Malware

GenPack:Win32.Neshta.H (file analysis)

Malware Removal

The GenPack:Win32.Neshta.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Win32.Neshta.H virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine GenPack:Win32.Neshta.H?


File Info:

crc32: 65C3AC15
md5: 855b13696cc6ddb21891c402628ccde1
name: 855B13696CC6DDB21891C402628CCDE1.mlw
sha1: c736197fc17216b6a078abe608bd7b8cd27b3a5a
sha256: 95c88b124c80244bcc0116fad523f7efac2d28edaccd1999db660c4870d36acb
sha512: fdb5c74392b241ac1684b4b33a38cfde91ee1b0d1771294b963346dc54d2740d65f46d82269d514fbb3a0050d1159a489bff74a1d3b6a422b0a87ce3325d2848
ssdeep: 768:RDVwESZbssifRZ1II0zSFQhROkag6KYIBZRp:RDCECs5fLxEqKdxvRp
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

GenPack:Win32.Neshta.H also known as:

BkavW32.AIDetect.malware2
LionicVirus.Win32.Neshta.n!c
Elasticmalicious (high confidence)
DrWebWin32.HLLP.Neshta
ClamAVWin.Malware.Neshta-6871301-0
CAT-QuickHealW32.Neshta.A
ALYacGenPack:Win32.Neshta.H
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaVirus:Win32/Neshta.554f9864
CyrenW32/HLLP.41472
SymantecW32.Neshuta
ESET-NOD32a variant of Win32/Neshta.D
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyVirus.Win32.Neshta.a
BitDefenderGenPack:Win32.Neshta.H
NANO-AntivirusVirus.Win32.Neshta.injaog
MicroWorld-eScanGenPack:Win32.Neshta.H
TencentVirus.Win32.Neshta.a
Ad-AwareGenPack:Win32.Neshta.H
SophosMal/Generic-R + W32/Neshta-D
ComodoVirus.Win32.Neshta.a0@1c5hiy
BitDefenderThetaAI:FileInfector.D5C3B0640E
VIPREBehavesLike.Win32.Malware.vfm (mx-v)
McAfee-GW-EditionBehavesLike.Win32.Generic.ph
FireEyeGeneric.mg.855b13696cc6ddb2
EmsisoftGenPack:Win32.Neshta.H (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.Lmir.dah
AviraW32/Delf.I
eGambitUnsafe.AI_Score_85%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGenPack:Win32.Neshta.H
Acronissuspicious
McAfeeW32/Generic.t.c
MAXmalware (ai score=88)
VBA32Virus.Win32.Neshta.a
PandaW32/Neshta.A
YandexTrojan.GenAsa!epqEUNloDOY
IkarusTrojan-Spy.Agent
FortinetW32/Neshta.A
AVGFileRepMalware
Paloaltogeneric.ml

How to remove GenPack:Win32.Neshta.H?

GenPack:Win32.Neshta.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment