Virus

Virus:Win32/Expiro.EK!MTB malicious file

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 1AFE0D8091E0A107673B.mlw
path: /opt/CAPEv2/storage/binaries/76b241c4f3576ad07e728ae094d1ec32c64e4a3e237bafdf1aaea77fd5d59f90
crc32: 4858720F
md5: 1afe0d8091e0a107673b1fc1e3fd2b87
sha1: 768822f24b5b4a3119272d789e198538491a1094
sha256: 76b241c4f3576ad07e728ae094d1ec32c64e4a3e237bafdf1aaea77fd5d59f90
sha512: f5f955a1e9918166dd3a07c4c6a538ccfd51d1bca2265f80e801071fba94b04bc52e992587b65af8a0438f5ff1c2087118b327800eb1cea276fe46f16559a747
ssdeep: 24576:DAkMojzaWXFol/j0ZQlHSCv1pRADdU4Lxts9:EEnaWGkQlHScUdUEI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B15EF5076D59032F6B34E315E78C6204E3EBD655C609E8F639839AE4E71AC0CA35F3A
sha3_384: 349d1a4f00c303a93d4ba42b6dd76d4771eb3ef6704707b313903a70eaa12c137cb2219ed87377890a6a2079d5a058bb
ep_bytes: e857050000e97afeffffc368702c4100
timestamp: 2020-12-09 13:24:04

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java(TM) Web Start Launcher
FileVersion: 11.281.2.09
Full Version: 11.281.2.09
InternalName: Java(TM) Web Start Launcher
LegalCopyright: Copyright © 2020
OriginalFilename: javaws.exe
ProductName: Java(TM) Platform SE 8 U281
ProductVersion: 8.0.2810.9
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.1afe0d8091e0a107
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.dc
MalwarebytesVirus.M0yv
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.24b5b4
BitDefenderThetaGen:NN.ZexaF.36744.6u0@a4KyLLii
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
IkarusVirus.Win32.Expiro
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
AhnLab-V3Malware/Win.KD.C4927876
Acronissuspicious
VBA32BScope.Trojan.Convagent
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.92 (RDML:qL+nTh5VEWqzOGO5+nC56w)
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.NDP!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment