Severity scale:  
  (67/100)

FormBook virus. How to remove? (Uninstall guide)

removal by Lucia Danes - - | Type: Malware

FormBook is malware that is used for stealing personal information

FormBook virus spreasd via malicious spam emails

FormBook is a data-stealing malware that spread via malicious spam emails. If a user is tricked into opening an obfuscated email attachment, the virus payload is dropped and executed on the system. During the lifetime, a malicious program caused most of the problems for users in the United States and South Korea.[1]

Summary
Name FormBook
Type Malware
Release year 2016
Danger level High. Makes system changes and steals sensitive data
Distribution method Malicious spam emails attachments (PDF, XSL, DOC, ZIP, etc.)
Symptoms Sluggish computer performance, sudden system shutdowns, delivery of errors.
Most affected countries The United States and South Korea
To uninstall FormBook, install Reimage and run a full system scan

FormBook malware mostly targets businesses and organizations in aerospace, defense contraction, and manufacturing sectors. Hence, home computer users are not the main targets of the malware.

The FormBook virus is known at least since 2016. A few years ago, creators of malware started advertising it in dark web and hacking forums. The program was advertised as:

<…> advance internet activity logging software
coded in low level language ASM/C which means it does not require any dependency to work perfectly on all version of windows.
FormBook is designed with aim to give you extensive and powerful internet monitoring experience
with its ultimate stability alongside flexibility that is above the edge of all existing monitoring/spy tools.

Therefore, FormBook operates not only as a data-stealing virus but malware-as-a-service too. The price for its license starts with $29 per month and ends with $299 for “Pro” version.[2] Though, any evil-minded programmer can obtain a program and try to cause problems for computer users. Meanwhile, developers of original malware generate passive income.

As we have already mentioned, the virus spreads via malicious spam emails and enters the system when a user opens an infected file. Once inside, malware connects to Command and Control (C&C) and starts its malicious tasks.

First of all, it makes system changes and downloads all malicious components in order to perform the following operations:

  • keylogging;
  • taking screenshots,
  • stealing passwords saved in a web browser and email clients;
  • clipboard monitoring;
  • stealing forms information;
  • grabbing network requests.

The loss of sensitive information definitely has a negative impact on company’s and people’s privacy and security. It’s unknown how and when aggregated might be used. However, it’s important to take security measures as soon as you learn about the cyber attack. It goes without saying that FormBook removal has to be your priority.

The complexity of the virus requires using reputable malware removal software to clean the device and fix its damage. We suggest victims to remove FormBook with Reimage or Plumbytes Anti-MalwareMalwarebytes Malwarebytes. Additionally, after virus elimination, people must change their passwords and monitor possible suspicious activities on their accounts.

Malicious email attachments spread data-stealing malware

Just like many similar malicious programs, FormBook spreads via malicious emails and gets into the system when a user opens an obfuscated file. This cyber threat was noticed spreading via archives that included a deadly exe file, such as:

  • ZIP;
  • RAR;
  • ACE;
  • ISOs.

However, malware payload was also noticed spreading via PDF with download links, and DOC and XLS files that contain malicious macro commands. The latter campaign was very active in 2017 and targeted computers in the U.S and South Korea.

The main tip to avoid infiltration of data-stealing malware is not to rush opening unknown email attachments. Indeed, phishing emails might be hard to identify, but you should look up for grammar mistakes, missing credentials or suspicious email address.

The golden rule is – if you did not expect to receive such email, it was not sent to you, and there’s no need to check what is hidden in the attachments. Cybersecurity specialists from Usunwirusa.pl[3] also suggest double-checking the information about the sender, company or provided issue online before opening attached files.

The correct way to eliminate FormBook malware

FormBook removal requires using professional and powerful security software. Malware downloads numerous malicious files and can affect legit system process. Therefore, there’s no way to locate and delete these entries safely.

Tools like Reimage, Plumbytes Anti-MalwareMalwarebytes Malwarebytes or Malwarebytes MalwarebytesCombo Cleaner can remove FormBook from the affected computer. However, if you have some difficulties, please follow the instructions below. They will explain how to disable the virus and run security software.

We want to remind that you should not forget to change your email, social network, online banking and other account passwords.

 

Offer
We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to remove virus damage. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.
More information about this program can be found in Reimage review.

If you decided to select another anti-spyware, uninstall Reimage from your computer.
Press mentions on Reimage
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with Malwarebytes.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with Combo Cleaner.

To remove FormBook virus, follow these steps:

Remove FormBook using Safe Mode with Networking

If you cannot run security software to eliminate FormBook, follow these steps to disable it and run security software:

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove FormBook

    Log in to your infected account and start the browser. Download Reimage or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete FormBook removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove FormBook using System Restore

This method might also help to activate security software which is needed for malware removal:

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of FormBook. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage and make sure that FormBook removal is performed successfully.

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from FormBook and other ransomwares, use a reputable anti-spyware, such as Reimage, Malwarebytes MalwarebytesCombo Cleaner or Plumbytes Anti-MalwareMalwarebytes Malwarebytes

About the author

Lucia Danes
Lucia Danes - Virus researcher

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Lucia Danes
About the company Esolutions

References