Malware

Win32/ServStart.OM removal

Malware Removal

The Win32/ServStart.OM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/ServStart.OM virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/ServStart.OM?


File Info:

name: 9492FC4090747117515D.mlw
path: /opt/CAPEv2/storage/binaries/406f070001e2559d72c51a4ae146a901afa41ee060746738e126494345945e52
crc32: 61475499
md5: 9492fc4090747117515d5f0cb06e3afa
sha1: 197e15602c4d1a234ba712b2fe2c1ba2daf75279
sha256: 406f070001e2559d72c51a4ae146a901afa41ee060746738e126494345945e52
sha512: 7051dc513cd655b59fce3de4bf73b748014b37fa941173cb3256dc79b7ed0f7486df324cb24b557159f67e37b706a437672399df68b9ee91bf1b4d570b788b6f
ssdeep: 1536:fDc1LfHfMYag1JzgyXVdtnPVg5OHNWnnn3CCCCd:fDoL1ayJzgyXVd1PqiM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE735C92F9808497E45701388C42FBF6A862BC75C94EAA53FF80BF4F4876E55F92450B
sha3_384: 0a44dee84852d0c5fb3dad96329099974c00b656ed3989da06339e85d81cb1c74aaa9c8641f2eda4b74e4c53e25256b8
ep_bytes: 558bec6aff6870614000685039400064
timestamp: 2017-05-05 08:29:26

Version Info:

Comments:
CompanyName: Hello World
FileDescription: Clien Local RunProcess
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
InternalName: hello.exe
LegalCopyright: All rights reserved.
LegalTrademarks:
OriginalFilename: Hello World
PrivateBuild:
ProductName: Hello World® Operating System
ProductVersion: 17.000.14393.08
SpecialBuild:
Translation: 0x0409 0x04b0

Win32/ServStart.OM also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Heur.Mint.Zard.30
ClamAVWin.Trojan.Nitol-6335025-0
FireEyeGeneric.mg.9492fc4090747117
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.lm
Cylanceunsafe
ZillyaTrojan.ServStart.Win32.35247
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0054d1101 )
K7GWTrojan ( 0054d1101 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.ServStart.as
VirITTrojan.Win32.Dnldr24.CYLH
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/ServStart.OM
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-DDoS.Win32.Nitol.gen
BitDefenderGen:Heur.Mint.Zard.30
NANO-AntivirusTrojan.Win32.Ric.fnolje
AvastWin32:Nitol-B [Trj]
TencentTrojan.Win32.Nitol.wa
EmsisoftGen:Heur.Mint.Zard.30 (B)
F-SecureHeuristic.HEUR/AGEN.1344615
DrWebTrojan.DownLoader24.51669
VIPREGen:Heur.Mint.Zard.30
TrendMicroTROJ_NITOL.SMN1
Trapminemalicious.high.ml.score
SophosTroj/Nitol-BF
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.ServStart.F
JiangminTrojan.Generic.bhzka
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1344615
Antiy-AVLVirus/Win32.Expiro.ropf
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.GameThief.Magania.~NWABI@1775fs
ArcabitTrojan.Mint.Zard.30
SUPERAntiSpywareTrojan.Agent/Gen-ServStart
ZoneAlarmVHO:Trojan-DDoS.Win32.Nitol.gen
MicrosoftDDoS:Win32/Nitol!atmnm
VaristW32/RopProof.H.gen!Eldorado
AhnLab-V3Trojan/Win.Nitol.R632954
Acronissuspicious
McAfeeGenericRXCU-PI!9492FC409074
MAXmalware (ai score=80)
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_NITOL.SMN1
RisingBackdoor.Overie!1.C6A2 (CLASSIC)
YandexTrojan.GenAsa!DM1KURgoIaA
SentinelOneStatic AI – Malicious PE
FortinetW32/Wacatac.B!tr
BitDefenderThetaGen:NN.ZexaF.36744.eu2@aa1Hqpfj
AVGWin32:Nitol-B [Trj]
DeepInstinctMALICIOUS

How to remove Win32/ServStart.OM?

Win32/ServStart.OM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment