Worm

Worm:Win32/Arhost.A removal

Malware Removal

The Worm:Win32/Arhost.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Arhost.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Worm:Win32/Arhost.A?


File Info:

name: ED7CBC22B0B35DB34A3B.mlw
path: /opt/CAPEv2/storage/binaries/27e36868f9ada20c24c9f7cb9a3050cf331e24bdd2b92991df7313bf4721b860
crc32: 231C4C8D
md5: ed7cbc22b0b35db34a3bd44973a38e0b
sha1: 751e278188f28ec81d9bbda7dfbf907c1bea365d
sha256: 27e36868f9ada20c24c9f7cb9a3050cf331e24bdd2b92991df7313bf4721b860
sha512: cd529db2c9507a48ab7dab6900e332c835fe84628770079e178ce1379d9f2d7476dfb66da588d8927cd5fa3bc3c553b118710b7c731aa94d46637f9908945a4a
ssdeep: 6144:liKQ+YDpUpAJmYAXgeT28ke2DSwl8T1spyo7aoU1Ur+4Usuxo:liK5YDpUpAJmT5P2ewyT1sp++Ozxo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132541214EBE50732F2E461B60E4AC7F7D56FECB52F513301C2804E45392A94E6E26ADE
sha3_384: 9508b4f756cbe6cd7f83238d6a31128120ca5357c3683f9775a09441837acffe7e2a7915ed3120d4ca4b07159f7f7741
ep_bytes: 558bec6aff6868514000686048400064
timestamp: 2010-02-22 23:28:42

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 2, 0, 0, 0
InternalName:
LegalCopyright: Copyright © 2009
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName:
ProductVersion: 2, 0, 0, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Worm:Win32/Arhost.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.liiQ
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen.14342
MicroWorld-eScanGen:Heur.Krypt.10
FireEyeGeneric.mg.ed7cbc22b0b35db3
McAfeeW32/Rimecud.gen.af
CylanceUnsafe
ZillyaWorm.AutoRun.Win32.63541
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0055e3991 )
AlibabaMalware:Win32/km_24de0.None
K7GWTrojan ( 0055e3991 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Krypt.10
BitDefenderThetaAI:Packer.9129C88320
CyrenW32/S-04534474!Eldorado
SymantecW32.Pilleuz
ESET-NOD32a variant of Win32/Injector.AZZ
APEXMalicious
TrendMicro-HouseCallWORM_EGGDROP.SMF
Paloaltogeneric.ml
ClamAVWin.Worm.Agent-859949
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Krypt.10
NANO-AntivirusTrojan.Win32.MLW.dkfnc
AvastWin32:Zbot-MQY [Trj]
TencentMalware.Win32.Gencirc.114be520
Ad-AwareGen:Heur.Krypt.10
EmsisoftGen:Heur.Krypt.10 (B)
ComodoTrojWare.Win32.Spy.Zbot.AAW@1p8hmz
VIPREGen:Heur.Krypt.10
TrendMicroWORM_EGGDROP.SMF
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Resdro-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bjbjd
Webroot
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.5E
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftWorm:Win32/Arhost.A
ViRobotWorm.Win32.A.AutoRun.287233
GDataWin32.Trojan.Agent.EF
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Palevo.R40484
VBA32Trojan.Win32.Bofa.01
ALYacGen:Heur.Krypt.10
MalwarebytesBackdoor.Bot
RisingWorm.Neeris!1.6595 (CLASSIC)
YandexTrojan.GenAsa!8XfTprydZQQ
IkarusP2P-Worm.Win32.Palevo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PackAntiEm.A!tr
AVGWin32:Zbot-MQY [Trj]
Cybereasonmalicious.2b0b35
PandaTrj/Genetic.gen

How to remove Worm:Win32/Arhost.A?

Worm:Win32/Arhost.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment