Threat Search: 

ThreatExpert's Statistics for W32.Neshuta [Symantec]:

W32.Neshuta [Symantec] is also known as:
Threat AliasNumber of Incidents
W32/HLLP.41472.e [McAfee]72
Virus.Win32.Neshta.a [Kaspersky Lab]71
Win32.Neshta.A [PC Tools]68
PE_NESHTA.A-O [Trend Micro]57
Virus:Win32/Neshta.A [Microsoft]39
W32/Bloat-A [Sophos]39
Virus.Win32.Neshta.a [Ikarus]19
PE_NESHTA.A [Trend Micro]16
Win32/Neshta [AhnLab]14
Virus.Neshta [PC Tools]5
BHO.Win32.CashOn [Ikarus]1
Mal/Behav-053 [Sophos]1
Trojan.Win32.Agent.rpf [Kaspersky Lab]1
Virus.Win32.Neshta.b [Kaspersky Lab]1
W32/HLLP.41472 [McAfee]1
Win32.Masha.B [PC Tools]1

W32.Neshuta [Symantec] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation41

W32.Neshuta [Symantec] is known to be created as:
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.