Trojan

Trojan:Win32/FormBook.PDI!MTB (file analysis)

Malware Removal

The Trojan:Win32/FormBook.PDI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.PDI!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Trojan:Win32/FormBook.PDI!MTB?


File Info:

name: 80FCFD94A2CEE1AB7CAD.mlw
path: /opt/CAPEv2/storage/binaries/4cdb484aff91fc4c74a8f2750296212dd12af808fee3e01bf9b8d0feafbd8fc1
crc32: 03AFE1D2
md5: 80fcfd94a2cee1ab7cad84457d74f816
sha1: 5bc3656f6e071c30f36581a8b9861824d40b7a49
sha256: 4cdb484aff91fc4c74a8f2750296212dd12af808fee3e01bf9b8d0feafbd8fc1
sha512: 4ca55b89c64e933f793ac1fd898bbd5bd9b764575e7a3f232a4e31fabf34fa6b21802ec2845990ab3adf96a65f09ed2e772824c0a7c3faf27280ed1bd076d081
ssdeep: 12288:82rYPxajxQmavadsF3JqGQKXGD4irUea+EdhhY2JfGBA+L93tVOp:8v5u1kadG3Jqy20ir/RWGA093ta
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167156C3697A0C8B1C6678534CD0E42DC552DFE103934F9C766E2BC9A0F396E8E476B86
sha3_384: e435c9839c1819e51e1d9c1df90ef5714474189d24ce14eb9dfa14ce0a29595d40e688d67718f417c63f979f9e909f13
ep_bytes: 558bec83c4f0b888174800e8e43bf8ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/FormBook.PDI!MTB also known as:

LionicTrojan.Win32.Remcos.m!c
MicroWorld-eScanTrojan.GenericKD.38459586
FireEyeTrojan.GenericKD.38459586
ALYacTrojan.GenericKD.38459586
CylanceUnsafe
SangforBackdoor.Win32.Remcos.gen
K7AntiVirusTrojan-Downloader ( 005829421 )
AlibabaBackdoor:Win32/FormBook.40576ef3
K7GWTrojan-Downloader ( 005829421 )
CyrenW32/Injector.NTWB-0202
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Delf.DIB
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderTrojan.GenericKD.38459586
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.11e17e4d
Ad-AwareTrojan.GenericKD.38459586
ComodoMalware@#bloofw13gnmc
DrWebTrojan.Siggen16.26963
TrendMicroTROJ_FRS.0NA103A722
McAfee-GW-EditionRDN/Formbook
EmsisoftTrojan-Downloader.Delf (A)
JiangminBackdoor.Remcos.dic
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Generic.ASMalwS.35018BA
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftTrojan.Win32.Downloader.sa
MicrosoftTrojan:Win32/FormBook.PDI!MTB
ViRobotTrojan.Win32.Z.Injector.928768.D
GDataWin32.Trojan-Downloader.DBatLoader.CJXSX1
AhnLab-V3Trojan/Win.FormBook.R462907
McAfeeRDN/Formbook
MAXmalware (ai score=85)
VBA32BScope.Trojan-Dropper.Injector
MalwarebytesTrojan.MalPack.DLF
TrendMicro-HouseCallTROJ_FRS.0NA103A722
RisingBackdoor.Remcos!8.B89E (CLOUD)
YandexTrojan.Igent.bXfImu.15
FortinetW32/Injector.EQPQ!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/FormBook.PDI!MTB?

Trojan:Win32/FormBook.PDI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment