Malware

Win32/Chir.A removal tips

Malware Removal

The Win32/Chir.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Chir.A virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine Win32/Chir.A?


File Info:

name: E84D3B30C6C039CCD7FE.mlw
path: /opt/CAPEv2/storage/binaries/760353685efa4c11c7a41391aa7bac830c42b866c99217c329f3663a9eb4ff63
crc32: 1E5AD2AC
md5: e84d3b30c6c039ccd7fe9d584dc2f6bf
sha1: d782117fdff9b7d01edc61eac16e9b937f6c2d79
sha256: 760353685efa4c11c7a41391aa7bac830c42b866c99217c329f3663a9eb4ff63
sha512: af126b9e4188ce388b26a792aef4d3c0719c14110467b0e4b3be5c337d9be31fd9d3bb985c4260dc3e591007a95d6d1a460623cdcbf7a434c67447a7fbc28781
ssdeep: 24576:Qd6zXvNeZDf/nnI7PLNU7xeR20CsdVhgcPPergg:egU7/nI7PLNU7xQqsdVT2Mg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9458E31B941C032E7A25172497CF67614ADE8300B2E45CBE3D85A3D2FA56C27F3969B
sha3_384: e36f75b3712b0ddea46224c99e22a86237b84cc7c4124bf15652ceacfa15005b24ea421ba2cff3994a0570b8ffdfcd26
ep_bytes: 60e8e61900008b742420e80800000061
timestamp: 2019-08-16 10:05:05

Version Info:

CompanyName: Sogou.com Inc.
FileDescription: 搜狗输入法 崩溃反馈
FileVersion: 9.4.0.3336
InternalName: SogouPY CrashRpt
LegalCopyright: © 2019 Sogou.com Inc. All rights reserved.
OriginalFilename: CrashRpt.exe
ProductName: 搜狗输入法
ProductVersion: 9.4.0.3336
Translation: 0x0804 0x04b0

Win32/Chir.A also known as:

BkavW32.ChirBPE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Runouce.B@mm
FireEyeGeneric.mg.e84d3b30c6c039cc
CAT-QuickHealW32.Runouce.B
SkyhighBehavesLike.Win32.Sality.th
McAfeeW32/Chir.b@MM
MalwarebytesGeneric.Malware.AI.DDS
SangforWorm.Win32-Script.Save.Nimda
K7AntiVirusTrojan ( 00176e371 )
K7GWTrojan ( 00176e371 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Virus.ChineseHacker.a
VirITWin32.Runouce.D
SymantecW32.Chir.B@mm
ESET-NOD32a variant of Win32/Chir.A
APEXMalicious
TrendMicro-HouseCallPE_Chir.B
ClamAVWin.Worm.Brontok-88
KasperskyHEUR:Virus.Win32.Chir.gen
BitDefenderWin32.Runouce.B@mm
NANO-AntivirusVirus.Win32.Runouce.bxafx
AvastWin32:Oncer [Inf]
TencentWorm.Win32.Runouce.d
TACHYONVirus/W32.Runouce
EmsisoftWin32.Runouce.B@mm (B)
GoogleDetected
F-SecureMalware.W32/Chir.B
DrWebWin32.Runonce.6652
ZillyaWorm.RunOnce.Win32.2
TrendMicroPE_Chir.B
SophosW32/Chir-A
IkarusWorm.Win32.Chir
JiangminWin32/cnPeace.b
VaristW32/Thecid.B@mm
AviraW32/Chir.B
Antiy-AVLWorm[Email]/Win32.Runouce.b
KingsoftWin32.Type.b.6637
MicrosoftVirus:Win32/Chir.B@mm
XcitiumEmailWorm.Win32.Runonce.~v001@1qup51
ArcabitWin32.Runouce.E2C45E
ViRobotWin32.Chir.B
ZoneAlarmHEUR:Virus.Win32.Chir.gen
GDataWin32.Worm.Runouce.A
CynetMalicious (score: 99)
AhnLab-V3Win32/ChiHack.6652
BitDefenderThetaAI:FileInfector.F1BE214812
ALYacWin32.Runouce.B@mm
MAXmalware (ai score=87)
VBA32Virus.Win32.Chur.A
Cylanceunsafe
PandaGeneric Malware
RisingWorm.ChineseHacker-2 (CLASSIC)
YandexI-Worm.Chir.B
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Runouce.B
FortinetW32/Chir.C!tr
AVGWin32:Oncer [Inf]
DeepInstinctMALICIOUS
alibabacloudVirus:Win/ChineseHacker.B(dyn)

How to remove Win32/Chir.A?

Win32/Chir.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment