Virus

Virus:Win32/Expiro.EK!MTB information

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 03E22B5C5EF8606DD8C0.mlw
path: /opt/CAPEv2/storage/binaries/04da727b8815639f99cbfa6c12b300bd3b5ff2d176ae93e6c47f1c162cf2db59
crc32: E0220BB1
md5: 03e22b5c5ef8606dd8c0b8f69305eec1
sha1: e08c84b07e9eb5d332d3835ed93bc2be2ebf037a
sha256: 04da727b8815639f99cbfa6c12b300bd3b5ff2d176ae93e6c47f1c162cf2db59
sha512: 05f2facbd4b7c37ad6f6d319e8e750592c8e463a57fbc26e5a00bac7a80d1f684d1f3d7f200af45374e5bb0424ed96ede471b310bc97d0f0b8f5b715fe611adb
ssdeep: 12288:twis92rQ9KbFwOKpOz5N9vWst3QVkBNhw6Y5o+SudAfh39z2Go:to9EQkbvK8N3t3QVkLhoo+SVfhl2/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16745024137E914A4F8B34E398C7041358A2AFC616DA5CE1BA790364F5678EE0DE32F36
sha3_384: 18104faa51b58598d25214122fe1d8930a4aec5b8d9d275d3c7a36dc085c8b6600c7c6e13cd2425815da6da4082232f5
ep_bytes: e8ca050000e97afeffff680b74400064
timestamp: 2020-12-09 13:31:53

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java(TM) Platform SE binary
FileVersion: 11.281.2.09
Full Version: 11.281.2.09
InternalName: Java SSV Agent Process
LegalCopyright: Copyright © 2020
OriginalFilename: ssvagent.exe
ProductName: Java(TM) Platform SE 8 U281
ProductVersion: 8.0.2810.9
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.03e22b5c5ef8606d
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
Cylanceunsafe
VIPREWin32.Expiro.Gen.7
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.ccea91c3
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminesuspicious.low.ml.score
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
Acronissuspicious
VBA32BScope.TrojanDownloader.Zenlod
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=88)
MalwarebytesVirus.M0yv
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:V4f2WqfWYGv1MeSKp5izJw)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
Cybereasonmalicious.07e9eb
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment