Trojan

About “Trojan:MSIL/Formbook.NN!MTB” infection

Malware Removal

The Trojan:MSIL/Formbook.NN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Formbook.NN!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:MSIL/Formbook.NN!MTB?


File Info:

name: BC82FC9A22376132A6F2.mlw
path: /opt/CAPEv2/storage/binaries/759206b1356754b89cce68e266bbe683466a19e459b54442b006c9a6cffa7ae1
crc32: 84C23B09
md5: bc82fc9a22376132a6f225a46d484875
sha1: a7e9f6b869567c7afcbd3f78e749566035d392c1
sha256: 759206b1356754b89cce68e266bbe683466a19e459b54442b006c9a6cffa7ae1
sha512: afde4859fc7a8c182c2da405f174e2898e584c89bffeefd58d05afaa130d2f63ea58782b343c708a8311bfbd996709014a49305c18cbb40f191b3996b12f50d3
ssdeep: 98304:WiNd0xSQCfUtLwh3+wgGauyZ/U7hM77KJRnGPsghywfNWIKB4L9KP0P58HG5MrJc:WiNdcxCfU5wSU7N7eA6K4vmR2XP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BCE63A82E1B09E1DD8FA4D3DBD9023D473F247166FA2DA84DC24FC29741D2D3AAC561A
sha3_384: 4adfe02cafc75d8317679295387ec44cfca0c604a7d82a894eee7210377fe768ae76642d3e9934d7862b9c1cf9a793ed
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-01-02 12:29:46

Version Info:

Translation: 0x0000 0x04b0
CompanyName: AhOgEyOPUQ
FileDescription: IhiOaKoue amEIu AsaGiFor ogECudeP IFaZamUFuci eqeVAUEvIvE.
FileVersion: 4.15.66.79
InternalName: AkauAlAUaMu
LegalCopyright: © 2027 AhOgEyOPUQ
OriginalFilename: aXIjOPEE
ProductName: uhuyA
ProductVersion: 4.15.66.79
Comments: AbIQuAote OZEgItepiL uyETOEugUFi UpUyo oXuJiOuOoX iPaNOaOuUr IQiliIeoe iAEXOIaNaN.

Trojan:MSIL/Formbook.NN!MTB also known as:

MicroWorld-eScanIL:Trojan.MSILZilla.30386
FireEyeIL:Trojan.MSILZilla.30386
SkyhighArtemis!Trojan
McAfeeArtemis!BC82FC9A2237
Cylanceunsafe
VIPREIL:Trojan.MSILZilla.30386
SangforTrojan.Msil.Kryptik.Vbur
BitDefenderIL:Trojan.MSILZilla.30386
K7GWTrojan ( 005b01df1 )
K7AntiVirusTrojan ( 005b01df1 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AKMO
APEXMalicious
TrendMicro-HouseCallBackdoor.Win32.ASYNCRAT.YXEADZ
AlibabaTrojan:MSIL/Formbook.f1588af0
AvastWin32:Malware-gen
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:p6FHOslvlPYC3zcNnJ+c5w)
EmsisoftIL:Trojan.MSILZilla.30386 (B)
F-SecureTrojan.TR/Kryptik.sgint
ZillyaTrojan.Kryptik.Win32.4446609
TrendMicroBackdoor.Win32.ASYNCRAT.YXEADZ
SophosMal/Generic-S
IkarusTrojan.MSIL.Injuke
GoogleDetected
AviraTR/Kryptik.sgint
VaristW32/ABRisk.KFTN-6284
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:MSIL/Formbook.NN!MTB
ArcabitIL:Trojan.MSILZilla.D76B2
GDataIL:Trojan.MSILZilla.30386
AhnLab-V3Trojan/Win.MSILZilla.C5570915
ALYacIL:Trojan.MSILZilla.30386
MAXmalware (ai score=87)
MalwarebytesTrojan.DTCrypt.MSIL.Generic
PandaTrj/Chgt.AD
TencentWin32.Trojan.FalseSign.Nqil
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3411146.susgen
FortinetMSIL/Formbook.AA!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Formbook.NN!MTB?

Trojan:MSIL/Formbook.NN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment