Virus

Virus:Win32/Expiro.EK!MTB removal instruction

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: F016436C43D4E427119B.mlw
path: /opt/CAPEv2/storage/binaries/aadf790b00fb3a7851e869d5814c7af19c569a3770d134b6949eca23ed371e2e
crc32: C5600942
md5: f016436c43d4e427119bd771ff9ac693
sha1: b3d11ff6ec00536f57fb629db6a31ef28a7be18a
sha256: aadf790b00fb3a7851e869d5814c7af19c569a3770d134b6949eca23ed371e2e
sha512: 7679139dd543b09a6e53fbbee36c90c602f00ef71b1c6445f7d73a0f51209c1573621dcdf83b397241ccb9608a6043c8876d6a1ce3484c53ae278ad8e501f7bd
ssdeep: 12288:xoPRPWX4GNscdB921r4JWJACmwrhSHVswKb3foE9A9T5piKw+9axA+:ARPWxNs298r3OCDIjG3gE9ow+8xA+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136552304FC4CE6B9D53B46B5A986F070A1376D48E8B622B6F2606F13BE7538A8711173
sha3_384: 72401a16d7e8ffc653ba3d8a27e8744791f59c694cdfa056446ec852cf22a06614fbb97d298be5299e2949e17afd1c17
ep_bytes: e82cfcffffe933fdffffff2590110030
timestamp: 2006-10-27 04:30:58

Version Info:

CompanyName: Microsoft Corporation
FileDescription: XML Editor
FileVersion: 12.0.4518.1014
InternalName: msoxmled.exe
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
LegalTrademarks3: InfoPath® is a registered trademark of Microsoft Corporation.
OriginalFilename: msoxmled.exe
ProductName: Microsoft Office InfoPath
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Virut.tt
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecW32.Xpiro.J!dam
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Virus.Expiro-9975087-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
IkarusVirus.Win32.Ausiv
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.860
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.EK!MTB
VaristW32/Expiro.AU.gen!Eldorado
VBA32Trojan.Sabsik.TE
MAXmalware (ai score=83)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:PYsA28F78hwF8e1uftJLMA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
Cybereasonmalicious.6ec005
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment