Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 806372B8333F4BCCB63A.mlw
path: /opt/CAPEv2/storage/binaries/4f9c6ff816cd1fdd9d597232756e2adcaa88e082a54928c64cb7e9f9108b4c73
crc32: D066AD3B
md5: 806372b8333f4bccb63a17e3eec30315
sha1: 7b88ab7c7ade4c3dbe59523dffd5ca28f958967f
sha256: 4f9c6ff816cd1fdd9d597232756e2adcaa88e082a54928c64cb7e9f9108b4c73
sha512: 6180abafe9011fc7f22f5754a5f6a27ba665db1374ad7c527626e64c61d79e904a3a9051b2dcce510d9fecbd0a5234a2688213865b05dba307a9f43c7247e927
ssdeep: 49152:XatQfOOwViT2YcsSo3ZH4BkNpvOoROs0hx4z7CNdsdZz6N3Q6itmOH:cV62YcsSo3ZH4qNUkOHhx4vdt6N3u5H
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T120A5BE3275E0A4B7E122313087AAE361556ECA30676285C733DCC77E1FB45C2993A79B
sha3_384: a47ee77539e9b18ed63bbe9e7ef1d012b7e40ff92bbe2f9616a1e18414e76d0d1c09a20579feeb4b3143d8de2b948023
ep_bytes: e880110000e968feffff3b0de0c15400
timestamp: 1993-03-19 00:28:29

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft IDL Compiler
FileVersion: 10.0.19041.685 (WinBuild.160101.0800)
InternalName: midlrt.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: midlrt.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.685
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.806372b8333f4bcc
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Virut.tc
ALYacWin32.Expiro.Gen.7
Cylanceunsafe
SangforVirus.Win32.Expiro.Vw13
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.47ae476d
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Virus.Expiro-9955278-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastFileRepMalware [Inf]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
McAfeeGenericRXRG-IP!806372B8333F
MAXmalware (ai score=83)
VBA32Trojan.Sabsik.TE
MalwarebytesVirus.M0yv
PandaW32/Moyv.A
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGFileRepMalware [Inf]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment