Virus

What is “Virus:Win32/Expiro.EK!MTB”?

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 22508E7EEA1EAF45FB38.mlw
path: /opt/CAPEv2/storage/binaries/bcf94a85e2556fbb5b93baa78de32eaac4c45e2de703bc4bb7735b191af28900
crc32: 6A2E5581
md5: 22508e7eea1eaf45fb3891293a35bf25
sha1: 6e2fec65d22b67fdc3229a7de96519f7412db1eb
sha256: bcf94a85e2556fbb5b93baa78de32eaac4c45e2de703bc4bb7735b191af28900
sha512: 08a562fe4152d831fed35523c2e7946312f9c168ac2531f1a9105725f4a95484e4d78d7f2c7179fab047f9ace86e34517fe1841d42fb2ca4f61015bcf355facb
ssdeep: 12288:xM+YSF2rQ9KbFwOKpOz5N9vWst3QVkBNhw6Y5o+SudAfh39z2Go:xnDFEQkbvK8N3t3QVkLhoo+SVfhl2/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED4512193BD534B1E9E21638C1393138813ABC35EDE6C25BFB603A4AA5F4A91F725713
sha3_384: c926e96eaa10498d0a8bf1560a3560654fc8fd64bf671f41454905badbc945ae53ef62c16fe9fb49d70a8c12bd30d200
ep_bytes: e8a6f6ffffe933fdffff538a5c2408f6
timestamp: 2006-10-27 03:04:43

Version Info:

CompanyName: Microsoft Corporation
FileDescription: 2007 Microsoft Office component
FileVersion: 12.0.4518.1014
InternalName: HEV
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: MsoHtmEd.Exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
CynetMalicious (score: 100)
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.RealProtect.tt
MalwarebytesMalware.AI.4062275134
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.37774daa
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.5d22b6
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastWin32:FileInfector-C [Heur]
RisingTrojan.Generic@AI.100 (RDML:UWz3bHrXX+7XaDEVsizMdA)
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
IkarusVirus.Win32.Expiro
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
VBA32BScope.Trojan.Convagent
TACHYONVirus/W32.Movia
Cylanceunsafe
PandaW32/Moyv.A
TencentVirus.Win32.VirMoiva.a
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment