Malware

Generic.ServStart.A.F69733F4 removal guide

Malware Removal

The Generic.ServStart.A.F69733F4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ServStart.A.F69733F4 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Deletes its original binary from disk
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
jayttyy.f3322.net
a.tomx.xyz

How to determine Generic.ServStart.A.F69733F4?


File Info:

crc32: 6D77A2E8
md5: 5c3e061cf8e24192ebb55b4c0dc1e0d8
name: slkor.exe
sha1: fc41925f514fdda6fe828f1235ce1c7792666700
sha256: 5632d099dbfd451cc69950de598807a87b36cdd3a3dbbdab236e18d2370ad6b6
sha512: 605613aea40fe0df42b30ab56f64f296fbf11551ac029e8c84328faec12b7ecacffb2795b0c11b3166761fb20b2c71ed1de2fc34580a6dd13cef96216df847b5
ssdeep: 3072:9A2Am/Sbmg1hz6IBpSTrNQz2lAT1vUS4BFRKKa:TpSB1hz6IBpStc2lAmSsj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709
InternalName: PlusFrame
FileVersion: 1, 0, 0, 1
CompanyName: x5c4fx5e55x63a7x5236x5e73x53f0x5e94x7528x7a0bx5e8f
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: PlusFrame x5e94x7528x7a0bx5e8f
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: PlusFrame
OriginalFilename: PlusFrame.EXE
Translation: 0x0804 0x04b0

Generic.ServStart.A.F69733F4 also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanDeepScan:Generic.ServStart.A.F69733F4
CAT-QuickHealTrojanDDos.Nitol.A.mue
CylanceUnsafe
VIPRETrojan.Win32.Nitol.b (v)
BitDefenderDeepScan:Generic.ServStart.A.F69733F4
Cybereasonmalicious.cf8e24
APEXMalicious
KasperskyHEUR:Trojan-DDoS.Win32.Nitol.gen
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazq3JHW2ue9rKtcky5kJ2VRh)
Ad-AwareDeepScan:Generic.ServStart.A.F69733F4
EmsisoftDeepScan:Generic.ServStart.A.F69733F4 (B)
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
F-SecureTrojan.TR/Dropper.Gen
Invinceaheuristic
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5c3e061cf8e24192
AviraTR/Dropper.Gen
FortinetW32/ServStart.OJJ!tr
Endgamemalicious (high confidence)
ArcabitDeepScan:Generic.ServStart.A.F69733F4
ZoneAlarmHEUR:Trojan-DDoS.Win32.Nitol.gen
MicrosoftTrojanDownloader:Win32/Yemrok.B
Acronissuspicious
BitDefenderThetaAI:Packer.4D4233E51F
ALYacDeepScan:Generic.ServStart.A.F69733F4
MAXmalware (ai score=82)
VBA32BScope.TrojanDownloader.Yemrok
ESET-NOD32a variant of Win32/ServStart.RK
TencentWin32.Trojan.Gen.Swli
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_86%
GDataDeepScan:Generic.ServStart.A.F69733F4
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Trojan.DDoS.36a

How to remove Generic.ServStart.A.F69733F4?

Generic.ServStart.A.F69733F4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment