Malware

How to remove “GenPack:Win32.Neshta.H (B)”?

Malware Removal

The GenPack:Win32.Neshta.H (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Win32.Neshta.H (B) virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine GenPack:Win32.Neshta.H (B)?


File Info:

crc32: B7B7B05A
md5: c504271aa0d5ca90c7bebe09a854b474
name: C504271AA0D5CA90C7BEBE09A854B474.mlw
sha1: 6e326aa4d21f725829112fc41e64159bf4472023
sha256: e572b42640bdaf1d33f905bbabababd69cdd587bbd890966f58441825e0b4092
sha512: 7fbbef0d5268cca724ca42fc01c11b8e03b016863bee90dd588e2f4bd959e8252c5991b4c89854c29b412e98079d561c4810a5f71b55d8b2ca4cba5063152c6a
ssdeep: 3072:lGQhfAzjo+EhcToVJ7NrRRIeFUpKI4b42dMBjOImsO/3d/4/opThQP2:44UQNYeY34bFMBSBsO/3lco5eP2
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

GenPack:Win32.Neshta.H (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052964f1 )
LionicVirus.Win32.Neshta.n!c
Elasticmalicious (high confidence)
DrWebWin32.HLLP.Neshta
CynetMalicious (score: 100)
CAT-QuickHealW32.Neshta.A
ALYacGenPack:Win32.Neshta.H
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaVirus:Win32/Neshta.57d819e6
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.aa0d5c
CyrenW32/S-65b583b9!Eldorado
SymantecW32.Neshuta
ESET-NOD32a variant of Win32/Neshta
APEXMalicious
AvastWin32:Malware-gen
KasperskyVirus.Win32.Neshta.a
BitDefenderGenPack:Win32.Neshta.H
NANO-AntivirusVirus.Win32.Neshta.fnxslw
MicroWorld-eScanGenPack:Win32.Neshta.H
TencentVirus.Win32.Neshta.a
Ad-AwareGenPack:Win32.Neshta.H
SophosMal/Generic-R + W32/Neshta-D
ComodoWin32.Neshta.A@3ypg
BitDefenderThetaAI:FileInfector.D5C3B0640E
VIPREBehavesLike.Win32.Malware.vfm (mx-v)
TrendMicroTROJ_GEN.R002C0CHO21
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
FireEyeGeneric.mg.c504271aa0d5ca90
EmsisoftGenPack:Win32.Neshta.H (B)
SentinelOneStatic AI – Malicious PE
JiangminVirus.Neshta.a
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASVirus.20D
MicrosoftVirus:Win32/Neshta.A
GDataGenPack:Win32.Neshta.H
AhnLab-V3Trojan/Win32.Neshta.R294653
Acronissuspicious
McAfeeW32/Generic.t.c
MAXmalware (ai score=84)
VBA32Virus.Win32.Neshta.a
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_GEN.R002C0CHO21
RisingWin32.Neshta.a (CLASSIC)
YandexPacked/MPress
IkarusTrojan.Agent
FortinetW32/Neshta.D
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove GenPack:Win32.Neshta.H (B)?

GenPack:Win32.Neshta.H (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment