Spy

Spyware.FormBook.NSIS removal guide

Malware Removal

The Spyware.FormBook.NSIS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.FormBook.NSIS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
tomational.com

How to determine Spyware.FormBook.NSIS?


File Info:

crc32: 648F1FC2
md5: fa84048ce7063232e43dd33669346eca
name: FA84048CE7063232E43DD33669346ECA.mlw
sha1: c6b2f196a0a95d1a1f9b82e2cd5e7e494ed360e5
sha256: 6aedee5beaafb15c042f69acc7a81d409161d071b0e1a8f55bf21cf4f19e73ef
sha512: 27d0fa7001c803431b61b8a8b5238a201d94bd09ca10b8958a035a618921883defc06bbc78eec7835ac2b5ca36d16f526074c212e676fd818fa938aecf73a8e0
ssdeep: 3072:jLk395hYXJLMTQ/lMvKtmZgbdma0qSLqC5zmm9kFPfIZ+0Jfkn+B:jQqqU/lMvKtmZ0maZY5F9oP8+0Q+B
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Spyware.FormBook.NSIS also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 100)
AlibabaTrojanSpy:Win32/Injector.64673143
Cybereasonmalicious.6a0a95
CyrenW32/Ninjector.E.gen!Camelot
ESET-NOD32NSIS/Injector.ALE
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
SUPERAntiSpywareTrojan.Agent/Gen-BHO
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Woreflint.A!cl
McAfeeArtemis!FA84048CE706
MalwarebytesSpyware.FormBook.NSIS
IkarusWin32.Outbreak
FortinetW32/Kryptik.AKX!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Spyware.FormBook.NSIS?

Spyware.FormBook.NSIS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment