Trojan

Trojan:MSIL/FormBook.I!MTB removal guide

Malware Removal

The Trojan:MSIL/FormBook.I!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/FormBook.I!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Network activity detected but not expressed in API logs
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients

How to determine Trojan:MSIL/FormBook.I!MTB?


File Info:

crc32: E4D08B28
md5: 83a61c0853987c2ee3f5cd30763aa887
name: 83A61C0853987C2EE3F5CD30763AA887.mlw
sha1: b6ffb818d94c77ab626fe513522ccf75bd84ae7b
sha256: de86e4f97202c410712eae65ca5145961a5da4ec6ff06bcb54ce16df3eac8f92
sha512: a9b079493850f4bc1e19c4363ac5a5ab2031b7185ca805a60ea18ede40371ba73f1e356b49657ff8bf2eb2ca3cc0fe4a155b7d4ccc353cf71d27d6b5287837d9
ssdeep: 12288:sRHS2JvgaZG2JVqhlEixRST5rE1xtUYgE:sRk2ShlEUosuE
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: img2.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: img2.exe

Trojan:MSIL/FormBook.I!MTB also known as:

DrWebTrojan.Siggen1.39351
MicroWorld-eScanGen:Variant.MSIL.Lynx.8
FireEyeGeneric.mg.83a61c0853987c2e
McAfeeGenericRXFV-JV!83A61C085398
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0015e4f01 )
BitDefenderGen:Variant.MSIL.Lynx.8
K7GWRiskware ( 0015e4f01 )
Cybereasonmalicious.853987
BitDefenderThetaGen:NN.ZemsilF.34804.ym0@aCg7OZh
CyrenW32/MSIL_Troj.R.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastMSIL:Inject-BS [Trj]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/FormBook.48d0948b
NANO-AntivirusTrojan.Win32.TrjGen.dbxxjr
TencentWin32.Trojan.Generic.Eane
Ad-AwareGen:Variant.MSIL.Lynx.8
SophosMal/Generic-R + Troj/MSIL-ITR
ComodoMalware@#1usve69lhl1dl
F-SecureTrojan.TR/Injector.EA.1
ZillyaTrojan.Injector.Win32.130863
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftGen:Variant.MSIL.Lynx.8 (B)
IkarusTrojan-Dropper.Small
JiangminTrojan/Generic.dxqq
WebrootW32.Malware.Gen
AviraTR/Injector.EA.1
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/FormBook.I!MTB
ArcabitTrojan.MSIL.Lynx.8
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.MSIL.Lynx.8
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dynamer.R163018
Acronissuspicious
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.MSIL.Lynx.8
MAXmalware (ai score=100)
MalwarebytesMalware.AI.1098676934
PandaGeneric Malware
ESET-NOD32a variant of MSIL/Injector.BYR
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.Injector!oVa8dOVgTJA
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetMSIL/Injector.BYR!tr
MaxSecureTrojan.Malware.300983.susgen
AVGMSIL:Inject-BS [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/Malware.QVM03.Gen

How to remove Trojan:MSIL/FormBook.I!MTB?

Trojan:MSIL/FormBook.I!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment