Trojan

Should I remove “Trojan:MSIL/FormBook.ADI!MTB”?

Malware Removal

The Trojan:MSIL/FormBook.ADI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/FormBook.ADI!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:MSIL/FormBook.ADI!MTB?


File Info:

name: 5D57CBFD68A82BBB6236.mlw
path: /opt/CAPEv2/storage/binaries/df757778956e59dda13ed21877d89a7b55902f285c5958d248300e2e9cfffb83
crc32: 1F07FE05
md5: 5d57cbfd68a82bbb62364a77919a6fb9
sha1: 69b00db4927791c0c19e038fa8d0d520ca475e6b
sha256: df757778956e59dda13ed21877d89a7b55902f285c5958d248300e2e9cfffb83
sha512: 1bb81433f5d07f191c9325461f646af20ebc0cec1de5e8ebd9b0cb18332e54ec90cb737dcaa78a230f00de59b312a41778e54d02cf967f2d5f528cef5015503b
ssdeep: 12288:kR+J2umzmcvSuYoZljMocNsfB6M3ePdH8KfNT2aoxzB:4n7zmxOoS6MqdH8cT2aoBB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4056BBA21D58107E8253175C897D1F32AFBAE602121D5CB6AD72F6FBC411BF911338A
sha3_384: c8f04ba010f3cd38efd3a4f7cad9d58b2a93cd64f212d85d3ef5135e6dbaf9e6e6b1ab2edccf194dfc1611bdbcf2ba12
ep_bytes: ff250020400000000000000000000000
timestamp: 2050-12-15 08:42:06

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Savas.Desktop
FileVersion: 1.0.0.0
InternalName: NsLg.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: NsLg.exe
ProductName: Savas.Desktop
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/FormBook.ADI!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Noon.l!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ransom.Loki.5691
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
SkyhighBehavesLike.Win32.Generic.ch
McAfeeRDN/Generic PWS.y
Cylanceunsafe
ZillyaTrojan.Noon.Win32.24683
K7AntiVirusTrojan ( 005995011 )
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 005995011 )
ArcabitTrojan.Ransom.Loki.D163B
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AGSP
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderGen:Variant.Ransom.Loki.5691
NANO-AntivirusTrojan.Win32.Noon.jtahzp
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-Spy.Noon.Kmnw
EmsisoftGen:Variant.Ransom.Loki.5691 (B)
F-SecureHeuristic.HEUR/AGEN.1311128
DrWebTrojan.Inject4.44905
VIPREGen:Variant.Ransom.Loki.5691
SophosTroj/Krypt-RI
IkarusTrojan.MSIL.Inject
JiangminTrojanSpy.MSIL.cvdf
VaristW32/MSIL_Kryptik.IDL.gen!Eldorado
AviraHEUR/AGEN.1311128
Antiy-AVLTrojan/MSIL.GenKryptik
Kingsoftmalware.kb.c.739
XcitiumMalware@#1ababvin4ibch
MicrosoftTrojan:MSIL/FormBook.ADI!MTB
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
GDataGen:Variant.Ransom.Loki.5691
GoogleDetected
AhnLab-V3Trojan/Win.PWSX-gen.C5275861
VBA32OScope.Trojan.MSIL.Bitrans.gen.P
MalwarebytesGeneric.Malware.AI.DDS
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:ovzayCI4KO2IglvhD6YZwQ)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.73691310.susgen
FortinetMSIL/Agent.ECJ!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/FormBook.ADI!MTB?

Trojan:MSIL/FormBook.ADI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment