Spy Trojan

How to remove “Trojan.Spy.Formbook.A”?

Malware Removal

The Trojan.Spy.Formbook.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Formbook.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Spy.Formbook.A?


File Info:

crc32: 18427666
md5: a4380ad25ad1372541c7e246eefcba35
name: upload_file
sha1: 56de45c6330590743cbae1f7ef145e7b8ff201de
sha256: d2f58b08f8abfe5055f3c1f0b8d991dfe1deb62807a5336b134ce2fb36d87284
sha512: de66d125364bf33ff75bb2d8789fd6cd6865934dc1cb7d120071dfa7327cfca2ccbc92dd21f6d1f80e6f2878e60a049a89acbc774a8a4754803df775a4237632
ssdeep: 3072:65iqvgcxI+2J/TaNkZknaCkivKoCABz8/yu6Cm2TZe+V:Hq3I+POZkayKoCAG/ll
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Spy.Formbook.A also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.Fbng.8
MicroWorld-eScanTrojan.Spy.Formbook.A
FireEyeGeneric.mg.a4380ad25ad13725
CAT-QuickHealTrojan.GenericPMF.S2589827
Qihoo-360HEUR/QVM20.1.6183.Malware.Gen
McAfeeGenericRXCD-ZZ!A4380AD25AD1
CylanceUnsafe
VIPREWin32.Malware!Drop
SangforMalware
K7AntiVirusTrojan ( 00536d121 )
BitDefenderTrojan.Spy.Formbook.A
K7GWTrojan ( 00536d121 )
Cybereasonmalicious.25ad13
TrendMicroTrojan.Win32.FormBook.SM
BitDefenderThetaAI:Packer.ACE09BBD1E
F-ProtW32/Formbook.A.gen!Eldorado
SymantecTrojan.Formbook
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Formbook-7399661-0
GDataTrojan.Spy.Formbook.A
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanSpy:Win32/Swotter.77277b29
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Agent.171008.X
AegisLabTrojan.Win32.Generic.4!c
RisingStealer.Fareit!8.170 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.Spy.Formbook.A (B)
ComodoTrojWare.Win32.Swotter.A@7i7pqi
F-SecureTrojan.TR/Crypt.ZPACK.Gen
ZillyaTrojan.Formbook.Win32.28
Invinceaheuristic
Trapminemalicious.high.ml.score
SophosTroj/Formbook-A
CyrenW32/Formbook.A.gen!Eldorado
JiangminTrojan.Generic.cdayr
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Spy.Formbook.A
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/FormBook!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Formbook.C2411820
Acronissuspicious
ALYacTrojan.Agent.FormBook
MAXmalware (ai score=100)
Ad-AwareTrojan.Spy.Formbook.A
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Formbook.AA
TrendMicro-HouseCallTrojan.Win32.FormBook.SM
TencentWin32.Trojan.Crypt.Lkdk
YandexTrojan.Agent!toGtE6BSBvM
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/GenKryptik.AYEB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.73376928.susgen

How to remove Trojan.Spy.Formbook.A?

Trojan.Spy.Formbook.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment