Trojan

Trojan:Win32/Togapy.A!rfn removal instruction

Malware Removal

The Trojan:Win32/Togapy.A!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Togapy.A!rfn virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

www.wa888.xyz

How to determine Trojan:Win32/Togapy.A!rfn?


File Info:

crc32: F382E674
md5: 466a2f3ef7f053582cb83c366fcb424b
name: 2211w.exe
sha1: a435c9c0edf0d22c9aba1bbd14fffb2acb68798d
sha256: 52018036b227689324f88856791ce83efca1523fa59617235718195707e02600
sha512: d9e085354889a4820df09653850f0988f7bacc8966900a72ec4659f426543843760dc89c45a2341680deef23c77f951f79a3d5b59cff96fcc455f35cc24e761b
ssdeep: 768:aHREBK+o6yMPqgRDMa6RwuFQXQ/6wo/4Jk8gqCfFC:aHK1Rt2/B9JkkUF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Togapy.A!rfn also known as:

BkavW32.Svchobst.Trojan
MicroWorld-eScanGen:Variant.Ulise.36613
FireEyeGeneric.mg.466a2f3ef7f05358
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360Win32/Trojan.Dropper.eed
McAfeeDoS-FAR!466A2F3EF7F0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Dorifel.b!c
SangforMalware
K7AntiVirusTrojan ( 0049587e1 )
BitDefenderGen:Variant.Ulise.36613
K7GWTrojan ( 0049587e1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_YODDOS.SMX
BitDefenderThetaAI:Packer.F019B6621F
F-ProtW32/S-d71876f0!Eldorado
BaiduWin32.Trojan.Agent.gr
TrendMicro-HouseCallTROJ_YODDOS.SMX
AvastWin32:Nitol-B [Trj]
ClamAVWin.Trojan.Agent-1279654
GDataGen:Variant.Ulise.36613
KasperskyTrojan-Dropper.Win32.Dorifel.axfp
AlibabaTrojanDropper:Win32/Dorifel.c732a675
NANO-AntivirusTrojan.Win32.Click3.ctkwdy
ViRobotTrojan.Win32.Agent.53760.AU
APEXMalicious
RisingTrojan.Farfli!1.65C0 (CLOUD)
Ad-AwareGen:Variant.Ulise.36613
SophosMal/Generic-S
ComodoTrojWare.Win32.Dynamer.JLS@5s363p
F-SecureTrojan.TR/Graftor.ytsgd
DrWebTrojan.Click3.28277
ZillyaTrojan.Agent.Win32.460378
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PWSOnlineGames.qt
EmsisoftGen:Variant.Ulise.36613 (B)
SentinelOneDFI – Malicious PE
CyrenW32/QQhelper.C.gen!Eldorado
JiangminTrojan/Generic.baish
WebrootW32.Malware.Gen
AviraTR/Graftor.ytsgd
MAXmalware (ai score=88)
Antiy-AVLTrojan[Dropper]/Win32.Dorifel
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D8F05
ZoneAlarmTrojan-Dropper.Win32.Dorifel.axfp
MicrosoftTrojan:Win32/Togapy.A!rfn
AhnLab-V3Trojan/Win32.Downloader.R97609
Acronissuspicious
VBA32BScope.Trojan.Bulta
ALYacGen:Variant.Ulise.36613
TACHYONTrojan/W32.Agent.53760.AGX
MalwarebytesTrojan.Dropper
PandaTrj/Genetic.gen
ZonerTrojan.Win32.29069
ESET-NOD32a variant of Win32/Agent.VOM
TencentMalware.Win32.Gencirc.10b704f5
YandexTrojan.Graftor!Yk/ayiYcGzo
IkarusTrojan.Win32.Togapy
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.VOM!tr
AVGWin32:Nitol-B [Trj]
Cybereasonmalicious.ef7f05
Paloaltogeneric.ml
MaxSecureTrojan.Malware.2588.susgen

How to remove Trojan:Win32/Togapy.A!rfn?

Trojan:Win32/Togapy.A!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment