Virus

Virus:Win32/Chir!dam removal

Malware Removal

The Virus:Win32/Chir!dam is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Chir!dam virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Chir!dam?


File Info:

name: D281C010F886E29DCC3A.mlw
path: /opt/CAPEv2/storage/binaries/85f3c8928ecb702f65d6284ad3e797513ce20d0cb4fe78610d76d573adf81472
crc32: 66708329
md5: d281c010f886e29dcc3ab6ee3d892600
sha1: 2f606ec5d49a0f55f6cbb8a30630bf28bc0564b5
sha256: 85f3c8928ecb702f65d6284ad3e797513ce20d0cb4fe78610d76d573adf81472
sha512: 7cc4dbaafb10a218dc27bbfc6c7d1508e446929fe6c047a27605c0ca533715db588b11fb96fadaea7a3897cfc3a0e0af8ac7c255627d0975edd4ecfc666fc81b
ssdeep: 3072:zJw8KYg5zA5GsMYSxSJiN/vGss9kTBf9pAXAtPOYQw9T:z035iMhL/vGsbTBl2wOs9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D147B2072C0C073C062147641B5C7F19EBB78755A66AA8BBBCB5FB90F352D2D62938D
sha3_384: fad3a121d8f160ffd13a1b9c15217b1afe8efefc4b37cf4f45ecbd5f44abe3e30f066e6b6bc0e579c9cddce09d4fb6b4
ep_bytes: 60e8e6190000101471766c3271762212
timestamp: 2009-01-29 11:57:09

Version Info:

0: [No Data]

Virus:Win32/Chir!dam also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Runouce.lk4E
AVGWin32:Crypt-RPY [Trj]
Elasticmalicious (high confidence)
DrWebJS.Nimda
MicroWorld-eScanWin32.Runouce.S
FireEyeGeneric.mg.d281c010f886e29d
CAT-QuickHealW32.Runouce.CR1
SkyhighBehavesLike.Win32.Kudj.ch
McAfeeW32/Chir.gen@MM!remanants
MalwarebytesChir.Spyware.Infostealer.DDS
VIPREWin32.Runouce.S
SangforWorm.Win32-Script.Save.Nimda
K7AntiVirusVirus ( 7000000b1 )
AlibabaVirus:Win32/Scribble.1f94b4b7
K7GWVirus ( 7000000b1 )
Cybereasonmalicious.0f886e
BitDefenderThetaGen:NN.ZexaF.36802.mqW@aCnjgIfi
VirITWin32.Runouce.D
SymantecW32.Chir.B@mm
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Worm.Brontok-88
KasperskyHEUR:Virus.Win32.Chir.gen
BitDefenderWin32.Runouce.S
NANO-AntivirusVirus.Win32.Runouce.bxafx
SUPERAntiSpywareWorm.Chir
AvastWin32:Crypt-RPY [Trj]
TencentWorm.Win32.Runouce.d
EmsisoftWin32.Runouce.S (B)
F-SecureMalware.W32/Chir.B
BaiduWin32.Trojan.Agent.bf
TrendMicroPE_Chir.B
SophosMal/Scribble-D
IkarusTrojan.SuspectCRC
JiangminBackdoor/Agent.bgb
GoogleDetected
AviraW32/Chir.B
Antiy-AVLWorm[Email]/Win32.Runouce.b
KingsoftWorm.NimdaT.d.18848
MicrosoftVirus:Win32/Chir.gen!dam
XcitiumEmailWorm.Win32.Runonce.~v001@1qup51
ArcabitWin32.Runouce.S
ZoneAlarmHEUR:Virus.Win32.Chir.gen
GDataWin32.Worm.Runouce.A
VaristW32/Agent.JX.gen!Eldorado
Acronissuspicious
MAXmalware (ai score=87)
Cylanceunsafe
PandaW32/Chir.P.worm
TrendMicro-HouseCallPE_Chir.B
RisingTrojan.Generic@AI.100 (RDML:vJBJElYaV+HEdls47OSJlQ)
YandexJS.Chir.B
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Runouce.B
FortinetHTML/Iframe.A!exploit
ZonerProbably Heur.ExeHeaderL
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudVirus:Win/Chir.A

How to remove Virus:Win32/Chir!dam?

Virus:Win32/Chir!dam removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment