Virus

Virus:Win32/Expiro.EK!MTB removal instruction

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: 754E180C049213AB108B.mlw
path: /opt/CAPEv2/storage/binaries/13648ff3ac8be477cd7a8e6c8e0c441b1b0d324eb6aad116a23e368d05f0d7d9
crc32: 1FA00B36
md5: 754e180c049213ab108b4e817168ca2a
sha1: d049bab7228f262f2eca76094b5d24f1dbe70e0c
sha256: 13648ff3ac8be477cd7a8e6c8e0c441b1b0d324eb6aad116a23e368d05f0d7d9
sha512: 7e6331c2fd9c741423dbd7cb1b81567ad6ebefca49a5cb66e9c07492fa7d17b89eda3ebbaa1ac37b5102c6ed19cb0571f12c7d4b722116104b11d8736392a069
ssdeep: 49152:2l20i8Ewu1R1v0njTDQRy1w0N/1dXl6zot:p0R4p0nfDQ0NdX0Q
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T106A5CE00F68321F6DF9B0231629FFB3AAB340605A7285DE7D3D06D61B5136E1693AB1D
sha3_384: 5daa562780a04991c394fe7cf763339a60ae6b2f882e6a4ea4b7625b3cb7186fb4af483b38913b16c2e2c09402d16eaa
ep_bytes: e8ed080000e974feffff558bec5de949
timestamp: 2021-04-15 08:18:15

Version Info:

CompanyName:
FileDescription:
FileVersion: 12.0.0 (LLVM 12.0.0)
InternalName: clang-format
OriginalFilename:
ProductName: clang
ProductVersion: 12.0.0 (LLVM 12.0.0)
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Dropper.vc
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Expiro.ee81bd50
K7GWVirus ( 005a8b911 )
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Evo-gen [Trj]
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-C
IkarusVirus.Win32.Expiro
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EK!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
TencentVirus.Win32.VirMoiva.a
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment