Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 6DCC320C9AE9000F473D.mlw
path: /opt/CAPEv2/storage/binaries/296f08ecfd9d00d494b7ab0f56220abf375a4122a3be067a4ad6a8a51a6efb07
crc32: 19D63918
md5: 6dcc320c9ae9000f473d0668f2428e25
sha1: 50871e221bae3d8e6ced56b00da968046ee0839c
sha256: 296f08ecfd9d00d494b7ab0f56220abf375a4122a3be067a4ad6a8a51a6efb07
sha512: 3ebfa5d3485fa53528931472005e8b339de753abd4cc67cf7ecbbeb5cbe71ce459e75ccb0f0543a31d52845dce2680093418e0a84b8ce5dd6a56efa46e86e842
ssdeep: 12288:/jHmn7d0NxksRpWE9FRHSfNm1wgbIxnBw7dzE+e3gxZC6LgjigDy5fdv8fWi+:/jGnCks7WE9F5pwg8zmdqQjC60jiHkU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA75125176D54CF2FF5A02328FA8B79587A9F8208F145ADBBA44625F1C7C2C24C3879B
sha3_384: d022522bde2bf4b9d4ac3ebcb716ac77a29f58853fec2264ac6f7e64e7cb328006c8bca33c61388a142fbcdca3503173
ep_bytes: e8b5060000e978feffff558bec6a00ff
timestamp: 2021-02-15 03:11:27

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Eula display
FileVersion: 21.1.20138.422477
InternalName: Eula.exe
LegalCopyright: Copyright 2010-2021 Adobe Systems Incorporated. All rights reserved.
OriginalFilename: Eula.exe
ProductName: EULA
ProductVersion: 21.1.20138.422477
Translation: 0x0409 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.6dcc320c9ae9000f
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tz
Cylanceunsafe
SangforVirus.Win32.Expiro.Vojc
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Malware.Expiro-9937504-0
KasperskyVirus.Win32.Moiva.a
AlibabaVirus:Win32/Expiro.a8536e67
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.high.ml.score
SophosW32/Moiva-C
IkarusTrojan.Patched
JiangminTrojan.Generic.hnsyo
ALYacWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
MAXmalware (ai score=83)
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Sabsik.TE
GoogleDetected
TACHYONVirus/W32.Movia
MalwarebytesVirus.M0yv
PandaW32/Moyv.A
RisingTrojan.Generic@AI.87 (RDML:Esg7MWw95OfRbTPhNrBJUg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment