Virus

What is “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 1158BDAAF0F3B89352C1.mlw
path: /opt/CAPEv2/storage/binaries/f1dca2202f801edfbbc38f95730877320db3546267e80ac1209a9fef440175cb
crc32: BC240197
md5: 1158bdaaf0f3b89352c181833e71301d
sha1: 179163e4b0fb9ed808c802bc329464b623b9b5d8
sha256: f1dca2202f801edfbbc38f95730877320db3546267e80ac1209a9fef440175cb
sha512: b577cf442cbb96cf15e36ebca05576f70ad6830d696fb4986a65fb7a50980f78930aab14c09a6c53f1c177219e59035f379fe826c1ce4a38d63229de1dfbb01a
ssdeep: 24576:vGQA0UTPdNaIhjGUQsAdP2H02xQdFYFbDRfXvvHA:uB0UTDaIhzQvL2x4FYdd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19185012436D0C032D563107152A5C7F38A7ABC75A566A49FBBCB2BB60F786D0D72930E
sha3_384: a0c8188c0edd1fa817f11917e7e668beee714ef74cb56b15aa034ed96ed6846db56c2062855e50adef9af9ebf260a143
ep_bytes: e8c6651a00e989feffff578bc683e00f
timestamp: 2012-04-04 02:16:07

Version Info:

0: [No Data]

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Sality.tt
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Moiva.4f604ae2
K7GWVirus ( 005a8b911 )
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Virus.Expiro-10015037-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusTrojan.SuspectCRC
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
KingsoftWin32.Infected.AutoInfector.a
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
VBA32Trojan.Sabsik.TE
MAXmalware (ai score=88)
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.100 (RDML:QxIQ1SUgPNIDvV515Oaeww)
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment