Malware

About “Heur.Variadic.A.148.1” infection

Malware Removal

The Heur.Variadic.A.148.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Variadic.A.148.1 virus can do?

  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the DLAgent02 malware family

How to determine Heur.Variadic.A.148.1?


File Info:

name: 2B2B52602239AF504447.mlw
path: /opt/CAPEv2/storage/binaries/8eb783070cc2abbb9522ca0750d4475719ae26c217e7e02c890d7cf9eccdce0f
crc32: 06B42D5C
md5: 2b2b52602239af504447e80fdb5614bf
sha1: b68ef03baf847c5ba2c0cc7ed85d2bd842cdba45
sha256: 8eb783070cc2abbb9522ca0750d4475719ae26c217e7e02c890d7cf9eccdce0f
sha512: 1ca413d8726b20f67d1296e373077066eac5eb335979184408037cac2aef5494777b2da25cabb3ba80299f216c6a3bf19a7b614c8da0480e8b94f46d6aa43306
ssdeep: 3072:RalzDZCVuAIyiJQYGyBIU9g+n3B+bRaLMPIlo52it4r:slz1CMIgQYGyiN+uaHody
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CCE3408926E8811EF4BA7B376FF0A0419DB7B9925909C53C096431BF05B2584CF6B7B3
sha3_384: 24dcf332be468edcd728f9405c9870854b64ccc6fa5d92c1d43984e7225e88e4dad11be7b1522fc777bc1023a593fbbb
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-02-21 00:38:37

Version Info:

CompanyName: Microsoft Corporation
FileDescription: .NET Native Compiler Toolchain
FileVersion: 1.7.27420.00 built by: PROJECTNGDR2
InternalName: .NET Native Compiler Toolchain
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: .NET Native Compiler Toolchain
ProductName: Microsoft® .NET Framework
ProductVersion: 1.7.27420.00 built by: PROJECTNGDR2
Translation: 0x0409 0x04e4

Heur.Variadic.A.148.1 also known as:

LionicTrojan.MSIL.NanoBot.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Variadic.A.148.1
FireEyeGen:Heur.Variadic.A.148.1
ALYacGen:Heur.Variadic.A.148.1
CylanceUnsafe
ZillyaDownloader.Agent.Win32.421973
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan-Downloader ( 00573a631 )
AlibabaBackdoor:MSIL/NanoBot.c6d26ae9
K7GWTrojan-Downloader ( 00573a631 )
Cybereasonmalicious.02239a
BitDefenderThetaGen:NN.ZemsilF.34212.im1@aieGO9ni
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.HCF
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
BitDefenderGen:Heur.Variadic.A.148.1
NANO-AntivirusTrojan.Win32.NanoBot.idfmlh
AvastWin32:DangerousSig [Trj]
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Heur.Variadic.A.148.1
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-FCTG!2B2B52602239
EmsisoftGen:Heur.Variadic.A.148.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Variadic.A.148.1
MaxSecureTrojan.Malware.73691366.susgen
AviraHEUR/AGEN.1235951
MAXmalware (ai score=82)
ArcabitTrojan.Variadic.A.148.1
ZoneAlarmHEUR:Backdoor.MSIL.NanoBot.gen
MicrosoftTrojan:Win32/Ymacco.AA8E
AhnLab-V3Malware/Win32.RL_Generic.C4274884
McAfeePWS-FCTG!2B2B52602239
MalwarebytesTrojan.Agent
APEXMalicious
IkarusTrojan-Downloader.MSIL.Agent
FortinetMSIL/Kryptik.YTC!tr
AVGWin32:DangerousSig [Trj]
PandaTrj/GdSda.A

How to remove Heur.Variadic.A.148.1?

Heur.Variadic.A.148.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment