Trojan

Trojan:Win32/WhisperGate.RA!MTB removal tips

Malware Removal

The Trojan:Win32/WhisperGate.RA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.RA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.RA!MTB?


File Info:

name: 04BB8933DAD8095A1F1D.mlw
path: /opt/CAPEv2/storage/binaries/3e8bff88c4edea82509089b12b513d845dd0252c12bc467a7b9d647a8f9932ad
crc32: D57CE7B1
md5: 04bb8933dad8095a1f1d95af7e3ce9a4
sha1: e029ae61b3cf70234fa885eb72921b167587977e
sha256: 3e8bff88c4edea82509089b12b513d845dd0252c12bc467a7b9d647a8f9932ad
sha512: c96efa8d94445b76ba25aba0e193fc28c1f41650840978dbb7a0ca8222bd297a9a6353fd75cc352760fb2b87e2769b039610c9fbcfaa1e006423e49b96069940
ssdeep: 768:Nc0OdE1a745upbqhmE9NXPP3lLuzZPKqnAChxan5Ex2hbIsgkRm:Nc00sgEhZRPP3lLuBZnACna5EQhbIs+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14A23F855BE698CEBE652633E80EBC3775B7DF1818B230B53B724BB305B137922494246
sha3_384: 0eb4916aed56eafdbac2f8029dca441bc43ff9ae2a711d3579abada970ff81ac6f1d127d64506f3a833be3dbe1a4d81e
ep_bytes: 83ec1cc7042401000000ff1540924000
timestamp: 2023-12-22 09:12:30

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.RA!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.531620
FireEyeGeneric.mg.04bb8933dad8095a
MalwarebytesTrojan.Injector
VIPREGen:Variant.Zusy.531620
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
K7GWTrojan ( 005b00591 )
CrowdStrikewin/malicious_confidence_70% (D)
ArcabitTrojan.Zusy.D81CA4
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@aaCvtse
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10017566-0
KasperskyVHO:Trojan.Win32.Sdum.gen
BitDefenderGen:Variant.Zusy.531620
EmsisoftGen:Variant.Zusy.531620 (B)
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.bjgvg
VaristW32/Kryptik.LIO.gen!Eldorado
Kingsoftmalware.kb.a.700
MicrosoftTrojan:Win32/WhisperGate.RA!MTB
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
GDataWin32.Trojan.PSE.11FY7F6
GoogleDetected
MAXmalware (ai score=80)
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:dGZlOgXMnwnYeq6k3Q)
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.CZK!tr
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.RA!MTB?

Trojan:Win32/WhisperGate.RA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment