Malware

Heur.Variadic.A.19.2 removal guide

Malware Removal

The Heur.Variadic.A.19.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Variadic.A.19.2 virus can do?

  • Executable code extraction
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

xiaokaikai.top
naziyuan.com

How to determine Heur.Variadic.A.19.2?


File Info:

crc32: EB8D8A83
md5: 2b6917cd635172d2953ef766a02de294
name: 2B6917CD635172D2953EF766A02DE294.mlw
sha1: f8815cd5db9297e68c09b14d11dd9e31b5468d88
sha256: 1db73b4852ecd7e17e90bdeea0ad87676f56770e225e27e9f4305358dd6266a4
sha512: b514be4c0418518aec3267a7d517e0e295b8443fc8fb22c75782c35ce73b31e7120281980da2e22204b1cc7852d4df59d8c68a1dee1b18d361d8dd4215ac8a44
ssdeep: 1536:dSP1fVnBfP1jImuLBq/n4Vhp99NAJzet1q:dSPpVBzkBQn4dzOJzetw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2007
InternalName: Elevate
FileVersion: 1, 0, 0, 2894
CompanyName: Johannes Passing
PrivateBuild: Elevate Application
LegalTrademarks: Elevate.exe
Comments: Tool for elevating applications on the command line
ProductName: cntrump@gmail.com Install
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: Elevate
OriginalFilename: Elevate Application
Translation: 0x0409 0x04e4

Heur.Variadic.A.19.2 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004b9abc1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.57839
CynetMalicious (score: 99)
ALYacGen:Heur.Variadic.A.19.2
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (W)
K7GWTrojan ( 004b9abc1 )
Cybereasonmalicious.d63517
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FNLC
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Antavmu.gen
BitDefenderGen:Heur.Variadic.A.19.2
MicroWorld-eScanGen:Heur.Variadic.A.19.2
TencentMalware.Win32.Gencirc.10cf885b
Ad-AwareGen:Heur.Variadic.A.19.2
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34294.iq0@aOcwZ8bb
McAfee-GW-EditionGenericRXES-WD!2B6917CD6351
FireEyeGeneric.mg.2b6917cd635172d2
EmsisoftGen:Heur.Variadic.A.19.2 (B)
AviraTR/Kryptik.itguo
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Variadic.A.19.2
GDataGen:Heur.Variadic.A.19.2
McAfeeGenericRXES-WD!2B6917CD6351
MAXmalware (ai score=88)
VBA32BScope.Backdoor.Lotok
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#77% (RDMK:cmRtazrct6/GsOGf9lu5WyIOVV8o)
FortinetW32/GenKryptik.FNLC!tr
AVGWin32:BackdoorX-gen [Trj]

How to remove Heur.Variadic.A.19.2?

Heur.Variadic.A.19.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment