Virus

Virus:Win32/Neshta.C removal guide

Malware Removal

The Virus:Win32/Neshta.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Neshta.C virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup

How to determine Virus:Win32/Neshta.C?


File Info:

crc32: 96FE6E88
md5: 032a95c4916f5da9d175246571ea7523
name: 032A95C4916F5DA9D175246571EA7523.mlw
sha1: f267a81d2c44a2298b6dfd27a40ca06c2ddadee4
sha256: 4824693d37ee0c444b89e21a2ae1cba396927f299e88751759635b2795c1bc96
sha512: e0633067a9ceec00cc2c07b2015c4e00558f0d6a840436fd8025604986be96fd351fcd998809f584bb89ebcbda32ef5ddc90ef16ef40a01b710146fb7446c71d
ssdeep: 98304:obXSmn+M4542KaQ2SWg29e6p/PE3vBwc5k:oT1nD4s2N9Vp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Virus:Win32/Neshta.C also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36390239
FireEyeGeneric.mg.032a95c4916f5da9
CAT-QuickHealTrojan.Generic
McAfeeArtemis!032A95C4916F
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00490ad51 )
BitDefenderTrojan.GenericKD.36390239
K7GWTrojan ( 00490ad51 )
Cybereasonmalicious.4916f5
BitDefenderThetaGen:NN.ZexaF.34590.ezW@aKdhrig
CyrenW32/Agent.BVV.gen!Eldorado
SymantecTrojan.Gen.6
ESET-NOD32multiple detections
BaiduWin32.Virus.Neshta.a
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaVirus:Win32/Neshta.288
NANO-AntivirusTrojan.Win32.Inject3.imhhua
RisingWin32.Neshta.a (CLASSIC:bWQ1OgW7Ztux+qZF3IO9nSiUdrU)
Ad-AwareTrojan.GenericKD.36390239
SophosMal/Generic-S
ComodoWin32.Neshta.A@3ypg
F-SecureHeuristic.HEUR/AGEN.1137410
DrWebTrojan.Inject3.3451
ZillyaTrojan.ScriptKD.JS.10
TrendMicroTROJ_GEN.R002C0DBM21
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftTrojan.GenericKD.36390239 (B)
IkarusTrojan-Dropper.MSIL.Agent
eGambitUnsafe.AI_Score_91%
AviraHEUR/AGEN.1137410
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.EnigmaProtect.a
KingsoftWin32.Infected.neshta.nl.(kcloud)
MicrosoftVirus:Win32/Neshta.C
GridinsoftVirus.Neshta.A.sd!yf
ArcabitTrojan.Generic.D22B455F
AhnLab-V3Trojan/Win32.RL_Generic.R367303
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Virus.Neshta.D
CynetMalicious (score: 100)
VBA32Trojan.Zpevdo
ALYacWin32.Neshta.A
MalwarebytesBackdoor.Bladabindi.Generic
ZonerVirus.Win32.19514
TrendMicro-HouseCallTROJ_GEN.R002C0DBM21
YandexTrojan.GenAsa!Mo0tdcmmg3o
SentinelOneStatic AI – Malicious SFX
FortinetRiskware/Generic
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Virus.Neshta.HwYDc7EA

How to remove Virus:Win32/Neshta.C?

Virus:Win32/Neshta.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment