Virus

Virus:Win32/Expiro.EK!MTB removal tips

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 3A73CF9036784225DF0C.mlw
path: /opt/CAPEv2/storage/binaries/7814b6d022b01bed11181661c9bf5aaab0a016fc80972ab9a6bf7ccf7b0159f3
crc32: ACEA16D0
md5: 3a73cf9036784225df0c5d9439e3dbd7
sha1: 3580d563cf89be50374f6da654c424cc41fba49c
sha256: 7814b6d022b01bed11181661c9bf5aaab0a016fc80972ab9a6bf7ccf7b0159f3
sha512: 2a5c7d449abecb36899c407f0df139da569dc94028032f139a712deaab487fa9f7baa0ee4ac66ab87f3a4233d895e07a4684b77ccb6172a2908027f096a2d91f
ssdeep: 24576:5z6eF8NDFKYmKOF0zr31JwAlcR3QC0OXxc0H:5z6ugDUYmvFur31yAipQCtXxc0H
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14975027176C4E073DA22127188B8C3A05229FE719F659D57B3AC370D6F710D2EA39A93
sha3_384: 664913c263c22a836a0165723e0e9559d209a5114c308ddbd1203e1d821d09c162a8307e46d5c2ddcbab8439aab93ccd
ep_bytes: e8ec1f2600e97bfeffffff35cc004300
timestamp: 2018-03-15 13:15:46

Version Info:

Comments: Program that checks the syntax of AutoIt v3 scripts
CompanyName: Tylo (modified by Jos)
FileDescription: Au3Check
FileVersion: 3.3.14.5
InternalName: Au3Check.exe
LegalCopyright: ©1999-2018 Jonathan Bennett & AutoIt Team
OriginalFilename: Au3Check.exe
ProductName: AutoIt3 Syntax checker
ProductVersion: 3.3.14.5
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.3a73cf9036784225
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesVirus.M0yv
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.a953351f
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
ClamAVWin.Trojan.Expiro-9962115-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.high.ml.score
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
AhnLab-V3Malware/Win.Generic.R559308
BitDefenderThetaGen:NN.ZexaCO.36744.Nr0@a4y9NZgi
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=81)
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.92 (RDML:DNp3GPlxlf3G/CuqxyDEjg)
IkarusVirus.Win32.Etap
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
Cybereasonmalicious.3cf89b
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment