Malware

W32/Chir-A removal instruction

Malware Removal

The W32/Chir-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Chir-A virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine W32/Chir-A?


File Info:

name: B877080BCCCD0FCE2568.mlw
path: /opt/CAPEv2/storage/binaries/b35d419936e3201f1a22158d9784a15a7359d4ec552c88976d11d3d98c313ba0
crc32: 660EDBAA
md5: b877080bcccd0fce25684f022b29712b
sha1: 5659b240f48fba095c8fdc757e96e3f8b7617c90
sha256: b35d419936e3201f1a22158d9784a15a7359d4ec552c88976d11d3d98c313ba0
sha512: 39ad725a72f71f5720e6c62b527ed78adece498654af95d527760a73d8ac3959e2e8d2ecc31acdb00302472f044bdd965ad4a6d21aa25965908c92fba6301e75
ssdeep: 49152:GRHtzu8ZT/XB8ycD6YvnnShEI9Z5aKXuyd2AZ4cU:GRyb7Ksvyd2AZ4c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11BE58E0133728CB4C84D4A7B9C3AD8887F307F819E95A325B4CFDF2E64E55458AD96B2
sha3_384: 9169083b9aca254146c3f264290325000bf4977a0f98073b6d5d53047376c9c9b2ff7bf822027efd40499660c998369c
ep_bytes: 60e8e61900008b742420e80800000061
timestamp: 2017-05-17 15:58:52

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Easeware
FileDescription: DriverEasy
FileVersion: 5.5.1
InternalName: DriverEasy.exe
LegalCopyright: Copyright © 2017, Easeware. All right reserved.
OriginalFilename: DriverEasy.exe
ProductName: DriverEasy
ProductVersion: 5.5.1
Assembly Version: 5.5.1.14322

W32/Chir-A also known as:

BkavW32.ChirBPE
Elasticmalicious (high confidence)
DrWebWin32.Runonce.6652
MicroWorld-eScanWin32.Runouce.B@mm
CAT-QuickHealW32.Runouce.B
SkyhighW32/Chir.b@MM
McAfeeW32/Chir.b@MM
Cylanceunsafe
SangforWorm.Win32-Script.Save.Nimda
K7AntiVirusTrojan ( 00176e371 )
K7GWTrojan ( 00176e371 )
BitDefenderThetaAI:FileInfector.F1BE214812
VirITWin32.Runouce.D
SymantecW32.Chir.B@mm
ESET-NOD32Win32/Chir.B
CynetMalicious (score: 99)
ClamAVWin.Worm.Brontok-88
KasperskyHEUR:Virus.Win32.Chir.gen
BitDefenderWin32.Runouce.B@mm
NANO-AntivirusVirus.Win32.Runouce.bxafx
AvastWin32:Oncer [Inf]
TencentWorm.Win32.Runouce.d
SophosW32/Chir-A
F-SecureMalware.W32/Chir.B
BaiduWin32.Virus.ChineseHacker.a
VIPREWin32.Runouce.B@mm
TrendMicroPE_Chir.B
EmsisoftWin32.Runouce.B@mm (B)
IkarusEmail-Worm.Win32.Runouce.B
JiangminWin32/cnPeace.b
VaristW32/Thecid.B@mm
AviraW32/Chir.B
Antiy-AVLWorm[Email]/Win32.Runouce.b
KingsoftWin32.Type.b.6637
MicrosoftVirus:Win32/Chir.B@mm
XcitiumEmailWorm.Win32.Runonce.~v001@1qup51
ArcabitWin32.Runouce.E2C45E
ViRobotWin32.Chir.B
ZoneAlarmHEUR:Virus.Win32.Chir.gen
GDataWin32.Runouce.B@mm
GoogleDetected
AhnLab-V3Win32/ChiHack.6652
VBA32Virus.Win32.Chur.A
TACHYONVirus/W32.Runouce
MalwarebytesNeshta.Virus.FileInfector.DDS
TrendMicro-HouseCallPE_Chir.B
RisingWorm.ChineseHacker-2 (CLASSIC)
YandexI-Worm.Chir.B
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Runouce.B
FortinetW32/Chir.C!tr
AVGWin32:Oncer [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove W32/Chir-A?

W32/Chir-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment