Spy Trojan

How to remove “TrojanSpy:Win32/Yogosojo.A”?

Malware Removal

The TrojanSpy:Win32/Yogosojo.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Yogosojo.A virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanSpy:Win32/Yogosojo.A?


File Info:

name: 3749D1A9E259895CA019.mlw
path: /opt/CAPEv2/storage/binaries/33891bd316c8155ec5760e49212b1c0f89edd8a5d067ad3085560e7215a9f792
crc32: 2920683B
md5: 3749d1a9e259895ca019b8e08af5619b
sha1: f5c77809773af4ee93ab0b35e7867faff37f6464
sha256: 33891bd316c8155ec5760e49212b1c0f89edd8a5d067ad3085560e7215a9f792
sha512: 66a87efc2b2fee9db1df1e9953cab2cf552d362b935f9a8d198d8d73f60971e10f768acac089b237790103f0c42921368bb1f6d6d5b6cbef7fe2f337c8170bb8
ssdeep: 3072:FfeRx7GoJ98DDsO6XFHkULXiqEdH+j90I9ooAFZDzjdu2DQfXAu4PhXWI52TLBZ2:FfeRHjYwOMHkULcs9FoHTbN5iMsooS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12834228FA6F47A98D091A035B9B8A1B87EFB577495E9CD4BF319D82026C96FC3210740
sha3_384: 1baf8cd2f81a41bd59a2528b665dadfb48f5daa82e1979275e58b3b751d07f4c78113e361c8f36635ff46307df28d152
ep_bytes: 60be00c046008dbe0050f9ff5789f368
timestamp: 2015-04-21 09:17:39

Version Info:

FileVersion: 2015.4.21.2
LegalCopyright: Copyright (C) 2014
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

TrojanSpy:Win32/Yogosojo.A also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Krap.mgDs
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Doina.11726
CAT-QuickHealTrojanSpy.Yogosojo.A.mue
McAfeePacked-FJ!3749D1A9E259
VIPREGen:Variant.Doina.11726
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:Win32/Yogosojo.5a19c22c
K7GWTrojan ( 0011f3561 )
K7AntiVirusTrojan ( 0011f3561 )
BaiduWin32.Trojan.Agent.ata
CyrenW32/S-97774107!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.XKJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Krap.jd
BitDefenderGen:Variant.Doina.11726
AvastWin32:Evo-gen [Trj]
TencentWin32.Packed.Krap.Bdhl
EmsisoftGen:Variant.Doina.11726 (B)
F-SecureTrojan.TR/Agent.murhs
DrWebTrojan.Siggen6.45268
ZillyaTrojan.KillFilesGen.Win32.2
TrendMicroTROJ_GEN.R002C0DGA23
McAfee-GW-EditionBehavesLike.Win32.PUPXAX.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3749d1a9e259895c
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Doina.11726
JiangminPacked.Krap.fxnu
AviraTR/Agent.murhs
Antiy-AVLTrojan[Packed]/Win32.Krap.jd
ArcabitTrojan.Doina.D2DCE
ViRobotTrojan.Win.Z.Krap.237056.AJ
ZoneAlarmPacked.Win32.Krap.jd
MicrosoftTrojanSpy:Win32/Yogosojo.A
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R147539
BitDefenderThetaAI:Packer.F508CE3226
ALYacGen:Variant.Doina.11726
MAXmalware (ai score=87)
VBA32TrojanSpy.Yogosojo
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DGA23
RisingTrojan.Agent!8.B1E (TFE:5:vOU6SearnHQ)
IkarusPacked.Win32.Krap
MaxSecurePacked.Krap.JD
FortinetW32/Generic.AC.F8832!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.9e2598
DeepInstinctMALICIOUS

How to remove TrojanSpy:Win32/Yogosojo.A?

TrojanSpy:Win32/Yogosojo.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment