Trojan

Trojan:MSIL/FormBook.KC!MTB removal guide

Malware Removal

The Trojan:MSIL/FormBook.KC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/FormBook.KC!MTB virus can do?

  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/FormBook.KC!MTB?


File Info:

crc32: A4DC498A
md5: 0bf971c91ce1997840caf20da0bcf262
name: wresdfgr.exe
sha1: fcc1070b8cf0d27b26af1516c891ffd72060cdee
sha256: 88efa753e46f6e0e87c67231482613c1145eb5ab7e43dbd17e19b1a9267b5896
sha512: 19c9a94e0d5fece986e99d527dc2db65a78a0a6708f14be66fd65c46e9d3ce8d1a1186a4a93034cdfdea44516bc264fa337786cbcc5c69a40e73a0276a3d8d09
ssdeep: 12288:v8m4k7f5e0ar5J+mpU2H077df9U4h0y+6J6b1X4eLpy3Q:vQ0f54XrUjLZ1XyCWA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2010 - 2019
Assembly Version: 0.0.0.0
InternalName: wresdfgr.exe
FileVersion: 5.8.11.13
CompanyName: 8Az_Rw$2x/7E(6Ym4s
Comments: 2n*Lt_Q9@C6mJo
ProductName: eW+3$5Jd6y*DQ@8i
ProductVersion: 5.8.11.13
FileDescription: eW+3$5Jd6y*DQ@8i
OriginalFilename: wresdfgr.exe

Trojan:MSIL/FormBook.KC!MTB also known as:

MicroWorld-eScanTrojan.GenericKDZ.68932
FireEyeGeneric.mg.0bf971c91ce19978
McAfeeFareit-FVT!0BF971C91CE1
CylanceUnsafe
K7AntiVirusTrojan ( 0056b0e11 )
BitDefenderTrojan.GenericKDZ.68932
K7GWTrojan ( 0056b0e11 )
TrendMicroTROJ_GEN.R002C0WGO20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Malware.Formbook-7399661-0
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
AegisLabTrojan.MSIL.Agensla.i!c
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKDZ.68932 (B)
F-SecureTrojan.TR/Kryptik.ckhgn
DrWebTrojan.Packed2.42516
Invinceaheuristic
FortinetMSIL/Kryptik.WZR!tr
SophosMal/Generic-S
IkarusTrojan-Spy.FormBook
CyrenW32/MSIL_Kryptik.BFD.gen!Eldorado
WebrootW32.Trojan.GenKDZ
AviraTR/Kryptik.ckhgn
MAXmalware (ai score=81)
ArcabitTrojan.Generic.D10D44
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
MicrosoftTrojan:MSIL/FormBook.KC!MTB
ALYacTrojan.GenericKDZ.68932
Ad-AwareTrojan.GenericKDZ.68932
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.WZR
TrendMicro-HouseCallTROJ_GEN.R002C0WGO20
RisingStealer.Formbook!1.C470 (CLOUD)
SentinelOneDFI – Malicious PE
GDataTrojan.GenericKDZ.68932
BitDefenderThetaGen:NN.ZemsilF.34138.3m0@amIfH4c
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM03.0.C87F.Malware.Gen

How to remove Trojan:MSIL/FormBook.KC!MTB?

Trojan:MSIL/FormBook.KC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment