Malware

How to remove “Generic.ServStart.A.1B0ACF94”?

Malware Removal

The Generic.ServStart.A.1B0ACF94 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ServStart.A.1B0ACF94 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

v8.ter.tf

How to determine Generic.ServStart.A.1B0ACF94?


File Info:

crc32: E492994B
md5: 0648eda5d1806b93e8430a151939f14e
name: svcyr.exe
sha1: 279c6de90d1292cc43cd432ee25f6e7082fa46f8
sha256: 98a49f3c2fce40132271e461df9b58911510ebd6eb0b9c250e1fdbfe705a2254
sha512: b984a87e8e259aee0afe3a9c5a651eb93faa39171b6cdf90aededf7ce126320a37cf33dc5d10dbbab4b7e6d8197c3d656b9996bd92ce5853f5670381854ed05d
ssdeep: 1536:ulU9MkRkqDFO/f8Wikwigo4PtyiZoXqRZg2CJd7Q+M4t6ZhZl0:uCsw4sWi3Fo4lOX8Zgh75Rt6ZF0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Microsoft Corporation. All rights reserved.
InternalName:
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft Operating System
SpecialBuild:
ProductVersion: 6.1.7600.16385
FileDescription: Windows Enhanced Storage Password Authentication Program
OriginalFilename: Authn.exe
Translation: 0x0809 0x04b0

Generic.ServStart.A.1B0ACF94 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGeneric.ServStart.A.1B0ACF94
ClamAVWin.Malware.Nitol-6802818-0
FireEyeGeneric.mg.0648eda5d1806b93
CAT-QuickHealPUA.MauvaiseRI.S5249243
ALYacGeneric.ServStart.A.1B0ACF94
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 000170ae1 )
BitDefenderGeneric.ServStart.A.1B0ACF94
K7GWTrojan ( 000170ae1 )
Cybereasonmalicious.5d1806
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34132.gq1@aynPfNgi
CyrenW32/Trojan.CZR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
TencentMalware.Win32.Gencirc.10b589d0
Ad-AwareGeneric.ServStart.A.1B0ACF94
ComodoTrojWare.Win32.Nitol.RT@7ul2hk
F-SecureBackdoor.BDS/Backdoor.Gen2
DrWebTrojan.DownLoader24.55929
VIPREBehavesLike.Win32.Malware.wsc (mx-v)
TrendMicroDDoS.Win32.NITOL.SMG
EmsisoftGeneric.ServStart.A.1B0ACF94 (B)
SentinelOneDFI – Suspicious PE
GDataGeneric.ServStart.A.1B0ACF94
JiangminTrojan.Generic.egobu
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen2
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitGeneric.ServStart.A.1B0ACF94
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Skeeyah.C1931365
VBA32BScope.TrojanDDoS.Macri
MalwarebytesBackdoor.Bot
ESET-NOD32a variant of Win32/Agent.RTQ
TrendMicro-HouseCallDDoS.Win32.NITOL.SMG
RisingTrojan.Agent!8.B1E (TFE:dGZlOgUq2dzR9+gejw)
YandexTrojan.Agent!0Ln37hOpnKA
MAXmalware (ai score=84)
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.RTQ!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM07.1.706F.Malware.Gen

How to remove Generic.ServStart.A.1B0ACF94?

Generic.ServStart.A.1B0ACF94 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment