Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 791D7BD0F354E0D10C71.mlw
path: /opt/CAPEv2/storage/binaries/dbc4722ccc49b472f11c50dcff6f98cc17d927a1be036e50432bd2ab82b8b36f
crc32: C337D47A
md5: 791d7bd0f354e0d10c717f23caf180a2
sha1: 06d5a07127e99a4b86f56234f7c07dbc9877317d
sha256: dbc4722ccc49b472f11c50dcff6f98cc17d927a1be036e50432bd2ab82b8b36f
sha512: 7c7aa93f8ebda0452d8bdf22de37a6fd3956d8b56236e24dadaf0cad307b3e19b1e01c7aa021908baa1903a24fe13680b60b4d41bf756760be0b086e65abacd1
ssdeep: 12288:Mp2rQ9KbFwOKpOz5N9vWst3QVkBNhw6Y5o+SudAfh39z2Go:WEQkbvK8N3t3QVkLhoo+SVfhl2/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10545225235F91581D8B6973D88216078C65EBC609F95C2C3B790399E82B7BD0FD3B32A
sha3_384: 3cd48ff7559c059d15af57e238c84221a2ae65e8d06e2d974fe0ae1d1b533999054cbeefa36c171e79265053b4b891fa
ep_bytes: e8dc030000e97afeffffe9a90b00003b
timestamp: 2021-10-26 21:10:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: ERRLOOK MFC Application
FileVersion: 14.29.30137.0 built by: vcwrkspc
InternalName: ERRLOOK
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: ERRLOOK.EXE
ProductName: Microsoft® Visual Studio®
ProductVersion: 14.29.30137.0
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Dropper.tt
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.059dfa4f
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
IkarusVirus.Win64.Expiro
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=80)
VBA32BScope.TrojanDownloader.Zenlod
MalwarebytesNeshta.Virus.FileInfector.DDS
PandaW32/Moyv.A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.127e99
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment