Malware

Heur.Variadic.A.261.1 removal guide

Malware Removal

The Heur.Variadic.A.261.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Variadic.A.261.1 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Tatar
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Heur.Variadic.A.261.1?


File Info:

name: 82557890242FD8361E62.mlw
path: /opt/CAPEv2/storage/binaries/0fdf29ffffcdd6b76d98fc244175b0a491641f16524b1da6b87f10a4cb1ec4bd
crc32: A7345A3E
md5: 82557890242fd8361e62d482514ad77b
sha1: 485408a5af03b8ef8264b929856920837968489d
sha256: 0fdf29ffffcdd6b76d98fc244175b0a491641f16524b1da6b87f10a4cb1ec4bd
sha512: 5eb232af49855ee6563792f9ae907063d97e8c5093aa2322cac44d65614e99842c60a510acd359389cbffbaa23faf5bca0d2a37c3f2a78de237e6028ce0f752a
ssdeep: 98304:ToDMBDuRWlLyqcRC616vTQVBs8MQ8KA/yDHCTjpjzo6lb:TdBZlLy3CMNVBs85p4yDHC/po6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109163310FAA3C074F5F216FA993D861C702A79A1AF6961CF51D416EA67383E19C32337
sha3_384: 17cfc8c477046ada19414f62026d5d7703b748efa1f08977515499b415f398f2062947b72aea3c5dc594b33a8a28f612
ep_bytes: 8bff558bece806de0000e8110000005d
timestamp: 2020-04-27 15:01:12

Version Info:

FileVersions: 7.0.0.23
ProductVersions: 67.0.20.45
InternalName: calinilimodumator.exe
LegalCopyrights: Vsekdag
Translation: 0x0409 0x1744

Heur.Variadic.A.261.1 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Blocker.mDYp
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Variadic.A.261.1
ClamAVWin.Malware.Generic-9834822-0
CAT-QuickHealTrojan.GenericRI.S19154351
McAfeePacked-GBE!82557890242F
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.3742026
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057850d1 )
AlibabaTrojan:Win32/Azorult.b4538cda
K7GWTrojan ( 0057850d1 )
Cybereasonmalicious.0242fd
CyrenW32/Trojan.FWF.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HJOS
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Eb.gen
BitDefenderGen:Heur.Variadic.A.261.1
NANO-AntivirusTrojan.Win32.Eb.imkufx
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan.Eb.Edhl
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/Crypt.XPACK.Gen3
VIPREGen:Heur.Variadic.A.261.1
TrendMicroTrojan.Win32.GLUPTEBA.SMD.hp
McAfee-GW-EditionBehavesLike.Win32.Lockbit.wc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.82557890242fd836
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.Variadic.A.261.1
JiangminTrojan.Eb.aek
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.EB
ArcabitTrojan.Variadic.A.261.1
ViRobotTrojan.Win32.Z.Variadic.4098048
ZoneAlarmHEUR:Trojan.Win32.Eb.gen
MicrosoftTrojan:Win32/Azorult.GKM!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Tofsee.R367511
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36164.6×0@a8zUKtgG
ALYacGen:Heur.Variadic.A.261.1
VBA32BScope.Trojan.Azorult
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.GLUPTEBA.SMD.hp
RisingTrojan.Kryptik!1.D2F7 (CLASSIC)
YandexTrojan.Eb!8hZhLCxtsxc
IkarusTrojan-Spy.Theft.Ficker
MaxSecureTrojan.Malware.74428152.susgen
FortinetW32/Kryptik.HJPF!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Heur.Variadic.A.261.1?

Heur.Variadic.A.261.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment