Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 3C97EE4548C25211FF77.mlw
path: /opt/CAPEv2/storage/binaries/49ffee548fd639597b3c3c30313ba5be8125e304ccb8a5a6222349e8317af3da
crc32: E1CF502D
md5: 3c97ee4548c25211ff778e1da6500163
sha1: 26397aab486b43c9564d33925a28afc8a6ed4725
sha256: 49ffee548fd639597b3c3c30313ba5be8125e304ccb8a5a6222349e8317af3da
sha512: 9e22e31c15d07dcf97b0abe59ab869ed546059cd653e0c9afdcffc6fd2bcd6cec2a5696bb22c39352de56eb2f4e651891a1bd73511d1eb97f1e2f36c1fabf184
ssdeep: 12288:9lGqd4OvXkLGHj0qTDz6Gt/sB1KcYmqgZvAMlUoUjG+YKtMfnkOeZb5JYiNAgAPh:PG5A0UTPdt/sBlDqgZQd6XKtiMJYiPU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF85022872C1C072D567257506B4C7B24E7B7C74AA66B48FABCB2B790F381D1D62831E
sha3_384: e330a18dd81e101f3b2eb93c5eac8e97524f0415b2b6d77c55f42eccd1e1a90da1205043a849928f71f080c6392404ce
ep_bytes: e8c6c51900e989feffff578bc683e00f
timestamp: 2012-04-04 02:16:07

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Malware.Expiro-9941636-0
FireEyeGeneric.mg.3c97ee4548c25211
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Sality.tt
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Expiro.304ab77f
K7GWVirus ( 005a8b911 )
K7AntiVirusVirus ( 005a8b911 )
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=83)
MalwarebytesVirus.M0yv
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:dUYHUm3c7brFvJVKpMJRFg)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment