Trojan

How to remove “Trojan:Win32/WhisperGate.ES!MTB”?

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: A57882965F5156C975EB.mlw
path: /opt/CAPEv2/storage/binaries/1f2319cfda6b37b19ea6cfde91d77381c3db6c2a04b5653eaefc091485c89717
crc32: 77A0EF13
md5: a57882965f5156c975eb969eb613a5b7
sha1: ee6fef1d521d8b4391813144a5d26110c403d7e2
sha256: 1f2319cfda6b37b19ea6cfde91d77381c3db6c2a04b5653eaefc091485c89717
sha512: 9196402882e3fef7f0a5c8c5ac3155aea97ebfa1e0135cee6d7274ccd79be5c69378905478aeba57eaaef87607a674581aebec4ba92dd8498801a61c46500c5d
ssdeep: 768:FsxE2l7cWqRpKB4mEbBiPP3lLuzZPKqOa/s1USdx2h8AsgkRm:c7cfK4/YPP3lLuBZOakeSdQh8As+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E6230995BA658CEBE651633E80EBC37B5B7DF1818B230B53B734FA305B537922094246
sha3_384: edda9050b5987ec1b5a245af42932d8a684062c9dce34f45ef035870352d648b02bfaddd1e283add46c2a8de04bdf0fa
ep_bytes: 83ec1cc7042401000000ff154c924000
timestamp: 2023-12-22 08:57:39

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.531569
FireEyeGeneric.mg.a57882965f5156c9
SkyhighBehavesLike.Win32.Injector.pm
McAfeeArtemis!A57882965F51
Cylanceunsafe
SangforTrojan.Win32.Agent.V5kp
K7AntiVirusTrojan ( 005b00591 )
AlibabaTrojan:Win32/WhisperGate.3b00c12b
K7GWTrojan ( 005b00591 )
Cybereasonmalicious.d521d8
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@auGbH1k
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10017566-0
KasperskyUDS:Trojan.Win32.Agent
BitDefenderGen:Variant.Zusy.531569
AvastFileRepMalware [Misc]
VIPREGen:Variant.Zusy.531569
EmsisoftGen:Variant.Zusy.531569 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bjgvg
VaristW32/Kryptik.LIO.gen!Eldorado
Kingsoftmalware.kb.a.905
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ArcabitTrojan.Zusy.D81C71
ZoneAlarmUDS:Trojan.Win32.Agent
GDataWin32.Trojan.PSE.1S14ZGS
GoogleDetected
MAXmalware (ai score=89)
MalwarebytesTrojan.Injector
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment