Virus

About “Virus:Win64/Expiro.DF!MTB” infection

Malware Removal

The Virus:Win64/Expiro.DF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win64/Expiro.DF!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus:Win64/Expiro.DF!MTB?


File Info:

name: D033C38B12A575B4954F.mlw
path: /opt/CAPEv2/storage/binaries/bebeff7a3810768daa7508b71b408d571c5808ebb9f5b56969eba493a3d47776
crc32: 0AED1353
md5: d033c38b12a575b4954fd1a2c40e7481
sha1: b0f193ce1cf148700269551885d35d6a177e980f
sha256: bebeff7a3810768daa7508b71b408d571c5808ebb9f5b56969eba493a3d47776
sha512: 4625527cf6d7cf731d481eac5d739385b7aa5a1e25c0d2b9ca8003558bb805e817c8696d384431b571585a360e78747dd40507b5e40e6a9e92026873136d0255
ssdeep: 12288:UU0Izsb5qSAKbUCQ8ABc5GESLKieFxqOF:50IzsbnUCQ8M+8Cx/
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T138A46A77EE7120DCC52E5E383BD9B9988940E660321661727CEF19B913BCBBEC364446
sha3_384: 9c3f43f70d1df5efdd981c137762fee69efeb2926e105f29c842f571d1e346db525b9600dab5e49c4008b1b5590c2163
ep_bytes: 515253b918000000648b1103c901d18b
timestamp: 2008-04-04 10:32:08

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Registry Initializer
FileVersion: 6.0.6001.18000 (longhorn_rtm.080118-1840)
InternalName: REGINI.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: REGINI.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.0.6001.18000
Translation: 0x0409 0x04b0

Virus:Win64/Expiro.DF!MTB also known as:

BkavW32.Common.E71F1EF6
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.d033c38b12a575b4
SkyhighBehavesLike.Win32.Expiro.gc
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Expiro.49363f32
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.CP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Expiro.ns
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
TencentWin32.Virus.Expiro.Rsmw
EmsisoftWin32.Expiro.Gen.6 (B)
F-SecureTrojan.TR/Patched.Gen
VIPREWin32.Expiro.Gen.6
TrendMicroVirus.Win32.EXPIRO.AD
Trapminemalicious.high.ml.score
SophosMal/EncPk-MK
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.6
JiangminTrojan.Scar.tww
GoogleDetected
AviraTR/Patched.Gen
ArcabitWin32.Expiro.Gen.6
ZoneAlarmVirus.Win32.Expiro.ns
MicrosoftVirus:Win64/Expiro.DF!MTB
VaristW32/Expiro.AW.gen!Eldorado
VBA32BScope.Trojan.Wacatac
ALYacWin32.Expiro.Gen.6
MAXmalware (ai score=83)
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallVirus.Win32.EXPIRO.AD
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.CP
AVGWin32:Xpirat-C [Inf]
Cybereasonmalicious.e1cf14

How to remove Virus:Win64/Expiro.DF!MTB?

Virus:Win64/Expiro.DF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment