Virus

Virus:Win32/Expiro.EK!MTB removal guide

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 9FA27C2746DA0510E58D.mlw
path: /opt/CAPEv2/storage/binaries/9259f2a80ca3ca4e4605799a7b635fd9fb0d8f1c6947aaec9a3f25dbb94466a4
crc32: 32546AE8
md5: 9fa27c2746da0510e58dd300df17ba21
sha1: da10958f028bec041859796dd3b5029dd142d24f
sha256: 9259f2a80ca3ca4e4605799a7b635fd9fb0d8f1c6947aaec9a3f25dbb94466a4
sha512: ad6ddab5a9e36cbe352cb01cc8509a00b6547f9761512299577274c382cb23f0e3f95284f1355694a9b75295a0af199c2561624d6273e9d99f169cca2d7c33b8
ssdeep: 24576:8U+qBCWHRlMugdD+JsRgZRJ4fM430Eg6nET7M/IiN:F+8xlMPdlR8v4UC0Eg6ET7M/I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC75E0707A8AC53BE65301718CFCFABF806ABE450FA511C3B3484B6E6E645D32E71916
sha3_384: 39f1317a9929f1dfd06fa8554ddec7e40362586b84aaf77f8ead26755790ca393b55e9f4c1b37188428e23a50b3e9c9b
ep_bytes: e86b060000e984feffff558bec6a00ff
timestamp: 2018-09-12 06:16:28

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Trojan.Generic-9935365-0
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesVirus.M0yv
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.5276fc7e
K7GWVirus ( 005a8b911 )
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
FireEyeWin32.Expiro.Gen.7
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraW32/Infector.Gen
MAXmalware (ai score=85)
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.98 (RDML:lBUPji7NemqIBrkcObeW1g)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FileInfector.C!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment