Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 63951B93F26F9E0B3D7B.mlw
path: /opt/CAPEv2/storage/binaries/a96069b1dd43c75c1855f09173ac4b847b9458d7d88d4f653b230e327537ac53
crc32: A2ABA78A
md5: 63951b93f26f9e0b3d7b508a61f8c594
sha1: 4edc5cc934234d74aa4d97d42777acb53335cefc
sha256: a96069b1dd43c75c1855f09173ac4b847b9458d7d88d4f653b230e327537ac53
sha512: b9e13c16eb996c4125041aa3a816439526f9e8e761dbe83ad581788ec6e2bed24e83390594daa4c3d6fb964d00aa19e603f3f884278a4bb00ee3c8a99ef332d9
ssdeep: 393216:EBCNImGSdL2bRW/BtxM/mIKKEt9NnLgf:ECNIpSdCt/mIKhXNnLgf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AD6AE167390919DC1B301305E8AB3B6F2FDFA711534465B6784AECE3EB15839B22B93
sha3_384: 17e6eecf424eebcaacccb6d1c083dad4a403273b936b6ac4b24ca4e1113de7bec9306054644b0aee874ff554243a7ba8
ep_bytes: e805000000e9c1000000558bec83ec14
timestamp: 2006-10-27 22:11:27

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Outlook
FileVersion: 12.0.4518.1014
InternalName: Outlook
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: Outlook.exe
ProductName: Microsoft Office Outlook
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.63951b93f26f9e0b
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Sality.rh
Cylanceunsafe
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Virus.Expiro-10016189-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Dh-A [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-A
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.high.ml.score
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
JiangminTrojan.Generic.hhqqu
VaristW32/Expiro.AU.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5175625
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=82)
MalwarebytesVirus.M0yv
PandaW32/Moyv.A
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Dh-A [Heur]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment