Virus

Virus:Win32/Expiro.EK!MTB removal

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 375CD0B57547E331264C.mlw
path: /opt/CAPEv2/storage/binaries/e5b35613c9539a5294d155163af30bcb1f67652ef804b3e5f1f4c42adb8e79bd
crc32: AA645145
md5: 375cd0b57547e331264c0f791e2b25a2
sha1: eb67f6f5a750404f5be5f4bd9e1dd1d26b1e7f30
sha256: e5b35613c9539a5294d155163af30bcb1f67652ef804b3e5f1f4c42adb8e79bd
sha512: 23e9a1d30bb73359c68f97b80b499e699b0b50d82f0ec2dd81e640dede543e33fc4a6eaee03f6b03a8115f6a70f5103fd03b98acd54ad224cd487142eff9b0ba
ssdeep: 12288:ip/SInr8vv2BDeT+bVYHTb3FRk/rMNxaXqqlPbJKTGv5DYFXOBnXREHa:E/i328ab4F+rM/aXq6bJfBUam6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3D42387A9D50429FA16BBF288ADB4680E2AF5F44D4A0753B6D87EAE74BFD004C0171D
sha3_384: 6871df52738cef65be09712a09b4f649340d51ce53acb14dacc34b3e9656bd098c095c43acf7da5aea0b35c238cc8a67
ep_bytes: e880240900e97afeffffe9570a00003b
timestamp: 2021-10-26 21:10:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft ® GUIDGEN Application
FileVersion: 14.29.30137.0 built by: vcwrkspc
InternalName: GuidGen
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: GuidGen.EXE
ProductName: Microsoft® Visual Studio®
ProductVersion: 14.29.30137.0
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9987983-0
FireEyeGeneric.mg.375cd0b57547e331
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Virut.hc
MalwarebytesExpiro.Virus.FileInfector.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.5a7504
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusTrojan.Patched
GoogleDetected
AviraW32/Infector.Gen
MAXmalware (ai score=88)
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
Cylanceunsafe
PandaW32/Moyv.A
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment