Virus

Should I remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 663F1AB4A8FE228F9DF2.mlw
path: /opt/CAPEv2/storage/binaries/3ec14e89aa4fad86e7f9757eeeaed26f6aa3508e46a7215d02718a0418a4e8ab
crc32: 702BE159
md5: 663f1ab4a8fe228f9df2315509bf6afb
sha1: a3cd0922e929169239d733459db63e70abb7da22
sha256: 3ec14e89aa4fad86e7f9757eeeaed26f6aa3508e46a7215d02718a0418a4e8ab
sha512: b89bca837b174539513905c396ffdc172a4c3187a83de345faa9f58c270c20ac413454459a11e427b675fc8e1611f2de85e7d7177cd773c0a3b36dadb2075dae
ssdeep: 12288:Sq2B+oRMBGt/sB1KcYmqgZvAMlUoUjG+YKtMfnkOeZb5JYiNAgAPh:Sq2B9RLt/sBlDqgZQd6XKtiMJYiPU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA75220774C2C8B1E6BA4D311CA5E850A9BB79285E1868AB73C4367D5F380C2DD39E77
sha3_384: ff2db6ff4b734663e8d9beb4c9f89e5e63b2d90cbb63b1f872445142b5c9dde7d46478a6997978849ad4d8c06589ee76
ep_bytes: e8f4020000e97afeffff3b0d08204100
timestamp: 2021-04-13 02:35:50

Version Info:

CompanyName: Google LLC
FileDescription: Google Update
FileVersion: 1.3.36.81
InternalName: Google Update
LegalCopyright: Copyright 2018 Google LLC
OriginalFilename: goopdate.dll
ProductName: Google Update
ProductVersion: 1.3.36.81
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesVirus.M0yv
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36680.Gv0@aCilb2ji
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32Win32/Expiro.CU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Expiro-9941636-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
SUPERAntiSpywareTrojan.Agent/Gen-Fragtor
AvastWin32:Vitro [Inf]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.958
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
GoogleDetected
Acronissuspicious
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
VBA32Trojan.Sabsik.TE
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:O83E0WN4eBEcfBQYGFqFNA)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.2e9291
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment