Malware

Win64/Expiro.DC removal tips

Malware Removal

The Win64/Expiro.DC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Expiro.DC virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win64/Expiro.DC?


File Info:

name: 4140FB95502EAB3109BD.mlw
path: /opt/CAPEv2/storage/binaries/95e95cf8d0bd1f06680956838c83efd6d33d37480697be2eace2c63ba8708558
crc32: E1AF1635
md5: 4140fb95502eab3109bd5ab4fcaa3892
sha1: 8bc99ecc21302bb4f847463c607d9f10e67e9f3a
sha256: 95e95cf8d0bd1f06680956838c83efd6d33d37480697be2eace2c63ba8708558
sha512: 67bfe89a73d4ecbfae0635e67e6ba119910bf550d36253e069574139ffbcbeded2ed5f2663e85223b7bfed3528bfc32fc21d5bcd1a52435a3cdf1fa927792c4a
ssdeep: 12288:qYXJkWHSEKECwUVpyNj3C/Ei9OQSt6uk3zO61zOQJjN6atJ6bVgwtZJz:q02WHgwUMj3C/Uvw3B8atQVpZJ
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T18E65F125C29414F8E4B7C274825A6B96FF31385D2F21D9CB18B8E91A3F13F60A93D719
sha3_384: f11ac7268682a81a2d4c030835cfadd841fd5e54574072ae75e1f7830eeea436d9949d33d332fac98de6bd1f060b4b97
ep_bytes: 4883ec28e8f70300004883c428e98afd
timestamp: 2021-08-10 10:45:01

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Storage Tiers Management
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
InternalName: TieringEngineService
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: TieringEngineService.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Translation: 0x0409 0x04b0

Win64/Expiro.DC also known as:

BkavW64.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin64.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9998486-0
FireEyeWin64.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
McAfeeArtemis!4140FB95502E
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7GWVirus ( 0058d9c51 )
K7AntiVirusVirus ( 0058d9c51 )
VirITWin64.Expiro.AJ
SymantecW64.Xpiro.J!dam
ESET-NOD32a variant of Win64/Expiro.DC
APEXMalicious
CynetMalicious (score: 100)
AlibabaVirus:Win64/Moiva.45824cdf
NANO-AntivirusVirus.Win64.Virut-Gen.bwpxnc
SophosW64/Moiva-B
F-SecureMalware.W32/Infector.Gen
VIPREWin64.Expiro.Gen.7
TrendMicroVirus.Win64.EXPIRO.SMAJC
Trapminesuspicious.low.ml.score
EmsisoftWin64.Expiro.Gen.7 (B)
IkarusVirus.Win64.Expiro
AviraW32/Infector.Gen
Antiy-AVLVirus/Win64.Expiro.dc
ArcabitWin64.Expiro.Gen.7
ZoneAlarmVirus.Win64.Moiva.a
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2155
Acronissuspicious
ALYacWin64.Expiro.Gen.7
TACHYONVirus/W64.Movia
DeepInstinctMALICIOUS
Cylanceunsafe
TencentVirus.Win64.VirMoiva.a
MAXmalware (ai score=84)
FortinetW64/Expiro.CV
PandaW64/Moyv.A
alibabacloudVirus:Win/Expiro.DW

How to remove Win64/Expiro.DC?

Win64/Expiro.DC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment