Trojan

How to remove “Trojan:Win32/WhisperGate.RA!MTB”?

Malware Removal

The Trojan:Win32/WhisperGate.RA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/WhisperGate.RA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/WhisperGate.RA!MTB?


File Info:

name: 6FC201F6D081EC61AD36.mlw
path: /opt/CAPEv2/storage/binaries/57c94328bf714cad500ba63395d62e62cf3dde1ce3d53a0c4a7ad7c83ec4777f
crc32: 150208AB
md5: 6fc201f6d081ec61ad36ebb5e1962e48
sha1: 4f54ebe35b68f877ced65a76f3a6ee9893de2da0
sha256: 57c94328bf714cad500ba63395d62e62cf3dde1ce3d53a0c4a7ad7c83ec4777f
sha512: cbcb07efda43fa028db1bb11e7771f238c58197b16ff583d04b6e1e656dae5fedb8efcfced9e23efd19c858a0c0c9222856747e3ae91f677e3667f240dc00093
ssdeep: 768:YSlE4vE4/i8gZ/uZEhRwPP3lLuzZPKqAOb081DL0kxo8kzgkRm:rEKgZu22PP3lLuBZAOw8130ka8kz+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E4230995BE648CEBE651633E80EBC77B5B7DF1818B231B53B734BB341B136922094246
sha3_384: 9fb5c625b101b59b73041176e59d149829e6e00fc876622320d824d18000101a0f4a044fd9ebb9c1ec96a937c20b1e95
ep_bytes: 83ec1cc7042401000000ff1520924000
timestamp: 2023-12-22 17:36:16

Version Info:

0: [No Data]

Trojan:Win32/WhisperGate.RA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Shellex.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.1206.833F4E0A
SkyhighBehavesLike.Win32.Injector.pm
McAfeeArtemis!6FC201F6D081
Cylanceunsafe
SangforTrojan.Win32.Save.a
BitDefenderGeneric.Dacic.1206.833F4E0A
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D81BB5
BitDefenderThetaGen:NN.ZexaF.36680.c0Y@amYonGg
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CZP
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Shellex.gen
TencentTrojan.Win32.Agent.hel
EmsisoftGeneric.Dacic.1206.833F4E0A (B)
VIPREGeneric.Dacic.1206.833F4E0A
SophosTroj/Inject-JGZ
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.bcmgf
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.a.972
MicrosoftTrojan:Win32/WhisperGate.RA!MTB
ZoneAlarmHEUR:Trojan.Win32.Shellex.gen
GDataWin32.Trojan.PSE.1LJBB7B
VaristW32/Kryptik.LIO.gen!Eldorado
AhnLab-V3Malware/Win.Generic.R629720
ALYacGen:Variant.Zusy.531381
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R002C0DAH24
RisingTrojan.Agent!8.B1E (TFE:5:rkVOqG5wOAQ)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.CZK!tr

How to remove Trojan:Win32/WhisperGate.RA!MTB?

Trojan:Win32/WhisperGate.RA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment