Virus

Virus:Win32/Expiro.EK!MTB information

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: C50D6043E4CB98A6B799.mlw
path: /opt/CAPEv2/storage/binaries/c48d5f37abba231594675a8f46f3bf2e349e7b84a8108d191b8e2ea151b3e264
crc32: 670DF80C
md5: c50d6043e4cb98a6b7991de87b1faef0
sha1: 5edca6175e09b9811ef8810fc5956a4075e052cd
sha256: c48d5f37abba231594675a8f46f3bf2e349e7b84a8108d191b8e2ea151b3e264
sha512: 67f67d47af4de40b04f891dee3e3dc0d8ffb69fe24207f8e093360043ab97bab7c299cec42c9dd609347635a801cec35c25d0340fee2345a15665c5b1229ce99
ssdeep: 12288:ne/ISzcQeTD2Mz7In9w5/lmFN0YNG4JEhBRK2tNLbrMKU5vBXdc:ne/mdTqMz69KlPY9EhBRxtNLM5vBXdc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C55022036C1C073C063117681A4C3F56D6ABCB55A65AA4BFBCB6FB84F352E1DA1938D
sha3_384: 8b3a61dd3b162fb94fb929445231af186e52fbf17b17ca4ef52f23a0ae2549a841a02791b4d3be3238581d38b28ed5d1
ep_bytes: e87dc40000e978feffff558bec83ec08
timestamp: 2009-01-29 13:02:55

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.c50d6043e4cb98a6
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tm
MalwarebytesVirus.M0yv
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.a197b55e
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36744.trW@aqtYM3hi
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.3X1J1B
GoogleDetected
AviraW32/Infector.Gen
MAXmalware (ai score=83)
Antiy-AVLVirus/Win32.Expiro.x
KingsoftWin32.Infected.AutoInfector.a
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.90 (RDML:qUZRL3Tu62S9LMyHTJrTIw)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment