Virus

Virus:Win64/Expiro.DF!MTB removal

Malware Removal

The Virus:Win64/Expiro.DF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win64/Expiro.DF!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus:Win64/Expiro.DF!MTB?


File Info:

name: 8277FFF8960ECD0B1C7F.mlw
path: /opt/CAPEv2/storage/binaries/01e2ac1ca790096516d011915657b6256d4b49b890f94087b4365c807d037f92
crc32: DB08FF5E
md5: 8277fff8960ecd0b1c7f08c647ceb3f4
sha1: 1413d7fd7a0c7a18a8f8be184c4dfda56db4d194
sha256: 01e2ac1ca790096516d011915657b6256d4b49b890f94087b4365c807d037f92
sha512: a0c5a5209051fa2d7b325217a232ec77495afbc130549822d790b0456a69685da2c8744f3eceb6a7e9fcdc153c854e2026711dddc2327e9999f483d521815115
ssdeep: 12288:4wTV/4zY4ErtKn9M5vomSzs7KbvPK0DxN:4wTVEMrt+9ofd76vPv/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169949E1067A4D94DC873F3FBB7ADB3A6764BD49DD2DD940963AD230836C8ABC3245809
sha3_384: 0fb637c3a2e8e960b574f553af092413bee86a5a069eef1dd6cb875e0119a95aa1e29a8eab6c269ce75306182efdfaa1
ep_bytes: 5257518d1518000000648b3a03d201fa
timestamp: 2009-05-05 16:38:09

Version Info:

CompanyName: Microsoft Corporation
FileDescription: COM Surrogate
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: dllhost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dllhost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Virus:Win64/Expiro.DF!MTB also known as:

BkavW32.Expiro2NHc.PE
LionicVirus.Win32.Expiro.n!c
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.8277fff8960ecd0b
SkyhighBehavesLike.Win32.Expiro.gc
McAfeeW32/Expiro.gen.rd
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00580a951 )
AlibabaVirus:Win32/Expiro.a11f3a06
K7GWVirus ( 00580a951 )
Cybereasonmalicious.d7a0c7
BitDefenderThetaAI:Packer.47E6589A1E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.CP
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Virus.Win32.Expiro.gen
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
TencentWin32.Virus.Expiro.Lzfl
SophosW32/Expiro-AV
F-SecureMalware.W32/Infector.Gen8
DrWebWin32.Expiro.152
VIPREWin32.Expiro.Gen.6
TrendMicroVirus.Win32.EXPIRO.AD
Trapminemalicious.high.ml.score
EmsisoftWin32.Expiro.Gen.6 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.S.gen!Eldorado
AviraW32/Infector.Gen8
KingsoftWin32.Infected.AutoInfector.a
MicrosoftVirus:Win64/Expiro.DF!MTB
ArcabitWin32.Expiro.Gen.6
ZoneAlarmHEUR:Virus.Win32.Expiro.gen
GDataWin32.Expiro.Gen.6
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2115
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacWin32.Expiro.Gen.6
MAXmalware (ai score=80)
PandaTrj/CI.A
TrendMicro-HouseCallVirus.Win32.EXPIRO.AD
RisingTrojan.Generic@AI.80 (RDML:2vO1btabs7X8/YQ6gKGuPQ)
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDG!tr
AVGWin32:Xpirat-C [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win64/Expiro.DF!MTB?

Virus:Win64/Expiro.DF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment