Malware

About “Win32/ServStart.AD” infection

Malware Removal

The Win32/ServStart.AD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/ServStart.AD virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
safe.wbcode.com

How to determine Win32/ServStart.AD?


File Info:

crc32: 0E5273EA
md5: b07ccfc39ca6e44c95566408427e0090
name: B07CCFC39CA6E44C95566408427E0090.mlw
sha1: a40756730d224bdb03e2b9bb441cb5af39e5417b
sha256: 7790998fd40650497dcf53526c46e66aa4a3c7c68b59949187afa9af0a832202
sha512: 3827416a04f9782a20b891729e9f40ad7673a7bd6e3c6532356533dd7e15300852447a846e96239923589111725eb9d3de3b886caed100c74cf5a2b1bd0b9f31
ssdeep: 768:SdHAFsAbn2JI5f0PTU+jpObl/Rpy2zroL6tdEa0OstWlYtGMyb+4LKMV7f:8HrAbZf0rX8w2z8L6fEbtxyb+4Lb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/ServStart.AD also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.30
FireEyeGeneric.mg.b07ccfc39ca6e44c
CAT-QuickHealTrojan.Nitol.B4
McAfeeGenericRXAI-ME!B07CCFC39CA6
MalwarebytesGeneric.Malware/Suspicious
VIPRETrojan.Win32.Nitol.b (v)
SangforMalware
K7AntiVirusTrojan ( 0051b1671 )
BitDefenderGen:Heur.Mint.Zard.30
K7GWTrojan ( 0051b1671 )
Cybereasonmalicious.39ca6e
CyrenW32/QQhelper.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallWORM_NITOL.SMB0
AvastWin32:ServStart-B [Trj]
ClamAVWin.Trojan.Generic-6297788-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaDDoS:Win32/Nitol.840c7ca1
NANO-AntivirusTrojan.Win32.ServStart.fkfzfs
AegisLabTrojan.Win32.Generic.4!c
RisingBackdoor.Overie!1.64BD (CLASSIC)
Ad-AwareGen:Heur.Mint.Zard.30
EmsisoftGen:Heur.Mint.Zard.30 (B)
ComodoTrojWare.Win32.TrojanDownloader.Small.CO@1b3vp6
F-SecureHeuristic.HEUR/AGEN.1134301
DrWebTrojan.DownLoader12.33416
TrendMicroWORM_NITOL.SMB0
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
SophosMal/Generic-S
GDataGen:Heur.Mint.Zard.30
JiangminTrojan/Generic.bbbzb
AviraHEUR/AGEN.1134301
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Mint.Zard.30
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftDDoS:Win32/Nitol.A
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.PcClient.R158398
BitDefenderThetaGen:NN.ZexaF.34804.fqW@a0hhd1gj
ALYacGen:Heur.Mint.Zard.30
MAXmalware (ai score=82)
VBA32BScope.Trojan.Downloader
CylanceUnsafe
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/ServStart.AD
YandexTrojan.GenAsa!C2SSpZD4daI
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetMalwThreat!E1E6IV
AVGWin32:ServStart-B [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/DDoS.Nitol.HwcBCNoA

How to remove Win32/ServStart.AD?

Win32/ServStart.AD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment