Virus

Virus:Win32/Expiro.EK!MTB (file analysis)

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: D5B712B872E7327CD9BB.mlw
path: /opt/CAPEv2/storage/binaries/668f74244f04a9a7f1e50f061155d084df097dfec1c6763dffd7b6ac3667df19
crc32: F47474AD
md5: d5b712b872e7327cd9bb7bc943c835e1
sha1: a0e8f24e7475c2e0f3bf597e3d005a6ec5b17f98
sha256: 668f74244f04a9a7f1e50f061155d084df097dfec1c6763dffd7b6ac3667df19
sha512: 501cc161bcc54949b6d1991d1480313464c7b182c004cf4c1168c2cac9f091b0ea6a7f9b87de5f965f2540005b20549f7593c2f95db8d6723726b72ab065d2b4
ssdeep: 24576:4GBebZj/bhoxayDcMkqQpRQmr/UN4MbN:1ebNhA7DcMlQpRQQMKMZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E65F17137E9C877F267423844F98676D6B57CC2AD30814F73E42B0ECA376519A22722
sha3_384: 9d72c2edeffdac84097ce1aec8ec0fb961ee134be0cb297e03a6e22b616257475a3a63d1a34093eea12c27b281e950c2
ep_bytes: e82ca01500e916feffff8b542404568b
timestamp: 2006-10-27 06:54:56

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Groove Migrator Utility
FileVersion: 0004, 0002, 0000, 0000
InternalName: GrooveMigrator
LegalCopyright: Copyright © 2006 Microsoft Corporation. All rights reserved.
OriginalFilename: GrooveMigrator.exe
ProductName: Groove Migrator Utility
ProductVersion: 0004, 0002, 0000, 0000
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
ClamAVWin.Dropper.Vindor-9886075-0
FireEyeGeneric.mg.d5b712b872e7327c
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Virut.tm
McAfeeArtemis!D5B712B872E7
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.e7475c
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusTrojan.Kazy
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=82)
VBA32Trojan.Sabsik.TE
PandaW32/Moyv.A
RisingTrojan.Generic@AI.89 (RDML:+blTQAz9ed6rANQvKYXiYw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment