Fake Trojan

About “TrojanFakeAV.Onescan” infection

Malware Removal

The TrojanFakeAV.Onescan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanFakeAV.Onescan virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz

How to determine TrojanFakeAV.Onescan?


File Info:

crc32: 0B7EE38D
md5: 5144a61fc6dea7a438395e3b423c6423
name: tvupdate.upd
sha1: 099aa5d9b22bc2b3a6362dd32c33074c75850dd8
sha256: 7bf5bae823d61dd4134800d3b5519498b81b9cfadb5170b361e1e62e1d49a2c9
sha512: 52e1f915314bc4b58a716903b5e85d998b532d36a419d7215bdeb43d6cd07fa9cff5c762f5dbf62e64f54d7f2aac8e551fc709906d8560816e2b90160c0bd0c8
ssdeep: 3072:vE4vYimQ87961Mf8Q1Rvz+D8EZWNePgfwb3Q08qykLYVSk1IEtMrdP:v/vYir87Ii1Rvz+3o+go7t8qyk/k1Po
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright(C) Everyzone Inc. All Rights Reserved.
InternalName: TurboVaccine Update R3
FileVersion: 2016, 12, 0, 1
CompanyName: Everyzone Inc.
ProductName: TurboVaccine Update R3
ProductVersion: 1, 1, 0, 73
FileDescription: TurboVaccine Update R3
OriginalFilename: TurboVaccine Update R3
Translation: 0x0412 0x04b0

TrojanFakeAV.Onescan also known as:

CAT-QuickHealTrojanFakeAV.Onescan
McAfeeArtemis!5144A61FC6DE
CyrenW32/GenBl.5144A61F!Olympus
TrendMicro-HouseCallSuspicious_GEN.F47V0629
NANO-AntivirusTrojan.Win32.Adkor.fermmn
RisingTrojan.Onescan!8.43A (CLOUD)
DrWebTrojan.Adkor.657
McAfee-GW-EditionArtemis
JiangminTrojan.Onescan.aik
Antiy-AVLTrojan[FakeAV]/Win32.Onescan
MicrosoftTrojan:Win32/Bitrep.A
MAXmalware (ai score=94)
FortinetW32/Onescan!tr
Qihoo-360Win32/Trojan.531

How to remove TrojanFakeAV.Onescan?

TrojanFakeAV.Onescan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment