Trojan

Should I remove “Trojan:Win32/WhisperGate.ES!MTB”?

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 550FA443FDCF7B11D531.mlw
path: /opt/CAPEv2/storage/binaries/2aad8bdb89e8e6726ddcb3635b1563d5b313fb2841f9336ffc442cf5e84ca7e5
crc32: DE554447
md5: 550fa443fdcf7b11d531f4f7e9a2f9b2
sha1: c94bda5a706af1bd1819bd389b5b6a6b6f4845cc
sha256: 2aad8bdb89e8e6726ddcb3635b1563d5b313fb2841f9336ffc442cf5e84ca7e5
sha512: 65ce590ebfff1c321b4cf20cf95572f7a902ccff0efe68e5cb769972ab72fa9072c3cd6796915a909fc464ce22690a86b7598a85a409a27d2ef7498c4446a520
ssdeep: 768:aB1yR0wVE9y/kpCgFkIsJtnmELJHPP3lLuzZPKq3Z0Kn+trBx2h823gkRm:w8R0u/khMJtnf9PP3lLuBZ3ZF+trBQhC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11C230855BE648CEBE651633E80EBC77B5B7CF5818B231B53B734FA302B136922094246
sha3_384: 4613023f1bd1ffdea499861f8281a5ece835febe6176948bc0eb94a3cded6915782d36bd8ef18dc8503f153efd6291a9
ep_bytes: 83ec1cc7042401000000ff1548924000
timestamp: 2023-12-22 08:23:57

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Sdum.4!c
MicroWorld-eScanGen:Variant.Zusy.531569
ClamAVWin.Trojan.Generic-10017566-0
FireEyeGeneric.mg.550fa443fdcf7b11
SkyhighBehavesLike.Win32.Injector.pm
ALYacGen:Variant.Zusy.531569
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/WhisperGate.0276e0a6
ArcabitTrojan.Zusy.D81C71
BitDefenderThetaGen:NN.ZexaF.36608.c0Y@aK@BSyk
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Sdum.gen
BitDefenderGen:Variant.Zusy.531569
AvastWin32:MalwareX-gen [Trj]
EmsisoftGen:Variant.Zusy.531569 (B)
VIPREGen:Variant.Zusy.531569
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bjgvg
GoogleDetected
Kingsoftmalware.kb.a.770
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
GDataWin32.Trojan.PSE.1S14ZGS
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R630085
McAfeeArtemis!550FA443FDCF
MAXmalware (ai score=88)
MalwarebytesTrojan.Injector
RisingTrojan.Agent!8.B1E (TFE:5:nseBDWGR98D)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment