Trojan

Trojan:Win32/Poshefus.STA removal instruction

Malware Removal

The Trojan:Win32/Poshefus.STA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Poshefus.STA virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan:Win32/Poshefus.STA?


File Info:

crc32: 73F2BE55
md5: 315138347a5c976c27a0231460126963
name: 315138347A5C976C27A0231460126963.mlw
sha1: 6fafe4f7cc7d336d5bf24c7fc1ee0ac27e1cd5e4
sha256: 2c7dd7200563c99dd49f9a862bf9515e38dde993a4a5dbba7408914aa03ebc73
sha512: 3bc80d0c0154b87321ee89c751f615b6d1d14eeb785f181b1fdff4ef63619e4e6c9d67665c9a376f6dadcec4978058f711681161e7a55116c587bac07e4a96a7
ssdeep: 12288:ldqNLhOsl/SbysAp2A6i37cu9p9FYYwn3Hhl8Ar:AhBSbyPp2Apwu9pvpwn3HAAr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Poshefus.STA also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.63001
MicroWorld-eScanTrojan.GenericKDZ.72859
FireEyeGeneric.mg.315138347a5c976c
ALYacTrojan.PSW.Racealer
CylanceUnsafe
VIPREWin32.Malware!Drop
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005777481 )
BitDefenderTrojan.GenericKDZ.72859
K7GWTrojan ( 005777481 )
Cybereasonmalicious.47a5c9
CyrenW32/Kryptik.DEX.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DC821
AvastWin32:BotX-gen [Trj]
ClamAVWin.Packed.Tofsee-9830352-0
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Poshefus.aa390356
RisingTrojan.Kryptik!1.D250 (CLOUD)
Ad-AwareTrojan.GenericKDZ.72859
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.amimu
TrendMicroTROJ_GEN.R002C0DC821
McAfee-GW-EditionPacked-GDK!315138347A5C
SentinelOneStatic AI – Malicious PE
EmsisoftMalCert.A (A)
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.amimu
MicrosoftTrojan:Win32/Poshefus.STA
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D11C9B
AhnLab-V3Trojan/Win32.RL_Kryptik.R365434
ZoneAlarmHEUR:Trojan.Win32.Agentb.gen
GDataTrojan.GenericKDZ.72859
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Kryptik.HJGZ
McAfeePacked-GDK!315138347A5C
MAXmalware (ai score=81)
MalwarebytesTrojan.MalPack.GS
PandaTrj/CI.A
APEXMalicious
FortinetW32/Kryptik.HJDH!tr
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Generic.HgIASQYA

How to remove Trojan:Win32/Poshefus.STA?

Trojan:Win32/Poshefus.STA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment