Virus

About “Virus:Win32/Expiro.EK!MTB” infection

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 33333220DEF0747E2CAD.mlw
path: /opt/CAPEv2/storage/binaries/6dd82dc71f7cb017490e3d4470d0f37b2ea6b9f3fc34074c8a901aecf8796f02
crc32: F4439EF5
md5: 33333220def0747e2cadc1abdb1a6b82
sha1: ac283e78774f375e4012c2a8778a999bfa798fb3
sha256: 6dd82dc71f7cb017490e3d4470d0f37b2ea6b9f3fc34074c8a901aecf8796f02
sha512: d2d18412ccee6c42eca88aa14947760a44e1be944a44a4c1bd92aeaa6005d2d6811c3e7303aadf8475142ab73345e4e6f9afc2dc82632da76bf63674f59f98c8
ssdeep: 12288:je4ISzcQeTD2MDGecwfqp0ju6aXQaZ+KzusYv6LbNEzxSLT5HC8opnl:je4mdTqMfcwAwSLxfq2+zc//6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19675012432C1C073C06365724171C7B69A7B38B96975698BBBC76FBA0F356D18B1A38C
sha3_384: a1cbdbea83892155784acb3905d7352f68a9b2197bded6bc50eb5419b1f54fe964d61decb98ff45d8ae2ecb0025ccad4
ep_bytes: e83d171800e978feffff558bec83ec08
timestamp: 2009-01-29 13:02:55

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
ALYacWin32.Expiro.Gen.7
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Moiva.cbcb5cfc
K7GWVirus ( 005a8b911 )
K7AntiVirusVirus ( 005a8b911 )
ArcabitWin32.Expiro.Gen.7
BitDefenderThetaGen:NN.ZexaF.36680.IrW@ayawtdmi
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
IkarusTrojan.SuspectCRC
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
TACHYONVirus/W32.Movia
VBA32Trojan.Sabsik.TE
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
RisingTrojan.Generic@AI.94 (RDML:I9G+YYI91pq3i1KuAXNrQA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment