Virus

Should I remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 6234697F982AC10234CB.mlw
path: /opt/CAPEv2/storage/binaries/74723e2bd3e162a2ebb8a937f9a2222e399ea9598bf9dab9d4b432b20f44c567
crc32: 26B1D7B2
md5: 6234697f982ac10234cb39adb20b5dcb
sha1: 24d084e4c2c14a3946a4a9d4f3a3a3cb47628d6b
sha256: 74723e2bd3e162a2ebb8a937f9a2222e399ea9598bf9dab9d4b432b20f44c567
sha512: 4cb22ea4edb83847755fa1facdbb98a518fffbc6ab86a726b27dd3d7842cc28199c6726986f5093f440027ed39c3c96b84f578874d6c5d4153691e4d126942fc
ssdeep: 98304:u1DuTSn3CLNby+qZTuUsUp/DSTCBpQYFo1pPx7f:u15/uceTCBptcpJ7f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125169E213B9050F6E3722232956E9779E2B9BF305E75414362F13E3E29705929B2C72F
sha3_384: 9500000d92a6a21e21dc5beeffb63286bc31906bb8957713704be884e975fb253b3b9bcac49f37b3a0e5b6bb630ba7fb
ep_bytes: e85c7e0000e989feffff3b0dd0a65800
timestamp: 2023-10-19 11:19:31

Version Info:

Comments: HP Installer
CompanyName: HPI
FileDescription: Launches HP Installer.
FileVersion: 5.0.3.5242
InternalName: Setup.exe
LegalCopyright: Copyright (C) 2017 HPDC LP. All rights reserved.
OriginalFilename: Setup.exe
ProductName: HP Installer
ProductVersion: 5.0.3.5242
Translation: 0x0409 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9985619-0
FireEyeGeneric.mg.6234697f982ac102
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Dropper.wm
MalwarebytesGeneric.Malware.AI.DDS
SangforVirus.Win32.Expiro.Vtul
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecW32.Xpiro.J!dam
ESET-NOD32Win32/Expiro.CU
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Dh-A [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-A
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
KingsoftWin32.Infected.AutoInfector.a
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
GoogleDetected
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=86)
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
IkarusExpiro.Win32
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Dh-A [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment