Malware

What is “Troj/Formbo-PB”?

Malware Removal

The Troj/Formbo-PB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Formbo-PB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Troj/Formbo-PB?


File Info:

crc32: B1E287D1
md5: d0e5bb36613f00ef4cedbbeca5e87b8a
name: D0E5BB36613F00EF4CEDBBECA5E87B8A.mlw
sha1: 50cfa9d5f4f391ff1c26c05feaea9a407903adfc
sha256: 091f6c53a4f73bdac192e08bda0459f5e8af953a3c2b5cdee175677301a8cef5
sha512: a652290958667872204d7848e2e2aa3cadf6e3c5143a4930acea247e13166422f8f5ae553096503847eca8c760b8f663f064a7bfc5e066e7f6321f426110a051
ssdeep: 12288:2uth3BLN/N0fxy1JwuNIyFgaDAF8Fm+wSScMtlfZBST:26h3B0fg1JZ0FamCJ4t
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Troj/Formbo-PB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35277438
FireEyeGeneric.mg.d0e5bb36613f00ef
Qihoo-360Generic/HEUR/QVM03.0.5A9F.Malware.Gen
McAfeeGenericRXMO-KY!D0E5BB36613F
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056ea7c1 )
BitDefenderTrojan.GenericKD.35277438
K7GWTrojan ( 0056ea7c1 )
Cybereasonmalicious.5f4f39
TrendMicroTrojan.MSIL.WACATAC.THKAHBO
BitDefenderThetaGen:NN.ZemsilF.34634.ImW@amn0Fyf
CyrenW32/MSIL_Kryptik.CDP.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/csharp.ali2000008
ViRobotTrojan.Win32.Z.Kryptik.571904.AD
Ad-AwareTrojan.GenericKD.35277438
SophosTroj/Formbo-PB
ComodoMalware@#1jzp72zdlggux
F-SecureTrojan.TR/Kryptik.qhjam
DrWebTrojan.PackedNET.461
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Troj/Formbo-PB
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
EmsisoftTrojan.GenericKD.35277438 (B)
IkarusTrojan.Inject
WebrootW32.Malware.Gen
AviraTR/Kryptik.qhjam
MicrosoftTrojan:Win32/AgentTesla!ml
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D21A4A7E
AegisLabTrojan.Win32.Generic.4!c
AhnLab-V3Trojan/Win32.RansomCrypt.R356005
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.35277438
CynetMalicious (score: 100)
ESET-NOD32a variant of MSIL/Kryptik.XTU
ALYacTrojan.GenericKD.35277438
MAXmalware (ai score=100)
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.MSIL.WACATAC.THKAHBO
TencentWin32.Trojan.Inject.Auto
YandexTrojan.Igent.bUPCSM.3
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.XTU!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Troj/Formbo-PB?

Troj/Formbo-PB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment