Home Malware Programs Viruses Neshuta

Neshuta

Posted: March 28, 2006

Neshuta is a virus designed to infect executable files with .exe and .com extensions. The virus infects all such files it finds in the compromised computer. It also creates their uninfected copies in C:WindowsTemp or C:WinntTemp folder. Neshuta does not carry any destructive payload. It runs every time an .exe file is executed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 svchost.com

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTexefileShellOpenCommand(Default)=%Windir%svchost.com%1%*
Loading...