Trojan

Trojan.Win32.ServStart.acty (file analysis)

Malware Removal

The Trojan.Win32.ServStart.acty is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.ServStart.acty virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.ServStart.acty?


File Info:

name: B777426297406A7C5AD1.mlw
path: /opt/CAPEv2/storage/binaries/c9a675ec69580bbd04435910d1a7f37c239aab6265764eccced4ea790d5d778a
crc32: FF61328C
md5: b777426297406a7c5ad1fbb75ff621e0
sha1: c30dd15fae955530d6943e0d3fb5ff20c23e689f
sha256: c9a675ec69580bbd04435910d1a7f37c239aab6265764eccced4ea790d5d778a
sha512: 35caeb6cd714defa7a2297c02feeede159221c66fcd5097eb3711d266dc3ee421ff0bceb5e2a63ee0fb87ec355c6303b0b26eaaaf8c444feee8a3f04fe0eee8d
ssdeep: 6144:T6sT1omDb+SmphFyAAMQ8rl6RKzCXM12AolJw3BFkkFu:TdghFNLQ8rlkCqA2jlJw3Bu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F647C1277E1C876D1B201334A56C7A9A7FABD219E2286477BC03B0EEE31241DF353A5
sha3_384: a7c593d26fe8d4f997ac82832e4d74274257367e877512e17c112357726a53eebdc5efad888026312cfaef3e24ba092e
ep_bytes: e873730000e916feffff5064ff350000
timestamp: 2019-12-08 07:16:42

Version Info:

CompanyName: Windows网络辅助功能插件
FileDescription: Windows Server
FileVersion: 1.0.0.1
InternalName: Windows网络辅助功能插件
LegalCopyright: Windows网络辅助功能插件
OriginalFilename: Windows网络辅助功能插件
ProductName: Windows网络辅助功能插件
ProductVersion: 1.0.0.1
Translation: 0x040c 0x04e4

Trojan.Win32.ServStart.acty also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Staser.tr65
DrWebTrojan.DownLoader30.41253
MicroWorld-eScanTrojan.Cud.Gen.1
ClamAVWin.Malware.Dropperx-9637476-0
FireEyeTrojan.Cud.Gen.1
Cylanceunsafe
ZillyaTrojan.ServStart.Win32.18794
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055a4b91 )
AlibabaBackdoor:Win32/Zlob.180910
K7GWTrojan-Downloader ( 0055a4b91 )
Cybereasonmalicious.297406
BitDefenderThetaGen:NN.ZexaF.36662.uq0@ae!FXcij
CyrenW32/Downldr.KF.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.EUJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.ServStart.acty
BitDefenderTrojan.Cud.Gen.1
NANO-AntivirusTrojan.Win32.ServStart.ginthm
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.10b2b78c
TACHYONTrojan/W32.ServStart.335872
EmsisoftTrojan.Cud.Gen.1 (B)
F-SecureHeuristic.HEUR/AGEN.1322136
BaiduWin32.Trojan-Downloader.Agent.cw
VIPRETrojan.Cud.Gen.1
McAfee-GW-EditionTrojan-FSAA!B77742629740
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Cud.Gen.1
JiangminTrojan.ServStart.acb
AviraHEUR/AGEN.1322136
Antiy-AVLTrojan/Win32.Servstart
XcitiumTrojWare.Win32.TrojanDownloader.Small.AP@8otdws
ArcabitTrojan.Cud.Gen.1
ZoneAlarmTrojan.Win32.ServStart.acty
MicrosoftTrojan:Win32/Ymacco
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R325188
McAfeeTrojan-FSAA!B77742629740
MAXmalware (ai score=84)
VBA32BScope.TrojanDownloader.Agent
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DHT23
RisingDownloader.Agent!8.B23 (TFE:5:ZAfQvTBkCwJ)
IkarusBackdoor.Win32.Zegost
FortinetW32/Agent.DPQ!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.ServStart.acty?

Trojan.Win32.ServStart.acty removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment