Malware

W32/Chir-A removal

Malware Removal

The W32/Chir-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/Chir-A virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Japanese
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine W32/Chir-A?


File Info:

name: B4E0E5F0073884D26B13.mlw
path: /opt/CAPEv2/storage/binaries/f7c4a8bf156dcbf15b8496cbbcb7596dcdaf30adf32fef30948e1ef5f7cdb64e
crc32: 2FD71462
md5: b4e0e5f0073884d26b130fdc36342988
sha1: 72209b5676a015372dbd4493754f03588c3eb479
sha256: f7c4a8bf156dcbf15b8496cbbcb7596dcdaf30adf32fef30948e1ef5f7cdb64e
sha512: ddfaa6c5c08d8c0fb702d05586e09b81a0bf6703d32f5cd645c59abd732d985b80fb38658bf338446a05d91d9270ac87257b51d9dbed3bfd6eb968bd59c87dc2
ssdeep: 1536:hAahbA+pyRnPXGBJLvqT28RFdezPE/4Ten4GteoiOeGjx+/x6M1shpisKldt:u0p2vYJLv8zl5eoiOeGjx+/x6MmhOx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18CA38D6235C0C033F19608B949A6C1A2DD3ABD740B3685CB7BE5426A5F71BD2DB36353
sha3_384: 84ead1c3cf5af7dee0f4b836084a30cf1ba90b20f184f450282abf44dc1571ec1e7b940e36b1a8b86ea98f13fa955206
ep_bytes: 60e8e61900008b742420e80800000061
timestamp: 2018-07-24 04:15:56

Version Info:

CompanyName: SEIKO EPSON CORPORATION
FileDescription: ENWSD
FileVersion: 3, 6, 1, 2100
InternalName: ENWSD
LegalCopyright: Copyright (C) SEIKO EPSON CORPORATION 2012-2013. All rights reserved.
LegalTrademarks: ENWSD
OriginalFilename: ENWSD.exe
ProductName: ENWSD
ProductVersion: 3, 6, 1, 2100
Translation: 0x0000 0x04b0

W32/Chir-A also known as:

BkavW32.ChirBPE
MicroWorld-eScanWin32.Runouce.B@mm
ClamAVWin.Worm.Brontok-88
FireEyeGeneric.mg.b4e0e5f0073884d2
CAT-QuickHealW32.Runouce.B
SkyhighW32/Chir.b@MM
ALYacWin32.Runouce.B@mm
MalwarebytesGeneric.Malware.AI.DDS
SangforWorm.Win32-Script.Save.Nimda
K7AntiVirusTrojan ( 00176e371 )
K7GWTrojan ( 00176e371 )
Cybereasonmalicious.007388
BitDefenderThetaAI:FileInfector.F1BE214812
SymantecW32.Chir.B@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Chir.B
TrendMicro-HouseCallPE_Chir.B
AvastWin32:Oncer [Inf]
CynetMalicious (score: 100)
KasperskyHEUR:Virus.Win32.Chir.gen
BitDefenderWin32.Runouce.B@mm
NANO-AntivirusVirus.Win32.Runouce.bxafx
TencentWorm.Win32.Runouce.d
EmsisoftWin32.Runouce.B@mm (B)
BaiduWin32.Virus.ChineseHacker.a
F-SecureMalware.W32/Chir.B
DrWebWin32.Runonce.6652
ZillyaWorm.RunOnce.Win32.2
TrendMicroPE_Chir.B
CMCVirus.Worm.Win32.Runouce.1!O
SophosW32/Chir-A
IkarusEmail-Worm.Win32.Runouce.B
JiangminWin32/cnPeace.b
AviraW32/Chir.B
MAXmalware (ai score=89)
Antiy-AVLWorm[Email]/Win32.Runouce.b
KingsoftWin32.Type.b.6637
XcitiumEmailWorm.Win32.Runonce.~v001@1qup51
ArcabitWin32.Runouce.E2C45E
ViRobotWin32.Chir.B
ZoneAlarmHEUR:Virus.Win32.Chir.gen
GDataWin32.Worm.Runouce.A
VaristW32/Thecid.B@mm
AhnLab-V3Win32/ChiHack.6652
Acronissuspicious
McAfeeW32/Chir.b@MM
TACHYONVirus/W32.Runouce
VBA32Virus.Win32.Chur.A
Cylanceunsafe
PandaGeneric Malware
RisingWorm.ChineseHacker-2 (CLASSIC)
YandexI-Worm.Chir.B
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Runouce.B
FortinetW32/Chir.C!tr
AVGWin32:Oncer [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirTool:Win/SignThief.A(dyn)

How to remove W32/Chir-A?

W32/Chir-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment