Trojan

Trojan:Win32/Msposer.I removal tips

Malware Removal

The Trojan:Win32/Msposer.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Msposer.I virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Msposer.I?


File Info:

name: 049796CF05A70E0AB5D4.mlw
path: /opt/CAPEv2/storage/binaries/3bff63e53140dcaf1b61e0838a180d9e6b997298c715553abc4cb56471221acc
crc32: 1B9B7657
md5: 049796cf05a70e0ab5d4a63737e3d4a6
sha1: 5e7607a18bc0501163a8f098e49b130054b3c94c
sha256: 3bff63e53140dcaf1b61e0838a180d9e6b997298c715553abc4cb56471221acc
sha512: 97de5d4d3d2f4e1a8634489391706e33a6cbfcf96d26bd0cf571c3d8522a500459c4388de2aade6ac1ed1bf4cf0b2c2a86e29ccaabeda0e138a6be300eb6d98b
ssdeep: 1536:nFyzF9MFVCujlsQoeQZZ86ukpj0nGGF9v+4DRUW:FyzQVCujl71QZZ4kp4F9XtUW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FC329137D11106BC455CEF088A99A7AB6B09F261EE1AD4732C4BB996CF0A077DF121F
sha3_384: 671d984866acbb12c0f57955f03ef525ad009b3e58f22da25c1339f0bcce505b7ce7dbdf3448a92b69408683e662c2fc
ep_bytes: 68782d4000e8eeffffff000048000000
timestamp: 2012-06-19 19:24:01

Version Info:

Translation: 0x0409 0x04b0
ProductName: Main
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Main
OriginalFilename: Main.exe

Trojan:Win32/Msposer.I also known as:

BkavW32.FamVT.RenamerV.Trojan
LionicTrojan.Win32.VB.to6k
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.250
MicroWorld-eScanTrojan.GenericKD.40387285
FireEyeGeneric.mg.049796cf05a70e0a
CAT-QuickHealTrojan.Msposer.A3
McAfeeGeneric VB.kr
MalwarebytesVB.Trojan.Generic.DDS
VIPRETrojan.GenericKD.40387285
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003b42321 )
AlibabaTrojan:Win32/Msposer.1366
K7GWP2PWorm ( 003b42321 )
Cybereasonmalicious.f05a70
BitDefenderThetaAI:Packer.8793CD9D20
VirITTrojan.Win32.Generic.ACKE
CyrenW32/Sisron.H.gen!Eldorado
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.QOT
APEXMalicious
ClamAVWin.Malware.Swisyn-9942393-0
KasperskyTrojan-Dropper.Win32.VB.blie
BitDefenderTrojan.GenericKD.40387285
NANO-AntivirusTrojan.Win32.VB.flqldy
SUPERAntiSpywareTrojan.Agent/Gen-Graftor
AvastWin32:VB-OJQ [Wrm]
TencentTrojan.Win32.Swisyn.wa
EmsisoftTrojan.GenericKD.40387285 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan.VB.gp
ZillyaDropper.VB.Win32.49357
TrendMicroPE_SWISB.A-O
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ch
Trapminemalicious.high.ml.score
SophosTroj/VB-GJY
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Agent.BID
JiangminTrojanDropper.VB.avfm
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Dropper]/Win32.VB
XcitiumTrojWare.Win32.VB.QOTT@4qfd0d
ArcabitTrojan.Generic.D26842D5
ZoneAlarmTrojan-Dropper.Win32.VB.blie
MicrosoftTrojan:Win32/Msposer.I
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Pincav.C12642
Acronissuspicious
ALYacTrojan.GenericKD.40387285
TACHYONTrojan-Dropper/W32.VB-Agent.125602
VBA32TrojanDropper.VB
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallPE_SWISB.A-O
RisingTrojan.VB!1.6519 (CLASSIC)
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.QOT!tr
AVGWin32:VB-OJQ [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Msposer.I?

Trojan:Win32/Msposer.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment