Trojan

Trojan:Win32/WhisperGate.ES!MTB removal guide

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 81C55FC87BE6CE95C728.mlw
path: /opt/CAPEv2/storage/binaries/a3510aab89f08b1391040b1a36d6d040aaa913cd74d59db6d080d51fcfa07d5b
crc32: C3E73B3A
md5: 81c55fc87be6ce95c728a7b26a6deb87
sha1: 2bd3076665a5d0bd091e18ebff290b03e645be07
sha256: a3510aab89f08b1391040b1a36d6d040aaa913cd74d59db6d080d51fcfa07d5b
sha512: b05d816c54698e5960cedc4318e177853134be07106b76605239f2bc4f1538bf184af115a80e2c1040663534191f843bf6d470f9844e62b41be60df599245bf0
ssdeep: 768:ax6hupLs9EqD+J/FAhsSaH1iPP3lLuzZPKqeUequw2zB2GhRmkegcRl:M1W+NoshYPP3lLuBZeUeDzBPhRmkeD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15C231995BE658CEBE651633E84EBC37B577CF1808B230B53B734BA346B537922094246
sha3_384: af3c9955d3940d920ed85029f6e5ed61c2f2093f2b0fd39064502f22608b2d79194d64dba0699a6ba609480875f5ec26
ep_bytes: 83ec1cc7042401000000ff1558924000
timestamp: 2023-12-22 07:04:16

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanGen:Variant.Zusy.531572
FireEyeGeneric.mg.81c55fc87be6ce95
SkyhighBehavesLike.Win32.Injector.pm
McAfeeArtemis!81C55FC87BE6
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005afe181 )
AlibabaTrojan:Win32/Generic.aaa3f46f
K7GWTrojan ( 005afe181 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZO
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10017566-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.531572
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.13fb8a22
SophosMal/Generic-S
F-SecureTrojan.TR/Agent_AGen.mulyw
VIPREGen:Variant.Zusy.531572
EmsisoftGen:Variant.Zusy.531572 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bjgvg
VaristW32/Agent.HZX.gen!Eldorado
AviraTR/Agent_AGen.mulyw
Antiy-AVLTrojan/Win32.Wacatac
KingsoftWin32.Trojan.Agent.gen
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ArcabitTrojan.Zusy.D81C74
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataWin32.Trojan.PSE.11FY7F6
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R629844
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@aGDkiqb
MAXmalware (ai score=80)
MalwarebytesTrojan.Injector
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CLU23
RisingTrojan.Agent!8.B1E (TFE:5:kAxDHGFSlQH)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment