Virus

Virus:Win32/Expiro.EK!MTB removal instruction

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 528279D4C15745FD6704.mlw
path: /opt/CAPEv2/storage/binaries/f2808979c2203e0f01917974c5078690ac6b583ba5ebb1a66c979f635f52fbd6
crc32: 8C1924DE
md5: 528279d4c15745fd67044ffb7e84048a
sha1: 2f72354e42ba21ef23ee18427878fc912c3296f2
sha256: f2808979c2203e0f01917974c5078690ac6b583ba5ebb1a66c979f635f52fbd6
sha512: e484aa8b3c24c570a270f6ef871d600c5613946e59104c307f7421826d9b88606afa6737c80789ee3cc3da9b6f1ae0d6f47984b3a2604759ffb98998e95db98a
ssdeep: 12288:TYm/76weWpqUMAdB8qr0zw9iXQ40AOzDr5YJjsF/5v3ZkHRik8:cm/WwMatr0zAiX90z/F0jsFB3SQk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12475121234C585F2E6820172461C9FBB8478FA3417E257D7F3D87E0F89745C39A36AAA
sha3_384: 1304e08c1e5363732d393908e652b5f8c66e0691e69fd3cf4b305a0bd23f8e49a801c4db811d3656c93741fc6218350a
ep_bytes: e887080000e978feffff8b4df464890d
timestamp: 2021-02-15 03:25:02

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Acrobat 32BitMAPIBroker
FileVersion: 21.1.20138.422477
LegalCopyright: Copyright 1984-2021 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName: Adobe Acrobat 32BitMAPIBroker
ProductVersion: 21.1.20138.422477
OriginalFilename: 32BitMAPIBroker.exe
Translation: 0x0409 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Trojan.Expiro-9937503-0
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.710
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Trojan.PSE.1B8DNQ8
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:7hqYMvTzCJJJDrttu0CI9Q)
IkarusVirus.Win32.Tufik
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment