Virus

Virus:Win32/Expiro.EK!MTB removal tips

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 0327DA52C5C394A2EE93.mlw
path: /opt/CAPEv2/storage/binaries/dd003187ffdd485db0786b7a8e38148cdc47bb3dd252376a4a608bd45e2bc2b2
crc32: 2CA5B942
md5: 0327da52c5c394a2ee93b612cccc6873
sha1: 506ec7671a9b2be7cedc1528a2925b5c33018f50
sha256: dd003187ffdd485db0786b7a8e38148cdc47bb3dd252376a4a608bd45e2bc2b2
sha512: 54d03aab9590d6179df787594e51dfb131865654ce1c77fd1e872bc23bc6f23bf4813f464cdb089b1ad20e508b9df17ff217e145ba826cb35690ad4c416344d9
ssdeep: 98304:q5ObAu2pmits24nYhQCWQdaQQo/mJPv4KYZPKBhYI5RuN4OL2wIjcsJWNg3joW:FAnRu24nR5QcTvYdmPuWOL2TcQWezp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18856330977B01AE1DD7B47F94E03AAA2B6978FF40E6311029C953B4DE1B78C86F93605
sha3_384: 8b446bf0e12851e0b038d57a4a40dae464fae7c84b8654ed8785914ac49a8c1c0d41c1a310fea3bfe0254c3383e0a08d
ep_bytes: 558bec83ec64568d4d9ce80ca385018d
timestamp: 2023-11-09 07:48:10

Version Info:

CompanyName: AnyDesk Software GmbH
FileDescription: AnyDesk
FileVersion: 8.0.6
ProductName: AnyDesk
ProductVersion: 8.0
LegalCopyright: (C) 2022 AnyDesk Software GmbH
Translation: 0x0409 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
MalwarebytesVirus.M0yv
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastFileRepMalware [Inf]
TencentVirus.Win32.VirMoiva.a
SophosW32/Moiva-C
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusVirus.Win64.Expiro
VaristW32/Expiro.AU.gen!Eldorado
AviraTR/Patched.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4488600
TACHYONVirus/W32.Movia
VBA32BScope.TrojanDownloader.Zenlod
PandaW32/Moyv.A
RisingTrojan.Generic@AI.80 (RDML:7v+ELBZnJaiBzMHqaH6B3Q)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGFileRepMalware [Inf]

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment