Malware

What is “Win32/ServStart.M”?

Malware Removal

The Win32/ServStart.M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/ServStart.M virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects Bochs through the presence of a registry key
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/ServStart.M?


File Info:

name: C0B0597E17832F90B8BA.mlw
path: /opt/CAPEv2/storage/binaries/6a5533bd0d2d45e7bbde43c5460c63a7c9858403900e052eefeb3368952f390f
crc32: 67216C24
md5: c0b0597e17832f90b8ba6880f4884f4a
sha1: 10ec6ebcbb8eeeee9d1962bd42f71bb80a35a339
sha256: 6a5533bd0d2d45e7bbde43c5460c63a7c9858403900e052eefeb3368952f390f
sha512: c0802fa8bfa051fcf2931a66d8bc21e6cb3ee7349020518ae3c790653e69672ec0461155f4d14d6026d374ae716cacf0b7ea2ff053951d0d4819c092e47ddc11
ssdeep: 6144:rBs27MMLyX5HXXXDTXXXOGqIII+pXXX5AYjKXXXDoXXXG6XXXxXXXLIIIEAkOCO/:rK20HXXX/XXXFqIIIcXXX5j2XXXcXXXu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E147C4A3D9496B5C44D013A08BBA39B27A23C2195DDD242BD80B7FF25FD6CCF62471A
sha3_384: edd45389434ab609ea4b10308a0b8a75d3e594208b8b93f1120e44f09045bfc4841dfa42bcbb2a0d9814b86d2d847f93
ep_bytes: 558bec6aff6870614000684039400064
timestamp: 2022-11-19 16:42:28

Version Info:

Comments:
CompanyName: Yagu Music
FileDescription: Clien RunProcess Local
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
InternalName: hello.exe
LegalCopyright: All rights reserved.
LegalTrademarks:
OriginalFilename: Yagu Music
PrivateBuild:
ProductName: Yagu Music® Operating System
ProductVersion: 17.000.14393.08
SpecialBuild:
Translation: 0x0409 0x04b0

Win32/ServStart.M also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.m2Bz
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.51669
MicroWorld-eScanGen:Heur.Mint.Zard.30
ClamAVWin.Trojan.Nitol-6335025-0
FireEyeGeneric.mg.c0b0597e17832f90
MalwarebytesGeneric.Trojan.ServStart.DDS
ZillyaWorm.ServStart.Win32.6655
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0054d1101 )
AlibabaTrojan:Win32/Nitol.361
K7GWTrojan ( 0054d1101 )
Cybereasonmalicious.e17832
BitDefenderThetaGen:NN.ZexaF.36196.mW3@aS7PGbdj
VirITTrojan.Win32.Dnldr24.CYLH
CyrenW32/Agent.QSZH-5909
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32Win32/ServStart.M
ZonerTrojan.Win32.82643
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Farfli.gen
BitDefenderGen:Heur.Mint.Zard.30
NANO-AntivirusTrojan.Win32.GenKryptik.fnpygk
AvastWin32:Nitol-B [Trj]
TencentTrojan-DDoS.Win32.Nitol.ka
EmsisoftGen:Heur.Mint.Zard.30 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPREGen:Heur.Mint.Zard.30
TrendMicroTROJ_GEN.R03BC0CEL23
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
SophosTroj/Nitol-BF
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.ServStart.F
JiangminTrojanDDoS.Nitol.cm
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.GameThief.Magania.~NWABI@1775fs
ArcabitTrojan.Mint.Zard.30
ViRobotDropper.Agent.54110
ZoneAlarmHEUR:Backdoor.Win32.Farfli.gen
MicrosoftDDoS:Win32/Nitol.A
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.C3534448
McAfeeGenericRXHB-SG!C0B0597E1783
MAXmalware (ai score=89)
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0CEL23
RisingBackdoor.Overie!1.C6A2 (CLASSIC)
YandexWorm.ServStart!4VbdgBaA4YM
SentinelOneStatic AI – Suspicious PE
MaxSecureDDoS.W32.Nitol.gen
FortinetMalwThreat!E1E6IV
AVGWin32:Nitol-B [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/ServStart.M?

Win32/ServStart.M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment