Trojan

Trojan:Win32/FormBook.SD!MTB removal guide

Malware Removal

The Trojan:Win32/FormBook.SD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.SD!MTB virus can do?

  • Authenticode signature is invalid

How to determine Trojan:Win32/FormBook.SD!MTB?


File Info:

name: FC26164FE63A87E88FAC.mlw
path: /opt/CAPEv2/storage/binaries/af007399531c8ceab8a3a9060db9a2cae49525e52fc78e9161b8330c9f791507
crc32: 8C2C8ED4
md5: fc26164fe63a87e88fac9f50b440b463
sha1: f80227ac829b4b7b06b30be43bd4e50d523dba0d
sha256: af007399531c8ceab8a3a9060db9a2cae49525e52fc78e9161b8330c9f791507
sha512: 11fdd3377d536e16c870fb885a0b100d61130f9fb83fe748b7b430382f2f62aa82df2e0eeb5313e1896e62c82665ea55bda15ca5466ad810170d9ed79b2cdc3b
ssdeep: 96:thuB/yRk146746IPtboynjqjgyodGSwHEVKwH:KB/W6k6IP1oynjqjRocSzgwH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17DB1E68B972108E2CA5D8FF42D31961C8F6614074B2A827986E78CC4C1F9B24A52331F
sha3_384: 2a7a261c3ff32640c630a7efcc684e6be1d2a91246ae3e46bd91c56d483464a95d17cc3cdeb6e060cd56078f5f51b15e
ep_bytes: 558bec6aff68f8204000686012400064
timestamp: 2023-03-14 08:02:56

Version Info:

0: [No Data]

Trojan:Win32/FormBook.SD!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Loader.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Molotov.IM.35.100
SkyhighBehavesLike.Win32.Downloader.zt
Cylanceunsafe
ZillyaTrojan.Injector.Win32.1638566
SangforSuspicious.Win32.Save.ins
AlibabaTrojan:Win32/Injector.8efec775
K7GWTrojan ( 005a0d7e1 )
K7AntiVirusTrojan ( 005a0d7e1 )
ArcabitTrojan.Molotov.IM.35.100
VirITTrojan.Win32.PSWStealer.EXM
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ESUG
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DBG24
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Heur.Molotov.IM.35.100
NANO-AntivirusTrojan.Win32.Loader.jvywhh
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Injector!1.E2E1 (CLASSIC)
EmsisoftGen:Heur.Molotov.IM.35.100 (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Loader.1341
VIPREGen:Heur.Molotov.IM.35.100
TrendMicroTROJ_GEN.R002C0DBG24
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fc26164fe63a87e8
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
WebrootW32.Injector.Gen
GoogleDetected
AviraTR/ATRAPS.Gen
VaristW32/Downloader-Sml!Eldorado
Antiy-AVLGrayWare/Win32.Wacapew
KingsoftWin32.HeurC.KVMH012.a
MicrosoftTrojan:Win32/FormBook.SD!MTB
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGen:Heur.Molotov.IM.35.100
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.NsisInject.R562450
McAfeeGenericRXAA-AA!FC26164FE63A
MAXmalware (ai score=100)
VBA32BScope.Trojan.Loader
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ZonerTrojan.Win32.154442
TencentMalware.Win32.Gencirc.10be7a8e
YandexTrojan.Injector!Gvje362edGo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.202989576.susgen
FortinetW32/Injector.ESTE!tr
BitDefenderThetaGen:NN.ZexaF.36804.aqW@aOZg23
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Trojan:Win32/FormBook.SD!MTB?

Trojan:Win32/FormBook.SD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment