Malware

Win32:Fosniw-D [Trj] removal tips

Malware Removal

The Win32:Fosniw-D [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Fosniw-D [Trj] virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32:Fosniw-D [Trj]?


File Info:

name: 14C9DE725AB3200C037F.mlw
path: /opt/CAPEv2/storage/binaries/23f5cec3694a5816309a9e9adc36f29dd6f8756b9cfb29da18a2bb89a7bdee11
crc32: 7A3FF87A
md5: 14c9de725ab3200c037fc76436b5213d
sha1: d17435fec93b0f166b20ee688adfa5ade9017275
sha256: 23f5cec3694a5816309a9e9adc36f29dd6f8756b9cfb29da18a2bb89a7bdee11
sha512: 6adc6586a9fa2d111a3e217c7e859ad8db17e6bfa5bb417ccfded92474087e8d05d0f248fcd105d28a89e69e1dbfa6e342515f47be7a0621bfa34cfd20058c1d
ssdeep: 1536:LwVG0Dz6ounUK45PuItRSII5eAXS9GkFN7PVgQRQkgH9:LcJDgR45JI5QNrVgQqkgH9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8C3061134F0CC7DF716E532C8F586AEDA3AA5301EE48D83BFE8077A5E15293563924A
sha3_384: 2e51947535715fc5f2830229e8141af9af1c3f92f1b5c70332dae9cfc6f039dfb2739dcd3b0e78fd6b7a41cc193981d2
ep_bytes: e8e85c0000e978feffffcccccccccccc
timestamp: 2010-11-10 13:51:18

Version Info:

0: [No Data]

Win32:Fosniw-D [Trj] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.14c9de725ab3200c
McAfeeArtemis!14C9DE725AB3
CylanceUnsafe
ZillyaWorm.Palevo.Win32.80026
SangforTrojan.Win32.Save.a
Cybereasonmalicious.ec93b0
CyrenW32/Fosniw.B.gen!Eldorado
SymantecW32.Palevo
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Fosniw.AU
CynetMalicious (score: 100)
APEXMalicious
KasperskyP2P-Worm.Win32.Palevo.bhnc
NANO-AntivirusTrojan.Win32.Palevo.seytw
ViRobotTrojan.Win32.Generic.94720.A
RisingDownloader.Fosniw!1.9D32 (CLASSIC)
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Click2.4559
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminemalicious.high.ml.score
IkarusTrojan-Downloader.Win32.Fosniw
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojanDownloader:Win32/Fosniw.C
ZoneAlarmHEUR:Trojan.Win32.Generic
GoogleDetected
AhnLab-V3Trojan/Win.Winsoft.R505962
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34592.hqW@aakGwF
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!J5xEI2pOBjY
SentinelOneStatic AI – Malicious PE
MaxSecureP2P-Worm.Palevo.bhnc
FortinetW32/Dloader.ANW!tr
AVGWin32:Fosniw-D [Trj]
AvastWin32:Fosniw-D [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:Fosniw-D [Trj]?

Win32:Fosniw-D [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment