Malware

W32/Chir-A removal

Malware Removal

The W32/Chir-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Chir-A virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine W32/Chir-A?


File Info:

name: F01CFE73EBCF0F5B8E29.mlw
path: /opt/CAPEv2/storage/binaries/780b4b60987b879635b21ae70997dbb30bb87c2ea78af78abb1663dea625e0ba
crc32: 800DCFC6
md5: f01cfe73ebcf0f5b8e29895a01f28ef7
sha1: fcb9227f863e04c941b27cc984209c0ead7a1ffa
sha256: 780b4b60987b879635b21ae70997dbb30bb87c2ea78af78abb1663dea625e0ba
sha512: 36976e203baa4316134f27b2a61f50aed402f2437077590c0344cf25a0788c634bd663e6de1ecb48bc65482b2ec23b17e6e588eef5d4832117129a881b1c695c
ssdeep: 768:Mbq2gEI6z3llID/PIPhyqVx22isKl4qN:ZPJ2isKldN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D5C2298B790B05F3C86286F0058F2EBAEE77C2588415567E87A8CC7DAF77D58314D219
sha3_384: 7f03e71222a729cbeba56413c8737bc6cfbcae7def22eb2670a33092090e80a37432ab420b7e2cb74a4244bc645be936
ep_bytes: 60e8e61900008b742420e80800000061
timestamp: 2006-12-20 05:58:22

Version Info:

0: [No Data]

W32/Chir-A also known as:

BkavW32.ChirBB.PE
LionicWorm.Win32.Runouce.mzBz
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Runouce.B@mm
FireEyeGeneric.mg.f01cfe73ebcf0f5b
CAT-QuickHealW32.Runouce.B
SkyhighBehavesLike.Win32.Backdoor.mh
McAfeeW32/Chir.b@MM
Cylanceunsafe
SangforWorm.Win32-Script.Save.Nimda
K7AntiVirusTrojan ( 00176e371 )
AlibabaVirus:Win32/Runouce.3ed7
K7GWTrojan ( 00176e371 )
Cybereasonmalicious.f863e0
ArcabitWin32.Runouce.E2C45E
BitDefenderThetaAI:FileInfector.F1BE214812
VirITWin32.Runouce.D
SymantecW32.Chir.B@mm
ESET-NOD32Win32/Chir.B
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Brontok-88
KasperskyHEUR:Virus.Win32.Chir.gen
BitDefenderWin32.Runouce.B@mm
NANO-AntivirusVirus.Win32.Runouce.bxafx
AvastWin32:Oncer [Inf]
TencentWorm.Win32.Runouce.d
TACHYONVirus/W32.Runouce
SophosW32/Chir-A
BaiduWin32.Virus.ChineseHacker.a
F-SecureMalware.W32/Chir.B
DrWebWin32.Runonce.6652
VIPREWin32.Runouce.B@mm
TrendMicroPE_Chir.B
EmsisoftWin32.Runouce.B@mm (B)
IkarusVirus.Win32.Expiro.l
JiangminWin32/cnPeace.b
WebrootW32.Chir.Gen
VaristW32/Thecid.B@mm
AviraW32/Chir.B
Antiy-AVLWorm[Email]/Win32.Runouce.b
KingsoftWin32.Type.b.6637
XcitiumEmailWorm.Win32.Runonce.~v001@1qup51
MicrosoftVirus:Win32/Chir.B@mm
ViRobotWin32.Chir.B
ZoneAlarmHEUR:Virus.Win32.Chir.gen
GDataWin32.Worm.Runouce.A
GoogleDetected
AhnLab-V3Win32/ChiHack.6652
Acronissuspicious
VBA32Virus.Win32.Chur.A
ALYacWin32.Runouce.B@mm
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallPE_Chir.B
RisingWorm.ChineseHacker-2 (CLASSIC)
YandexI-Worm.Chir.B
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Runouce.B
FortinetW32/Chir.C!tr
AVGWin32:Oncer [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove W32/Chir-A?

W32/Chir-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment