Trojan

Trojan:Win32/FormBook.AH!MTB removal tips

Malware Removal

The Trojan:Win32/FormBook.AH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.AH!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/FormBook.AH!MTB?


File Info:

crc32: 1AE201CE
md5: 5b64bc80af0b9461233e5cdedf8e5497
name: nw1.exe
sha1: c5c7a06a98ad8b9237c6d101ce032faa9c8f6b06
sha256: 042323d9484c21c3f2e54146025e32971f450a99f6e55b1ea017fa0dcd3a483e
sha512: 15353481b1e250acad0598a38ed231c109df4183c8fb1aee40085ccf137177915c5ad8c0fafa7057fdc328afa4784ce9ca05009e341841b14758e7a51bca6991
ssdeep: 768:Xcp1Roj92/f+SeTd5+AFgF0rVw1mU9YONnoBhy:X0Hhc7+6re1m6oBhy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: THOMISTICASCE
FileVersion: 1.00
CompanyName: Vodafone
ProductName: SURBRDETSBRNDS
ProductVersion: 1.00
FileDescription: Blabbered
OriginalFilename: THOMISTICASCE.exe

Trojan:Win32/FormBook.AH!MTB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33531805
Qihoo-360Win32/Trojan.4b8
CylanceUnsafe
AegisLabTrojan.Win32.Vebzenpak.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderTrojan.GenericKD.33531805
K7GWTrojan ( 005622601 )
K7AntiVirusTrojan ( 005622601 )
ArcabitTrojan.Generic.D1FFA79D
TrendMicroTROJ_GEN.R057C0DCB20
CyrenW32/VB_Troj.AD.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.EKZG
APEXMalicious
ClamAVWin.Trojan.Generic-7614798-0
KasperskyTrojan.Win32.Vebzenpak.gqf
AlibabaTrojan:Win32/Vebzenpak.b6bb806e
TencentWin32.Trojan.Vebzenpak.Sxeq
Endgamemalicious (moderate confidence)
EmsisoftTrojan.GenericKD.33531805 (B)
F-SecureTrojan.TR/Injector.osqya
DrWebTrojan.Inject3.36060
McAfee-GW-EditionFareit-FRP!5B64BC80AF0B
FortinetW32/GuLoader.VHHM!tr
Trapminemalicious.high.ml.score
SophosMal/FareitVB-W
IkarusTrojan-Spy.Keylogger.AgentTesla
F-ProtW32/VB_Troj.AD.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Injector.osqya
Antiy-AVLTrojan/Win32.Vebzenpak
MicrosoftTrojan:Win32/FormBook.AH!MTB
ZoneAlarmTrojan.Win32.Vebzenpak.gqf
AhnLab-V3Trojan/Win32.VBKrypt.R328182
ALYacTrojan.GenericKD.33531805
Ad-AwareTrojan.GenericKD.33531805
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
RisingTrojan.Injector!8.C4 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKD.33531805
BitDefenderThetaGen:NN.ZevbaCO.34100.dm0@a0uLIppi
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Trojan:Win32/FormBook.AH!MTB?

Trojan:Win32/FormBook.AH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment