Trojan

Trojan:Win32/FormBook.PI!MTB removal

Malware Removal

The Trojan:Win32/FormBook.PI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.PI!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Anomalous binary characteristics

How to determine Trojan:Win32/FormBook.PI!MTB?


File Info:

crc32: BC90D8BF
md5: c05d971ead362b8163a51bec038261fa
name: C05D971EAD362B8163A51BEC038261FA.mlw
sha1: 324ec5d8540321fe90ae84fe39ccc8c2af187269
sha256: 1e5241525e65fdfc2540e30a5e54b0147240a9d0f5da4063ef94509379a19feb
sha512: 835051bc3aba499f415615d0dead28bb6de10426dfca46da0a679f19e96dff86777941f9201814b6d4e78e25351d813f177733820be256a3ccb09e94ed835878
ssdeep: 12288:EyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyEks4stiiBO8JD10ddQ0x6KqM0:Eyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/FormBook.PI!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.2854
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.36638601
CylanceUnsafe
SangforTrojan.Win32.FormBook.PI
CrowdStrikewin/malicious_confidence_80% (W)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Injector.AGS.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/Formbook.AA
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderTrojan.GenericKD.36638601
MicroWorld-eScanTrojan.GenericKD.36638601
Ad-AwareTrojan.GenericKD.36638601
SophosMal/Generic-S + Troj/Formbo-YC
ComodoMalware@#l6d7fhik4dun
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.gh
FireEyeGeneric.mg.c05d971ead362b81
EmsisoftTrojan.GenericKD.36638601 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.gthqm
WebrootW32.Adware.Gen
AviraTR/AD.Swotter.fvfxd
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/FormBook.PI!MTB
GridinsoftTrojan.Win32.Downloader.oa!s1
ArcabitTrojan.Generic.D22F0F89
GDataTrojan.GenericKD.36638601
AhnLab-V3Trojan/Win.FormBook.C4405064
McAfeeArtemis!C05D971EAD36
MAXmalware (ai score=86)
MalwarebytesTrojan.Loader
IkarusTrojan.Win32.Injector
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Noon.HoMASSIA

How to remove Trojan:Win32/FormBook.PI!MTB?

Trojan:Win32/FormBook.PI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment