Malware

W32/Chir-A removal

Malware Removal

The W32/Chir-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Chir-A virus can do?

  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine W32/Chir-A?


File Info:

name: BE631192EFC2ABA68B0E.mlw
path: /opt/CAPEv2/storage/binaries/b6dbe7bcbf5608ccbdca05b6aa47addae043f40ce1a6ef0407f56330f232b9a6
crc32: 2C14B01D
md5: be631192efc2aba68b0e5c8c7d7f2f33
sha1: 83a3dcad32d121615270de4e7aa9da55f5700ad3
sha256: b6dbe7bcbf5608ccbdca05b6aa47addae043f40ce1a6ef0407f56330f232b9a6
sha512: 88347d1e035e131bce27bafc859d92f685976e0f9e96c24bdee33f9ca9388ff062aa56527d4240dac743af0b789d3851add003663369efb6797e3018d9fe06ea
ssdeep: 3072:wNaCYfrbwgDO8Wwi81SUHFJV7VDgTMagiuy8F+0yx:wdY/wgq55cSWFJVlC9gA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118F35B01B6E1C0B5E5EE263000F51BBA6E34ED250B3992FB9F51D83A59325909D3AF1F
sha3_384: 9f586cd4800ae808e2ee56824431a3b94a822102d3c07b5aaf9f066d69411b701850ba5ef6214f348127145c4411e26e
ep_bytes: 60e8e61900008b742420e80800000061
timestamp: 1999-01-07 18:10:41

Version Info:

CompanyName: InstallShield Software Corporation
FileDescription: PackageForTheWeb Stub
FileVersion: 2.04.001
InternalName: STUB.EXE
LegalCopyright: Copyright © 1996-1999 InstallShield Software Corporation
OriginalFilename: STUB32.EXE
ProductName: PackageForTheWeb Stub
ProductVersion: 2.04.001
Translation: 0x0409 0x04b0

W32/Chir-A also known as:

BkavW32.ChirBPE
DrWebWin32.Runonce.6652
MicroWorld-eScanWin32.Runouce.B@mm
FireEyeGeneric.mg.be631192efc2aba6
CAT-QuickHealW32.Runouce.B
SkyhighBehavesLike.Win32.Infected.ch
McAfeeW32/Chir.b@MM
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Runouce.B@mm
SangforWorm.Win32-Script.Save.Nimda
K7AntiVirusTrojan ( 00176e371 )
K7GWTrojan ( 00176e371 )
Cybereasonmalicious.2efc2a
BitDefenderThetaAI:FileInfector.F1BE214812
VirITWin32.Runouce.D
SymantecW32.Chir.B@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Chir.B
TrendMicro-HouseCallPE_Chir.B
ClamAVWin.Worm.Brontok-88
KasperskyHEUR:Virus.Win32.Chir.gen
BitDefenderWin32.Runouce.B@mm
NANO-AntivirusVirus.Win32.Runouce.bxafx
AvastWin32:Oncer [Inf]
TencentWorm.Win32.Runouce.d
EmsisoftWin32.Runouce.B@mm (B)
F-SecureMalware.W32/Chir.B
BaiduWin32.Virus.ChineseHacker.a
ZillyaWorm.RunOnce.Win32.2
TrendMicroPE_Chir.B
SophosW32/Chir-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
JiangminWin32/cnPeace.b
GoogleDetected
AviraW32/Chir.B
VaristW32/Thecid.B@mm
Antiy-AVLWorm[Email]/Win32.Runouce.b
KingsoftWin32.Type.b.6637
MicrosoftVirus:Win32/Chir.B@mm
XcitiumEmailWorm.Win32.Runonce.~v001@1qup51
ArcabitWin32.Runouce.E2C45E
ViRobotWin32.Chir.B
ZoneAlarmHEUR:Virus.Win32.Chir.gen
GDataWin32.Worm.Runouce.A
CynetMalicious (score: 99)
AhnLab-V3Win32/ChiHack.6652
Acronissuspicious
VBA32Virus.Win32.Chur.A
ALYacWin32.Runouce.B@mm
TACHYONVirus/W32.Runouce
Cylanceunsafe
PandaGeneric Malware
ZonerProbably Heur.ExeHeaderL
RisingWorm.ChineseHacker-2 (CLASSIC)
YandexI-Worm.Chir.B
IkarusEmail-Worm.Win32.Runouce.B
MaxSecureVirus.W32.Runouce.B
FortinetW32/Chir.C!tr
AVGWin32:Oncer [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirus:Win/ChineseHacker.B(dyn)

How to remove W32/Chir-A?

W32/Chir-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment