Trojan

Trojan:Win32/FormBook.AW!MTB (file analysis)

Malware Removal

The Trojan:Win32/FormBook.AW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.AW!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/FormBook.AW!MTB?


File Info:

crc32: A554523E
md5: 3f331cffb81124a2d8002e3878774517
name: midsignltd_crypt.exe
sha1: 4acc1b68a550395e332f9d1179234f10b4f3c56a
sha256: e0793753a553fe36bee711835ddba00f52328c260ea80ee15224445ef0219b87
sha512: 3567d0a122ac0ec8f44ea6daf06664e4337bae16555139505e1863a2fd68cfeb4eaa8aba75fa3f97de1e38a3b58d7d45555bbf595827ff815f9804b8757efd12
ssdeep: 768:cE1PbPiobzavlzsFTpzJZJhPBzJrJPF7xDs0oTY:cE1dxp1fbJrJE0ok
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: SOWEDEF
FileVersion: 1.00
CompanyName: ubISOFT
Comments: ubISOFT
ProductName: Klageber6
ProductVersion: 1.00
FileDescription: MAYEYE
OriginalFilename: SOWEDEF.exe

Trojan:Win32/FormBook.AW!MTB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33552250
Qihoo-360Win32/Trojan.IM.92a
McAfeeArtemis!3F331CFFB811
MalwarebytesTrojan.GuLoader.VB
K7AntiVirusTrojan ( 00562d2c1 )
BitDefenderTrojan.GenericKD.33552250
K7GWTrojan ( 00562d2c1 )
TrendMicroTROJ_FRS.0NA103CI20
BitDefenderThetaGen:NN.ZevbaCO.34100.cm0@am1T8nei
F-ProtW32/Injector.AAM.gen!Eldorado
TrendMicro-HouseCallTROJ_FRS.0NA103CI20
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33552250
KasperskyTrojan.Win32.Vebzenpak.imh
AlibabaTrojan:Win32/vbcrypt.ali2000008
AegisLabTrojan.Win32.Vebzenpak.4!c
APEXMalicious
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareTrojan.GenericKD.33552250
SophosMal/FareitVB-W
F-SecureTrojan.TR/Injector.llclx
DrWebTrojan.PackedENT.133
McAfee-GW-EditionRDN/Generic.grp
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.33552250 (B)
SentinelOneDFI – Suspicious PE
CyrenW32/Injector.AAM.gen!Eldorado
AviraTR/Injector.llclx
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Vebzenpak
ArcabitTrojan.Generic.D1FFF77A
ZoneAlarmTrojan.Win32.Vebzenpak.imh
MicrosoftTrojan:Win32/FormBook.AW!MTB
ALYacTrojan.Agent.Vebzenpak
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ELCE
TencentWin32.Trojan.Vebzenpak.Llrf
IkarusTrojan.VB.Crypt
FortinetW32/GuLoader.VHHS!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.79539807.susgen

How to remove Trojan:Win32/FormBook.AW!MTB?

Trojan:Win32/FormBook.AW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment