.EXPIRO.SMAJC
EmsisoftWin64.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win64/Expiro.DD!MTB
ZoneAlarmVirus.Win64.Moiva.a
GDataWin64.Expiro.Gen.7
VaristW64/Expiro.AR.gen!Eldorado
AhnLab-V3Malware/Win.Generic.C5227293
Acronissuspicious
ALYacWin64.Expiro.Gen.7
TACHYONVirus/W64.Movia
PandaW64/Moyv.A
RisingVirus.Expiro!1.A140 (CLASSIC)
IkarusVirus.Win64.Expiro
FortinetW64/Expiro.CU
AVGWin64:Expiro-AJ [Inf]
DeepInstinctMALICIOUS

How to remove Virus:Win64/Expiro.DD!MTB?

Virus:Win64/Expiro.DD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment