Malware

Mal/Generic-S + Troj/Formbo-ABC removal tips

Malware Removal

The Mal/Generic-S + Troj/Formbo-ABC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Formbo-ABC virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Mal/Generic-S + Troj/Formbo-ABC?


File Info:

crc32: 4F8EC639
md5: b325d6106069f2d19f617ccf008d58cc
name: B325D6106069F2D19F617CCF008D58CC.mlw
sha1: b8f8ee1f74e903431518f83158616a1f8a058fc0
sha256: 70def7c02d96cb8aab6702e0d6f32c72d7fafbd2b883e09007de9fe204cd3f59
sha512: a574f76a5d4b115cf26a3c51b67bf741cab85736a61839c948c548c4dcdcba55634ac9d6a0f0baa19169fd185242931a40edfcfb56cc0b6a5ac8f6db602d00a9
ssdeep: 12288:vxrxk7Vod2sgvthh9hEx9+hHWeYafxV40+KqKimUHuc/zbxKMzz2Kr/EIRqCvGr:vxrwo0HjqMNYuqoNsf/8MGyj
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Ben Nordick 2017-2021
Assembly Version: 1.2.0.0
InternalName: IEnumerable.exe
FileVersion: 1.2.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Sprint Core
ProductVersion: 1.2.0.0
FileDescription: Sprint Core
OriginalFilename: IEnumerable.exe

Mal/Generic-S + Troj/Formbo-ABC also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.665
ALYacTrojan.Agent.FormBook
CylanceUnsafe
SangforTrojan.Win32.AgentTesla.ml
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 0057af3d1 )
CyrenW32/MSIL_Kryptik.DLO.gen!Eldorado
ESET-NOD32a variant of MSIL/Kryptik.AAMD
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.GenericKD.36715762
MicroWorld-eScanTrojan.GenericKD.36715762
Ad-AwareTrojan.GenericKD.36715762
SophosMal/Generic-S + Troj/Formbo-ABC
ComodoTrojWare.Win32.Agent.pwyph@0
BitDefenderThetaGen:NN.ZemsilF.34678.bn0@aezoDA
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.b325d6106069f2d1
EmsisoftTrojan.GenericKD.36715762 (B)
WebrootW32.Trojan.Gen
AviraTR/AD.Swotter.fvuaf
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/Tnega.RV!MTB
AegisLabTrojan.MSIL.Noon.l!c
GDataTrojan.GenericKD.36715762
AhnLab-V3Trojan/Win.AgentTesla.C4420409
McAfeePWS-FCXL!B325D6106069
MAXmalware (ai score=85)
PandaTrj/GdSda.A
RisingSpyware.Noon!8.E7C9 (CLOUD)
FortinetMalicious_Behavior.SB
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASS0A

How to remove Mal/Generic-S + Troj/Formbo-ABC?

Mal/Generic-S + Troj/Formbo-ABC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment