Malware

Win32/ServStart.OP removal tips

Malware Removal

The Win32/ServStart.OP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/ServStart.OP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/ServStart.OP?


File Info:

name: E0ACD849A891A6E36119.mlw
path: /opt/CAPEv2/storage/binaries/dc09ab4c459f6c2ac3f0b0f900dc919282191100272b8f134640575e6af227aa
crc32: 863FE63E
md5: e0acd849a891a6e361195a61f6755dcb
sha1: f9804c98f5fb98744cc91407bacf0c06f97b0029
sha256: dc09ab4c459f6c2ac3f0b0f900dc919282191100272b8f134640575e6af227aa
sha512: 1b90c3d2a0a1e0a5557279e9b03b256d424ebe48976229db58deadd5297c92271958ccef1c97f7214e3731e513870e9d10e6ed9914d3c6bd8f4cd8729619d115
ssdeep: 1536:g1s/+L8V2eJkJGCBXSZHALyaqZd5RNNNI:f/3+JGKXSZHDaq75RNNNI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168536BC5FAA44C9DC62457F046B657B29437AC0D3B025E4F83C0F97E98361CEAE6624E
sha3_384: fb3a419c4d48ed8702366fbfd4ed3bd71f50d4b3480a13a9f74f7ba9db8054212f1ab5c4b73c0eb4073eb9a02bedec7f
ep_bytes: 558bec6aff68c845400068ae30400064
timestamp: 2017-05-28 15:44:20

Version Info:

Comments: OMFG Studio
CompanyName: OMFG Studio
FileDescription: Clien Local RunPross Auto
FileVersion: 32, 2,34, 5374
InternalName: Clock
LegalCopyright: OMFG Studio All rights reserved.
LegalTrademarks:
OriginalFilename: Clock.exe
PrivateBuild:
ProductName: Clock.exe
ProductVersion: 32, 2,34, 5374
SpecialBuild:
Translation: 0x0804 0x04b0

Win32/ServStart.OP also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Glomaru.lwu8
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.63361
MicroWorld-eScanTrojan.GenericKD.47031300
FireEyeGeneric.mg.e0acd849a891a6e3
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXBS-GQ!E0ACD849A891
CylanceUnsafe
ZillyaTrojan.Magania.Win32.71162
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_24689.None
K7GWTrojan ( 00560bb71 )
K7AntiVirusTrojan ( 00560bb71 )
BitDefenderThetaGen:NN.ZexaF.34114.dq2@aa7J7Dlj
VirITTrojan.Win32.Dnldr24.DPSZ
CyrenW32/Magania.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ServStart.OP
TrendMicro-HouseCallTROJ_GEN.R002C0DKS21
Paloaltogeneric.ml
ClamAVWin.Malware.Magania-7170120-0
KasperskyTrojan-GameThief.Win32.Magania.uhbd
BitDefenderTrojan.GenericKD.47031300
NANO-AntivirusTrojan.Win32.Magania.epgxys
AvastWin32:BotX-gen [Trj]
TencentMalware.Win32.Gencirc.10ce6333
Ad-AwareTrojan.GenericKD.47031300
EmsisoftTrojan.GenericKD.47031300 (B)
ComodoTrojWare.Win32.ServStart.CB@7486ss
TrendMicroTROJ_GEN.R002C0DKS21
McAfee-GW-EditionBehavesLike.Win32.Generic.km
SophosML/PE-A + Troj/Agent-BCHT
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47031300
JiangminTrojan.Generic.azxao
MaxSecureTrojan.Malware.10977295.susgen
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.206F97B
GridinsoftRansom.Win32.Gen.sa
MicrosoftDDoS:Win32/Nitol.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Magania.C1982352
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacTrojan.GenericKD.47031300
TACHYONTrojan-PWS/W32.OnLineGames.62040.B
MalwarebytesMalware.AI.631638963
APEXMalicious
RisingTrojan.Generic@ML.98 (RDML:TdTGBYxEh/kfNYTP5WXGew)
IkarusBackdoor.Win32.Inject
FortinetW32/GenKryptik.AWIY!tr
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.9a891a
PandaTrj/Genetic.gen

How to remove Win32/ServStart.OP?

Win32/ServStart.OP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment