Malware

Win32/ServStart.DD removal instruction

Malware Removal

The Win32/ServStart.DD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/ServStart.DD virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

apple.vzboot.com

How to determine Win32/ServStart.DD?


File Info:

crc32: CEB4AC19
md5: c71eacf3ffaf82787a533eb452bcf3e7
name: c.exe
sha1: c9149fdc1eacf2c61e606050d5d3e82284578ffb
sha256: 927d0f45bf59f19e915b8a8807372f547d151b60455a7fe40f696b8742d3ae3a
sha512: 26c9deb31071f1606b2eb8c09e3c1ea761701be0c8ba99673986abd44bb42affb9e8787e46059a277e9c2e40827f3619cbeaf39fefdedeb20a2a4e6925ca815e
ssdeep: 1536:GRtxXnig5/VUJyWryEXe8T1g6hypxc/lkJ5jj1fV8cGDmtw:GhN5/VmbTC6hyQ/OJRj1V8cGCtw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/ServStart.DD also known as:

BkavW32.DefayliLTAD.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Malware.gqW@aK8ldHk
FireEyeGeneric.mg.c71eacf3ffaf8278
CAT-QuickHealTrojan.Malex.E4
McAfeeDoS-FAE!C71EACF3FFAF
CylanceUnsafe
ZillyaTrojan.ServStart.Win32.2090
AegisLabTrojan.Win32.Reconyc.toaz
SangforMalware
K7AntiVirusTrojan ( 0055e40a1 )
BitDefenderGen:Trojan.Malware.gqW@aK8ldHk
K7GWTrojan ( 0055e40a1 )
Cybereasonmalicious.3ffaf8
TrendMicroTROJ_SERVSTART.SMB
BaiduWin32.Trojan.Swisyn.d
CyrenW32/NewMalware-Rootkit-I-based!
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.ANZWCeC
APEXMalicious
AvastWin32:Nitol-B [Trj]
ClamAVWin.Trojan.Gh0stRAT-7480037-0
KasperskyTrojan.Win32.Reconyc.fuzv
AlibabaTrojan:Win32/Reconyc.175cba6e
NANO-AntivirusTrojan.Win32.Swisyn.cteraq
ViRobotTrojan.Win32.DDoS-Agent.98304.A
Ad-AwareGen:Trojan.Malware.gqW@aK8ldHk
EmsisoftTrojan.ServStart (A)
ComodoTrojWare.Win32.Malex.EQ@5tewhp
F-SecureWorm.WORM/Rbot.Gen
DrWebTrojan.Inject1.29007
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Troj/Sdbot-DQA
McAfee-GW-EditionDoS-FAE!C71EACF3FFAF
SophosTroj/Sdbot-DQA
IkarusBackdoor.Win32.Farfli
JiangminTrojan/Swisyn.wmy
WebrootW32.Malware.Gen
AviraWORM/Rbot.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
MicrosoftTrojan:Win32/Malex.gen!E
ArcabitTrojan.Malware.E30E85
SUPERAntiSpywareTrojan.Agent/Gen-ServStart
ZoneAlarmTrojan.Win32.Reconyc.fuzv
GDataGen:Trojan.Malware.gqW@aK8ldHk
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bagsu.R175660
VBA32BScope.Trojan.Downloader
ALYacTrojan.Agent.ServStart
TACHYONTrojan/W32.Swisyn.98304.AO
MalwarebytesTrojan.ServStart
PandaGeneric Malware
ESET-NOD32Win32/ServStart.DD
TrendMicro-HouseCallTROJ_SERVSTART.SMB
RisingBackdoor.Jusi2!1.9DB2 (CLASSIC)
YandexTrojan.ServStart!1cgk/h5vYpM
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/ServStart.DD!tr
BitDefenderThetaGen:NN.ZexaF.34570.gqW@aK8ldHk
AVGWin32:Nitol-B [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Reconyc.B

How to remove Win32/ServStart.DD?

Win32/ServStart.DD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment