Trojan

Should I remove “Trojan:Win32/WhisperGate.ES!MTB”?

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: F6055A18E8BF86AE37F1.mlw
path: /opt/CAPEv2/storage/binaries/da4a8fe0d85e8d8ca90351917589a5cf3b6a30308ed4a0b42672bcaeb2efc1f8
crc32: 3FE136B8
md5: f6055a18e8bf86ae37f178a00d43a667
sha1: 3b3353e88059bc6f637bb3914b4aed5dba427bec
sha256: da4a8fe0d85e8d8ca90351917589a5cf3b6a30308ed4a0b42672bcaeb2efc1f8
sha512: 2bf3223ea2125d7794ff0f6634bf7aa5e02cc7614c216703525588e986902c9153592773cb4334742f5b18c98ab7a7be7d81bde50d88b8760ff74944d72ecc4f
ssdeep: 768:7JEZZ6GpFFD/ntav9nPP3lLuzZPKqXE6mCuIwxGgh/X8gcR5:e6+xnyVPP3lLuBZXE6uIwIgh/X8P
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13C231A95BE658CEBE651633E80EBC37B577DF5818B230B53B734BA305B137922094286
sha3_384: d0f7f14a9b4fe19e0622c5bbfc973260cbd315d1e98830d9b83b2e850790b4ef83a335c5fbce117759c84fa6d56fff52
ep_bytes: 83ec1cc7042401000000ff154c924000
timestamp: 2023-12-22 08:06:47

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f6055a18e8bf86ae
SkyhighBehavesLike.Win32.Injector.pm
McAfeeArtemis!F6055A18E8BF
MalwarebytesTrojan.Injector
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005afe181 )
AlibabaTrojan:Win32/WhisperGate.b77884b1
K7GWTrojan ( 005afe181 )
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@aetxjUi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZO
ClamAVWin.Trojan.Generic-10017566-0
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGeneric.Dacic.1206.C79AA7F1
MicroWorld-eScanGeneric.Dacic.1206.C79AA7F1
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Shellex.ka
EmsisoftGeneric.Dacic.1206.C79AA7F1 (B)
F-SecureTrojan.TR/Agent_AGen.vpkzx
VIPREGeneric.Dacic.1206.C79AA7F1
TrendMicroTROJ_GEN.R002C0DA224
SophosTroj/Inject-JGZ
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.11FY7F6
JiangminTrojan.Generic.bjgvg
GoogleDetected
AviraTR/Agent_AGen.vpkzx
Antiy-AVLTrojan/Win32.Convagent
Kingsoftmalware.kb.a.729
ArcabitGeneric.Dacic.1206.C79AA7F1
ViRobotTrojan.Win.Z.Zusy.48210.I
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R630086
ALYacGeneric.Dacic.1206.C79AA7F1
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DA224
RisingTrojan.Agent!8.B1E (TFE:5:dAiTvKKdYFG)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment