Trojan

Trojan:Win32/FormBook.AC!MTB malicious file

Malware Removal

The Trojan:Win32/FormBook.AC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.AC!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/FormBook.AC!MTB?


File Info:

crc32: CE257503
md5: d3ee27cef3a593fb5d539c6999b8a56a
name: postback_i.exe
sha1: 6f8e002b7a1f826fd1a5d2acd74c46e1a60219d0
sha256: f48d5594db0ca34bce18a042ade423504f5f9ff7c66343fd3e02eee2f81dfe92
sha512: eec125305b78b1b9d57d7985fd4710077c2af8dfdb9522000718ecd9a29452f06e31db93422d89bd17e98f342c978749d53aa0655f7bdefabebcfb0cb23910ef
ssdeep: 768:VIfgjfK7cs1WHL0SqZsqomMjk5Nw7HqeuMoBB02WQq0/o4+lb:VI4K7csuL0SqZZMCiq1MoBBPWQjo4ib
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: Synsmaad6
FileVersion: 1.00
OriginalFilename: Synsmaad6.exe
ProductName: Vidunde

Trojan:Win32/FormBook.AC!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.33500826
FireEyeTrojan.GenericKD.33500826
McAfeeRDN/Generic.dx
CylanceUnsafe
ZillyaTrojan.Vebzenpak.Win32.1341
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33500826
K7GWRiskware ( 0040eff71 )
TrendMicroTrojan.Win32.WACATAC.THCOBBO
F-ProtW32/Injector.ZO.gen!Eldorado
APEXMalicious
ClamAVWin.Dropper.Fareitvb-7604866-0
GDataTrojan.GenericKD.33500826
KasperskyTrojan.Win32.Vebzenpak.ers
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.33500826
EmsisoftTrojan.GenericKD.33500826 (B)
DrWebTrojan.Siggen9.16725
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic.dx
Trapminemalicious.moderate.ml.score
SophosMal/FareitVB-W
IkarusTrojan-Spy.LokiBot
CyrenW32/Injector.ZO.gen!Eldorado
MAXmalware (ai score=82)
ArcabitTrojan.Generic.D1FF2E9A
ZoneAlarmTrojan.Win32.Vebzenpak.ers
MicrosoftTrojan:Win32/FormBook.AC!MTB
BitDefenderThetaGen:NN.ZevbaCO.34096.em0@auhArcbi
ALYacTrojan.GenericKD.33500826
VBA32TScope.Trojan.VB
MalwarebytesTrojan.MalPack.VB.Generic
ESET-NOD32a variant of Win32/Injector.EKVC
TrendMicro-HouseCallTrojan.Win32.WACATAC.THCOBBO
TencentWin32.Trojan.Vebzenpak.Wsty
eGambitUnsafe.AI_Score_90%
FortinetW32/Injector.EKVY!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/FormBook.AC!MTB?

Trojan:Win32/FormBook.AC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment