Formbook is an information-stealing malware that's been circulating since 2016, and it remains one of the most frequently detected threats in our Roswell shop today. It's distributed as malware-as-a-service on underground forums, meaning dozens of criminal operators can rent access to deploy it against victims. Once installed, Formbook silently records everything you type—passwords, credit card numbers, bank logins—and sends it all back to whoever infected you.
Think you're infected right now? Disconnect from the internet immediately (unplug Ethernet or disable WiFi). Do not enter any passwords or financial information. Call us at (770) 569-3487 or bring your machine to our Roswell location at 1000 Mansell Exchange West. We can typically isolate and remove Formbook infections same-day.

Threat Profile

Threat Name Formbook
Aliases win.xloader, XLoader (later variant)
Classification Information Stealer / Keylogger
Platform Windows (all versions from XP through 11)
File Type Windows PE Executable
First Observed Early 2016
Distribution Model Malware-as-a-Service (MaaS)
Crypter/Packer Custom "Babushka Crypter" with unique RunPE behavior
Target Data Credentials, browser data, FTP clients, email, keystrokes, screenshots
Persistence Method Registry Run keys, scheduled tasks, startup folder entries
Detection Rate High across major antivirus engines (often 40+ detections)
Threat Level High — immediate financial and identity theft risk

How It Spreads

Formbook reaches victims almost exclusively through email campaigns. The operators behind each rental deployment craft phishing messages tailored to their targets—we've seen invoices, shipping notices, job applications, tax documents, and COVID-related lures. The initial file is rarely the malware itself; instead, you'll receive an attachment designed to trick you into executing the payload. Because Formbook is rented out to many different criminal groups, distribution methods vary week to week. What doesn't change is the reliance on social engineering to get you to open something you shouldn't. The operators know that antivirus software watches for known malware signatures, so they constantly rotate the delivery mechanism to stay ahead of detection. Common distribution vectors include: - **Malicious email attachments** — typically archive files (ZIP, RAR, 7Z) containing executables disguised with PDF or DOC icons - **Office documents with macros** — Word or Excel files that prompt you to "Enable Content" or "Enable Editing," which executes hidden code - **Weaponized PDF files** — exploit documents that launch the payload when opened in vulnerable PDF readers - **JavaScript droppers** — .JS or .JSE files that download and execute Formbook when double-clicked - **Trojanized software installers** — legitimate-looking programs bundled with the malware, often distributed via fake download sites or torrent repositories - **Archive bombs** — nested ZIP files designed to evade automated email scanners before delivering the payload

What It Does On Your Machine

Once executed, Formbook unpacks itself using a custom crypter nicknamed "Babushka" by malware researchers. This crypter employs a technique called process hollowing or RunPE: it launches a legitimate Windows process (often explorer.exe or a system utility), suspends it, replaces its memory with malicious code, and resumes execution. To your Task Manager, everything looks normal—no suspicious filenames, no obvious red flags. Formbook then establishes persistence so it survives reboots. It typically writes itself to hidden folders in your user profile or AppData directories, then creates registry entries or scheduled tasks to ensure it runs every time Windows starts. The malware operates almost entirely in memory to avoid leaving obvious traces on disk, which makes traditional file-based scanning less effective. The primary function is credential theft. Formbook hooks into your web browsers, email clients, and FTP programs to intercept login credentials as you type them. It captures HTTP POST data before encryption occurs, meaning even HTTPS-protected sites offer no defense once your machine is compromised. It also takes periodic screenshots and logs every keystroke across all applications. All this stolen data gets encrypted and transmitted to a command-and-control server, typically using HTTP POST requests to hacked WordPress sites or compromised web servers.
Observed Formbook Indicators (from sandbox analysis): C:\Users\[username]\AppData\Local\Temp\[random].exe ← initial dropper location C:\Users\[username]\AppData\Roaming\[random folder name]\ ← persistence installation Registry modifications (persistence): HKCU\Software\Microsoft\Windows\CurrentVersion\Run [random value name] = "[path to payload]" Process injection targets (observed): explorer.exe ← memory injection detected svchost.exe ← alternate injection target Network communication: HTTP POST to compromised domains ← exfiltration channel Encrypted data payload in POST body
Beyond stealing credentials, Formbook functions as a general-purpose backdoor. Operators can issue commands to download and execute additional malware, update the infection, or uninstall it remotely if they believe they've been detected. This means a Formbook infection can serve as the entry point for ransomware, banking trojans, or other secondary threats.

Manual Removal — Step by Step

01

Disconnect from the internet immediately

Unplug your Ethernet cable or disable WiFi. This stops Formbook from transmitting any additional stolen data and prevents the operators from issuing remote commands to your infected machine.

Formbook — cybersecurity illustration
Photo by Lucas Andrade on Pexels
02

Boot into Safe Mode with Networking

Restart your computer. As it boots, press F8 repeatedly (or Shift+F8 on newer systems) to access Advanced Boot Options. Select "Safe Mode with Networking." This loads Windows with minimal drivers and prevents most malware from auto-starting, including Formbook's persistence mechanisms.

03

Run a full scan with updated antivirus software

Open your existing antivirus program and update its definitions before scanning. If you don't have antivirus installed, download Malwarebytes or HitmanPro from a clean computer and transfer via USB drive. Run a complete system scan—this will take 30 minutes to several hours depending on your drive size.

04

Manually check startup programs and scheduled tasks

Press Win+R, type msconfig, and hit Enter. Go to the Startup tab (or open Task Manager > Startup tab on Windows 8/10/11). Look for unfamiliar entries with random names or paths pointing to AppData folders. Disable anything suspicious. Then open Task Scheduler (search for it in Start menu) and review scheduled tasks for recently-added entries with gibberish names.

05

Inspect registry Run keys

Press Win+R, type regedit, and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Look for entries you don't recognize. Right-click and delete any suspicious values—but be cautious, as legitimate programs also use these keys.

06

Delete temporary and AppData folders manually

Navigate to C:\Users\[YourUsername]\AppData\Local\Temp and delete all contents. Then check AppData\Roaming for recently-created folders with random names (usually 8-10 characters). Formbook often hides here. Delete any folders you don't recognize, but note that some legitimate programs also store data in AppData.

07

Clear browser data and check for extensions

Formbook can inject malicious browser extensions. Open each browser (Chrome, Firefox, Edge), go to Extensions or Add-ons, and remove anything you didn't intentionally install. Then clear your browsing history, cache, and saved passwords entirely—assume all stored credentials have been compromised.

08

Run a second-opinion scanner

Download and run a different scanning tool (if you used Malwarebytes earlier, now try HitmanPro or Microsoft Safety Scanner). Different engines detect different signatures, and Formbook's crypter can sometimes evade a single product. Scan again and remove any additional threats found.

09

Change all passwords from a clean device

This is critical: do not change passwords from the infected computer, even after cleaning. Use your phone, tablet, or a different computer. Change passwords for email, banking, shopping sites, social media—everything. Enable two-factor authentication wherever possible.

10

Monitor financial accounts and consider a credit freeze

Review your bank and credit card statements for unauthorized transactions. Set up fraud alerts with your bank. If you entered Social Security numbers, tax information, or other sensitive data during the infection period, consider placing a credit freeze with the three major bureaus (Equifax, Experian, TransUnion).

Prevention

  1. Never enable macros in unsolicited Office documents. If a Word or Excel file asks you to "Enable Content" or "Enable Editing" and you weren't expecting it, delete it immediately. Legitimate businesses rarely send macro-enabled documents to strangers.
  2. Scrutinize email attachments before opening. Look at the sender address carefully—not just the display name. Hover over links to see where they really point. If you receive an unexpected invoice, shipping notice, or resume, contact the supposed sender through a separate channel to verify authenticity.
  3. Avoid opening archive files from unknown sources. ZIP and RAR attachments are a favorite Formbook delivery method. If you must open one, scan it with antivirus first and examine the contents before executing anything inside.
  4. Keep Windows and all software updated. Many Formbook campaigns exploit known vulnerabilities in PDF readers, Office, or Windows components. Enable automatic updates for Windows, Adobe Reader, Java, browsers, and any other frequently-used software.
  5. Use a reputable antivirus with real-time protection. Free options like Windows Defender are acceptable if kept updated, but paid solutions often include behavior-based detection that catches Formbook's process injection techniques before they succeed.
  6. Disable Windows Script Host if you don't need it. Many Formbook droppers arrive as .JS or .VBS files. Most home users never legitimately run script files. You can disable WSH through Group Policy or registry edits, eliminating an entire attack vector.
  7. Implement email filtering for executable attachments. If you run a small business, configure your email server or service to block .exe, .scr, .js, .vbs, .jar, and other executable file types, even inside archives. Legitimate vendors can send installers via download links instead.
  8. Back up your data regularly to an offline or cloud location. While Formbook itself isn't ransomware, it's often a precursor to it. Regular backups ensure you can recover if a secondary infection encrypts your files.
Our 90-Day Warranty: When we remove Formbook (or any malware) from your machine, that work is covered by our 90-day guarantee. If the same infection comes back within three months, we'll re-clean your system at no additional charge. We stand behind our work because we do it right the first time.

Bring It In

Formbook removal requires more than running a quick scan. The malware's process injection techniques and memory-resident behavior mean infections often survive superficial cleaning attempts. We've removed dozens of Formbook infections from Roswell-area computers over the past few years, and we've developed reliable procedures to eliminate it completely—including the forensic steps needed to verify your system is truly clean. Our shop is located at 1000 Mansell Exchange West in Roswell, just off Mansell Road near the Publix shopping center. Bring your machine in and we'll perform a full diagnostic and cleaning, typically completing the work same-day for infected systems. We'll also walk you through the password-change process and help you secure your accounts against the data that was stolen. Call us at (770) 569-3487 to check current wait times or schedule a drop-off. Don't let stolen credentials turn into drained bank accounts—get it taken care of today.