Malware

Should I remove “Fochi.Bulz.84”?

Malware Removal

The Fochi.Bulz.84 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fochi.Bulz.84 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Fochi.Bulz.84?


File Info:

crc32: A2333A46
md5: f7606e983076805e17d86856b210c521
name: F7606E983076805E17D86856B210C521.mlw
sha1: 4e1e3a339266d8e0b265de3211cb2105157f4442
sha256: 9725d3a837977dddbbfdabd1c6497032d514d305ba084c874ee9963f18eda370
sha512: 06c41e90f5b8769f27ae2ec13ca8739343aed86f9724f6153dff7981e2724f05311920e66bf1dd11aea7785222b481090e4c042bd9c3b21bde76abaa31b1348d
ssdeep: 12288:pDOLLvFRrpT+ru2ltLawvjIeOhFnXzvKQI9FW7kx/k7F28Zy4bbkKaesHZz+Kb+:UvPrArRlNo
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: Rubeus.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Rubeus
ProductVersion: 1.0.0.0
FileDescription: Rubeus
OriginalFilename: Rubeus.exe

Fochi.Bulz.84 also known as:

K7AntiVirusTrojan ( 00577e681 )
LionicTrojan.Win32.Ruberoid.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Fochi.Bulz.84
CylanceUnsafe
ZillyaTrojan.Ruberoid.Win32.57
SangforTrojan.Win32.Ruberoid.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Ruberoid.f95059ba
K7GWTrojan ( 00577e681 )
Cybereasonmalicious.830768
CyrenW32/Rubeus.A.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Riskware.Rubeus.B
APEXMalicious
AvastWin32:MiscX-gen [PUP]
ClamAVWin.Trojan.HackTool_MSIL_Rubeus_1-9805032-0
KasperskyTrojan.Win32.Ruberoid.gen
BitDefenderGen:Variant.Fochi.Bulz.84
MicroWorld-eScanGen:Variant.Fochi.Bulz.84
TencentWin32.Trojan.Ruberoid.Eddg
Ad-AwareGen:Variant.Fochi.Bulz.84
SophosATK/Rubeus-B
BitDefenderThetaGen:NN.ZemsilF.34266.Om0@ai7Iqff
TrendMicroHackTool.MSIL.Rubeus.SMA
McAfee-GW-EditionHackTool-FEY!F7606E983076
FireEyeGeneric.mg.f7606e983076805e
EmsisoftGen:Variant.Fochi.Bulz.84 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Fochi.Bulz.84
ZoneAlarmTrojan.Win32.Ruberoid.gen
GDataGen:Variant.Fochi.Bulz.84
McAfeeHackTool-FEY!F7606E983076
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
MalwarebytesHackTool.Rubeus
PandaTrj/GdSda.A
TrendMicro-HouseCallHackTool.MSIL.Rubeus.SMA
YandexTrojan.Ruberoid!67a42Hb7RL4
IkarusVirus.Win32.Kekeo
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Rubeus
AVGWin32:MiscX-gen [PUP]
Paloaltogeneric.ml

How to remove Fochi.Bulz.84?

Fochi.Bulz.84 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment