Virus

Virus:Win32/Expiro.EK!MTB (file analysis)

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: DA4AA4C5643579061390.mlw
path: /opt/CAPEv2/storage/binaries/a965520d7f8a5583e3c0c7d962934f85b1d37cd374b77e160b8e18f1bc098c90
crc32: EDF07E5B
md5: da4aa4c564357906139092b9408cc8d1
sha1: 03d72825cc9ef285f94a565ff7e3c8e76ef5f010
sha256: a965520d7f8a5583e3c0c7d962934f85b1d37cd374b77e160b8e18f1bc098c90
sha512: ac7ebe2fb2562cd17358182c49ab5d14da80977c6d005ae71f83d22fb26692a1564c36c5bb68da11221c79e98266eba20f6ceeb5186d9beabd3122f98175723a
ssdeep: 24576:eJgOXUAPTYwroA2ScQZS+Sin83L7Uoc9vQY85WIgL:ekOTdroA2VXisUovYwgL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D67512B21E4A91FBCAFB00BD80F5560DA76DFB2403540CCB92C8775A14627E55BB22ED
sha3_384: 666a1b1c6aa0315c20b9b8e4644a455e33ecfeeeecb83b9669dd466de55df478e09b5a25bb1fb73cfa8d7e5367f3d9b4
ep_bytes: e9c38f0100e94c8f0100e987d80000e9
timestamp: 2020-12-09 13:07:56

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java(TM) Platform SE binary
FileVersion: 8.0.2810.9
Full Version: 1.8.0_281-b09
InternalName: unpack200
LegalCopyright: Copyright © 2020
OriginalFilename: unpack200.exe
ProductName: Java(TM) Platform SE 8
ProductVersion: 8.0.2810.9
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesVirus.M0yv
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.301ba84f
K7GWVirus ( 005a8b911 )
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32Win32/Expiro.DL
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:elO6iUoeQ+ND3FpK52vz2g)
IkarusWorm.Win32.Soulclose
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment