Malware

W32/Chir-A removal

Malware Removal

The W32/Chir-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Chir-A virus can do?

  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine W32/Chir-A?


File Info:

name: 7F59F1EB1B4EB84EF8EE.mlw
path: /opt/CAPEv2/storage/binaries/d807d7765ffe3ff32dd23249f6212ff9ee25bf718059eece58d32d432399a61a
crc32: 2CB5535F
md5: 7f59f1eb1b4eb84ef8ee9028547d5ebf
sha1: a04756f2e50475abbd039d6ee886a15aa9bcf74c
sha256: d807d7765ffe3ff32dd23249f6212ff9ee25bf718059eece58d32d432399a61a
sha512: c754adfae5480b9b88def5689e015c69e41ba50eb097d89e5a48981ef73d382fa120a0c5f1ade72ad08842937a429eaf74a3ce8486e34f006e22525f1fc35db2
ssdeep: 196608:FTXOkp6Ta1P3jtTmRnyLFRQbu8vF5YhcvcX2mV3DJZgovw3IFa0CylqoQXB0jzQS:xXOkp6Ta17knyLFn8vF5YrXL3XdYPZ4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115C66C51F712C22BD4637BB489DA46E84AB1AE20553198DB33DA3F4D7BB16813E27307
sha3_384: 3924a72c53e2ee3b4b0961d5f82c8650e0078bfbcbe03e74c8dae5e178b7049c6ec297eb740f0a4b99e94ce0e641d86a
ep_bytes: 60e8e61900008b742420e80800000061
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Cheat Engine
FileDescription: Cheat Engine
ProductVersion: 7.3
Comments:
FileVersion: 7.3.0.7199
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
Translation: 0x0409 0x04e4

W32/Chir-A also known as:

BkavW32.ChirBPE
LionicWorm.Win32.Runouce.mzMg
DrWebWin32.Runonce.6652
MicroWorld-eScanWin32.Runouce.B@mm
ClamAVWin.Worm.Brontok-88
CAT-QuickHealW32.Runouce.B
SkyhighBehavesLike.Win32.Generic.wh
McAfeeW32/Chir.b@MM
Cylanceunsafe
SangforWorm.Win32-Script.Save.Nimda
K7AntiVirusTrojan ( 00176e371 )
AlibabaVirus:Win32/Runouce.3ed7
K7GWTrojan ( 00176e371 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Runouce.E2C45E
BitDefenderThetaAI:FileInfector.F1BE214812
VirITWin32.Runouce.D
SymantecW32.Chir.B@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Chir.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Virus.Win32.Chir.gen
BitDefenderWin32.Runouce.B@mm
NANO-AntivirusVirus.Win32.Runouce.bxafx
AvastWin32:Oncer [Inf]
TencentWorm.Win32.Runouce.d
EmsisoftWin32.Runouce.B@mm (B)
F-SecureMalware.W32/Chir.B
BaiduWin32.Virus.ChineseHacker.a
VIPREWin32.Runouce.B@mm
TrendMicroPE_Chir.B
SophosW32/Chir-A
IkarusWorm.Win32.Chir
JiangminWin32/cnPeace.b
GoogleDetected
AviraW32/Chir.B
Antiy-AVLWorm[Email]/Win32.Runouce.b
KingsoftWin32.Type.b.6637
XcitiumVirus.Win32.Sality.gen@1egj5j
MicrosoftVirus:Win32/Chir.B@mm
ViRobotWin32.Chir.B
ZoneAlarmHEUR:Virus.Win32.Chir.gen
GDataWin32.Worm.Runouce.A
VaristW32/Thecid.B@mm
AhnLab-V3Win32/ChiHack.6652
VBA32Virus.Win32.Chur.A
ALYacWin32.Runouce.B@mm
TACHYONVirus/W32.Runouce
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallPE_Chir.B
RisingWorm.ChineseHacker-2 (CLASSIC)
YandexI-Worm.Chir.B
MaxSecureVirus.W32.Runouce.B
FortinetW32/Chir.C!tr
AVGWin32:Oncer [Inf]
DeepInstinctMALICIOUS

How to remove W32/Chir-A?

W32/Chir-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment