Trojan

Trojan:Win32/WhisperGate.ES!MTB removal tips

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 68320D39ED6AF32971C4.mlw
path: /opt/CAPEv2/storage/binaries/2b3cce8bfa998f14edae6dbfcbcb70030afbddd265b98ade3752337083ca6efa
crc32: B0D286EE
md5: 68320d39ed6af32971c4abae1d5db9a4
sha1: 4963e90bb205b29d10162907819aeff6d0801e45
sha256: 2b3cce8bfa998f14edae6dbfcbcb70030afbddd265b98ade3752337083ca6efa
sha512: c2ffd37e760d1cecc5bedc70d17a21af9cf1cf74a4afca75a3ab108a4e322abd4305f2e6209d5afa3cfa319993fa4c38ab85eab5371dbf8b9edb8c545441b5e6
ssdeep: 768:WbuRRE8uN7Rupf2tmEYNIPP3lLuzZPKqUkeBQGta8x2hbfsgdRm:WSaN0ot0ePP3lLuBZUkQQGta8QhbfsT
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FD230855BA658CEBE651633E84EBC37B5B7DF1818B230B53BB34BB301B133922494646
sha3_384: 846eaa3167524eb8b752449089aa07c094744ba84f96a253038bd1f9b4709c43e21a43f59d0d2e14225a10e9724e6118
ep_bytes: 83ec1cc7042401000000ff153c924000
timestamp: 2023-12-22 09:24:13

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Sdum.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.68320d39ed6af329
SkyhighBehavesLike.Win32.Injector.pm
McAfeeArtemis!68320D39ED6A
MalwarebytesTrojan.Injector
VIPREGen:Variant.Zusy.531603
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
AlibabaTrojan:Win32/WhisperGate.4cfa10da
K7GWTrojan ( 005b00591 )
CrowdStrikewin/malicious_confidence_70% (D)
ArcabitTrojan.Zusy.D81C93
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZP
ClamAVWin.Trojan.Generic-10017566-0
KasperskyUDS:Trojan.Win32.Agent
BitDefenderGen:Variant.Zusy.531603
MicroWorld-eScanGen:Variant.Zusy.531603
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Zusy.531603 (B)
DrWebBACKDOOR.Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bjgvg
GoogleDetected
Kingsoftmalware.kb.a.820
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ZoneAlarmUDS:Trojan.Win32.Agent
GDataWin32.Trojan.PSE.1S14ZGS
VaristW32/Kryptik.LIO.gen!Eldorado
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@a0JQPHl
MAXmalware (ai score=89)
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:5:eoYcfIW0sgG)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.bb205b
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment