Virus

Should I remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 8C9D0088BF82E5B195C2.mlw
path: /opt/CAPEv2/storage/binaries/18bcb7b4b2466c0f6757235d795514d87d0a234bb3a488aa1d265f93a1194fee
crc32: D0C9F329
md5: 8c9d0088bf82e5b195c2a5bc2f760365
sha1: fe8b8b8fed0ce99ebba39f93e66b62e78014fb02
sha256: 18bcb7b4b2466c0f6757235d795514d87d0a234bb3a488aa1d265f93a1194fee
sha512: 82a2c6367a7277271996fa4c29c9cba17a51a84d284b8e0c81b24074724796f7b7ff973e853697f220cd876de36dd76f905e1dc13f04060a835c6956c2e2f912
ssdeep: 12288:0FZ90+Xq1gYgR+8DAoczI2ZfnwlQTePINayz+ByIne7xmmZjIUTSl+0/1:c/MdIuwe3zfIe7xmvH/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183D4122BB3C5D0BAE29202B09944B2F221FCDE795C618B1FEF605F1E7F709169864613
sha3_384: 229374aaa7cfb6dfd2943ef49d94a0f5be33c290b44ae068bb0e5230c35bcfb1136e119affa66807ad8d57118b1e5974
ep_bytes: e89ef6ffffe936fdffffff25e8120030
timestamp: 2006-10-27 02:56:57

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft® Office Document Scanning DCOM Component
FileVersion: 12.0.4518.1014
InternalName: MSPOCRDC.DLL
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
LegalTrademarks3: Office Document Scanning (R) is a registered trademark of Microsoft Corporation.
OriginalFilename: MSPOCRDC.DLL
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

CyrenCloudW32/Expiro.AU.gen!Eldorado
BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.8c9d0088bf82e5b1
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Virut.jc
ALYacWin32.Expiro.Gen.7
Cylanceunsafe
VIPREWin32.Expiro.Gen.7
SangforVirus.Win32.Expiro.Vcbr
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.035ead2e
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ElasticWindows.Virus.Expiro
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Virus.Expiro-9940198-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
Ad-AwareWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.high.ml.score
SophosW32/Moiva-A
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2164
Acronissuspicious
MAXmalware (ai score=88)
VBA32Trojan.Sabsik.TE
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
IkarusExpiro.Win32
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
Cybereasonmalicious.fed0ce
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment