Malware

What is “Win32:Fosniw-E [Trj]”?

Malware Removal

The Win32:Fosniw-E [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Fosniw-E [Trj] virus can do?

  • Authenticode signature is invalid

How to determine Win32:Fosniw-E [Trj]?


File Info:

name: 91ED42521B89723F226D.mlw
path: /opt/CAPEv2/storage/binaries/25c1137e21bb0110ffbbad3708c65b5e546b62616d861427cd9a98407d568801
crc32: 5D90317B
md5: 91ed42521b89723f226db1b5740b6041
sha1: 54d4edb83bac552d7a6d4de14ab26ee7fe5d2f1f
sha256: 25c1137e21bb0110ffbbad3708c65b5e546b62616d861427cd9a98407d568801
sha512: 6b25162c5382032c1684dedbcf96ec5c9be6e0a7dbc573f9dc492c34dd4bb305802f6ab8458883b8f23b28597535e123d3f7b22d8a3794235457625886fac2ca
ssdeep: 3072:IrsIDqxMyrkuJ+VCkYJiuUK3ep1lNWPcTHGXBfIthtoJH+yt14Q:v2qxMyrEVeU0eXlMvfIoJHuQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18D443B007A50C036F453147A897EC7B65A6EB8217B15B9E7ABC41E7D8F386F3B63050A
sha3_384: 54be4db4ca4924b2acab35ac5cad1aa9a892edb392e167950dc3135addd5263089d7eb95e1dd5edba3dd573339fc5c97
ep_bytes: e82fb80000e978feffffcccc68502d41
timestamp: 2010-12-02 15:38:22

Version Info:

0: [No Data]

Win32:Fosniw-E [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.llHj
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.480378
FireEyeGeneric.mg.91ed42521b89723f
CAT-QuickHealTrojanDownloader.Fosniw.C5
SkyhighBehavesLike.Win32.Generic.dh
ALYacGen:Variant.Graftor.480378
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Scar.Win32.77718
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004edc381 )
BitDefenderGen:Variant.Graftor.480378
K7GWTrojan ( 004edc381 )
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Fosniw.AU
APEXMalicious
KasperskyTrojan.Win32.Scar.efuj
AlibabaTrojanDownloader:Win32/Fosniw.4c0583af
NANO-AntivirusRiskware.Win32.IEKeyword.qsrhj
ViRobotTrojan.Win32.Fosniw.Gen
RisingTrojan.Agent!1.6A26 (CLASSIC)
SophosMal/Generic-S
F-SecureTrojan.TR/Dldr.Fosniw.BA
DrWebTrojan.DownLoader3.18924
VIPREGen:Variant.Graftor.480378
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.480378 (B)
IkarusTrojan.Win32.Scar
JiangminTrojan/Scar.arqq
GoogleDetected
AviraTR/Dldr.Fosniw.BA
VaristW32/S-31f1e95c!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Fosniw.au
MicrosoftTrojanDownloader:Win32/Fosniw.C
XcitiumApplicUnwnt.Win32.AdWare.Agent.cljb@4f3c9v
ArcabitTrojan.Graftor.D7547A
ZoneAlarmTrojan.Win32.Scar.efuj
GDataGen:Variant.Graftor.480378
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.C290574
BitDefenderThetaAI:Packer.F3B8467C1E
DeepInstinctMALICIOUS
VBA32Trojan.Scar
Cylanceunsafe
PandaTrj/Genetic.gen
TencentWin32.Trojan.Scar.Htgl
YandexTrojan.GenAsa!aeopJSsKQPk
SentinelOneStatic AI – Malicious PE
FortinetW32/Dloader.ANW!tr
AVGWin32:Fosniw-E [Trj]
AvastWin32:Fosniw-E [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32:Fosniw-E [Trj]?

Win32:Fosniw-E [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment