Virus

Virus:Win32/Expiro.EK!MTB information

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 259D54B7B93DAAF87302.mlw
path: /opt/CAPEv2/storage/binaries/820b2c8b0c64c43990c658db08f808bad1d76284469225af6e439604149f64ca
crc32: CB509900
md5: 259d54b7b93daaf87302e353028a3326
sha1: 36767b08d1beb6e253bb3813ff07dde2eabea309
sha256: 820b2c8b0c64c43990c658db08f808bad1d76284469225af6e439604149f64ca
sha512: 78ecf6fa680c407d1e11219f4887fa91faf75edff5a0ab0cccd5bd741208628bda9d2028e7a052b2e3de6b5f63bc435dff9982813304a78340324898e3dfdff1
ssdeep: 12288:e7/xqTSgZG5GnWMBUKZGYaJ08vTZLfX+PdgdnW:e7xVirnlBUKZ408vTZrX+lgdW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD552301328548B6D17B17B099F4FA20F3FFBC669C71561733A03B4A9D77CD6A8252A2
sha3_384: e379716712a3d3794904118eb962c5fc39c60aeb8109bf10ee1c0fb2565a421ab507537e057d739634bc3be3a3155c13
ep_bytes: e823fcffffe935fdffffff2590100030
timestamp: 2006-10-27 03:42:35

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Outlook OST Integrity Check
FileVersion: 12.0.4518.1014
InternalName: ScanOST.exe
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
LegalTrademarks3: Microsoft Office Outlook® is a registered trademark of Microsoft Corporation.
OriginalFilename: ScanOST.exe
ProductName: Microsoft Office Outlook
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Expiro.Gen.7
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.8d1beb
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Expiro-9933728-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
IkarusVirus.Win32.Expiro
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:DR9XKT/7JC2q2pXf5eNfIw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment