Trojan

Trojan:Win32/WhisperGate.ES!MTB removal tips

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 1838C39859F5263DB834.mlw
path: /opt/CAPEv2/storage/binaries/4d808987b5215d93bd6c97938c7d50802d6be75dddcfad5c4c7e6dd1038fa69e
crc32: 43873E15
md5: 1838c39859f5263db8341252f9712422
sha1: 2de63e28f5d8831e6df696ee8af04ca69a67b7b2
sha256: 4d808987b5215d93bd6c97938c7d50802d6be75dddcfad5c4c7e6dd1038fa69e
sha512: fba417f1babc3c7e4282069518feea70082abe5acb06598bb787d936246e755456c379cfcda26368019320e9f0aea02ed6c2de031601359ef64d2f603ce83f7b
ssdeep: 768:LGb1EKGZSJYKA3amEPtGPP3lLuzZPKq+9bC2OExQhhhPgkR5:KWZeMaLQPP3lLuBZ+9bPOE+hhhPR
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T128231955BA698CEBE691633E84EBC37B577DF1818B230B53B734FA301B537922094246
sha3_384: f6bb400a5fe9b06f21f5e8ca55a5e9fb869894f456367e53f5c46dcd77dae9f07d83ed9c21ccacddeaa871341597ae95
ep_bytes: 83ec1cc7042401000000ff1558924000
timestamp: 2023-12-22 15:33:15

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Shellex.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.531620
SkyhighBehavesLike.Win32.Injector.pm
ALYacGen:Variant.Zusy.531620
Cylanceunsafe
VIPREGen:Variant.Zusy.531620
SangforTrojan.Win32.Agent.V0y2
K7AntiVirusTrojan ( 005b00591 )
AlibabaTrojan:Win32/WhisperGate.c97fb8ce
K7GWTrojan ( 005b00591 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@a0dvNHd
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10017566-0
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGen:Variant.Zusy.531620
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Agent.hel
SophosTroj/Inject-JGZ
TrendMicroTROJ_GEN.R002C0DAE24
EmsisoftGen:Variant.Zusy.531620 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.11FY7F6
JiangminTrojan.Generic.bjgvg
VaristW32/Kryptik.LIO.gen!Eldorado
Kingsoftmalware.kb.a.892
ArcabitTrojan.Zusy.D81CA4
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R630323
McAfeeArtemis!1838C39859F5
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
RisingTrojan.Agent!8.B1E (TFE:5:IRvoJryShwP)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment