Virus

What is “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 62ED4A85FE535191B6B7.mlw
path: /opt/CAPEv2/storage/binaries/3db9b2fd3fd2bd2a4236e563b681fadd22ec0c72b2ad6b102fcfeb193a35cd8b
crc32: AC1FD20A
md5: 62ed4a85fe535191b6b74a206eac17a7
sha1: 1e21bc0b77ff423bf9ad2ac288b2e86682d231f0
sha256: 3db9b2fd3fd2bd2a4236e563b681fadd22ec0c72b2ad6b102fcfeb193a35cd8b
sha512: 3eb53eb30b863ac6e0a032f348b3e87c5818480ed97d463023050e3530b9f460994a41fc147ec9882f558f5003f9f2eda8fb535f9388608cb880f90ea95fbb8a
ssdeep: 12288:x1FCrNDFKYmKIiirRGW2phzrvXuayM1J3AAlrAf0d83QC0OXxcpGHMki:78NDFKYmKOF0zr31JwAlcR3QC0OXxc0H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143D4236369AD90D2D9328334497DF1A49A6F39B45B418BE772243B2E0172EC6CC3C56F
sha3_384: 41bdc10507cf60c3a6c111ea6bcb46e2adee662c48837fae291b2f9821a1cf66b94830510f67ca3a227b871592880730
ep_bytes: e829500900e97afeffffe9a90b00003b
timestamp: 2021-10-26 21:10:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: ERRLOOK MFC Application
FileVersion: 14.29.30137.0 built by: vcwrkspc
InternalName: ERRLOOK
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: ERRLOOK.EXE
ProductName: Microsoft® Visual Studio®
ProductVersion: 14.29.30137.0
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Trojan.Expiro-9962115-0
FireEyeGeneric.mg.62ed4a85fe535191
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Virut.jc
MalwarebytesVirus.M0yv
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.302d5259
K7GWVirus ( 005a8b911 )
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=85)
Cylanceunsafe
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FileInfector.C!tr
AVGWin32:Evo-gen [Trj]
PandaW32/Moyv.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment