Virus

What is “Virus:Win64/Expiro.DD!MTB”?

Malware Removal

The Virus:Win64/Expiro.DD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win64/Expiro.DD!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win64/Expiro.DD!MTB?


File Info:

name: 77B467DBC7569B5C1CF4.mlw
path: /opt/CAPEv2/storage/binaries/57aab2252b92b5297b901d11f871bd81dffef41a545c04b70d31598b05f33de1
crc32: 4E897508
md5: 77b467dbc7569b5c1cf4c8dcf4f4d155
sha1: eba5be7973b89595ba8fa7a14b2d2478691b65a4
sha256: 57aab2252b92b5297b901d11f871bd81dffef41a545c04b70d31598b05f33de1
sha512: 0d2f17aa42eb8ed0a261c4d4267f8b64b3221f9d71636aeea38d2da06b678e84cbf597349c445c322932f31a8894ae55f72f90076140fd5abc4380b736108f6a
ssdeep: 24576:aTcnpwJ+RIatr0zAiX90z/F0jsFB3SQk:CIdIaB0zj0yjoB2
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1CC95F11AB36118F8FC27D13CCA618512E971F86507A1EADF1394A72A2F332D05A3FB55
sha3_384: fbefcfe5f840a9407a83baf09bb29d63cfcf238260f0dc0cd9ba1051addadb200e026abd580dff1d5a8ea75999b90bb8
ep_bytes: 4883ec28e86b0600004883c428e96afe
timestamp: 2020-01-17 20:46:22

Version Info:

Comments:
LegalCopyright: License: MPL 2
CompanyName: Mozilla Foundation
FileDescription: Firefox Software Updater
FileVersion: 72.0.2
ProductVersion: 72.0.2
InternalName:
LegalTrademarks: Mozilla
OriginalFilename: updater.exe
ProductName: Firefox
BuildID: 20200117190643
Translation: 0x0000 0x04b0

Virus:Win64/Expiro.DD!MTB also known as:

BkavW64.AIDetectMalware
DrWebWin32.Expiro.158
MicroWorld-eScanWin64.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win64.Dropper.tt
MalwarebytesNeshta.Virus.FileInfector.DDS
VIPREWin64.Expiro.Gen.7
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a9e7d1 )
K7GWVirus ( 005a9e7d1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin64.Expiro.Gen.7
SymantecW64.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/Expiro.DP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Expiro-9937503-0
KasperskyVirus.Win64.Moiva.a
BitDefenderWin64.Expiro.Gen.7
NANO-AntivirusVirus.Win64.Virut-Gen.bwpxnc
AvastWin64:Expiro-AJ [Inf]
EmsisoftWin64.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
ZillyaTrojan.Kryplod.Win64.575
TrendMicroVirus.Win64.EXPIRO.SMAJC
SophosW64/Moiva-B
IkarusVirus.Win64.Expiro
VaristW64/Expiro.AR.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win64/Expiro.DD!MTB
ZoneAlarmVirus.Win64.Moiva.a
GDataWin64.Expiro.Gen.7
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2155
Acronissuspicious
ALYacWin64.Expiro.Gen.7
TACHYONVirus/W64.Movia
PandaW64/Moyv.A
TencentVirus.Win64.VirMoiva.a
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW64/Expiro.CU
AVGWin64:Expiro-AJ [Inf]
Cybereasonmalicious.973b89
DeepInstinctMALICIOUS

How to remove Virus:Win64/Expiro.DD!MTB?

Virus:Win64/Expiro.DD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment