Virus

Should I remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 6705D3396F86C30A30BF.mlw
path: /opt/CAPEv2/storage/binaries/c82691fc05cce7ed2d11032deae49ff9a43efe219d25fd8f43466cf1d52610ac
crc32: 448A0D87
md5: 6705d3396f86c30a30bf530b1cc79e17
sha1: f20c5cec832ba2567713f8e012ac9362712ba86a
sha256: c82691fc05cce7ed2d11032deae49ff9a43efe219d25fd8f43466cf1d52610ac
sha512: 6d4afde0b8535930b9afe22f68f2c73e3872ab69954aad10f649b3f87c1d8706b4a798d623d9b56a1959861b1660c990ced07a174b8bfd78f7100ff3d8ec7345
ssdeep: 24576:2GBebZjKbhoCRSkr2dw0tbBFWWCKPlpp1IOn:rebohHl50VB2KPDnIOn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E85F16137E9C8B3F263423588F9867AD6B67CC29D31815B73F06B0EC9366518A32753
sha3_384: 0158f3bed0868e6107fc51c5d4d1e71cbc2782b3044609b300ed95fdc2a880278b0ccd46b632518b10f14406f28234c8
ep_bytes: e8a44d0000e916feffff8b542404568b
timestamp: 2006-10-27 06:54:56

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Groove Migrator Utility
FileVersion: 0004, 0002, 0000, 0000
InternalName: GrooveMigrator
LegalCopyright: Copyright © 2006 Microsoft Corporation. All rights reserved.
OriginalFilename: GrooveMigrator.exe
ProductName: Groove Migrator Utility
ProductVersion: 0004, 0002, 0000, 0000
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.6705d3396f86c30a
SkyhighBehavesLike.Win32.Expiro.tt
ALYacWin32.Expiro.Gen.7
Cylanceunsafe
SangforVirus.Win32.Expiro.V7mr
K7AntiVirusVirus ( 00594aea1 )
AlibabaVirus:Win32/Expiro.f539ad0f
K7GWVirus ( 00594aea1 )
Cybereasonmalicious.96f86c
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Dropper.Vindor-9886075-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Vitro [Inf]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraW32/Infector.Gen
VaristW32/Expiro.AU.gen!Eldorado
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
CynetMalicious (score: 100)
McAfeeArtemis!6705D3396F86
MAXmalware (ai score=80)
VBA32Trojan.Sabsik.TE
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
RisingTrojan.Generic@AI.86 (RDML:fbmq3ve6n4wxeVXqqxU1Yg)
IkarusTrojan.Kazy
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudVirus:Win/Expiro.A

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment