Trojan

How to remove “Trojan:Win32/WhisperGate.RA!MTB”?

Malware Removal

The Trojan:Win32/WhisperGate.RA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.RA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.RA!MTB?


File Info:

name: 677F396EE642DB421B89.mlw
path: /opt/CAPEv2/storage/binaries/9ab643124aef5309be4e79a076dddf56e50c56fd4c87b651c917ddccb2a19f5b
crc32: 689DF080
md5: 677f396ee642db421b89367de3d78aef
sha1: 581a660a90dd5730fe808b9151983299662db06c
sha256: 9ab643124aef5309be4e79a076dddf56e50c56fd4c87b651c917ddccb2a19f5b
sha512: ebaa5b1cb1b7f1d4f34add283a6fa560230220e81d6f4b60ce48947f77d091adc51c910f885860c96cd4ce2e1fbcaa19c0a4380fa60b15e06b00be89a82438ed
ssdeep: 768:Uh+9EgckwiRngZE1dlPP3lLuzZPKqATfPMxIePmxob1zgkRm:4fklpgK3PP3lLuBZATfPmxmab1z+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16A230955BA648CEBE652633E80EBC77B5B7DF1808B235B53B734FB301B132922095246
sha3_384: 4dd1d43d4963973b7e796e0fafd28ff73769999d0e80b749bc6f6c66f742b7ad8e42dc21f5a599fc5241a74100a97f49
ep_bytes: 83ec1cc7042401000000ff1518924000
timestamp: 2023-12-22 13:55:39

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.RA!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Fragtor.480574
ClamAVWin.Trojan.Generic-10017566-0
MalwarebytesTrojan.Injector
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b00591 )
K7GWTrojan ( 005b00591 )
ArcabitTrojan.Fragtor.D7553E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Shellex.gen
BitDefenderGen:Variant.Fragtor.480574
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Agent.hel
SophosTroj/Inject-JGZ
VIPREGen:Variant.Fragtor.480574
EmsisoftGen:Variant.Fragtor.480574 (B)
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.bjgvg
GoogleDetected
Antiy-AVLTrojan/Win32.WhisperGate
Kingsoftmalware.kb.a.961
MicrosoftTrojan:Win32/WhisperGate.RA!MTB
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
GDataWin32.Trojan.PSE.1B885XN
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R630086
ALYacGen:Variant.Fragtor.480574
TACHYONTrojan/W32.Agent.46451.D
Cylanceunsafe
RisingTrojan.Agent!8.B1E (TFE:5:FrU15itl4AO)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CZK!tr
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@aKjCpXj
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/WhisperGate.RA!MTB?

Trojan:Win32/WhisperGate.RA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment