Virus

Virus:Win32/Expiro.EK!MTB information

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: C5D27A18418BE9F21BB3.mlw
path: /opt/CAPEv2/storage/binaries/7ff362a94f7bd8f22312f1d8fe8202d7ee98b045fc504770045fcf9136a3c4c5
crc32: BC9CBB33
md5: c5d27a18418be9f21bb3303235284299
sha1: b363766000b689c5c5253e75536a649b42973ee2
sha256: 7ff362a94f7bd8f22312f1d8fe8202d7ee98b045fc504770045fcf9136a3c4c5
sha512: 58e72af91837760b4d8e35871ebd2f268303acc625aea1ad9dbc054a98dee31b0cb80c43fcb0f0c8f874ce0177407f0b49370f9c139948de53c26b1976ce89e5
ssdeep: 12288:IUMAdB8qr0zw9iXQ40AOzDr5YJjsF/5v3ZkHRik8:Iatr0zAiX90z/F0jsFB3SQk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18665234B341F41F2CCC32B3566848C0B1AB95AB076E3AB85B1D27F0FAA3C5C655656CB
sha3_384: 8c164b20524ab1b6ee073351e87cf7795d7fbfbec97bb01864c8849cdcea58e599c3e9b4e29f54105c58d8520597b173
ep_bytes: e82efcffffe935fdffff558bec81ec28
timestamp: 2006-10-27 02:52:04

Version Info:

CompanyName: Microsoft Corporation
FileDescription: 2007 Microsoft Office component
FileVersion: 12.0.4518.1014
InternalName: smarttaginstall
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: SmartTagInstall.exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tz
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Expiro.Gen.7
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Expiro-9937503-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
IkarusVirus.Win32.Expiro
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2164
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.87 (RDML:Pszw1d+bJCE0vq9WyOF+pA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
Cybereasonmalicious.000b68
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment