Virus

Virus:Win32/Expiro.EK!MTB removal

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 39853187BBB0DD4CEA8B.mlw
path: /opt/CAPEv2/storage/binaries/3a42ca8457e174a1dc13a0dc94e5da822335dd15d4b79eeb1f2747a087f9e088
crc32: 4FFC6DFB
md5: 39853187bbb0dd4cea8bd96c1dc0e1f2
sha1: ea32a171542f04d401b0ecc1e0ad66c3c601f523
sha256: 3a42ca8457e174a1dc13a0dc94e5da822335dd15d4b79eeb1f2747a087f9e088
sha512: dae4e116c37c2afea57e2f2090b1f8d96d1c85a4d67686322ee64252a93fe77dad61081e83f5fb773646f51c76848359ad634333af4ba8a9f581c6444030e200
ssdeep: 24576:Tw3yd2OluON4fA9uCRt/sBlDqgZQd6XKtiMJYiPU:Tw3yd2OluON4fA9ui/snji6attJM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A75D0F26B92DFF5F41602B4840246635A03BD7DE50F40D7A442FE166E7E68328DAAC7
sha3_384: 5783277c474bc55f8c53374152aa1b6e3d9303cb1c581b86863b2af24af0bc4921d6f6a6aba1a67f163635be2749742f
ep_bytes: e8ddfeffff6a5c6828644000e8270400
timestamp: 2006-10-27 22:12:40

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Groove
FileVersion: 12.0.4518.1014
InternalName: Groove
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
OriginalFilename: Groove.exe
ProductName: Microsoft Office Groove
ProductVersion: 4.2.0.2623
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.39853187bbb0dd4c
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Sality.tt
Cylanceunsafe
SangforVirus.Win32.Expiro.V5qx
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.3e35b334
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.1542f0
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDW
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Expiro-9941636-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Vitro [Inf]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
IkarusTrojan-Dropper.Win32.Qhost
VaristW32/Expiro.AU.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=80)
PandaW32/Moyv.A
RisingTrojan.Generic@AI.90 (RDML:5utH6q3jTa37k6cIeyNlag)
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment