Trojan

How to remove “Trojan:Win32/FormBook.AN!MTB”?

Malware Removal

The Trojan:Win32/FormBook.AN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.AN!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/FormBook.AN!MTB?


File Info:

name: 8B500976FC28F7358EBA.mlw
path: /opt/CAPEv2/storage/binaries/053166ff37507398e22d75b5ad58dc5a3732e670c3f86a7e328b489e3675fee4
crc32: 112BED99
md5: 8b500976fc28f7358eba1853ca01bd99
sha1: 6413f0dd964d5c92e84ccb4b4d55ddc46aeac278
sha256: 053166ff37507398e22d75b5ad58dc5a3732e670c3f86a7e328b489e3675fee4
sha512: 4ffbb10a7bb93645cbda7be060eb90b0ca60277d9a8e09e4ed78f6a04c3ceb8c7242230eb4ff59929d47a654fbfa48bac93794cd2e3cfebcef6d3f2adc71d84c
ssdeep: 6144:nw82uaAJScHj0N86PEN1Jc6bbi/smvB7Lumz9+ZKG2l3eGy+0tt1OSkTJZRN:281JNmvB7qw/uGy+0tTOSEzRN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19EA406852006B769D6550B71BB9AD00E4F7B58BAAAC2850F32D57EFE77AC00DD34312B
sha3_384: 8e7324c2a80c40300786ab8f5cf7ad2547333c29e0aad69b0b49b2281ee3f360bc3067cae56332f4015fd3adccc51ac4
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Trojan:Win32/FormBook.AN!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.GenericML.4!c
MicroWorld-eScanDropped:Generic.NSIS.Injector.A.497020EE
FireEyeDropped:Generic.NSIS.Injector.A.497020EE
CAT-QuickHealTrojan.TnegaPMF.S26660187
McAfeeRDN/Generic.grp
CylanceUnsafe
ZillyaTrojan.Noon.Win32.22773
SangforTrojan.Win32.Noon.gen
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/SpyNoon.a2d2c403
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34806.huW@aWmUHuii
CyrenW32/Kryptik.GEH.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ERCD
TrendMicro-HouseCallTROJ_GEN.R002C0DBD22
Paloaltogeneric.ml
ClamAVWin.Trojan.Noon-9939287-0
KasperskyHEUR:Trojan.Win32.Formbook.gen
BitDefenderDropped:Generic.NSIS.Injector.A.497020EE
NANO-AntivirusVirus.Win32.Gen.ccmw
APEXMalicious
TencentWin32.Trojan-spy.Noon.Ebqm
Ad-AwareDropped:Generic.NSIS.Injector.A.497020EE
EmsisoftDropped:Generic.NSIS.Injector.A.497020EE (B)
ComodoMalware@#2gomyy7bi5t61
DrWebTrojan.Siggen16.42348
VIPREDropped:Generic.NSIS.Injector.A.497020EE
TrendMicroTROJ_GEN.R002C0DBD22
McAfee-GW-EditionRDN/Generic.grp
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
GDataWin32.Trojan.Kryptik.SP
JiangminTrojan.Multi.hiv
WebrootW32.Trojan.Multi.GenML.xnet
AviraTR/AD.Swotter.uznbv
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.56CE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/FormBook.AN!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R472593
VBA32Trojan.Sabsik.FL
ALYacDropped:Generic.NSIS.Injector.A.497020EE
MalwarebytesTrojan.Injector
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Generic@AI.84 (RDMK:Pf/No4Y4Hqg4uQEchoDKXA)
YandexTrojan.Injector!7A/1c9FSdKk
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.GMVH!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.d964d5
PandaTrj/CI.A

How to remove Trojan:Win32/FormBook.AN!MTB?

Trojan:Win32/FormBook.AN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment