Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 89BAE68762DB6FC2BD5D.mlw
path: /opt/CAPEv2/storage/binaries/92a1d0adb35b96d3d8d56b5edeabd39d60805ca212cd637811c87659b6d51296
crc32: DDFADEF9
md5: 89bae68762db6fc2bd5de1ad9c893ee9
sha1: 37ed27050ecf3337a75ce86d730dcfe0eb1b4bc1
sha256: 92a1d0adb35b96d3d8d56b5edeabd39d60805ca212cd637811c87659b6d51296
sha512: c1a3037a1659c591f23f1c3baa6fb2c41155dc254b118d66a036e35f505c9f58adff28ae82a8ed85db016083ed5c53fe79301f02c4212f23a0644136c360b072
ssdeep: 24576:nB+4UT1FSqZLQEQkbvK8N3t3QVkLhoo+SVfhl2/:B+nxQErvL73RLSo+2fhl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12365E0013F918EB6F5A2807F496A672D562ABD224F10D2C3B3607B5DD8325C5DE3E31A
sha3_384: 39078cdf3d481d7f35eecd2912d70450640c02372f6ee6b90a707962d3fe068bcc47c13daa27fd0275b8cddd5c3f6b45
ep_bytes: e8660a0000e978feffffcccccccccccc
timestamp: 2020-07-30 23:26:35

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe PDF Broker Process for Internet Explorer
FileVersion: 20.12.20041.394260
InternalName: AcroBroker.exe
LegalCopyright: Copyright 1984-2020 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename: AcroBroker.exe
ProductName: Adobe PDF Broker Process for Internet Explorer
ProductVersion: 20.12.20041.394260
Translation: 0x0409 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-10015624-0
FireEyeGeneric.mg.89bae68762db6fc2
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tm
ALYacWin32.Expiro.Gen.7
MalwarebytesVirus.M0yv
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Expiro.128561ca
K7GWVirus ( 005a8b911 )
K7AntiVirusVirus ( 005a8b911 )
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusVirus.Win32.Tufik
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
KingsoftWin32.Infected.AutoInfector.a
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
MAXmalware (ai score=84)
VBA32BScope.TrojanDownloader.Zenlod
Cylanceunsafe
PandaW32/Moyv.A
RisingVirus.Moiva!8.143D0 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment