Virus

Virus.Win32.Chir removal instruction

Malware Removal

The Virus.Win32.Chir is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Win32.Chir virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

java.com
www.bing.com

How to determine Virus.Win32.Chir?


File Info:

crc32: 649A8181
md5: a8815f0214064331d641102dc381c30e
name: A8815F0214064331D641102DC381C30E.mlw
sha1: a45fdf0946eab5825cb2cc1eff207584be5d5c0e
sha256: 95fe4658c762a7c27ef5bcec83b6823d7c16170a3b8d944a87faba11dc96496b
sha512: e22704c1f77c87fe5280e665a3e40d00a33601e99bb01fc456fa6daa943478935ffc0683cc50f11e8660eb690cf9063e643c1eeab75087ae1c5e322dfb72ef21
ssdeep: 49152:s6bzNo1axh73Ku2zJoXDV+PvKZYcym62m2SSg0zmzkq2pBUTwZAVPQm9:s2o1a2zKX5+ClN6Gjgm+zQa
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Syndicate, LLC, http://www.technicpack.net
InternalName: launcher
FileVersion: 3.0.0.342
CompanyName:
ProductName: Technic Launcher
ProductVersion: 3.0.0.342
FileDescription: Technic Launcher
OriginalFilename: launcher.exe
Translation: 0x0409 0x04e4

Virus.Win32.Chir also known as:

BkavW32.ChirBPE
K7AntiVirusTrojan ( 00176e371 )
Elasticmalicious (high confidence)
DrWebWin32.Runonce.6652
CynetMalicious (score: 100)
CAT-QuickHealW32.Runouce.B
ALYacWin32.Runouce.B@mm
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00176e371 )
Cybereasonmalicious.214064
BaiduWin32.Virus.ChineseHacker.a
CyrenW32/Thecid.B@mm
SymantecW32.Chir.B@mm
ESET-NOD32Win32/Chir.B
APEXMalicious
AvastWin32:Oncer [Inf]
ClamAVWin.Worm.Brontok-88
KasperskyHEUR:Virus.Win32.Chir.gen
BitDefenderWin32.Runouce.B@mm
NANO-AntivirusVirus.Win32.Runouce.bxafx
ViRobotWin32.Chir.B
MicroWorld-eScanWin32.Runouce.B@mm
TencentWorm.Win32.Runouce.d
Ad-AwareWin32.Runouce.B@mm
SophosML/PE-A + W32/Chir-B
ComodoEmailWorm.Win32.Runonce.~v001@1qup51
BitDefenderThetaAI:FileInfector.F1BE214812
VIPREVirus.Win32.Chir.c (v)
TrendMicroPE_Chir.B
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.vc
FireEyeGeneric.mg.a8815f0214064331
EmsisoftWin32.Runouce.B@mm (B)
SentinelOneStatic AI – Suspicious PE
JiangminWin32/cnPeace.b
AviraW32/Chir.B
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASVirus.F
MicrosoftVirus:Win32/Chir.B@mm
GDataWin32.Virus.Chir.A
TACHYONVirus/W32.Runouce
AhnLab-V3Win32/ChiHack.6652
McAfeeW32/Chir.b@MM
MAXmalware (ai score=89)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesWorm.RunOnce
PandaGeneric Malware
TrendMicro-HouseCallPE_Chir.B
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazrXbRTN1vS84j2r9EA/meKP)
YandexI-Worm.Chir.B
MaxSecureVirus.W32.Runouce.B
FortinetW32/Chir.B@mm
AVGWin32:Oncer [Inf]

How to remove Virus.Win32.Chir?

Virus.Win32.Chir removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment