Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: A34EE3F77B8FEB40D967.mlw
path: /opt/CAPEv2/storage/binaries/c2f13086466da3bbf9c801f259d57315548463e6a973d0532602816c2fa85ca3
crc32: 2DAF054A
md5: a34ee3f77b8feb40d9679c9dde21cd02
sha1: a30ad5293dad7d67c3259ff2f79519b10dc09eaa
sha256: c2f13086466da3bbf9c801f259d57315548463e6a973d0532602816c2fa85ca3
sha512: f8fea08f4839b5f3c62e234402c86b6a536c4040663a0d71e5ef261f83ae3f42ce3a76d48200f9af76ac837aeac6a84f9119c6381fbbbfc168e4d48171c029db
ssdeep: 12288:HV3VfCfHcqNS0zKepmlDlpVfjp8EizX+AuV27snt5odJMs:lVg9N9JMlDlfjRiVuVsWt5MJMs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F74523AE714659F7C95B82B1CA338385CF275B5976D68143D2B105D2DAFC0A2AC0FAC3
sha3_384: 9e5eb2185df30f03eb6cde80828fbcea1d7656ec0279d7d4b493e67380a22a0e09ef343bc8060cb89b46e3ecdd2dfe1b
ep_bytes: e852181300e984feffffc3558bec6a00
timestamp: 2020-02-04 19:20:46

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.a34ee3f77b8feb40
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Malware.Expiro-9951780-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=88)
JiangminTrojan.Generic.henen
GoogleDetected
AviraW32/Infector.Gen
VaristW32/Expiro.AU.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.987
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
CynetMalicious (score: 100)
AhnLab-V3Virus/Win.Expiro.X2164
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
PandaW32/Moyv.A
RisingTrojan.Generic@AI.88 (RDML:p3Dj6KGljmJ8MoYc7VfI5w)
IkarusVirus.Win32.Tufik
FortinetW32/Expiro.NDP!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment