Virus

About “Virus:Win64/Expiro.DD!MTB” infection

Malware Removal

The Virus:Win64/Expiro.DD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win64/Expiro.DD!MTB virus can do?

  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Virus:Win64/Expiro.DD!MTB?


File Info:

name: 33F90B5A082EFE5596D4.mlw
path: /opt/CAPEv2/storage/binaries/4324b883bf3868c250a703313c6c6e61835a0498e200b8f633f3deb74b724f40
crc32: 97BFCBBB
md5: 33f90b5a082efe5596d4f0435fe47c4d
sha1: 3c4476b1ae4cd615c5a916ac2ad5ffe6ff9fc171
sha256: 4324b883bf3868c250a703313c6c6e61835a0498e200b8f633f3deb74b724f40
sha512: 74d01b86567f6b85144292689361c259d6f1f061aa42a1d6643692926a36da7dc3e398fee2917fc7f4f36c11f564d77446c7aa3b4dfe628921df8c08f37b1b89
ssdeep: 24576:3O+WHRlMugdD+JsRgZRJ4fM430Eg6nET7M/IiN:+rxlMPdlR8v4UC0Eg6ET7M/I
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1275523C465C4E15BF1220EB18C6FF02FC3761F431BA221D36A462B46FF5C9D39AAA615
sha3_384: b6320744f2c7dfa3058d20091ebcb6b6b510b042197a40ecc992df6478720d2152acc6f37c073d4aa7b505fa26536164
ep_bytes: 4883ec28e8571b09004883c428e92afe
timestamp: 2096-02-28 07:10:41

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Rpc Locator
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
InternalName: locator.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: locator.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Translation: 0x0409 0x04b0

Virus:Win64/Expiro.DD!MTB also known as:

BkavW64.AIDetectMalware
MicroWorld-eScanWin64.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9892813-0
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win64.Expiro.tt
VIPREWin64.Expiro.Gen.7
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 00592e701 )
K7GWVirus ( 00592e701 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitWin64.Expiro.Gen.7
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/Expiro.CV
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win64.Moiva.a
BitDefenderWin64.Expiro.Gen.7
AvastWin64:Expiro-AJ [Inf]
RisingVirus.Expiro!1.A140 (CLASSIC)
EmsisoftWin64.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
SophosW64/Moiva-B
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win64.Expiro.cv
MicrosoftVirus:Win64/Expiro.DD!MTB
ZoneAlarmVirus.Win64.Moiva.a
GDataWin64.Expiro.Gen.7
VaristW64/Expiro.AR.gen!Eldorado
AhnLab-V3Malware/Win.Generic.C5036640
Acronissuspicious
ALYacWin64.Expiro.Gen.7
TACHYONVirus/W64.Movia
PandaW64/Moyv.A
TencentVirus.Win64.VirMoiva.a
IkarusVirus.Win64.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW64/Expiro.CU
AVGWin64:Expiro-AJ [Inf]
Cybereasonmalicious.1ae4cd
DeepInstinctMALICIOUS

How to remove Virus:Win64/Expiro.DD!MTB?

Virus:Win64/Expiro.DD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment