Malware

Generic.ServStart.A.4E8616D3 (B) information

Malware Removal

The Generic.ServStart.A.4E8616D3 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ServStart.A.4E8616D3 (B) virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
ipconfig.52yuxiao.cn
www.ffwlll.win
www.ffwlll.cc
a.tomx.xyz

How to determine Generic.ServStart.A.4E8616D3 (B)?


File Info:

crc32: E8D866BE
md5: 44c410b92c6a9accb83710d8746b4062
name: Dapp.exe
sha1: aeffa6a16ce302ef68617e605a652a62102b7231
sha256: e12c7d14e694a96b91a553f5dfef15d4520e83183747b97e0ca7ffcf7215b24a
sha512: 4f5e04e29e1255e3d0c534e75e13fb37c168206665d47fa93ced06a1daad9e07c29586ebd2127141689f71568e0411008d426defcb7e2f87b49fb09409482ad6
ssdeep: 768:cXvryXXQkZuzQE98Fs+UmlMVVPG42EmAjE/yQd07d21a1Xxu:cXvryXgkA5eEFjtQd07k1sX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.ServStart.A.4E8616D3 (B) also known as:

DrWebTrojan.PWS.Gamania.44384
MicroWorld-eScanGeneric.ServStart.A.4E8616D3
FireEyeGeneric.mg.44c410b92c6a9acc
CAT-QuickHealDdos.Nitol.18525
Qihoo-360Win32/Worm.Nitol.A
McAfeeBackDoor-FBOD!44C410B92C6A
MalwarebytesBackdoor.Bot
SangforMalware
K7AntiVirusTrojan ( 0051b1671 )
BitDefenderGeneric.ServStart.A.4E8616D3
K7GWTrojan ( 0051b1671 )
Cybereasonmalicious.92c6a9
Invinceaheuristic
BitDefenderThetaAI:Packer.BA2556631E
F-ProtW32/Nitol.R.gen!Eldorado
SymantecTrojan!im
APEXMalicious
AvastWin32:Nitol-B [Trj]
ClamAVWin.Worm.Agent-5819819-0
GDataWin32.Worm.ServStart.B
KasperskyTrojan-DDoS.Win32.Macri.atk
AlibabaDDoS:Win32/Macri.c776ea39
NANO-AntivirusTrojan.Win32.Gamania.emsoeh
ViRobotBackdoor.Win32.ServStart.Gen.A
AegisLabTrojan.Win32.Macri.9!c
RisingTrojan.DDOS!1.AF40 (CLOUD)
Ad-AwareGeneric.ServStart.A.4E8616D3
SophosTroj/Nitol-AR
ComodoTrojWare.Win32.ServStart.bre@6az8zh
F-SecureTrojan.TR/Staser.apzjs
BaiduWin32.Trojan.ServStart.l
VIPRETrojan.Win32.Nitol.b (v)
TrendMicroTROJ_NITOL.SMN1
McAfee-GW-EditionBehavesLike.Win32.Derdero.nh
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Farfli.1!O
EmsisoftGeneric.ServStart.A.4E8616D3 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Nitol.R.gen!Eldorado
JiangminTrojanDDoS.Macri.fo
WebrootW32.Nitol.B
AviraTR/Staser.apzjs
Antiy-AVLTrojan[DDoS]/Win32.Macri
Endgamemalicious (high confidence)
ArcabitGeneric.ServStart.A.4E8616D3
ZoneAlarmTrojan-DDoS.Win32.Macri.atk
MicrosoftDDoS:Win32/Nitol.A
AhnLab-V3Backdoor/Win32.Nitol.C1031684
Acronissuspicious
VBA32BScope.TrojanDDoS.Macri
ALYacGeneric.ServStart.A.4E8616D3
MAXmalware (ai score=100)
CylanceUnsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.52716
ESET-NOD32a variant of Win32/ServStart.D
TrendMicro-HouseCallTROJ_NITOL.SMN1
TencentTrojan.Win32.Lapka.bw
IkarusTrojan.Win32.ServStart
eGambitTrojan.Generic
FortinetW32/SDBot.BX!tr
AVGWin32:Nitol-B [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.9555478.susgen

How to remove Generic.ServStart.A.4E8616D3 (B)?

Generic.ServStart.A.4E8616D3 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment