Virus

Virus:Win32/Expiro.EK!MTB (file analysis)

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: B8107847CC4A2F41D890.mlw
path: /opt/CAPEv2/storage/binaries/73e63a9e7d715687e7fa05288ba304c4edf17d35151928b61a7d98a841733baf
crc32: 74A90FDF
md5: b8107847cc4a2f41d8902dcddd6a9bab
sha1: 050fd7cd7861ee1d1fcb8d09893f702a57d93396
sha256: 73e63a9e7d715687e7fa05288ba304c4edf17d35151928b61a7d98a841733baf
sha512: 88d5aa00bff461f256c62314261a80e84afebbdd896ef686b763e16cc0118f410d30dee941e642277cfa0e663b7fdfa4e3e3a052c2a9ef9b4d123c612ed886f9
ssdeep: 393216:pEb9f6Ol1FFtm/deMigK39RK8pVeh9sYq4Awc5UCC2iB4P:pEb9f6Ol1FFo/deMig2R/eh9sYq4Awc5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12DF67C52F7D204B1E89301B0717BEB3BCD366D344B348AD787606E5AA9716D10B3BB86
sha3_384: 40bfec7442b4ed49d844a86af6c164334647f83103ff1991b7d8950ce73dd0f9f1668d85aaf05c67f82d800db68c7b21
ep_bytes: e8900b0000e97afeffff68885d3101ff
timestamp: 2023-10-24 21:07:43

Version Info:

CompanyName: Epic Games, Inc.
LegalCopyright: Copyright Epic Games, Inc. All Rights Reserved.
ProductName: CrashReportClient
ProductVersion: 15.17.1-29053586+++Portal+Release-Live
FileDescription: CrashReportClient
InternalName: UnrealEngine
OriginalFilename: CrashReportClient.exe
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.Common.5336BF96
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9976460-0
FireEyeWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Virus.wh
Cylanceunsafe
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.4bc80de0
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastFileRepMalware [Inf]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusVirus.Win64.Expiro
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
AhnLab-V3Virus/Win.Expiro.X2164
VBA32BScope.TrojanDownloader.Zenlod
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
RisingVirus.Expiro!8.375 (CLOUD)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGFileRepMalware [Inf]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment