Virus

About “Virus:Win32/Expiro.EK!MTB” infection

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Authenticode signature is invalid

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 9877B91D1C1D72344494.mlw
path: /opt/CAPEv2/storage/binaries/dad3b52792c12593310bb3a131713bdeb954f766375301a5b0568a8986e449d4
crc32: 8AF46254
md5: 9877b91d1c1d72344494af59a6b6a5bd
sha1: 6544f16d741619fdf6c2684f5160ca457c3d0009
sha256: dad3b52792c12593310bb3a131713bdeb954f766375301a5b0568a8986e449d4
sha512: 243c05cd0c54f5d54cd30ce93c587cf7332981443cb565f5b619556e0ae50e84e88f406cf607cb5aba866e3fb21f9f19e0cec69210480da26f0bc6c5c908aeed
ssdeep: 12288:ePUMAdB8qr0zw9iXQ40AOzDr5YJjsF/5v3ZkHRik8S:eatr0zAiX90z/F0jsFB3SQkf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B955230B351F42F3CCC35B715694885B16BB6A70B6E39647E2C13F0FAA381C25926AD7
sha3_384: d497d17b0ee3df75ef541d187b0ab2c95dbe127338058f8418ed8d91a673950f640b69dc30545073a406b61a03ae65c9
ep_bytes: e816fcffffe935fdffff558bec81ec28
timestamp: 2006-10-27 06:53:53

Version Info:

CompanyName: Microsoft Corporation
FileDescription: GrooveMonitor Utility
FileVersion: 0004, 0002, 0000, 0000
InternalName: GrooveMonitor
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
OriginalFilename: GrooveMonitor.exe
ProductName: GrooveMonitor Utility
ProductVersion: 0004, 0002, 0000, 0000
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Trojan.Expiro-9937503-0
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Trojan.tt
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.ec2b06b4
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.d74161
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Vitro [Inf]
RisingTrojan.Generic@AI.81 (RDML:YL015kwV4FZckMr4Ft4G5w)
TACHYONVirus/W32.Movia
SophosW32/Moiva-A
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
FireEyeGeneric.mg.9877b91d1c1d7234
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
AhnLab-V3Virus/Win.Expiro.X2164
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=80)
Cylanceunsafe
PandaW32/Moyv.A
TencentVirus.Win32.VirMoiva.a
IkarusTrojan-Dropper.Win32.Decay
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment