Malware

Win32/Formbook.AL removal tips

Malware Removal

The Win32/Formbook.AL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Formbook.AL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Formbook malware family
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Touches a file containing cookies, possibly for information gathering
  • Harvests information related to installed mail clients
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Formbook.AL?


File Info:

name: 96D4E822CB0D8974A42A.mlw
path: /opt/CAPEv2/storage/binaries/ba0b493974021eb6d5159719c5380086bd90847a5d664c77be725df3105a51df
crc32: 2C21D6B6
md5: 96d4e822cb0d8974a42aa179b379224f
sha1: d8b61a54818a5b8b3ccb90d5e02271d9068c6ab4
sha256: ba0b493974021eb6d5159719c5380086bd90847a5d664c77be725df3105a51df
sha512: ee3c50ae589d1bcc5142913d591f913e0bd90d48fe229fc6dc14cf05d41fb4a80d9c8e91ee586f803063003c927aab24f24adce260ee084025a9176dd0a2302d
ssdeep: 3072:qlpyE9Y0CUHp1IdunpGrySy++Nyy65H/1YFlgpOvy2:Ybp6QnpGrySy/NP65HW4O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14404AE36D642C030E2B251B5F67D1B7B493E0E343294A4AAE3F215E06EB19A5F47931F
sha3_384: ab0e1becb0cf06aa64b730088b57072d3439b645e1013957cc501499731c0745c2a3e2b65b5c7f7f8116f015e9ac984a
ep_bytes: 558bec83ec64e835c9ffff8be55dc3e8
timestamp: 2001-06-27 03:48:48

Version Info:

0: [No Data]

Win32/Formbook.AL also known as:

BkavW32.AIDetectMalware
ElasticWindows.Trojan.Formbook
DrWebTrojan.Siggen9.48175
MicroWorld-eScanGen:Variant.Razy.769934
ClamAVWin.Malware.Formbook-7399661-0
FireEyeGeneric.mg.96d4e822cb0d8974
McAfeeGenericRXCD-ZZ!96D4E822CB0D
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00536d121 )
K7GWTrojan ( 00536d121 )
Cybereasonmalicious.2cb0d8
BitDefenderThetaAI:Packer.1121F0391E
CyrenW32/Formbook.F.gen!Eldorado
SymantecTrojan.Formbook
ESET-NOD32a variant of Win32/Formbook.AL
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.769934
NANO-AntivirusVirus.Win32.Gen.ccmw
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
EmsisoftGen:Variant.Razy.769934 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPREGen:Variant.Razy.769934
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
SophosTroj/Formbook-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10Z9ZNT
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLGrayWare/Win32.Formbook.A
ArcabitTrojan.Razy.DBBF8E
ZoneAlarmUDS:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Formbook!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Formbook.X2185
Acronissuspicious
VBA32BScope.TrojanPSW.Banker
ALYacGen:Variant.Razy.769934
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
RisingStealer.Formbook!1.C470 (CLASSIC)
IkarusTrojan.Win32.Formbook
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.AYEB!tr
AVGWin32:Formbook-B [Trj]
AvastWin32:Formbook-B [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Formbook.AL?

Win32/Formbook.AL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment