Virus

Virus:Win32/Expiro.EK!MTB removal tips

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: EB0EF814A8292F7181E5.mlw
path: /opt/CAPEv2/storage/binaries/fbd6f7cd4a85dccfa4e27c03f8da0f147931426fa28d4f09fdd519b58db47351
crc32: 9B8B1956
md5: eb0ef814a8292f7181e56d8a41016d5e
sha1: 9e528ce70701ffb085452ace16ca7b20f2ccd039
sha256: fbd6f7cd4a85dccfa4e27c03f8da0f147931426fa28d4f09fdd519b58db47351
sha512: 8dd5154c38a5370827e322932c32405cb5b57177a64f9e21ce1a8bc1297874a3fbb190e3cba5f12d14b3c4c8cd8e095c758b2587cd7ab6a7db3b7ddafdd00c0d
ssdeep: 12288:mobsRxiXMzUBL8252uui8FbECP7BhdfswdJ0NXdU8ZWH7DEP1rCJ7U3c:xbsRoczt2rR8FfBhRJUEbDk1ulUs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9451221B1D0C972F3560171997CDBBA8024FC291FB1ABC3B3E84D3E15744D29A72BA6
sha3_384: 56ea8d04169ec39761b23aaafa05fbf51e8f3bff9a8f96ea55e6d37ef5578e0ce3aea5df1bedbbdbcbe0f285b824d288
ep_bytes: e887080000e978feffff8b4df464890d
timestamp: 2020-07-30 22:58:33

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Acrobat 32BitMAPIBroker
FileVersion: 20.12.20041.394260
LegalCopyright: Copyright 1984-2020 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName: Adobe Acrobat 32BitMAPIBroker
ProductVersion: 20.12.20041.394260
OriginalFilename: 32BitMAPIBroker.exe
Translation: 0x0409 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9976460-0
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tm
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
IkarusVirus.Win64.Expiro
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5230480
Acronissuspicious
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
VBA32BScope.TrojanDownloader.Zenlod
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:NtwYm1mcR1LcMeI4eM20Xg)
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment