Virus

Virus:Win32/Expiro.EK!MTB information

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: C964DE3F40E983989778.mlw
path: /opt/CAPEv2/storage/binaries/8b03d3f0f02d742ea0fd6cc85f038167c796cc9dcf0cab3a0d6f2edb66d1f348
crc32: C4B792BC
md5: c964de3f40e9839897787b560ee92454
sha1: b985f24e81a14ccfc285e90f31c8000f8dab988a
sha256: 8b03d3f0f02d742ea0fd6cc85f038167c796cc9dcf0cab3a0d6f2edb66d1f348
sha512: 5948f5bb4f593db4a3d63df6c89facf2e584562c5e640182906e28716ea7cd7a6d509b8d71d2c15bc71a043238d1b297cbf7b3d1d248d1e4ecd22df4b14e4f7d
ssdeep: 12288:heMTmkJR4Do07Y86gw5CtCjX+NLuFhNpBeZT3X:ZSkQ/7Gb8NLEbeZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18A45235770A845B3E1720FB218B8481019EB7DC65F31323ABBD8962F6BBEC54DC6B521
sha3_384: 5171d46cb273d4d2a244efde24d106a7033e71090b11352d2c92b62b4dc2e654f23a9a8acb48cc6604506d0ad39adc77
ep_bytes: e88c9a1200e99efdffff558bec81ec28
timestamp: 2006-10-27 06:43:33

Version Info:

CompanyName: Microsoft Corporation
FileDescription: GrooveClean Utility
FileVersion: 12.0.4518.1014
InternalName: GrooveClean
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
OriginalFilename: GrooveClean.exe
ProductName: GrooveClean Utility
ProductVersion: 4.2.0.2623
SpecialBuild:
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Trojan.Filerepmalware-10008115-0
FireEyeGeneric.mg.c964de3f40e98398
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Expiro.tt
McAfeeArtemis!C964DE3F40E9
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.d165aec9
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Vitro [Inf]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
IkarusTrojan.Patched
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.978
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
VBA32BScope.TrojanDownloader.Zenlod
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.e81a14
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment