Trojan

About “Trojan.ServStart” infection

Malware Removal

The Trojan.ServStart is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ServStart virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

apple.vzboot.com

How to determine Trojan.ServStart?


File Info:

crc32: CEB4AC19
md5: c71eacf3ffaf82787a533eb452bcf3e7
name: 360vz.exe
sha1: c9149fdc1eacf2c61e606050d5d3e82284578ffb
sha256: 927d0f45bf59f19e915b8a8807372f547d151b60455a7fe40f696b8742d3ae3a
sha512: 26c9deb31071f1606b2eb8c09e3c1ea761701be0c8ba99673986abd44bb42affb9e8787e46059a277e9c2e40827f3619cbeaf39fefdedeb20a2a4e6925ca815e
ssdeep: 1536:GRtxXnig5/VUJyWryEXe8T1g6hypxc/lkJ5jj1fV8cGDmtw:GhN5/VmbTC6hyQ/OJRj1V8cGCtw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.ServStart also known as:

BkavW32.DefayliLTAD.Trojan
MicroWorld-eScanGen:Win32.Malware.gqW@aK8ldHk
FireEyeGeneric.mg.c71eacf3ffaf8278
CAT-QuickHealTrojan.Malex.E4
Qihoo-360Win32/Trojan.Reconyc.B
McAfeeDoS-FAE!C71EACF3FFAF
ALYacGen:Win32.Malware.gqW@aK8ldHk
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0055e40a1 )
BitDefenderGen:Win32.Malware.gqW@aK8ldHk
K7GWTrojan ( 0055e40a1 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34090.gqW@aK8ldHk
F-ProtW32/NewMalware-Rootkit-I-based!
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.ANZWCeC
BaiduWin32.Trojan.Swisyn.d
TrendMicro-HouseCallTROJ_SERVSTART.SMB
AvastWin32:Nitol-B [Trj]
ClamAVWin.Trojan.Gh0stRAT-7480037-0
GDataGen:Win32.Malware.gqW@aK8ldHk
KasperskyTrojan.Win32.Reconyc.fuzv
AlibabaTrojan:Win32/Reconyc.f721b05c
NANO-AntivirusTrojan.Win32.Swisyn.cteraq
ViRobotTrojan.Win32.DDoS-Agent.98304.A
RisingBackdoor.Jusi2!1.9DB2 (CLOUD)
Endgamemalicious (high confidence)
SophosTroj/Sdbot-DQA
ComodoTrojWare.Win32.Malex.EQ@5tewhp
F-SecureWorm.WORM/Rbot.Gen
DrWebTrojan.Inject1.29007
ZillyaTrojan.ServStart.Win32.2090
TrendMicroTROJ_SERVSTART.SMB
McAfee-GW-EditionDoS-FAE!C71EACF3FFAF
SentinelOneDFI – Suspicious PE
Trapminemalicious.moderate.ml.score
CMCTrojan.Win32.Reconyc!O
EmsisoftGen:Win32.Malware.gqW@aK8ldHk (B)
APEXMalicious
CyrenW32/NewMalware-Rootkit-I-based!
JiangminTrojan/Swisyn.wmy
WebrootW32.Malware.Gen
AviraWORM/Rbot.Gen
ArcabitGen:Win32.Malware.E30E85
SUPERAntiSpywareTrojan.Agent/Gen-ServStart
ZoneAlarmTrojan.Win32.Reconyc.fuzv
MicrosoftTrojan:Win32/Malex.gen!E
TACHYONTrojan/W32.Swisyn.98304.AO
AhnLab-V3Trojan/Win32.Bagsu.R175660
Acronissuspicious
VBA32BScope.Trojan.Downloader
MAXmalware (ai score=83)
Ad-AwareGen:Win32.Malware.gqW@aK8ldHk
MalwarebytesTrojan.ServStart
PandaGeneric Malware
ESET-NOD32Win32/ServStart.DD
TencentMalware.Win32.Gencirc.10b3c9e6
YandexTrojan.ServStart!1cgk/h5vYpM
IkarusBackdoor.Win32.Farfli
eGambitUnsafe.AI_Score_100%
FortinetW32/ServStart.DD!tr
AVGWin32:Nitol-B [Trj]
Cybereasonmalicious.3ffaf8
Paloaltogeneric.ml
MaxSecureTrojan.Malware.7164915.susgen

How to remove Trojan.ServStart?

Trojan.ServStart removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment