Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 294E60FEB1ABEBBB23FB.mlw
path: /opt/CAPEv2/storage/binaries/e0d2f007368ac28f7b051853466bb62ddb0d25a2fb33a3833d5593c7189127dd
crc32: B1015C4F
md5: 294e60feb1abebbb23fb5a5353c4a8b5
sha1: d9ece530266bd8b961d34dcffe3ccf8f1bf3e280
sha256: e0d2f007368ac28f7b051853466bb62ddb0d25a2fb33a3833d5593c7189127dd
sha512: 7952c0cc15de4a6ff2dcccf321bd3ce05bf7a26760614a7a63c4caf1b71a987e3b31ef0fde64099378436604b0eb813fbbcb39fd78aea119cc90f6e62ec0d606
ssdeep: 24576:4G1HhBo7zpXzXatr0zAiX90z/F0jsFB3SQk:/1SzXaB0zj0yjoB2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11885E0023B518EB6F5A3807B196A671E1A6ABD211B10D3C3B3607F4DCD325C59E3E356
sha3_384: bb561d9931c7f87799e623405aa4403884f5c308db0df009071a85bfe58234e65462237b3878c978d20f98f80bbd7fac
ep_bytes: e88b801800e978feffffcccccccccccc
timestamp: 2021-02-15 03:25:01

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe PDF Broker Process for Internet Explorer
FileVersion: 21.1.20138.422477
InternalName: AcroBroker.exe
LegalCopyright: Copyright 1984-2021 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename: AcroBroker.exe
ProductName: Adobe PDF Broker Process for Internet Explorer
ProductVersion: 21.1.20138.422477
Translation: 0x0409 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Trojan.Expiro-9937503-0
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Expiro.Gen.7
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWVirus ( 005a8b911 )
K7AntiVirusVirus ( 005a8b911 )
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.294e60feb1abebbb
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraW32/Infector.Gen
MAXmalware (ai score=89)
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
AhnLab-V3Virus/Win.Expiro.X2164
Acronissuspicious
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.88 (RDML:bUukOm0wHYt1PUWAhKyOHw)
IkarusTrojan.Generic
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment