Virus

What is “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 07646C19880A4A12BA4D.mlw
path: /opt/CAPEv2/storage/binaries/8d57d5176aa3b4eecfe600f7a591ea1497e0c7d3bd7e65bccb8aa228ea1af9ca
crc32: 9B903D62
md5: 07646c19880a4a12ba4d230d20093137
sha1: 05c9c1f884871eac6bfa78c274f47da6e7717bd1
sha256: 8d57d5176aa3b4eecfe600f7a591ea1497e0c7d3bd7e65bccb8aa228ea1af9ca
sha512: ec9478131560ce9082f6ac10be366788152d2cb402d34348d08d24aa521a56f9164526338d1ce443e6274e1f117b6dcf942f2d43c1838250f537da9230198f4c
ssdeep: 24576:++/HoiZMrCxuYYatr0zAiX90z/F0jsFB3SQk:WmMriuzaB0zj0yjoB2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA85011270E280F2D8B31A3409F4AA714EBDBD710A619E6F63D43B1E4E756D18526FB3
sha3_384: 323bfb0990fc490e9059e14759a553cb3db7555f84a9f8ed12d6c41101b20025425aa1a0d44896f7270d3383811c6b48
ep_bytes: e8e61b1a00e97afeffff558bec6a00ff
timestamp: 2021-07-27 00:26:21

Version Info:

CompanyName: Google LLC
FileDescription: Google Update Core
FileVersion: 1.3.36.101
InternalName: Google Update
LegalCopyright: Copyright 2018 Google LLC
OriginalFilename: GoogleUpdate.exe
ProductName: Google Update
ProductVersion: 1.3.36.101
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.884871
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Expiro-9937503-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
RisingTrojan.Generic@AI.90 (RDML:tCYv0f7XUOT36mZ2SJK+9A)
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusTrojan.Patched
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Trojan.PSE.JB13RC
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2164
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
PandaW32/Moyv.A
TencentVirus.Win32.VirMoiva.a
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment