Malware

What is “Win32/Neshta.A”?

Malware Removal

The Win32/Neshta.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Neshta.A virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Win32/Neshta.A?


File Info:

crc32: 872F4B35
md5: c11412e6040c245d2d6d3b9bf5751a08
name: connect_updater.exe
sha1: 7330c22b6f38fc4f245fc2ce3d7a181cd7fe6a23
sha256: 83f3f361a4e103e819a13badff309507ff0a417e322ddedff13b5e8bee084145
sha512: 81ff3cac7a0e4fea3e686d454444678518b1b0c188f43e4aac4bcbb7bc940eb89a1af48409cb2ff35d0d5ef1d8b77ab64463c731ddac9579cf11005fc8b3fa80
ssdeep: 3072:tr85CHR5GtRYUqP1KQyWZ5hDCMKN4Lne3:x9xOqP1BjvLe3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Neshta.A also known as:

BkavW32.NeshtaB.PE
DrWebWin32.HLLP.Neshta
MicroWorld-eScanWin32.Neshta.A
FireEyeGeneric.mg.c11412e6040c245d
CAT-QuickHealW32.Neshta.C8
McAfeeW32/HLLP.41472.e
CylanceUnsafe
VIPREVirus.Win32.Neshta.a (v)
AegisLabVirus.Win32.Neshta.tn9H
SangforMalware
K7AntiVirusVirus ( 00556e571 )
BitDefenderWin32.Neshta.A
K7GWVirus ( 00556e571 )
Cybereasonmalicious.6040c2
Invinceaheuristic
BitDefenderThetaAI:FileInfector.D5C3B0640E
F-ProtW32/Trojan2.PZKG
SymantecW32.Neshuta
TotalDefenseWin32/Neshta.A
APEXMalicious
AvastWin32:Apanas [Trj]
ClamAVWin.Trojan.Neshuta-1
GDataWin32.Virus.Neshta.D
KasperskyVirus.Win32.Neshta.a
AlibabaVirus:Win32/Neshta.5c475251
NANO-AntivirusTrojan.Win32.Winlock.fmobyw
ViRobotWin32.Neshta.Gen.A
RisingWin32.Neshta.a (CLOUD)
Endgamemalicious (high confidence)
SophosW32/Neshta-D
ComodoWin32.Neshta.A@3ypg
BaiduWin32.Virus.Neshta.a
ZillyaVirus.Neshta.Win32.1
TrendMicroPE_NESHTA.A
McAfee-GW-EditionBehavesLike.Win32.HLLP.ch
Trapminemalicious.high.ml.score
CMCVirus.Win32.Neshta!O
EmsisoftWin32.Neshta.A (B)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.OBIX-2981
JiangminVirus.Neshta.a
MaxSecureVirus.Infector.Gen9
AviraW32/Neshta.A
Antiy-AVLVirus/Win32.Neshta.a
KingsoftWin32.Neshta.nl.30720
MicrosoftVirus:Win32/Neshta.A
ArcabitWin32.Neshta.A
ZoneAlarmVirus.Win32.Neshta.a
AhnLab-V3Win32/Neshta
Acronissuspicious
VBA32Virus.Win32.Neshta.a
ALYacWin32.Neshta.A
TACHYONVirus/W32.Neshta
Ad-AwareWin32.Neshta.A
MalwarebytesVirus.Neshta
PandaW32/Neshta.A
ZonerVirus.Win32.19514
ESET-NOD32Win32/Neshta.A
TrendMicro-HouseCallPE_NESHTA.A
TencentVirus.Win32.Neshta.a
YandexWin32.Neshta.A
MAXmalware (ai score=84)
eGambitUnsafe.AI_Score_100%
FortinetW32/Generic.AC.171!tr
AVGWin32:Apanas [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Virus.Win32.Neshta.B

How to remove Win32/Neshta.A?

Win32/Neshta.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment