Virus

Virus:Win32/Expiro.EK!MTB malicious file

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 9C8E53F2CCAD13D60231.mlw
path: /opt/CAPEv2/storage/binaries/6a7418d27341946abbd10e8127b0c0dcb0fb7b17f9b8dfac8fb55db7f613a05e
crc32: 5E5FEAEA
md5: 9c8e53f2ccad13d60231ac275473d851
sha1: d34e2e3e517840c70d94f1d07011f16b2c985baa
sha256: 6a7418d27341946abbd10e8127b0c0dcb0fb7b17f9b8dfac8fb55db7f613a05e
sha512: 92a896be9a603305e58ee2028998a67f3d5cf6864f25917a41be0e7985b8df2d9c389e6a6fc59062a68433bb8b08fb3da99f630264cd448f4d12a5866a47bb6a
ssdeep: 24576:+3z3taqRLJoJCjkliTwQ9Ctw7cmVr+EucFc:uaqxvwYTV9CtsFTFc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B255123FA2C284F6D92760B151A53FBAE927FD04C306E2DB87A8F5A954332C9D135253
sha3_384: 80db882486ac120aa6b8e4fb1ed95e739927ec80b621d7bae9a9dab0393e029e29c9bf89d0f73be54b338eca38bdb7cb
ep_bytes: 558bec6aff686884410068881c410064
timestamp: 2005-08-17 07:19:49

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
AVGFileRepMalware [Inf]
ElasticWindows.Virus.Expiro
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.9c8e53f2ccad13d6
CAT-QuickHealW32.Expiro.R3
SkyhighArtemis!Trojan
McAfeeArtemis!9C8E53F2CCAD
Cylanceunsafe
VIPREWin32.Expiro.Gen.7
SangforVirus.Win32.Expiro.Vyu7
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.01d4f4d2
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecW32.Xpiro.J!dam
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Expiro.CY
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastFileRepMalware [Inf]
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.923
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2164
VBA32BScope.Trojan.Inject
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:VrbXBRFtTuAgcP1HGYk/ag)
YandexTrojan.GenAsa!QfhMLEUNsKc
IkarusVirus.Win32.Virut
FortinetW32/Expiro.NDP!tr
Cybereasonmalicious.2ccad1
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment