Spy Trojan

TrojanSpy:Win32/FormBook.AR!MTB removal guide

Malware Removal

The TrojanSpy:Win32/FormBook.AR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/FormBook.AR!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:Win32/FormBook.AR!MTB?


File Info:

crc32: CDA0ED59
md5: 4a13e1bcf729ed0164f8c1b53ea78bfc
name: karaflerne.exe
sha1: e64439ed29b85d512c53fe4a857897c31bb05f2b
sha256: f9b3a6d95c8273bc7063d174ddd44f02f242a476eb5c959f8df60caa35c44803
sha512: 4d1ad45750c96652d006a846b6f829c5addbd087f5c24b2ea1c3773bce097387eb7a7783457231d987a85ed3847071b7efd18290888533db6ff49065df5152dd
ssdeep: 768:LjgxD7pXaKF0vdrtTOijGgl1lnUrJ88bvGPtGjCvXsF0cJ:4F7GlZO6lDUreNXWB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: karaflerne
FileVersion: 2.05
CompanyName: KEYstore
Comments: KEYstore
ProductName: MYELOSU
ProductVersion: 2.05
OriginalFilename: karaflerne.exe

TrojanSpy:Win32/FormBook.AR!MTB also known as:

MicroWorld-eScanTrojan.GenericKDZ.66806
Qihoo-360Win32/Trojan.389
McAfeeFareit-FSJ!4A13E1BCF729
MalwarebytesTrojan.Injector
AegisLabTrojan.Multi.Generic.4!c
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKDZ.66806
TrendMicroTROJ_GEN.R002C0DDS20
BitDefenderThetaGen:NN.ZevbaCO.34108.fm0@aWeS2wni
CyrenW32/VBKrypt.AJI.gen!Eldorado
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKDZ.66806
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Injector.2f8c0618
Ad-AwareTrojan.GenericKDZ.66806
SophosMal/FareitVB-AC
F-SecureTrojan.TR/Injector.isqon
McAfee-GW-EditionFareit-FSJ!4A13E1BCF729
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKDZ.66806 (B)
IkarusTrojan.VB.Crypt
F-ProtW32/VBKrypt.AJI.gen!Eldorado
AviraTR/Injector.isqon
ArcabitTrojan.Generic.D104F6
ZoneAlarmTrojan.Win32.Vebzenpak.mcq
MicrosoftTrojanSpy:Win32/FormBook.AR!MTB
AhnLab-V3Trojan/Win32.Injector.R334392
ALYacGen:Variant.Graftor.735633
MAXmalware (ai score=82)
ESET-NOD32a variant of Win32/Injector.ELPV
TrendMicro-HouseCallTROJ_GEN.R002C0DDS20
RisingTrojan.Injector!8.C4 (CLOUD)
eGambitUnsafe.AI_Score_67%
FortinetW32/GuLoader.VHIM!tr
AVGFileRepMalware
PandaTrj/GdSda.A

How to remove TrojanSpy:Win32/FormBook.AR!MTB?

TrojanSpy:Win32/FormBook.AR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment