Trojan

Should I remove “Trojan:MSIL/FormBook.ST!MTB”?

Malware Removal

The Trojan:MSIL/FormBook.ST!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/FormBook.ST!MTB virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Trojan:MSIL/FormBook.ST!MTB?


File Info:

name: 75148A48554BF658B5BC.mlw
path: /opt/CAPEv2/storage/binaries/5750f0a05c92bfe3323fb9e1e3c316a44e01338b9e2f02f4099424c3e37bc8cc
crc32: F4AE62E9
md5: 75148a48554bf658b5bca72fd77b69ed
sha1: 35efb5dec83f1a802b05c6d8f6a1046a4dc9c14e
sha256: 5750f0a05c92bfe3323fb9e1e3c316a44e01338b9e2f02f4099424c3e37bc8cc
sha512: 46b4627fbce1a35ea77f62890ed7fbff0f2adb04a71056a847fd387dbf5e887d92d077e92fdf949cb0d8bf064f004592bb4410ad8b7d878840011e707a195742
ssdeep: 12288:ELGSDInWnA0+rjumRpcasoOnkk34kr5oR9FMBh+OQhNOi:K4u75VE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11EE4CD2A38BA100DB2719D6C6BBCB1B6911EF7F226365CBB0DF7050611129F0DB9D627
sha3_384: bc52f7447093bc75b0c1068c2b35ab554417c4a31b9d38209d92be870e50b89521f791c692000b96377de05106c20103
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-03 08:19:26

Version Info:

Translation: 0x0000 0x04b0
FileDescription: WWCCVFDT
FileVersion: 1.0.0.0
InternalName: WWCCVFDT.exe
LegalCopyright: Copyright © 2022
OriginalFilename: WWCCVFDT.exe
ProductName: WWCCVFDT
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/FormBook.ST!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Autoruns.GenericKD.38877877
FireEyeGeneric.mg.75148a48554bf658
CAT-QuickHealBackdoor.MSIL
McAfeeRDN/Formbook
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0058b7b11 )
AlibabaBackdoor:MSIL/Remcos.22fd8ffd
K7GWTrojan-Downloader ( 0058b7b11 )
Cybereasonmalicious.ec83f1
BitDefenderThetaGen:NN.ZemsilF.34212.Pm0@aCKq0C
CyrenW32/MSIL_Kryptik.GBO.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.JSF
TrendMicro-HouseCallTROJ_FRS.0NA103B422
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Remcos.gen
BitDefenderTrojan.Autoruns.GenericKD.38877877
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-downloader.Agent.Aexo
Ad-AwareTrojan.Autoruns.GenericKD.38877877
EmsisoftTrojan.Autoruns.GenericKD.38877877 (B)
ComodoMalware@#2uk4wuuizs90z
DrWebTrojan.Siggen9.48175
TrendMicroTROJ_FRS.0NA103B422
McAfee-GW-EditionRDN/Formbook
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
WebrootW32.Malware.Gen
AviraTR/AD.Swotter.mfjsi
Antiy-AVLTrojan/Generic.ASMalwS.352218F
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:MSIL/FormBook.ST!MTB
GDataTrojan.Autoruns.GenericKD.38877877
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Injector.C4950251
ALYacTrojan.Autoruns.GenericKD.38877877
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.884393997
YandexTrojan.Igent.bXr2RU.10
IkarusTrojan.Inject
FortinetMSIL/Agent.JSF!tr.dldr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/FormBook.ST!MTB?

Trojan:MSIL/FormBook.ST!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment