Virus

Virus:Win32/Expiro.EK!MTB removal tips

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: A60352FD6F34D7ADA02D.mlw
path: /opt/CAPEv2/storage/binaries/3b1d00d21e637935f57dce63b8b93546e24548e67d25e56d2ef436620eb1ae32
crc32: D9B3BA77
md5: a60352fd6f34d7ada02de681747b6bcd
sha1: 9149b74f06590f9d6783d917ed25943936019a1e
sha256: 3b1d00d21e637935f57dce63b8b93546e24548e67d25e56d2ef436620eb1ae32
sha512: 31ad1e5ee51442eb795635dd00836269053eaa77aba06dc9e0b44857f9901e6ffd2e125c10d0c47a5c60ac6cbb8bc13a82663937ae0c773e7e61b71942275842
ssdeep: 12288:fpaVtaU0FlYcBkOGt/sB1KcYmqgZvAMlUoUjG+YKtMfnkOeZb5JYiNAgAPh:BaOoc0t/sBlDqgZQd6XKtiMJYiPU
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18855F111758ACF72D66F11719D68AAF5827BAD38CF1013D7A3C5BE2E38381C26932653
sha3_384: cd22c51f7d41a5129094f256e9cf3546d1a0ce69cc82f303e1296d3c29e783cff93c47d7307bc0b398a0ca2218433ba8
ep_bytes: e8f30b0000e968feffff8b4df464890d
timestamp: 2021-02-15 03:27:17

Version Info:

CompanyName: Adobe Systems Inc.
FileDescription: Adobe Create PDF plug-in listener for Chrome
FileVersion: 21.1.20138.422477
LegalCopyright: Copyright 1984-2021 Adobe Systems Incorporated
OriginalFilename: WCChromeNativeMessagingHost.exe
ProductName: Adobe Create PDF
ProductVersion: 21.1.20138.422477
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
CynetMalicious (score: 100)
FireEyeGeneric.mg.a60352fd6f34d7ad
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Sality.tt
MalwarebytesVirus.M0yv
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.abbbcb51
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Malware.Expiro-9941636-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminesuspicious.low.ml.score
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.12DR9FL
JiangminTrojan.Gen.byg
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=89)
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:xQSqdghRR5/GBOZX/0BjiQ)
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment