Fake

NSIS:FakeAV-AO [Trj] malicious file

Malware Removal

The NSIS:FakeAV-AO [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:FakeAV-AO [Trj] virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine NSIS:FakeAV-AO [Trj]?


File Info:

crc32: 1F51A434
md5: 282daf00ca9bea1b55bbb75278754f0d
name: pcclear2006_kbench20060921.exe
sha1: 46d5aaf1f3ffba59bdebccdd27b6e7d44b3876c9
sha256: 2dd23ac99b9d2feaa2570a88d9e1afd465b9ac5b7a739e5f40fe506288e6cd23
sha512: 62af5953541b3502d11bf523ab63389e98c624f76b037dcf0601217f4394ab8e6f62dd38aff4a393e243412643ea70ea8b5adfbcbd3e48859a923f2ebf17ee55
ssdeep: 49152:0H6kswrs+uJi5MbXUTR6hwJEYoij+/DTVqeL3x8CnkIFs/rWzSdbN5hWB4CDCL+n:25wXJi5Mb0RqwuY7jQT5zx8x/0+iBfDp
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

NSIS:FakeAV-AO [Trj] also known as:

CAT-QuickHealTrojan.Multi
McAfeeArtemis!282DAF00CA9B
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Invinceaheuristic
CyrenW32/Trojan.JAKT-2211
KasperskyHEUR:Trojan-FakeAV.Win32.Onescan.gen
AlibabaTrojanFakeAV:Win32/Onescan.b2818720
AegisLabTrojan.Multi.Generic.4!c
SophosNetboan (PUA)
ComodoApplicUnsaf.Win32.AdWare.PCTurbo.~H@669er
F-SecureTrojan.TR/Dldr.Agent.xqfzk
DrWebTrojan.DownLoader23.20263
ZillyaTrojan.Onescan.Win32.734
TrendMicroTROJ_GEN.R03FC0PH819
McAfee-GW-EditionPUP-XBM-AC
IkarusPUA.PCClear
AviraTR/Dldr.Agent.xqfzk
MicrosoftPUA:Win32/Presenoker
ZoneAlarmHEUR:Trojan-FakeAV.Win32.Onescan.gen
CylanceUnsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03FC0PH819
YandexTrojan.PWS.Lmir!FmZxyTjUxq0
AVGNSIS:FakeAV-AO [Trj]
AvastNSIS:FakeAV-AO [Trj]

How to remove NSIS:FakeAV-AO [Trj]?

NSIS:FakeAV-AO [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment