Trojan

Should I remove “Trojan.Win32.Cosmu.dnej”?

Malware Removal

The Trojan.Win32.Cosmu.dnej is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cosmu.dnej virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Overwrites multiple files with zero bytes (hex 00) indicative of a wiper

How to determine Trojan.Win32.Cosmu.dnej?


File Info:

name: 9488465D35FD9545751C.mlw
path: /opt/CAPEv2/storage/binaries/311e76ed7346476fe6dc9913856ec1368ea0907d967cb6b73d8066ca3b926bcf
crc32: A64857B8
md5: 9488465d35fd9545751c38aae7e12af4
sha1: 59a41da744758ec29605da74d5ecf38576687eee
sha256: 311e76ed7346476fe6dc9913856ec1368ea0907d967cb6b73d8066ca3b926bcf
sha512: fe08300869db21235e50e804e214bf922023493d5d3f28bd6e27cdadd82185144a6d65e1f528fc1c3ae72133f6d5365dfd785a508c505f6da5efda734408543d
ssdeep: 3072:jPgp5XXRvjxCb5NgXDY7uSlkJcUa7kYQTcqW2NdQQGH/UDhSCUc4aqTBW1JrP:zElKgzelZNQSBQGH/CSpWqTG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D94F15179E2C8B2D49289364CAA8B169737BA178A74D043B7D90F8F5E713C49F2F342
sha3_384: a4f8279a4c6a42ba2b8625a0e8e085a830bca2e72a1799915ff6879db4412b6034909516dee15d2af3e23a2f7cd0c5da
ep_bytes: e812470000e916feffff558bec81ec28
timestamp: 2008-09-27 04:51:42

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Watson Subscriber for SENS Network Notifications
FileVersion: 11.0.8160
InternalName: dwtrig20.exe
LegalCopyright: Copyright © 2002-2003 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: dwtrig20.exe
ProductName: Watson Subscriber for SENS Network Notifications
ProductVersion: 11.0.8160
Translation: 0x0000 0x04e4

Trojan.Win32.Cosmu.dnej also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanWorm.Generic.388260
CAT-QuickHealW32.Cosmu.D4
ALYacWorm.Generic.388260
CylanceUnsafe
VIPREWorm.Generic.388260
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.d35fd9
BaiduWin32.Worm.Agent.bg
VirITTrojan.Win32.MulDrop4.JZQ
CyrenW32/Agent.BYQ.gen!Eldorado
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32Win32/Agent.NLP
APEXMalicious
KasperskyTrojan.Win32.Cosmu.dnej
BitDefenderWorm.Generic.388260
NANO-AntivirusTrojan.Win32.Agetn2.bbdyxx
AvastWin32:Malware-gen
TencentTrojan.Win32.Cosmu.c
Ad-AwareWorm.Generic.388260
EmsisoftWorm.Generic.388260 (B)
ComodoTrojWare.Win32.Cosmu.NLP@7v4zem
DrWebWin32.HLLW.Siggen.10550
ZillyaWorm.Cosmu.Win32.58
McAfee-GW-EditionBehavesLike.Win32.Generic.gt
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9488465d35fd9545
SophosML/PE-A + W32/Renamer-I
IkarusWorm.Agent
GDataWin32.Trojan.PSE.OQKX5H
JiangminWorm/Generic.abjq
WebrootW32.Trojan.Gen
AviraWORM/Agent.2170901
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.E5
ArcabitWorm.Generic.D5ECA4
MicrosoftVirus:Win32/Emdup.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cosmu.R230705
Acronissuspicious
McAfeeGenericRXFU-SQ!9488465D35FD
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingWorm.Agent!1.B398 (CLASSIC)
YandexTrojan.GenAsa!LdHJgsFIunw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Naglov.OA!tr
BitDefenderThetaGen:NN.ZexaF.34582.Aq1@aiultXo
AVGWin32:Malware-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Cosmu.dnej?

Trojan.Win32.Cosmu.dnej removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment