Virus

Virus:Win32/Expiro.EK!MTB malicious file

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: B27EB46B43397C7190F1.mlw
path: /opt/CAPEv2/storage/binaries/db3441ce0ec526b12f9715a211890c53284d6951a3da38f0472917f97ca3bec1
crc32: BC11D9C0
md5: b27eb46b43397c7190f1096823c9194e
sha1: 3c8e312cc731c21c5d8c654f33bdc0fb2ebc9aa9
sha256: db3441ce0ec526b12f9715a211890c53284d6951a3da38f0472917f97ca3bec1
sha512: e98225afc06903f4c12b4e6499f62ef88aa5859693b5b0a9a4faf464b1bc2a20e82889294568858c4e5387fe18cb2a889b64dd3302a3ee7f1efdc0a776e5cb9b
ssdeep: 12288:4Pvv3DFaBfvfoPDct6SlxlwkJJrqQoUhTFfPLgpRtHmr/UNvp8hMoZUDNk:4PBayDcMkqQpRQmr/UN4MbN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1904512A3F2D59085E53787302D389931893A7CA95C70CD1F6398361F8C7B7E189A6E36
sha3_384: 3835a7e655c3fd6c798e364e51b59763d5148e3948aae006de83a294c39c558d4f3ac344802f5a407cf8e9f1c705c260
ep_bytes: e8ed251300e97afeffff558bec56ff75
timestamp: 2020-12-09 13:25:31

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java Control Panel
FileVersion: 11.281.2.09
Full Version: 11.281.2.09
InternalName: Java Control Panel
LegalCopyright: Copyright © 2020
OriginalFilename: javacpl.exe
ProductName: Java(TM) Platform SE 8 U281
ProductVersion: 8.0.2810.9
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9996938-0
FireEyeGeneric.mg.b27eb46b43397c71
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=88)
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:XDEcF/CjCP/JLFjlEd+ATw)
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment