Virus

Virus:Win32/Expiro.EK!MTB removal guide

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: CB0624C007DDB8AE664D.mlw
path: /opt/CAPEv2/storage/binaries/fc2c3ed6c376b5a77bb62d205be6771211a717d20f31a92ae06d7fea738b9daf
crc32: 60A82CC3
md5: cb0624c007ddb8ae664d3088d20f48f8
sha1: 424b090226f3bba3388ed313a152ce09ff2671a7
sha256: fc2c3ed6c376b5a77bb62d205be6771211a717d20f31a92ae06d7fea738b9daf
sha512: 013676d315fbea521768a1eba66d63ba3e86f720c924e643172a215a2a82a3dd4fc9e850269a14eeb2522a1c9eebf90f2eca395c46fc082e970a55d0f6026e9e
ssdeep: 12288:tHIhm1f942TgHlNFC+tTrjxtLPWV4po440sUrioo0PPvO2HhB:tmm1142TgFNFznnLbJrl+2HhB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138552347B3C61510C4E9333888E578254A499D60AE4241CBA6F33B3E1A3D8E7A77D97F
sha3_384: 504367bb4061ca0532dae9c761a92483ec7d26e6b8ea2bf818bbcd52743a2918fef30f61c1c7a3aa29c9c5cff6879ae8
ep_bytes: e856020000e978feffff558becff7508
timestamp: 2023-09-12 02:54:55

Version Info:

Comments:
LegalCopyright: ©Firefox and Mozilla Developers; available under the MPL 2 license.
CompanyName: Mozilla Corporation
FileDescription: Firefox
FileVersion: 117.0.1
ProductVersion: 117.0.1
InternalName: Firefox
LegalTrademarks: Firefox is a Trademark of The Mozilla Foundation.
OriginalFilename: private_browsing.exe
ProductName: Firefox
BuildID: 20230912013654
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.cb0624c007ddb8ae
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Sality.tt
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Expiro.6216ca21
K7GWVirus ( 005a8b911 )
K7AntiVirusVirus ( 005a8b911 )
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.moderate.ml.score
SophosW32/Moiva-C
IkarusTrojan.Patched
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
MAXmalware (ai score=82)
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
MalwarebytesVirus.M0yv
PandaW32/Moyv.A
RisingTrojan.Generic@AI.90 (RDML:AQpFjRnCPopLONsq0wuLxQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment