Trojan

Trojan:MSIL/FormBook.EWN!MTB information

Malware Removal

The Trojan:MSIL/FormBook.EWN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/FormBook.EWN!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:MSIL/FormBook.EWN!MTB?


File Info:

name: 6C24C79151A8B293925F.mlw
path: /opt/CAPEv2/storage/binaries/e1877fc42d45eead303cdbf14e148c2e75d2b988778539b432e12b6974e60612
crc32: B3D70136
md5: 6c24c79151a8b293925fb8d8460ea26a
sha1: 043678385c7880c52be22ac74890070f0d69dfeb
sha256: e1877fc42d45eead303cdbf14e148c2e75d2b988778539b432e12b6974e60612
sha512: 502daa719b7d1a3a91cdca888d1d11f62b9a3d8f55abf1f2457095633d02db55308bef211482b6912751b9b5bdc865ba822a6e263c803d6a55d4c2b6a280c3bb
ssdeep: 12288:Vr2GrP/SdVbqWjsZ5uEd2iN+cS6rgIaapKPFPFcPpKLL2J:OdVb/W5X1Px80pKPFqRFJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DCD4E12177F45B05C5BA47B486A8513107B3BC22A563F31E9EC135E92DB3B418E1BB2B
sha3_384: a202ebf3c23211fdea36822e5267ccc8ba5869cdf0ed0b45d3e728c6ef39ca896557e2dc9fefc48f4a182ce97d4bb90c
ep_bytes: ff250020400000000000000000000000
timestamp: 2091-12-22 02:07:39

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: CIS3309F20FP
FileVersion: 1.0.0.0
InternalName: IRemotingTypeI.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: IRemotingTypeI.exe
ProductName: CIS3309F20FP
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/FormBook.EWN!MTB also known as:

BkavW32.AIDetectMalware.CS
tehtrisGeneric.Malware
DrWebTrojan.PackedNET.1400
MicroWorld-eScanTrojan.Ransom.Loki.CAE
FireEyeGeneric.mg.6c24c79151a8b293
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
SkyhighGenericRXTM-WJ!6C24C79151A8
McAfeeGenericRXTM-WJ!6C24C79151A8
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.4661071
SangforSpyware.Msil.Kryptik.Vfrj
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:MSIL/FormBook.27308061
K7GWTrojan ( 00594f4a1 )
K7AntiVirusTrojan ( 00594f4a1 )
BitDefenderThetaGen:NN.ZemsilF.36802.Lm0@aCe4GCd
VirITTrojan.Win32.MSIL_Heur.A
SymantecScr.Malcode!gdn34
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AFPQ
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DCB24
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.Ransom.Loki.CAE
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.13bf7902
EmsisoftTrojan.Ransom.Loki.CAE (B)
F-SecureHeuristic.HEUR/AGEN.1308640
VIPRETrojan.Ransom.Loki.CAE
TrendMicroTROJ_GEN.R002C0DCB24
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraHEUR/AGEN.1308640
VaristW32/MSIL_Kryptik.HOW.gen!Eldorado
Antiy-AVLTrojan[Spy]/MSIL.Noon
MicrosoftTrojan:MSIL/FormBook.EWN!MTB
ArcabitTrojan.Ransom.Loki.CAE
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
GDataTrojan.Ransom.Loki.CAE
AhnLab-V3Trojan/Win.PWSX-gen.C5185575
VBA32OScope.Trojan.MSIL.Remcos.gen
ALYacTrojan.Ransom.Loki.CAE
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Chgt.AA
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:a8s2rUoDauLqHTrkJDPD7w)
IkarusTrojan-Spy.BluStealer
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.HOW!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/FormBook.EWN!MTB?

Trojan:MSIL/FormBook.EWN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment