Virus

About “Virus:Win32/Expiro.EK!MTB” infection

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 8780522348713DFFBB00.mlw
path: /opt/CAPEv2/storage/binaries/ee4682747852d472e25fc6d1b19a034b568b075d50b54f2eb1f8e6998b763c35
crc32: EE28D4B2
md5: 8780522348713dffbb003ce55f7afe48
sha1: d24118e67e9518650cc2caa82619ac05294cdcc1
sha256: ee4682747852d472e25fc6d1b19a034b568b075d50b54f2eb1f8e6998b763c35
sha512: e4d038af41002bc55f3ecf7ab40493a637203b6b8b399ec98acbcb505b269059bcc6da2590985048c6a221d11a9f515aff65ecf96a19c2255d98a93e615bae8d
ssdeep: 12288:jp3JLmULaOx47oLxiBdg5xtyZcNbUavOJ/qcdpLncsbqGI:xJLPWO8oLMBdg5DEuUaE/9rLnbI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14BD423C7BBD6CBC6C0A21CF6F803E71125518C989E87980363F6B16FAD3DD24A864D64
sha3_384: c1200de40f382eb6798beb635e751207d252b9be3bba410fb757b45b9848daf8404e31e6e5eacd826fb4f91d3892d350
ep_bytes: e8e74c0900e940fdffff8bff558bec8b
timestamp: 2013-05-15 20:43:41

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.8780522348713dff
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Sality.hc
MalwarebytesVirus.M0yv
SangforVirus.Win32.Expiro.V0jv
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.341f595b
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.67e951
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2164
MAXmalware (ai score=86)
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.99 (RDML:zDyX8M9vfa4hEfLxQp/DBg)
IkarusTrojan.Patched
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment