Virus

Virus:Win32/Expiro.EK!MTB removal

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: ECFA43A7BB471D2E940D.mlw
path: /opt/CAPEv2/storage/binaries/34b240435c8928dbe06993efabdcbee9d3807c8ec0133c1ae5d9a21144ae6849
crc32: 86D938A8
md5: ecfa43a7bb471d2e940df40d736a3021
sha1: d92a5e8585a75352ba112457997ef8726722e3b7
sha256: 34b240435c8928dbe06993efabdcbee9d3807c8ec0133c1ae5d9a21144ae6849
sha512: 379417bf36d19c85520b3a6ebf6b2abe6b85984040ad2d4452b84424a82df7dd93ba35fd16ad821b0512a17826b5ae7596b670d41b4d27c46a2fe78f6d2b922f
ssdeep: 24576:1YK2eXikQ38NDFKYmKOF0zr31JwAlcR3QC0OXxc0H:1RH1YgDUYmvFur31yAipQCtXxc0H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C850266A14960F1DD5F2236286EB73AE7301D182B0549DBF3F82F1AC9387D46836D4E
sha3_384: 1f4c6a269347bc10ace463388f40730abd3a310f401d4edd20d6339a8a2291713aac59f9249f91752bc50ce89a346865
ep_bytes: e81b0a1800e978feffff8b0d0c004300
timestamp: 2021-05-04 16:36:13

Version Info:

Comments:
LegalCopyright: License: MPL 2
CompanyName: Mozilla Foundation
FileDescription:
FileVersion: 88.0.1
ProductVersion: 88.0.1
InternalName:
LegalTrademarks: Mozilla
OriginalFilename: crashreporter.exe
ProductName: Firefox
BuildID: 20210504152106
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Trojan.Expiro-9962115-0
FireEyeGeneric.mg.ecfa43a7bb471d2e
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Virus.tt
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.585a75
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
MAXmalware (ai score=88)
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
AhnLab-V3Malware/Win.IS.C5064324
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment