Trojan

Trojan:Win32/WhisperGate.ES!MTB removal tips

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: E616F1E1FB88407F3152.mlw
path: /opt/CAPEv2/storage/binaries/f9fd86b2fa6b758551bde82e68e302b7a5f8a072cdd53d83ab9d3d3d9baf4931
crc32: D08CE54D
md5: e616f1e1fb88407f31524141f4030d4a
sha1: 554d4be8bdf408a3f458a936c8d046db9e611301
sha256: f9fd86b2fa6b758551bde82e68e302b7a5f8a072cdd53d83ab9d3d3d9baf4931
sha512: 61be9c43284b3cd99366bf3cd07a84c49fb395167c7e659b84393f4865db1c354109141367f7c0c21c37478cdb11e19e63c4e940b4082bc0da311c983beb856e
ssdeep: 768:eeotEGeD2BqVMeKtabRPPP3lLuzZPKqu8AAIxIcxGG8eXzgcRm:n2ARKeJPP3lLuBZu8bIxIcIG8eXzs
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C1230995BE648CEBE651633E80EBC77A577CF5818B230B53BB34FB301B536922494246
sha3_384: d0f0d2342af145ad04fa69bea0ec8cb375b9f5ba155b76fb82407ceb2396e47b7c223dcda9b67330bdd9bd82fd674e62
ep_bytes: 83ec1cc7042401000000ff1538924000
timestamp: 2023-12-22 21:19:49

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.Common.6264A07A
LionicTrojan.Win32.Dacic.4!c
MicroWorld-eScanGeneric.Dacic.1206.6137943D
FireEyeGeneric.mg.e616f1e1fb88407f
SkyhighBehavesLike.Win32.Generic.pm
McAfeeArtemis!E616F1E1FB88
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b11261 )
AlibabaTrojan:Win32/WhisperGate.82d0ff44
K7GWTrojan ( 005b11261 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
ClamAVWin.Trojan.Generic-10017566-0
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGeneric.Dacic.1206.6137943D
NANO-AntivirusTrojan.Win32.Shellex.khkkic
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Shellex.ka
SophosTroj/Inject-JGZ
F-SecureTrojan.TR/Agent_AGen.iguon
VIPREGeneric.Dacic.1206.6137943D
TrendMicroTROJ_GEN.R002C0DAL24
EmsisoftGeneric.Dacic.1206.6137943D (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.18RZSMS
JiangminTrojan.Generic.bjgvg
GoogleDetected
AviraTR/Agent_AGen.iguon
VaristW32/Kryptik.LIO.gen!Eldorado
Antiy-AVLTrojan/Win32.Convagent
ArcabitGeneric.Dacic.1206.6137943D
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R630086
BitDefenderThetaGen:NN.ZexaF.36744.c0Y@aGalWYh
ALYacGeneric.Dacic.1206.6137943D
MAXmalware (ai score=87)
VBA32Trojan.Shellex
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DAL24
RisingTrojan.Agent!8.B1E (TFE:5:oWIwunIXweH)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment