Trojan

Trojan:Win32/FormBook.BB!MTB removal

Malware Removal

The Trojan:Win32/FormBook.BB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.BB!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/FormBook.BB!MTB?


File Info:

crc32: 7B3ECB14
md5: 56557a947a15e0c1bb7226dffa0f5387
name: big.exe
sha1: ded28a38f108dc084ac87bd31bb0191278999092
sha256: 51a4f59ddc8c429d6af5e0e9baf6511b8f8497441970e66913bb8823440335af
sha512: 482985c716fb0701dfcec8f46d93b3a28016b7ae9fa9fd20a934ab13bafcba6583d4ed7043af60c4b96bd9af842265fe6d9dde6f98432726e1008def885fb401
ssdeep: 768:THS0UfgX7a2vHSxJVdfHYaAG4ugEEg4TDV81IYeqo+oUKXwHWEPK:TS0UsIGSPv4dOtet+WdEPK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Unlumberings7
FileVersion: 1.00
CompanyName: SMARt
Comments: SMARt
ProductName: preprocesso
ProductVersion: 1.00
FileDescription: VIDEOK
OriginalFilename: Unlumberings7.exe

Trojan:Win32/FormBook.BB!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.33563078
McAfeeArtemis!56557A947A15
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005634621 )
BitDefenderTrojan.GenericKD.33563078
K7GWTrojan ( 005634621 )
Cybereasonmalicious.8f108d
BitDefenderThetaGen:NN.ZevbaF.34104.hm0@a4XGp@ki
F-ProtW32/Kryptik.BHP.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.ELFD
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33563078
KasperskyBackdoor.Win32.Remcos.nut
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Backdoor.Remcos.Suxp
Ad-AwareTrojan.GenericKD.33563078
EmsisoftTrojan.GenericKD.33563078 (B)
ComodoTrojWare.Win32.VBKrypt.VZB@8pua28
F-SecureTrojan.TR/Injector.aqjnr
DrWebTrojan.DownLoader33.20798
TrendMicroTROJ_GEN.R049C0PCQ20
McAfee-GW-EditionRDN/Generic BackDoor
Trapminemalicious.moderate.ml.score
SophosMal/FareitVB-W
IkarusWorm.Win32.Vobfus
CyrenW32/Kryptik.BHP.gen!Eldorado
AviraTR/Injector.aqjnr
MAXmalware (ai score=81)
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D20021C6
ZoneAlarmBackdoor.Win32.Remcos.nut
MicrosoftTrojan:Win32/FormBook.BB!MTB
VBA32Backdoor.Remcos
ALYacTrojan.Downloader.Agent
MalwarebytesTrojan.GuLoader.VB
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R049C0PCQ20
RisingBackdoor.Remcos!8.B89E (CLOUD)
YandexTrojan.Injector!KLMYmdihdCw
eGambitUnsafe.AI_Score_91%
FortinetW32/GuLoader.VHHX!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Backdoor.cd2

How to remove Trojan:Win32/FormBook.BB!MTB?

Trojan:Win32/FormBook.BB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment