Trojan

About “Trojan:Win32/WhisperGate.ES!MTB” infection

Malware Removal

The Trojan:Win32/WhisperGate.ES!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.ES!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.ES!MTB?


File Info:

name: 451C37D3924254E5FDFE.mlw
path: /opt/CAPEv2/storage/binaries/a3b3896d5d72c4051dc09536838fc3b5c8fbbbac579ed7df880877a52db5250a
crc32: 1B668CFB
md5: 451c37d3924254e5fdfe383001e03eea
sha1: 49ca58e044ef04c81e1884e488409863fb1e98b1
sha256: a3b3896d5d72c4051dc09536838fc3b5c8fbbbac579ed7df880877a52db5250a
sha512: cd2f8d8145bd2fe5ebc8b79bc0eb0e405c79ad3cbd6af407b743008a115de543bb7fd9db6cfe1a2feb1c0614718d895fd1808e0ec2e5b44a6040760bf3988d1b
ssdeep: 768:F7Z9EgE5KBp5PdAtag5MPP3lLuzZPKqnBwQYwBGFsxGG8aE8gLRm:F7o5sBA1CPP3lLuBZnBEwBGFsIG8aE8T
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T147230A55BE658CEBE652633E80EBC77B5B7DF1818A230B53B734FB301B132922495246
sha3_384: db8e6f9216f6ba7a66e3d54f1c1dcdc7cb4987101af6883d54a9584f4773ea808b2a519801b4b45388f7463313ce6bc4
ep_bytes: 83ec1cc7042401000000ff1528924000
timestamp: 2023-12-22 09:53:32

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.ES!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.531379
MalwarebytesTrojan.Injector
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
K7GWTrojan ( 005b00591 )
Cybereasonmalicious.044ef0
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10017566-0
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Zusy.531379
AvastWin32:MalwareX-gen [Trj]
EmsisoftGen:Variant.Zusy.531379 (B)
VIPREGen:Variant.Zusy.531379
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.PSE.119QQ95
JiangminTrojan.Generic.bjgvg
VaristW32/Kryptik.LIO.gen!Eldorado
ArcabitTrojan.Zusy.D81BB3
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/WhisperGate.ES!MTB
GoogleDetected
AhnLab-V3Trojan/Win.WhisperGate.R630450
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@a8SLFBl
MAXmalware (ai score=84)
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:5:nSJVdkk9jCF)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/WhisperGate.ES!MTB?

Trojan:Win32/WhisperGate.ES!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment