Malware

What is “Win32/Filecoder.Chimera.A”?

Malware Removal

The Win32/Filecoder.Chimera.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Chimera.A virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

How to determine Win32/Filecoder.Chimera.A?


File Info:

crc32: 0DFE644C
md5: 1f87a027a27d8d6ca02fc93b9b2e02c7
name: 1F87A027A27D8D6CA02FC93B9B2E02C7.mlw
sha1: 707f2971d7d7d652f7772c13e14aa730ad4c0b84
sha256: 402839f739650e7093e86ba33f65ed6729e732c7c096f4267064ff26aa9fd4ae
sha512: 2f86b3c3037f208f9533243e41142d8784809ab7e19f2aba54c09455fd16ab3b733fd68c99e98147dda5492473a26f9d735c957b85d002b46d90b736c62cf70f
ssdeep: 6144:nLbii5bkgVuN+xSKV7Wkrsf7LsKR1HXb8R:nXikbkgaISKVq3b8R
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
InternalName: 7z.sfx
FileVersion: 9.20
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.20
FileDescription: 7z Console SFX
OriginalFilename: 7z.sfx.exe
Translation: 0x0409 0x04b0

Win32/Filecoder.Chimera.A also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Chimera.j!c
DrWebTrojan.Encoder.25485
ALYacGen:Heur.Ransom.REntS.Gen.1
AlibabaRansom:Win32/Chimera.f4832b50
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.7a27d8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Chimera.A
AvastWin32:Crypchim-A [Trj]
KasperskyTrojan-Ransom.Win32.Chimera.a
BitDefenderGen:Heur.Ransom.REntS.Gen.1
NANO-AntivirusTrojan.Win32.Chimera.eahtgp
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
SophosGeneric Reputation PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1106859
BitDefenderThetaGen:NN.ZedlaF.34142.fq4@a4pxdfj
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPCHIM.CE
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Heur.Ransom.REntS.Gen.1
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
SentinelOneStatic AI – Malicious SFX
JiangminTrojan.Chimera.d
AviraHEUR/AGEN.1106859
eGambitTrojan.Generic
Antiy-AVLTrojan[Ransom]/Win32.Chimera
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Chicrypt.A
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmTrojan-Ransom.Win32.Chimera.a
GDataWin32.Trojan-Ransom.Chimera.A
McAfeeArtemis!1F87A027A27D
MAXmalware (ai score=89)
VBA32TrojanDownloader.Agresbeak
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRYPCHIM.CE
RisingTrojan.Generic@ML.92 (RDML:fyL65DiJ/zOCgpvHlv+z+w)
YandexTrojan.Chimera!JZHTgb6TksY
IkarusPUA.RiskWare.Reflectivepick
FortinetW32/Generic.AP.3505650!tr
AVGWin32:Crypchim-A [Trj]
Paloaltogeneric.ml

How to remove Win32/Filecoder.Chimera.A?

Win32/Filecoder.Chimera.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment