Virus

Virus:Win32/Expiro.EK!MTB removal guide

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: F9B85F6570D30955E4EE.mlw
path: /opt/CAPEv2/storage/binaries/244e5a58a909325062b76acc2705c4f1b389b391d97ebcbdc35078404ed79a82
crc32: 77D55D7B
md5: f9b85f6570d30955e4ee50b8118ac738
sha1: 9aa6120d04b192f63659f426a92e56674b34b4da
sha256: 244e5a58a909325062b76acc2705c4f1b389b391d97ebcbdc35078404ed79a82
sha512: ecf1778b1a27f6bd98ee9669a01eec390ae2bf2963613bd5dc13c1e2eb4ecdb409cd26801941cb78af4e1fb4eda50f4aea8cf7f74039d8ca3e4a51fc80d5f2f5
ssdeep: 12288:HUgsS7B9EgLYwTMzE0TbkZPnLdGUhB3Pidfu4C8h9:H3/Beg0wIY08PnLhBf81X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C855230A607FE86AC2545D7714B2F4B071647CECA88309DFEFB02466C57E887C0BA5B6
sha3_384: 0a97d829c4cfcbe486ac18a951a5c94bba87057e14ac9a1b02b1e442ead53de818c948b8c788f3b807936447bc8b3417
ep_bytes: e852681500e984feffffc3558bec6a00
timestamp: 2020-02-04 19:20:46

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.f9b85f6570d30955
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.db8ce4c4
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecW32.Xpiro.J!dam
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Virus.Expiro-10014101-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.VirMoiva.a
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusVirus.Win32.Tufik
MAXmalware (ai score=86)
GDataWin32.Expiro.Gen.7
JiangminTrojan.Generic.henen
GoogleDetected
AviraW32/Infector.Gen
VaristW32/Expiro.AU.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
CynetMalicious (score: 100)
AhnLab-V3Virus/Win.Expiro.X2164
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.96 (RDML:VJobqlsKW/R7f9R3noTPBQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment