Virus

Should I remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Arabic (Algeria)
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: C8F81E78AE65C15DE84B.mlw
path: /opt/CAPEv2/storage/binaries/e2a048c8f2e71762c1f956ffa8b131eb0b3a4fda3153e36ad7f788897781e146
crc32: 6B92760A
md5: c8f81e78ae65c15de84b8312482e0f0c
sha1: cf4b1d1b3419dcac11f32958e786c311a2b64030
sha256: e2a048c8f2e71762c1f956ffa8b131eb0b3a4fda3153e36ad7f788897781e146
sha512: c58d76645929133ca0c97fdaca7df92f5d971c48f88775781e3e2740ed4a0fa50b101af070fb2bf84559a7c0f7eb2aafd23c2ddad4ea89c4e179f8a30386e18e
ssdeep: 24576:/4iBD8NDFKYmKOF0zr31JwAlcR3QC0OXxc0H:/dDgDUYmvFur31yAipQCtXxc0H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14775F11276F85169F0B31B3098B993915A7ABC72DE25DB3E1694172E0E30C91DE20F7B
sha3_384: a7a6ed90c23f20155d62132ee05ac46038e3cc6801ee10de696e072479770cc0b94b082b7b44faa1b25a2ffee16e5575
ep_bytes: e8b9bb1800e97afeffffc3558bec6a00
timestamp: 2021-07-27 00:25:54

Version Info:

CompanyName: Google LLC
FileDescription: Google Installer
FileVersion: 1.3.36.101
InternalName: Google Update
LegalCopyright: Ауторска права 2007–2010. Google LLC
OriginalFilename: GoogleUpdate.exe
ProductName: Google ажурирање
ProductVersion: 1.3.36.101
Translation: 0x081a 0x04e2

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.c8f81e78ae65c15d
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
Cylanceunsafe
VIPREWin32.Expiro.Gen.7
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.087b9e7f
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36744.Kv0@aObnx6nP
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Trojan.Expiro-9962115-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Vitro [Inf]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.moderate.ml.score
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusTrojan.Patched
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
VaristW32/Expiro.AU.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=81)
MalwarebytesVirus.M0yv
PandaW32/Moyv.A
RisingTrojan.Generic@AI.90 (RDML:ep7J/Jb1Xg2MeLMUm0NKIg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FileInfector.C!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.b3419d
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment