Virus

Virus:Win32/Expiro.EK!MTB removal guide

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 987670FF80A2A34D425E.mlw
path: /opt/CAPEv2/storage/binaries/4d1641432e03997aef3fca88ea469ba205b26989b7891b7885320a98cdf24131
crc32: 2D6472CD
md5: 987670ff80a2a34d425ec98dfd73e229
sha1: 69e219e7851e510448b4b06269fcd1aeefd33604
sha256: 4d1641432e03997aef3fca88ea469ba205b26989b7891b7885320a98cdf24131
sha512: 58b5569250d46dede04eeb045042c59319cef126b9789f8465e556b9cc148ae78db87decc969d4023ba434e1dcf3f5c9b1ccbd8d593fb7698590b75bd7abdcbf
ssdeep: 12288:J4+/x8J7ct3z5htUcQ1MlhrmQgwwJzt5+7fyZkCtXFiWZF/3o:J4+mIJz5IcuMlQHJxrDiSi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C4523AAF7ADB887FF7F0A7416409AF0E248FF7A760816932118366771FED439815124
sha3_384: 00bc63ef2deded8d85b5206e32e668f689da3dbf4fba3d7c089ded26f0eecb2ec6f9508bf446e0b99649b00ddd4301e8
ep_bytes: e852781200e984feffffc3558bec6a00
timestamp: 2020-02-04 19:20:46

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9970348-0
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecW32.Xpiro.J!dam
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Evo-gen [Trj]
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
IkarusVirus.Win32.Tufik
GDataWin32.Expiro.Gen.7
JiangminTrojan.Generic.henen
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.954
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
VBA32BScope.TrojanDownloader.Zenlod
PandaW32/Moyv.A
RisingTrojan.Generic@AI.93 (RDML:kBc7SrKE4S8wUYtietFtIw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment