Trojan

How to remove “Trojan:Win32/WhisperGate.RA!MTB”?

Malware Removal

The Trojan:Win32/WhisperGate.RA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.RA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.RA!MTB?


File Info:

name: B7A96F5E15030B353C1B.mlw
path: /opt/CAPEv2/storage/binaries/0013166c6c5881f428d28cc4ca14c7d95266741239002711b93560917908f3f6
crc32: 9E1B7D6E
md5: b7a96f5e15030b353c1b1315f082a628
sha1: 46fdaa1f2685fc735475a7185816627af0a5e3bd
sha256: 0013166c6c5881f428d28cc4ca14c7d95266741239002711b93560917908f3f6
sha512: 3a4d20b49f4df23d0e8ed730d2002a689f76594217876db560454fad1ec5e7596ef7db0a67cd0c8505a1ef91938f482a86b49c715a7c7355e9d86b3e78f4d6a1
ssdeep: 768:/tfTRxEUhQnfwRfW4TpZEF1cPP3lLuzZPKqAa1Oa3ocFxobR8gkRm:/tfTNQeO4TpyuPP3lLuBZAa1BocFabRH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C4230955BE658CEBE552633E80EBC37B5B7DF1818B230B53BB34BB341B532922095246
sha3_384: c47c99f918555568fb7e2694a2c0fd103ce55256768f3c206ba779250f9ee80199cc8f22a2f23a9c877d6bbaef9867dc
ep_bytes: 83ec1cc7042401000000ff1514924000
timestamp: 2023-12-22 22:10:01

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.RA!MTB also known as:

MicroWorld-eScanGeneric.Dacic.1206.FD39EFC0
ClamAVWin.Trojan.Generic-10017566-0
MalwarebytesTrojan.Injector
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitGeneric.Dacic.1206.FD39EFC0
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@ayTLtAk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGeneric.Dacic.1206.FD39EFC0
RisingTrojan.Agent!8.B1E (TFE:5:H5UYNyBUaKJ)
EmsisoftGeneric.Dacic.1206.FD39EFC0 (B)
VIPREGeneric.Dacic.1206.FD39EFC0
SophosTroj/Inject-JGZ
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.bjgvg
GoogleDetected
Kingsoftmalware.kb.a.721
MicrosoftTrojan:Win32/WhisperGate.RA!MTB
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
GDataGeneric.Dacic.1206.FD39EFC0
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R630384
ALYacGeneric.Dacic.1206.FD39EFC0
Cylanceunsafe
TencentTrojan.Win32.Agent.hel
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
Cybereasonmalicious.f2685f
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.RA!MTB?

Trojan:Win32/WhisperGate.RA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment