Virus

Virus:Win32/Expiro.EK!MTB removal

Malware Removal

The Virus:Win32/Expiro.EK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.EK!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Virus:Win32/Expiro.EK!MTB?


File Info:

name: AD916EA942E0956A3AAD.mlw
path: /opt/CAPEv2/storage/binaries/01f236a9aed9b0942d8da50ee76bc7453e8428dc40ffc1bebbd8b05ff6d96a98
crc32: 988762FC
md5: ad916ea942e0956a3aad1456db1b275a
sha1: 3b5ebe37fc2583a525d60654227985c1c481f221
sha256: 01f236a9aed9b0942d8da50ee76bc7453e8428dc40ffc1bebbd8b05ff6d96a98
sha512: 6685504158c48dd2e2cdf9e0ee86ed8dc9da5f4468cdffa8f4f535752ee9ea0918b04172637aae497f3553ce363921e63d08deed1f51009eef27c24de37a00f5
ssdeep: 24576:ZbSnUw1xJEgt/sBlDqgZQd6XKtiMJYiPU:ZHXK/snji6attJM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB650201394224F1D80674723D1DAB39A932432AAF1745CBFB94BDC5AFB8DE1253639E
sha3_384: 2a8fdcfa256d0d845bc881db8493891c5c32c72fae181c258ec922db248be1760b86deec5f89da5a8640a5fbc146a6ec
ep_bytes: e87d000000e968feffff558bec51833d
timestamp: 2023-09-12 03:13:38

Version Info:

Comments:
LegalCopyright: License: MPL 2
CompanyName: Mozilla Corporation
FileDescription: Plugin Container for Firefox
FileVersion: 117.0.1
ProductVersion: 117.0.1
InternalName: Firefox
LegalTrademarks: Mozilla
OriginalFilename: plugin-container.exe
ProductName: Firefox
BuildID: 20230912013654
Translation: 0x0000 0x04b0

Virus:Win32/Expiro.EK!MTB also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Malware.Expiro-9941636-0
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Trojan.tm
Cylanceunsafe
VIPREWin32.Expiro.Gen.7
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 00594aea1 )
AlibabaVirus:Win32/Moiva.5f31b460
K7GWVirus ( 00594aea1 )
Cybereasonmalicious.7fc258
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Xpirat-B [Inf]
TencentVirus.Win32.VirMoiva.a
SophosW32/Moiva-A
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusTrojan.Win32.Patched
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
KingsoftWin32.Infected.AutoInfector.a
MicrosoftVirus:Win32/Expiro.EK!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
VBA32Trojan.Sabsik.TE
MalwarebytesMalware.AI.3491273654
PandaW32/Moyv.A
RisingTrojan.Generic@AI.87 (RDML:w+QzDP33X+hYn+nlybN9RA)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Xpirat-B [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Virus:Win32/Expiro.EK!MTB?

Virus:Win32/Expiro.EK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment