How to remove Fucobha Spyware from PC?

In this article, I will tell you about the symptoms of Fucobha spyware appearance, and also the best way to eliminate Fucobha spyware virus from your system.

GridinSoft Anti-Malware
Editor's choice
GridinSoft Anti-Malware
Manual Fucobha removal might be a lengthy and complicated process that requires expert skills. GridinSoft Anti-Malware is a professional antivirus tool that is recommended to get rid of this Fucobha spyware trojan.
By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for GridinSoft Anti-Malware. 6 days free trial available.

Describing Fucobha spyware

Fucobha TrojanSpy as the virus is not a solitary application, but a part of considerably larger as well as tricky malware – trojan-stealer. It’s a kind of trojan, which is targeted on your personal data, and accumulates literally whatever about you and your computer. Typically, stealers have keylogger functions1, which allow them to catch your keystrokes. In addition to that, this virus can gather your cookie files, your phone number, location; it additionally can thieve all your passwords from the keychain inside of the browser.

Name Fucobha
Infection Type Spyware
  • Unconventionial language used in binary resources: Chinese (Simplified);
  • Authenticode signature is invalid;
Similar behavior Tzeebot, Mbdis, Delgent
Fix Tool

See If Your System Has Been Affected by Fucobha spyware

However, the large share of Fucobha spy are hunting for your banking information: credit card number, security codes and expiration date. For instance, if you utilize online banking, the Fucobha stealer virus has the ability to jeopardize your login and password, so the criminals will get access to your bank account. Different business data might likewise be an object of attention of Fucobha virus distributors, and an instance of big companies such data leakage can provoke catastrophic impacts.

Statistics of spyware activity in 2020
TrojanSpy activity in 2020, compared to backdoor viruses activity

The main dispersal ways of Fucobha spyware are similar to other trojans. Nowadays, the majority of such apps are dispersed through email additions. These additions (. docx,. pdf files) have corrupted macroses, that are used by Fucobha spy to invade your personal computer. Sometimes, these mails consist of web links to the phishing copies of familiar sites, like Facebook, Twitter, LinkedIn or so.

Rating of different spyware activity

Most popular spyware in 20202

It is essential to state that there is an autonomous category of spyware – for Android operating system. Such applications have comparable capabilities as the computer edition does, however, mobile malware is spread as an official application for monitoring the wife’s or children’s geographic location. Nonetheless, besides swiping various private data, it can additionally display you a totally incorrect geographic location of the gadget you are attempting to track. Such situations can trigger beefs out of the blue.

How can I understand that my computer is infected with Fucobha spyware?

Fucobha spy is a really stealth malware, simply because its performance depends upon the length of time it will operate prior to being detected. So, Fucobha spyware makers made everything to make their program appearance as imperceptible as possible. Of course, you will see that your accounts in social networks are swiped, as well as finances from your financial account is moving away, but it is far too late.

Fucobha also known as

Lionic Trojan.Win32.Icefog.m!c
DrWeb Trojan.DownLoader7.61743
MicroWorld-eScan Gen:Variant.Cerbu.99550
FireEye Generic.mg.fba7b9ffd08110e3
McAfee Artemis!FBA7B9FFD081
Cylance Unsafe
VIPRE Gen:Variant.Cerbu.99550
Sangfor Backdoor.Win32.Icefog.ulxpg
K7AntiVirus Trojan ( 004e73e41 )
Alibaba Backdoor:Win32/Fucobha.18d140cd
K7GW Trojan ( 004e73e41 )
Cybereason malicious.fd0811
BitDefenderTheta Gen:NN.ZexaF.34592.hqW@aqrg7Ljb
Symantec Backdoor.Hormesu!gen2
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Fucobha.A
APEX Malicious
TrendMicro-HouseCall BKDR_FUCOBHA.AX
Paloalto generic.ml
ClamAV Win.Trojan.Agent-7117994-0
Kaspersky Backdoor.Win32.Icefog.ak
BitDefender Gen:Variant.Cerbu.99550
NANO-Antivirus Trojan.Win32.Agent.bgpizd
Avast Win32:Fucobha-A [Trj]
Tencent Malware.Win32.Gencirc.114b9585
Ad-Aware Gen:Variant.Cerbu.99550
Sophos Mal/Generic-R
Comodo Malware@#axp36dybkrym
Zillya Backdoor.Icefog.Win32.8
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.ch
Trapmine malicious.moderate.ml.score
Emsisoft Gen:Variant.Cerbu.99550 (B)
SentinelOne Static AI – Suspicious PE
Jiangmin TrojanDownloader.Agent.ekdn
Google Detected
Avira TR/Spy.Fucobha.A.23
MAX malware (ai score=94)
Antiy-AVL Trojan/Generic.ASMalwS.13
Kingsoft Win32.Troj.Undef.(kcloud)
Microsoft TrojanSpy:Win32/Fucobha.A
ViRobot Trojan.Win32.A.Downloader.128000.CB
GData Gen:Variant.Cerbu.99550
Cynet Malicious (score: 100)
AhnLab-V3 Backdoor/Win32.Icefog.R83653
VBA32 TrojanDownloader.Agent
ALYac Gen:Variant.Cerbu.99550
TACHYON Trojan/W32.Agent.127488.SB
Malwarebytes Malware.AI.3661036933
Rising [email protected] (RDML:vw0Lxyoms8jEH8VzVJbDpw)
Yandex Trojan.GenAsa!prNldzNn+Ns
Ikarus Trojan-Spy.Win32.Fucobha
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Agent.B!tr.dldr
AVG Win32:Fucobha-A [Trj]
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_100% (W)

Domains that associated with Fucobha:

What are the symptoms of Fucobha trojan?

  • Unconventionial language used in binary resources: Chinese (Simplified);
  • Authenticode signature is invalid;

To prevent infiltration of Fucobha spyware, stay clear of setting up any kind of attachments to the e-mails from unfamiliar addresses. These days, during quarantine, email-distributed malware becomes even more active. Users (especially ones who began ordering every little thing on online-marketplaces) do not take note to the strange e-mail addresses, and open everything which reaches their email. And Fucobha stealer is right in these emails.

How to remove Fucobha spyware?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • “Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

You can attempt to do it by hand, however, like any other trojan, Fucobha TrojanSpy executes the changes pretty deep inside of the system. Thus, it’s incredibly tough to locate all these changes, and even harder to clean them out. To take care of this unsafe malware totally, I can advise you to utilize GridinSoft Anti-Malware.


To detect and delete all malicious programs on your computer with GridinSoft Anti-Malware, it’s better to use Standard or Full scan. Quick Scan is not able to find all malicious programs, because it scans only the most popular registry entries and folders.

Scan types in Gridinsoft Anti-Malware

You can spectate the detected malicious programs sorted by their possible hazard till the scan process. But to choose any actions against the viruses, you need to hold on until the scan is over, or to stop the scan.

GridinSoft Anti-Malware during the scan

To set the action for every spotted malicious or unwanted program, click the arrow in front of the name of detected virus. By default, all the viruses will be moved to quarantine.

List of detected malware after the scan

How to remove Fucobha Spyware?

Name: Fucobha

Description: Fucobha TrojanSpy is classified as a type of malware — malicious software designed to gain access to or damage your computer, often without your knowledge. The Fucobha gathers your personal information and relays it to advertisers, data firms, or external users. The Fucobha can install additional software and change the security settings on your PC.

Operating System: Windows

Application Category: Spyware

User Review
4 (8 votes)
Comments Rating 0 (0 reviews)
  1. What is Spyware: https://en.wikipedia.org/wiki/Spyware
  2. ESET quaterly report: ESET_Threat_Report_Q22020.pdf

William Reddy

I am from Ireland. My parents bought me a computer when I was 11, and several month after I have got a virus on this PC. I decided to enter the INSA Centre Val de Loire university after being graduated from the school. This French educational institution was offering a brand-new cybersecurity course. After getting the master degree in cybersecurity, I've started working in as virus analyst in a little anti-malware vendor. In 2018, I've decided to start Virus Removal project. The main target of this site is to help people to deal with PC viruses of any kind.

Leave a Reply

Your email address will not be published. Required fields are marked *


Back to top button