Malware

Heur.BZC.PZQ.Boxter.591.59845369 removal guide

Malware Removal

The Heur.BZC.PZQ.Boxter.591.59845369 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.591.59845369 virus can do?

  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to execute a powershell command with suspicious parameter/s
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Heur.BZC.PZQ.Boxter.591.59845369?


File Info:

crc32: 90ACC32C
md5: 4d9b6738da02682eeff3fe36480c8f80
name: 4D9B6738DA02682EEFF3FE36480C8F80.mlw
sha1: cf3428823d20e1fa80e84d9ac0ccf9fb5c7c0b9c
sha256: 954b378ff72e0659020c46d9ba11c92289308fcdb82d6387a4a86dd29f4faa78
sha512: 7e581bc9fcfcff8fa3b70cff1145294ad355f042b2e5a81fc84f6ca6c92b49ad779f29404c412405ad6d4df4d1550c97ea34f0bc7d887d7ec383461e5c0f469d
ssdeep: 1536:XH7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIfbw4PO/:XbFfHgTWmCRkGbKGLeNTBfbhU
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.591.59845369 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052419b1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacHeur.BZC.PZQ.Boxter.591.59845369
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0052419b1 )
Cybereasonmalicious.8da026
CyrenW32/SchoolBoy.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
AvastPwrSh:Dropper-G [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderHeur.BZC.PZQ.Boxter.591.59845369
MicroWorld-eScanHeur.BZC.PZQ.Boxter.591.59845369
Ad-AwareHeur.BZC.PZQ.Boxter.591.59845369
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/B2E.Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.Ransom.nh
FireEyeGeneric.mg.4d9b6738da02682e
EmsisoftHeur.BZC.PZQ.Boxter.591.59845369 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/B2E.Dropper.Gen
eGambitUnsafe.AI_Score_93%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitHeur.BZC.PZQ.Boxter.591.59845369
GDataHeur.BZC.PZQ.Boxter.591.59845369
TACHYONRansom/W32.FileCoder.92672
Acronissuspicious
MAXmalware (ai score=81)
RisingTrojan.Generic@ML.95 (RDMK:9WDzGJ8oxZHJ3QEcIOTsGQ)
IkarusTrojan.PowerShell.Crypt
MaxSecureTrojan.Malware.300983.susgen
AVGPwrSh:Dropper-G [Trj]

How to remove Heur.BZC.PZQ.Boxter.591.59845369?

Heur.BZC.PZQ.Boxter.591.59845369 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment