Virus

Virus:Win32/Expiro.EK!MTB removal instruction

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: A4D70E9C569757236C28.mlw
path: /opt/CAPEv2/storage/binaries/ac72cddb2a203569422cb6d678804904d0dde178c31a884154968ae3704c5501
crc32: 341B2B7C
md5: a4d70e9c569757236c2849a96d1afb3c
sha1: 173432effa09537e44c7b745d8c612a81472d22a
sha256: ac72cddb2a203569422cb6d678804904d0dde178c31a884154968ae3704c5501
sha512: 37f5a92947ecd8e77356004fe24fa311c70d927ea57a54d6c17cc741121137b29d1e58cf8035aeca38696012796167c3fc509bedfefb241a7145b5945fc88a70
ssdeep: 12288:lRX3IiFQ/RlJmXTi3/itAU2l0YiC274K1VfnPjjrtodIKCGk5AWY/RvGOY:lWiFQJlJCTJajg4YVfnbtNWgAvGx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19445230A06EC0847DF827F3EB6242CEBF961DECCE66DA526709275271675C24CC099EC
sha3_384: b0c6d2bb843f8ccb7a22faa076f336c3c39a96283ff46ec816b70cc484b9dc920f39bbc915ccd2a78d583175414b47db
ep_bytes: e874140900e974feffff558bec6a00ff
timestamp: 2023-05-20 01:52:31

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a4d70e9c56975723
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
McAfeeArtemis!A4D70E9C5697
MalwarebytesVirus.M0yv
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 0059041f1 )
AlibabaVirus:Win32/Expiro.db90c208
K7GWVirus ( 0059041f1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecW32.Xpiro.J!dam
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusTrojan.Patched
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
GoogleDetected
Acronissuspicious
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=83)
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.88 (RDML:SHeJNWhJMexe9Ph7a+/h0g)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment