Virus

Virus:Win32/Expiro.EK!MTB malicious file

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 5D2E531E82C51C061F75.mlw
path: /opt/CAPEv2/storage/binaries/0a327ebace7697a42bb9b11986bfe5cf5d248a4150e4d36bfa14733a29648be4
crc32: 671ED030
md5: 5d2e531e82c51c061f75a04b59ccb11b
sha1: d7dc5c303e53e9d57b1fa48e8b9fb0ade9a68170
sha256: 0a327ebace7697a42bb9b11986bfe5cf5d248a4150e4d36bfa14733a29648be4
sha512: 0c71e7e27a45cc83d81e2fd351c505fb0e43e0a685ad218d591f37f4cb8fb414fa60953949270294498b94064092b269db29be9df1283127dd089b53217381ff
ssdeep: 12288:VHIhZaCt5Wgd+gkvMQDabQ82kbj3BmfWBEHN36h/98QPK0t:VmZaCt5Wgd+Z0y6n2kPUfWl/9u
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18855220A2B8E9156CA807670C8A53E648D979D741E4705C3AAF3F73E057C2E77B3247A
sha3_384: a2cc2e228855d36a840e2c303f38c7e94ed406e6b16b454b1462602a7c8c4ec4cede91420fb67e511ed0dfcd5214aa2b
ep_bytes: e856020000e978feffff558becff7508
timestamp: 2023-09-12 02:54:55

Version Info:

Comments:
LegalCopyright: ©Firefox and Mozilla Developers; available under the MPL 2 license.
CompanyName: Mozilla Corporation
FileDescription: Firefox
FileVersion: 117.0.1
ProductVersion: 117.0.1
InternalName: Firefox
LegalTrademarks: Firefox is a Trademark of The Mozilla Foundation.
OriginalFilename: private_browsing.exe
ProductName: Firefox
BuildID: 20230912013654
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 00594aea1 )
AlibabaVirus:Win32/Moiva.7ddf30ac
K7GWVirus ( 00594aea1 )
Cybereasonmalicious.03e53e
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
SophosW32/Moiva-A
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusVirus.Win32.Expiro
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.970
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
RisingTrojan.Generic@AI.90 (RDML:+ladrgfbX84W2uBFxx4QYg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment