Trojan

Trojan:Win32/Formbook.RPX!MTB information

Malware Removal

The Trojan:Win32/Formbook.RPX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Formbook.RPX!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Formbook.RPX!MTB?


File Info:

name: B794418CCE0BEACB8EAB.mlw
path: /opt/CAPEv2/storage/binaries/a94ed8371035cbc5f21d14be02444b5d85cf2d4feeba9a869ec3a446222721df
crc32: 84529D33
md5: b794418cce0beacb8eab531605e194b7
sha1: 859a978d7252563cffd21140a6869f0f685f8f6d
sha256: a94ed8371035cbc5f21d14be02444b5d85cf2d4feeba9a869ec3a446222721df
sha512: faffc010ac7a8fdf9159b3b3d5754526c3bf9859746ede2979c5dcaeeabae49c6ab65789968967e23a994e8c092873aa69642070bb9f014f98c9a03f0dcc0644
ssdeep: 3072:dvYj4niJm88KBNW6scNkdDsodx6C2gE2Y7rn+/CYUJlx6:dW/m88KnW6Bk7jv2wYHn9H6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178146A01B5818032E8B302B74AFE4668963CFD510B6569DBA3DC5E4D9B36AE17F31327
sha3_384: 9b917cd4f0dc6547ee25855c51c6227c3b224b8f323779e0c07d333abaec950b28bf3933407ad8be1c01eccaf08827be
ep_bytes: e80f5b0000e97ffeffff558bec568b75
timestamp: 2023-11-20 23:11:41

Version Info:

0: [No Data]

Trojan:Win32/Formbook.RPX!MTB also known as:

LionicTrojan.Win32.Formbook.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.523062
FireEyeGeneric.mg.b794418cce0beacb
SkyhighBehavesLike.Win32.CoinMiner.ch
McAfeeGenericRXWL-PU!B794418CCE0B
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Formbook.96e7ef86
K7GWTrojan ( 005aeddd1 )
K7AntiVirusTrojan ( 005aeddd1 )
BitDefenderThetaGen:NN.ZexaF.36744.lmW@a8Euu1b
VirITTrojan.Win32.GenusT.DTWD
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ETMH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Strab.gen
BitDefenderGen:Variant.Zusy.523062
NANO-AntivirusTrojan.Win32.Strab.kdzrvy
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.13f7d6b8
EmsisoftGen:Variant.Zusy.523062 (B)
DrWebTrojan.Loader.1550
VIPREGen:Variant.Zusy.523062
TrendMicroTrojan.Win32.FORMBOOK.USBLKO23
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
GDataWin32.Trojan.PSE.QYNA3B
WebrootW32.Strab.Gen
GoogleDetected
Antiy-AVLTrojan/Win32.Formbook
KingsoftWin32.Trojan.Strab.gen
XcitiumMalware@#3ovv79zimdp42
ArcabitTrojan.Zusy.D7FB36
ViRobotTrojan.Win.Z.Strab.194048
ZoneAlarmHEUR:Trojan.Win32.Strab.gen
MicrosoftTrojan:Win32/Formbook.RPX!MTB
VaristW32/Ninjector.KZ.gen!Eldorado
AhnLab-V3Malware/Win.Generic.R623405
VBA32BScope.Trojan.Strab
ALYacGen:Variant.Zusy.523062
MAXmalware (ai score=83)
MalwarebytesTrojan.FormBook
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.FORMBOOK.USBLKO23
RisingTrojan.Formbook!8.F858 (TFE:5:7gBKttt5UqT)
YandexTrojan.Igent.b1fFge.6
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.124015119.susgen
FortinetW32/ShellcodeRunner.CA!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Formbook.RPX!MTB?

Trojan:Win32/Formbook.RPX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment