Malware

About “Fosniw.13” infection

Malware Removal

The Fosniw.13 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fosniw.13 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Fosniw.13?


File Info:

name: DAF5DB226288D1FDAE83.mlw
path: /opt/CAPEv2/storage/binaries/aa6ed758a7ae53f8b02785c00ffcc50071b12e21da57884a360b355af14a2815
crc32: 0B2AB879
md5: daf5db226288d1fdae83e3be68e75067
sha1: f2d5b15d746153d18e2ed43a136ae5bfbdf56648
sha256: aa6ed758a7ae53f8b02785c00ffcc50071b12e21da57884a360b355af14a2815
sha512: 83698287ae489c600447d98aa9b106e7f3b8a995eaee361555ebff94857fff56acd3b6b17df8eede0152f2a73e5e2e83ceae8bcff7e50824a72f77b58fc7cc2a
ssdeep: 768:FUlH5WpC47Z5kqSEuaiwJI+TTIyvKLclDYIy0Pt6jInhLtrlm3BsEvkEA:FSH5WpC6cEjiwJI+TjyolDHnPThRlm3W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AD03F1CDE969E752E076667387737068A4FE0A04FE4E82469739043FD3B67422738726
sha3_384: d0f5b8f7b91efa3ef076eafa911bb4d734258e310230d2936ed312ddf9a46ed918959c628702c939c19df78775286575
ep_bytes: b8b02d42005064ff3500000000648925
timestamp: 2011-08-06 21:54:43

Version Info:

0: [No Data]

Fosniw.13 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Fosniw.lqe3
DrWebTrojan.DownLoad3.2425
MicroWorld-eScanGen:Variant.Fosniw.13
FireEyeGeneric.mg.daf5db226288d1fd
CAT-QuickHealTrojan.Generic.30020
SkyhighBehavesLike.Win32.Corrupt.nc
McAfeeArtemis!DAF5DB226288
MalwarebytesGeneric.Malware/Suspicious
ZillyaDownloader.Fosniw.Win32.48343
SangforDownloader.Win32.Fosniw.V115
AlibabaTrojanDownloader:Win32/Fosniw.24a8349c
Cybereasonmalicious.26288d
BitDefenderThetaGen:NN.ZexaF.36802.cmWfaW0VWFl
VirITTrojan.Win32.DownLoad3.DPH
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Fosniw.AO
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DAT24
AvastWin32:Evo-gen [Trj]
ClamAVWin.Downloader.126474-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Fosniw.13
NANO-AntivirusTrojan.Win32.PEPM.uyjyr
TencentWin32.Trojan.Generic.Rimw
SophosTroj/Fosniw-F
F-SecureTrojan.TR/Crypt.PEPM.Gen
VIPREGen:Variant.Fosniw.13
TrendMicroTROJ_GEN.R002C0DAT24
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Fosniw.13 (B)
IkarusTrojan-Downloader.Win32.Fosniw
MAXmalware (ai score=100)
JiangminTrojan/PSW.Lmir.dah
GoogleDetected
AviraTR/Crypt.PEPM.Gen
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojanDownloader:Win32/Fosniw.B
XcitiumMalware@#2qzfjrpkt7tz4
ArcabitTrojan.Fosniw.13
ViRobotTrojan.Win32.A.Downloader.37888.CG
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Fosniw.13
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Winsoft.R9826
VBA32TrojanDownloader.Fosniw
ALYacGen:Variant.Fosniw.13
Cylanceunsafe
PandaTrj/Genetic.gen
RisingDownloader.Fosniw!8.9DA (TFE:4:qRAp7Wg3VaM)
YandexTrojan.DL.Fosniw!Qo9lgDAQtjA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3380730.susgen
FortinetW32/Fosniw.AP!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan

How to remove Fosniw.13?

Fosniw.13 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment