Worm

How to remove “Worm:Win32/Arhost.B”?

Malware Removal

The Worm:Win32/Arhost.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Arhost.B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Arhost.B?


File Info:

name: 58529D2BA94E1A33AB1B.mlw
path: /opt/CAPEv2/storage/binaries/51452deac683daaab31eb478b23efa6aaa4ba2dfeaa54d98231dcd6fdeb38a8a
crc32: 392DFDF0
md5: 58529d2ba94e1a33ab1ba2a8eedaf962
sha1: 66324fe1cf5e79a40a02ebacf92bef7cfb4fbd50
sha256: 51452deac683daaab31eb478b23efa6aaa4ba2dfeaa54d98231dcd6fdeb38a8a
sha512: 128e46fc495efab6cb1782a6dd4d26df00e4e36234d7fed3738dc108a3376d08869f240786179fc2f0976ca147aeb7209ce3fdf8148cd636f57108f79e804012
ssdeep: 6144:IKG0xJ75KzESGXN2FtpygMe1BEoqaM7T6yHDg8o6MNkLdOj82labP1T2Dy/5+m:UmJuPOKyHD939F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE448007AB00B02BE95364B03965E1AEA9157C3306D4EE177783BF9662345D3A9F072F
sha3_384: 6083ce1e1982ab8de49095c31b3aaa9667663d032f35e521c4e8500e5446f2a40754c882b2f281ef79a2c54c00278419
ep_bytes: 68e82d4000e8f0ffffff000000000000
timestamp: 2010-07-11 00:53:07

Version Info:

Translation: 0x0409 0x04b0
ProductName: sdfsdf
FileVersion: 1.00
ProductVersion: 1.00
InternalName: b
OriginalFilename: b.exe

Worm:Win32/Arhost.B also known as:

BkavW32.AIDetectMalware
AVGWin32:DropperX-gen [Drp]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.521454
FireEyeGeneric.mg.58529d2ba94e1a33
CAT-QuickHealTrojan.Swisyn.ai3
SkyhighSwisyn.z
McAfeeSwisyn.z
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Swisyn.Win32.34030
SangforSuspicious.Win32.Save.vb
K7AntiVirusP2PWorm ( 00132c7f1 )
K7GWP2PWorm ( 00132c7f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.FB1912691F
VirITTrojan.Win32.Generic.AGTR
SymantecW32.SillyFDC
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.RR
CynetMalicious (score: 99)
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Trojan.VB-1372
KasperskyTrojan.Win32.Swisyn.aikq
BitDefenderGen:Variant.Zusy.521454
NANO-AntivirusTrojan.Win32.Swisyn.bnpsh
TencentMalware.Win32.Gencirc.10b89618
EmsisoftGen:Variant.Zusy.521454 (B)
BaiduWin32.Worm.VB.f
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen2.11631
VIPREGen:Variant.Zusy.521454
TrendMicroWORM_VB.SMOW
SophosMal/Generic-R
IkarusTrojan.Win32.Swisyn
JiangminTrojan/Swisyn.vlc
WebrootWorm:Win32/Arhost.B
VaristW32/VB.AM.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Swisyn
MicrosoftWorm:Win32/Arhost.B
XcitiumTrojWare.Win32.swisyn.AIKQ@2na1s7
ArcabitTrojan.Zusy.D7F4EE
ViRobotTrojan.Win32.A.Swisyn.258088
ZoneAlarmTrojan.Win32.Swisyn.aikq
GDataGen:Variant.Zusy.521454
GoogleDetected
AhnLab-V3Trojan/Win32.Swisyn.R855
VBA32Trojan.VBRA.04037
ALYacGen:Variant.Zusy.521454
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VB.SMOW
RisingTrojan.Win32.Generic.1232ECE2 (C64:YzY0Ol+i2FXtXSkn)
YandexTrojan.GenAsa!+pRnGKswLCs
MAXmalware (ai score=87)
FortinetW32/Swisyn.AIK!tr
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Worm:Win32/Arhost.B?

Worm:Win32/Arhost.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment