Virus

How to remove “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 434122D48A7A6CABDA71.mlw
path: /opt/CAPEv2/storage/binaries/a0366e485b59fb2282d97a196c4fca8e0bca78196e82fb2061af9518f5b37d04
crc32: 4D851E2A
md5: 434122d48a7a6cabda7195af1c9a0cba
sha1: f1fbf2e559be2c0674f325278e119714e3df791c
sha256: a0366e485b59fb2282d97a196c4fca8e0bca78196e82fb2061af9518f5b37d04
sha512: f4408cbfd15c82fec39988e36b20107588c5a12eb70e53009d9f8e817d230d460451df728b9424a683bf7f802e7337b8f558c3e8336bef92cd8ca30e51b79d1d
ssdeep: 12288:YtOw6BavGt/sB1KcYmqgZvAMlUoUjG+YKtMfnkOeZb5JYiNAgAPh:m6Bft/sBlDqgZQd6XKtiMJYiPU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B875F11376C28063D5633A31386FEB3F4629BD2F5B20B873679C7F4A9D741819929632
sha3_384: 74c19fcc4718548996f7d44b00d44506d97d4887ec3b019fd87e9873b6ab421f300d733d37b1a3695e913bd4523908ab
ep_bytes: e8e43a0000e97ffeffff558bec832568
timestamp: 2018-03-15 13:15:15

Version Info:

Comments: http://www.autoitscript.com/autoit3/
CompanyName: AutoIt Team
FileDescription: Au3Info
FileVersion: 3, 3, 14, 5
InternalName: Au3Info.exe
LegalCopyright: ©1999-2018 Jonathan Bennett & AutoIt Team
OriginalFilename: Au3Info.exe
ProductName: Au3Info
ProductVersion: 3, 3, 14, 5
Translation: 0x0809 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Malware.Expiro-9941636-0
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesVirus.M0yv
VIPREWin32.Expiro.Gen.7
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWVirus ( 005a8b911 )
K7AntiVirusVirus ( 005a8b911 )
ArcabitWin32.Expiro.Gen.7
BitDefenderThetaGen:NN.ZexaCO.36680.Kv0@aKz5xBii
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
SophosW32/Moiva-A
F-SecureMalware.W32/Infector.Gen
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraW32/Infector.Gen
MAXmalware (ai score=87)
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.971
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.81 (RDML:zPAomspDM6KZOprNi6nxHQ)
IkarusTrojan.Agent
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
Cybereasonmalicious.559be2
DeepInstinctMALICIOUS

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment