Trojan

Trojan:Win32/WhisperGate.ES!MTB removal tips

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 617278B5C188FD7F9FFA.mlw
path: /opt/CAPEv2/storage/binaries/2be3a84e9a9a844d6b70fe1259740887630e5dcd8b8b587ff26f5a79753fa470
crc32: 74F50641
md5: 617278b5c188fd7f9ffa57f117c32171
sha1: c0cc12e37276386112a27138adc27a543ecfab51
sha256: 2be3a84e9a9a844d6b70fe1259740887630e5dcd8b8b587ff26f5a79753fa470
sha512: 56350bb13d87a6bc6696c38612ac9069e80f8085a862b5307a387d3bfb6515996a522e35af4911ad1709495f1049883625d24ae7afc61a1032dea6ce651aafb0
ssdeep: 768:18hE5E1R8fpBny2Q2xSaqJLPP3lLuzZPKqDAYklMk8WlgxGqhOaEPgLR5:1U16jN/xwxPP3lLuBZDA98WlgIqhOaEq
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C823F755BA658CEBEA51633E84EBC37B5B7DF1818B230B53B734BB301B133922494646
sha3_384: d4ed0e044227776e84cec7bd946147094377a49c8eaad5828bd72b0720960bf3bd92f8a9ab586020f1eb32f2bec31908
ep_bytes: 83ec1cc7042401000000ff155c924000
timestamp: 2023-12-22 09:31:50

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
MicroWorld-eScanGen:Variant.Zusy.531666
ClamAVWin.Trojan.Generic-10017566-0
SkyhighBehavesLike.Win32.Generic.pm
McAfeeArtemis!617278B5C188
MalwarebytesTrojan.Injector
VIPREGen:Variant.Zusy.531666
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
AlibabaTrojan:Win32/WhisperGate.7785b2b7
K7GWTrojan ( 005b00591 )
Cybereasonmalicious.372763
ArcabitTrojan.Zusy.D81CD2
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Agent
BitDefenderGen:Variant.Zusy.531666
AvastFileRepMalware [Misc]
SophosMal/Generic-S
DrWebBACKDOOR.Trojan
EmsisoftGen:Variant.Zusy.531666 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bjgvg
GoogleDetected
KingsoftWin32.Trojan.Convagent.gen
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
ZoneAlarmUDS:Trojan.Win32.Agent
GDataWin32.Trojan.PSE.11FY7F6
VaristW32/Kryptik.LIO.gen!Eldorado
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@a8oKGDl
MAXmalware (ai score=88)
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:5:f9cKNm0weQU)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment