Malware

W32/Chir-A removal tips

Malware Removal

The W32/Chir-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Chir-A virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine W32/Chir-A?


File Info:

name: 049A802C6D2CFFFEF2C7.mlw
path: /opt/CAPEv2/storage/binaries/672f5c5c7efbe877c7ef3860b91124f4787d1f248029e24bcf990d0531a1ab57
crc32: D48E37E4
md5: 049a802c6d2cfffef2c7c6a9fe900097
sha1: acb1047a019e7f1be65d795e53dd5c9c1c2035f9
sha256: 672f5c5c7efbe877c7ef3860b91124f4787d1f248029e24bcf990d0531a1ab57
sha512: fd0b7f6dd340dd78eec4a63b0d2aa7d5f28092a64200253ddca3ac3b55e873a620b5083b713fc70ff81a93149acf2f96f40729f9df1a5d5e2246f5572d6f3316
ssdeep: 12288:a5gArEmi72peZWc68liMXPI7XHgZQKhJgeCm7Dz/:a59i7WescHiMXwLHgZpJEI/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BF4CF52F7E19932F1B293304AB5B335DA7FBD390C23831F95246D6A38716A19A75303
sha3_384: e54479d7f5b28a20d311352cfa4e963ce0b6db60e183035b3ff31f0bdef8da803e808200d7f803295adea00a86769bd3
ep_bytes: 60e8e61900008b742420e80800000061
timestamp: 2010-03-16 09:56:22

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Document Cache
FileVersion: 14.0.4757.1000
InternalName: Cache
LegalCopyright: © 2010 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: msosync.exe
ProductName: Microsoft Office 2010
ProductVersion: 14.0.4757.1000
Translation: 0x0000 0x04e4

W32/Chir-A also known as:

BkavW32.ChirBPE
LionicWorm.Win32.Runouce.lk4E
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Runouce.B@mm
ClamAVWin.Worm.Brontok-88
FireEyeGeneric.mg.049a802c6d2cfffe
CAT-QuickHealW32.Runouce.B
SkyhighBehavesLike.Win32.Virut.bc
McAfeeW32/Chir.b@MM
Cylanceunsafe
ZillyaWorm.RunOnce.Win32.2
SangforWorm.Win32-Script.Save.Nimda
K7AntiVirusTrojan ( 00176e371 )
AlibabaVirus:Win32/Runouce.3ed7
K7GWTrojan ( 00176e371 )
Cybereasonmalicious.a019e7
BitDefenderThetaAI:FileInfector.F1BE214812
VirITWin32.Runouce.D
SymantecW32.Chir.B@mm
ESET-NOD32Win32/Chir.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Virus.Win32.Chir.gen
BitDefenderWin32.Runouce.B@mm
NANO-AntivirusVirus.Win32.Runouce.bxafx
AvastWin32:Oncer [Inf]
TencentWorm.Win32.Runouce.d
TACHYONVirus/W32.Runouce
EmsisoftWin32.Runouce.B@mm (B)
BaiduWin32.Virus.ChineseHacker.a
F-SecureMalware.W32/Chir.B
DrWebWin32.Runonce.6652
VIPREWin32.Runouce.B@mm
TrendMicroPE_Chir.B
Trapminemalicious.high.ml.score
CMCVirus.Worm.Win32.Runouce.1!O
SophosW32/Chir-A
IkarusEmail-Worm.Win32.Runouce.B
GDataWin32.Worm.Runouce.A
JiangminWin32/cnPeace.b
GoogleDetected
AviraW32/Chir.B
Antiy-AVLWorm[Email]/Win32.Runouce.b
KingsoftWin32.Type.b.6637
XcitiumEmailWorm.Win32.Runonce.~v001@1qup51
ArcabitWin32.Runouce.E2C45E
ViRobotWin32.Chir.B
ZoneAlarmHEUR:Virus.Win32.Chir.gen
MicrosoftVirus:Win32/Chir.B@mm
VaristW32/Thecid.B@mm
AhnLab-V3Win32/ChiHack.6652
VBA32Virus.Win32.Chur.A
ALYacWin32.Runouce.B@mm
MAXmalware (ai score=84)
MalwarebytesChir.Spyware.Infostealer.DDS
PandaGeneric Malware
TrendMicro-HouseCallPE_Chir.B
RisingWorm.ChineseHacker-2 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.W32.Runouce.B
FortinetW32/Chir.C!tr
AVGWin32:Oncer [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove W32/Chir-A?

W32/Chir-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment