Malware

Application.Fochi.3 removal instruction

Malware Removal

The Application.Fochi.3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Fochi.3 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Application.Fochi.3?


File Info:

crc32: 8174F10E
md5: 9d9f61ace4c10b4469c5cade8fc976fb
name: 9D9F61ACE4C10B4469C5CADE8FC976FB.mlw
sha1: 8e4fadc34b2c287b33ee48c97c6fae6cab2642d0
sha256: 11b3b90d0bb4292f07beffb7ff4d9bee76a49ad8b715c3f62ad71db444123481
sha512: 2b7fd5522392f1fc3d20cd6561ad9496ba556c89585ada9eec9dc8eef247439c30a69faf16da2b0356aaf4e57f37020e1a9991b11303b8b7d1c85427aeaefe6c
ssdeep: 98304:g7/xV6zRhld9E1BlYb9uto2jgrGeweoSYp2prwvLWaNFXvow17IugzlHbGSZBN7:8pV8ld98BlON2jnbNswvBXvowJgzl7G
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: Rubeus.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Rubeus
ProductVersion: 1.0.0.0
FileDescription: Rubeus
OriginalFilename: Rubeus.exe

Application.Fochi.3 also known as:

K7AntiVirusTrojan ( 00577e681 )
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Application.Fochi.3
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRiskWare:MSIL/Rubeus.5632fcf3
K7GWTrojan ( 00577e681 )
Cybereasonmalicious.ce4c10
CyrenW32/Rubeus.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Riskware.Rubeus.F
APEXMalicious
AvastWin32:HacktoolX-gen [Trj]
ClamAVWin.Trojan.HackTool_MSIL_Rubeus_1-9805032-0
KasperskyHEUR:HackTool.MSIL.Rubeus.gen
BitDefenderGen:Variant.Application.Fochi.3
MicroWorld-eScanGen:Variant.Application.Fochi.3
Ad-AwareGen:Variant.Application.Fochi.3
SophosATK/Rubeus-B
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.9d9f61ace4c10b44
EmsisoftGen:Variant.Application.Fochi.3 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Variant.Application.Fochi.3
McAfeeHackTool-FEY!9D9F61ACE4C1
MAXmalware (ai score=72)
MalwarebytesHackTool.Rubeus
TrendMicro-HouseCallTROJ_GEN.R002H0CKD21
YandexRiskware.Rubeus!lZZxFmqOeKc
IkarusVirus.Win32.Kekeo
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Rubeus
AVGWin32:HacktoolX-gen [Trj]
Paloaltogeneric.ml

How to remove Application.Fochi.3?

Application.Fochi.3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment