Trojan

Trojan:Win32/WhisperGate.RA!MTB removal

Malware Removal

The Trojan:Win32/WhisperGate.RA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.RA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.RA!MTB?


File Info:

name: 5BA00CEB77126CEFF207.mlw
path: /opt/CAPEv2/storage/binaries/751518abca6aa16fdeda410868d185ca1b33ae0e6c59d6a11d3a8cad26eb500d
crc32: 32286C83
md5: 5ba00ceb77126ceff207b89cb97b69c1
sha1: eb932abc594b8d6766f78426c730755e17954c28
sha256: 751518abca6aa16fdeda410868d185ca1b33ae0e6c59d6a11d3a8cad26eb500d
sha512: 6365d88c78aebd1e40bf1ecef7ec715204bb629f44374c59d6a23682aa9cd01e4f8e2574dfa5fdce4e50bd8fe24a71dc0a05e21796e5c59dc033ff621e9c8d71
ssdeep: 768:xgxEmXpJbDioJzBhBQSa3lCPP3lLuzZPKqONN3MlNxG808vXXgcRm:OpZiSl/QV0PP3lLuBZONSlNI808vXXs
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EF23F895BE658CEBE651633E84EBC37B577DF1808B231B53B730BA341B433962494246
sha3_384: bf852f468da8d2cd7e35c50b15ee2aed44bd16a3576faaaab8ecd27d788b796955baf26324096f18254221f11206cee4
ep_bytes: 83ec1cc7042401000000ff155c924000
timestamp: 2023-12-21 09:56:40

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.RA!MTB also known as:

BkavW32.Common.448DED2B
LionicTrojan.Win32.Dacic.4!c
MicroWorld-eScanGeneric.Dacic.1206.73C8BD84
ClamAVWin.Trojan.Generic-10017566-0
FireEyeGeneric.mg.5ba00ceb77126cef
SkyhighBehavesLike.Win32.Generic.pm
ALYacGeneric.Dacic.1206.73C8BD84
Cylanceunsafe
SangforTrojan.Win32.Whispergate.V15i
K7AntiVirusTrojan ( 005b11261 )
AlibabaTrojan:Win32/WhisperGate.b372cffe
K7GWTrojan ( 005b11261 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGeneric.Dacic.1206.73C8BD84
NANO-AntivirusTrojan.Win32.Shellex.khsejo
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Shellex.ka
SophosTroj/Inject-JGZ
F-SecureTrojan.TR/Agent_AGen.sbfua
VIPREGeneric.Dacic.1206.73C8BD84
TrendMicroTROJ_GEN.R002C0DAL24
EmsisoftGeneric.Dacic.1206.73C8BD84 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11FY7F6
JiangminTrojan.Generic.bjgvg
GoogleDetected
AviraTR/Agent_AGen.sbfua
Antiy-AVLTrojan/Win32.Convagent
KingsoftWin32.Trojan.Shellex.gen
ArcabitGeneric.Dacic.1206.73C8BD84
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
MicrosoftTrojan:Win32/WhisperGate.RA!MTB
VaristW32/Agent.PSMG-5087
AhnLab-V3Trojan/Win.Generic.R630085
McAfeeArtemis!5BA00CEB7712
MAXmalware (ai score=84)
VBA32Trojan.Sdum
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DAL24
RisingTrojan.Agent!8.B1E (TFE:5:dYTLhqgRts)
YandexTrojan.Shellex!SyaksBeWU+E
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
BitDefenderThetaGen:NN.ZexaF.36744.c0Y@aCswe4p
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/WhisperGate.RA!MTB?

Trojan:Win32/WhisperGate.RA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment