Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: C681EF224CB703E97DBE.mlw
path: /opt/CAPEv2/storage/binaries/d458d1b465702826d2c0ed781f0eddc3f16df178d77c7652a125be303c81365c
crc32: 805C2D50
md5: c681ef224cb703e97dbed44191971ebf
sha1: 077a47348481d706e0668b43fa862e4a91235c3e
sha256: d458d1b465702826d2c0ed781f0eddc3f16df178d77c7652a125be303c81365c
sha512: 6cd4a95ca36e791c348d7c9414b2c083128404972d4d15cda6a49c8ab5035f5730be5fcaa658868ba1a069fbadfe437f326f74a003683bd37be66a78e3b4ec38
ssdeep: 24576:5prdr8RsAD/sX+E1suGD6yJGt0GqxB10sCfmd:5v86qUrsuGD6kGiGqxBes4md
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AE750251B7D448F1E6730A301CB44A6586BEFE652CA1EE17E384344F4578AE2CE28F76
sha3_384: f7ba75b73e819db17e4d080371a0684f33cdb67ee147939b68c9c5f1c9058cc4d4ca666767a1a8a4cc1735a0f3398d42
ep_bytes: e8147f1700e97afeffff558bec56ff75
timestamp: 2020-12-09 13:28:09

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java(TM) Web Launcher
FileVersion: 11.281.2.09
Full Version: 11.281.2.09
InternalName: Java(TM) Web Launcher
LegalCopyright: Copyright © 2020
OriginalFilename: jp2launcher.exe
ProductName: Java(TM) Platform SE 8 U281
ProductVersion: 8.0.2810.9
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.c681ef224cb703e9
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesVirus.M0yv
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.48481d
SymantecW32.Xpiro.J!dam
ESET-NOD32Win32/Expiro.CU
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminesuspicious.low.ml.score
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
MAXmalware (ai score=89)
Antiy-AVLVirus/Win32.Expiro.x
GridinsoftRansom.Win32.Sabsik.sa
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
AhnLab-V3Malware/Win.Expiro.C4927842
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.83 (RDML:ZlnPwEjKRn6D5N78FH4fNA)
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment