Virus

Virus:Win32/Expiro.EK!MTB information

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: F65B70A82236628C02B0.mlw
path: /opt/CAPEv2/storage/binaries/dd9078ed2d7d02c08f8edd56713e3b6ee2597ada14893c9a4f3c121fe2f2ff9f
crc32: 072F529F
md5: f65b70a82236628c02b0cc332825c025
sha1: 981f79860fe8f1ec316910c0c6ddb6087cf589e2
sha256: dd9078ed2d7d02c08f8edd56713e3b6ee2597ada14893c9a4f3c121fe2f2ff9f
sha512: 961676645e475205d4149643d3cef47e70b19d3b64ceacf40384425615d52a59293ba0f17a013d56953c88a242d9336b64f016846edf3efca32909037f4d943c
ssdeep: 98304:5NDwSlUk9KPsUxfAdNmqVi+qkPZKOBuyaoY7cjGiEnW6at:51Uk9KmdNmqsOBuyaopjGhnW9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170567B317D06C039E2A101715DADBFF580CE9A398BB105CBBA945F6A6A213C72D31F76
sha3_384: 1d4fb4cd8e162cfb63cba05bebdb87c3b65922a6783fe3acaee4caaddde659b603dbcdb171258ec9e2c593610a147ea4
ep_bytes: e8d6070000e978feffff558bec6a00ff
timestamp: 2020-09-11 13:29:46

Version Info:

CompanyName: Adobe Systems Incorporated
EnglishName: English
FileDescription: Adobe Collaboration Synchronizer 20.12
FileVersion: 20.12.20048.400142
LanguageId: 0409
LegalCopyright: Copyright 1984-2020 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename: AdobeCollabSync.exe
ProductVersion: 20.12.20048.400142
Signature: Read
ProductName: Adobe Collaboration Synchronizer
Translation: 0x0409 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f65b70a82236628c
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Sality.th
MalwarebytesVirus.M0yv
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.fcdba9ad
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Malware.Expiro-9941636-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastFileRepMalware [Inf]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-A
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.moderate.ml.score
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusTrojan.Win32.Patched
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win64.Expiro.dc
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
Acronissuspicious
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=82)
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGFileRepMalware [Inf]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment