Trojan

Trojan:Win32/FormBook.DSSS!MTB information

Malware Removal

The Trojan:Win32/FormBook.DSSS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.DSSS!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • Authenticode signature is invalid

How to determine Trojan:Win32/FormBook.DSSS!MTB?


File Info:

name: CE70989C3233A936F8DD.mlw
path: /opt/CAPEv2/storage/binaries/505a32624edaabbb379b27b71fdbeceba56ce6575f7b8b4ae430448194517ebc
crc32: 1969F040
md5: ce70989c3233a936f8dd60679487b85b
sha1: 8503823aaf0f6647d2de432c6f6aaf20a5c81707
sha256: 505a32624edaabbb379b27b71fdbeceba56ce6575f7b8b4ae430448194517ebc
sha512: 0733e928bf1d165f65124aaee32c3cd0ac038051aeec4d43da078cdb41a4354426b8ca4ea830fa1d2c7ec7562897d828f3248d9184c1b8970d8261d80407dff6
ssdeep: 48:qB7eA42Gf/zWJyW4zhVAIksyT989uJIvMp7I6AJGJS2l5GkR4sxrIT/r3HdNKSMl:zzWJyWsyT+9uJIvMp0dqvW/r3HdN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T106B191476B7848E2D50DCFF90BBA8C6C1DBC1543007466755AA3DCC6C2F9B9A700AB9C
sha3_384: f651efa08ca24a3581523343cb44b6241be41a5effad7fcf7b242a001cd9209a3a22155345744f1a64ac7d6ee0f85376
ep_bytes: 558bec515356578d45fc33ff50ff1540
timestamp: 2022-06-06 07:24:37

Version Info:

0: [No Data]

Trojan:Win32/FormBook.DSSS!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.39746267
FireEyeGeneric.mg.ce70989c3233a936
ALYacTrojan.GenericKD.39746267
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1539315
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005949e61 )
AlibabaTrojan:Win32/FormBook.428bef36
K7GWTrojan ( 005949e61 )
BitDefenderThetaGen:NN.ZexaE.34582.amW@ai9URDj
VirITTrojan.Win32.PSWStelaer.KM
CyrenW32/Ninjector.BQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ERTH
TrendMicro-HouseCallTROJ_GEN.R002C0DFA22
BitDefenderTrojan.GenericKD.39746267
AvastWin32:InjectorX-gen [Trj]
Ad-AwareTrojan.GenericKD.39746267
SophosMal/Generic-S
VIPRETrojan.GenericKD.39746267
TrendMicroTROJ_GEN.R002C0DFA22
McAfee-GW-EditionRDN/Wacatac
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.39746267 (B)
APEXMalicious
GDataWin32.Trojan.PSE.9OM9L1
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.56CE
MicrosoftTrojan:Win32/FormBook.DSSS!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.InjectorX-gen.R496487
McAfeeRDN/Wacatac
MAXmalware (ai score=88)
VBA32Trojan.FormBook
MalwarebytesTrojan.Injector
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.Igent.bX8oND.1
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.184381978.susgen
FortinetW32/Injector.ERTF!tr
AVGWin32:InjectorX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/FormBook.DSSS!MTB?

Trojan:Win32/FormBook.DSSS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment