Virus

What is “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 7CA42C2A85FF471F5888.mlw
path: /opt/CAPEv2/storage/binaries/4c6ea74337e1f17e98c7b459074e7ff1c150dd8cb22c05be212ae1f3beb7107a
crc32: 96AE5567
md5: 7ca42c2a85ff471f5888c75b5c6de7bc
sha1: 84fac7f728a26acd06b621840f6ff86ddb81d2ca
sha256: 4c6ea74337e1f17e98c7b459074e7ff1c150dd8cb22c05be212ae1f3beb7107a
sha512: 2dbbf9f80e5f50ac6083025f0cd428f69a5d023e23ab2203546027822f352be96f49d5d8a0fb33ca46f58cebe2cbe9ecb214ebb37509756ef792fe0d5f4895ed
ssdeep: 12288:7q2B+oRMCUMAdB8qr0zw9iXQ40AOzDr5YJjsF/5v3ZkHRik8:7q2B9R7atr0zAiX90z/F0jsFB3SQk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126751203349284F1D4E3493119A4DC6559BFBD701AA15EAB73C03B2F9F385C2993AEA7
sha3_384: cb8399fabe5640ab86c42fe5a8a4e764322c56923e47b1b48e3dc57d9348a4a9c2c56c088ef593c075cf77db2b043e84
ep_bytes: e8f4020000e97afeffff3b0d08204100
timestamp: 2021-04-13 02:35:50

Version Info:

CompanyName: Google LLC
FileDescription: Google Update
FileVersion: 1.3.36.81
InternalName: Google Update
LegalCopyright: Copyright 2018 Google LLC
OriginalFilename: goopdate.dll
ProductName: Google Update
ProductVersion: 1.3.36.81
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.7ca42c2a85ff471f
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
ALYacWin32.Expiro.Gen.7
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.d5819ed7
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitWin32.Expiro.Gen.7
BitDefenderThetaGen:NN.ZexaF.36608.Iv0@ayPyrndi
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Expiro-9937503-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
SUPERAntiSpywareTrojan.Agent/Gen-Fragtor
AvastWin32:Vitro [Inf]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.moderate.ml.score
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusTrojan.Patched
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
KingsoftWin32.Infected.AutoInfector.a
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
Acronissuspicious
MAXmalware (ai score=82)
VBA32Trojan.Sabsik.TE
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
RisingTrojan.Generic@AI.84 (RDML:T8oSo/L6Q4pjeoAFWlBABw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.728a26
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment