Trojan

Trojan:Win32/FormBook.W!MTB removal instruction

Malware Removal

The Trojan:Win32/FormBook.W!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/FormBook.W!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/FormBook.W!MTB?


File Info:

crc32: 4D606219
md5: ed4fd4842ed4f6b6564e03bfebe84d8d
name: win32.exe
sha1: d2c0721d50beafb065dc2621ae39e7f385fe5674
sha256: cb5db0ab3dba394df47917f79b38a5412950f5c836e095d3c1d55495f7b66b70
sha512: 4e5bacc0330c9deabfe49f6aafbd066ed828cddc5e536069626f0c741e65184dc1f45e9756558c8a9f5bd2bf611cc41d571bc6083c9ddd86573ddce4bf90c1e9
ssdeep: 384:c5VwhZJ9GtRVDFEKd9qZa9Qw32bMZhnkfvpC0elTzQnQ1IbrTnv+:cfwd9GtRVDKeFsQvup6QQ1Irv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: collaborates
InternalName: Skringspunkt7
FileVersion: 1.00.0001
CompanyName: Overalt
LegalTrademarks: Tilskuer4
Comments: MASSACHUSET
ProductName: FENDERS
ProductVersion: 1.00.0001
FileDescription: skjortebryst
OriginalFilename: Skringspunkt7.exe

Trojan:Win32/FormBook.W!MTB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33371746
FireEyeGeneric.mg.ed4fd4842ed4f6b6
Qihoo-360Generic/Trojan.18f
McAfeeRDN/Generic.dx
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005615471 )
BitDefenderTrojan.GenericKD.33371746
K7GWTrojan ( 005615471 )
TrendMicroTROJ_GEN.R002C0PBQ20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33371746
KasperskyTrojan-Spy.Win32.Noon.aveo
AlibabaTrojanSpy:Win32/Injector.9cd21ea7
NANO-AntivirusTrojan.Win32.Noon.hctqkt
AegisLabTrojan.Win32.Noon.l!c
RisingSpyware.Noon!8.E7C9 (CLOUD)
EmsisoftTrojan.GenericKD.33371746 (B)
F-SecureTrojan.TR/AD.VBCryptor.rajxh
McAfee-GW-EditionRDN/Generic.dx
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.VB.Crypt
CyrenW32/Trojan.WQCR-1110
AviraTR/AD.VBCryptor.rajxh
MAXmalware (ai score=100)
ArcabitTrojan.Generic.D1FD3662
ZoneAlarmTrojan-Spy.Win32.Noon.aveo
MicrosoftTrojan:Win32/FormBook.W!MTB
VBA32TScope.Trojan.VB
ALYacTrojan.Agent.Wacatac
Ad-AwareTrojan.GenericKD.33371746
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKTZ
TrendMicro-HouseCallTROJ_GEN.R002C0PBQ20
TencentWin32.Trojan-spy.Noon.Alsp
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.EKRR!tr
BitDefenderThetaGen:NN.ZevbaF.34090.cm0@amNuuRpb
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.74976047.susgen

How to remove Trojan:Win32/FormBook.W!MTB?

Trojan:Win32/FormBook.W!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment