Worm

Worm:Win32/Arhost removal tips

Malware Removal

The Worm:Win32/Arhost is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Arhost virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Worm:Win32/Arhost?


File Info:

crc32: 6A5493DE
md5: b6f106dab6339ab545f3e94499237c70
name: B6F106DAB6339AB545F3E94499237C70.mlw
sha1: 16cf8658fbf324aa18db5823601a76e4da059b19
sha256: 643f03c2c1e33e659292ff91113cbe872cc24f6f6992fd90e7d13dc1aea48969
sha512: d4016039273bf23cc83d52f7a41c8aa1d777dc0127ed5ee5418e55e344a80d91a0bcc5ba1725d1886901f84b0d5c6a66b37629649abd19facaabc28ebcf7bdca
ssdeep: 1536:/VR7UAyM/Pt+AoBhxzhILCrwA7wI2y2Q67VZYfRmQVq:PUqd+1KmwIZ167VZaRmQVq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: ccc
FileVersion: 1.00
CompanyName: Cush
ProductName: ccc
ProductVersion: 1.00
OriginalFilename: ccc.exe

Worm:Win32/Arhost also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.15448
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.VP2.fm1@aOW5H1fi
CylanceUnsafe
ZillyaTrojan.Sadlamnos.Win32.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Blocker.601d18a5
Cybereasonmalicious.ab6339
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Sadlamnos.H
APEXMalicious
AvastWin32:Downloader-FEC [Trj]
ClamAVWin.Dropper.Cobra-8328644-0
KasperskyTrojan-Ransom.Win32.Blocker.bqiw
BitDefenderGen:Trojan.Heur.VP2.fm1@aOW5H1fi
NANO-AntivirusTrojan.Win32.Vobfus.lbriv
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Cush]
MicroWorld-eScanGen:Trojan.Heur.VP2.fm1@aOW5H1fi
TencentWin32.Trojan.Blocker.Pijp
Ad-AwareGen:Trojan.Heur.VP2.fm1@aOW5H1fi
ComodoMalware@#lv1398962n42
BitDefenderThetaAI:Packer.83AC5FAB20
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Trojan.mc
FireEyeGeneric.mg.b6f106dab6339ab5
EmsisoftGen:Trojan.Heur.VP2.fm1@aOW5H1fi (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.cvw
Webrootnone
AviraHEUR/AGEN.1115306
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.253174
MicrosoftWorm:Win32/Arhost
ArcabitTrojan.Heur.VP2.E18875
GDataGen:Trojan.Heur.VP2.fm1@aOW5H1fi
TACHYONRansom/W32.VB-Blocker.84998
McAfeeW32/Rimecud.gen.ak
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3808381160
PandaTrj/Genetic.gen
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Sadlamnos!CJeuYA2LGAM
IkarusTrojan-Dropper.Win32.VB
FortinetW32/Rimecud.AK
AVGWin32:Downloader-FEC [Trj]
Paloaltogeneric.ml

How to remove Worm:Win32/Arhost?

Worm:Win32/Arhost removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment