Malware

How to remove “Heur.BZC.PZQ.Boxter.591.2F8BC87B”?

Malware Removal

The Heur.BZC.PZQ.Boxter.591.2F8BC87B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.591.2F8BC87B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments

How to determine Heur.BZC.PZQ.Boxter.591.2F8BC87B?


File Info:

name: 253805FAADAC635FEC73.mlw
path: /opt/CAPEv2/storage/binaries/c42fedacc80fcb69261cd3af0d19061e129ad12983ac94ca76181d677ad3ce3e
crc32: 9EE8837C
md5: 253805faadac635fec734d93171110e0
sha1: 1f27cec0fed207879fbc85f871aa2c60d04a6024
sha256: c42fedacc80fcb69261cd3af0d19061e129ad12983ac94ca76181d677ad3ce3e
sha512: fecc11092eab9eda363431eab0dc56f4376fc5aa8b4e3fe1717b79989e56fda0a8927032f08dc11c8ed9c495098a9c80f2ce6daa02351ddc7ab4ac10ded9c55c
ssdeep: 1536:cQ7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIfXweOW:cuFfHgTWmCRkGbKGLeNTBfXF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FF937D45F2E242F7E6F2053201A6716FE735A2388724E8DBC74C2D429953AD1A73D3E9
sha3_384: 4ca71f18b1cf644f45aaeb4719bd892fc39945f7069e1148941e833e607134b0b20501288ddff1d71183430af75584d1
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2018-02-01 20:18:05

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.591.2F8BC87B also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ALYacHeur.BZC.PZQ.Boxter.591.2F8BC87B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
BitDefenderHeur.BZC.PZQ.Boxter.591.2F8BC87B
K7GWTrojan ( 0052419b1 )
Cybereasonmalicious.aadac6
CyrenW32/SchoolBoy.B.gen!Eldorado
ESET-NOD32PowerShell/Kryptik.H
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
MicroWorld-eScanHeur.BZC.PZQ.Boxter.591.2F8BC87B
RisingBackdoor.Agent!8.C5D (RDMK:cmRtazrvOQ4FltweXXOzJBR+zSxY)
EmsisoftHeur.BZC.PZQ.Boxter.591.2F8BC87B (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
FireEyeGeneric.mg.253805faadac635f
SophosGeneric ML PUA (PUA)
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
AviraTR/B2E.Dropper.Gen
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.N1K38E
SentinelOneStatic AI – Malicious PE
CylanceUnsafe
IkarusTrojan.PowerShell.Crypt
eGambitUnsafe.AI_Score_93%
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]

How to remove Heur.BZC.PZQ.Boxter.591.2F8BC87B?

Heur.BZC.PZQ.Boxter.591.2F8BC87B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment