Malware

What is “Heur.BZC.PZQ.Boxter.591.30DB91B7”?

Malware Removal

The Heur.BZC.PZQ.Boxter.591.30DB91B7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.591.30DB91B7 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments

How to determine Heur.BZC.PZQ.Boxter.591.30DB91B7?


File Info:

name: 226C8BF00549A1045623.mlw
path: /opt/CAPEv2/storage/binaries/ce4b51a70cc4d1c6b5bfc88b676c13276cba4352f31336cc3482191851e6064f
crc32: 7DBAFA1A
md5: 226c8bf00549a10456232af0ea909f87
sha1: d2039fc8cca91684225185a76623385f920243e5
sha256: ce4b51a70cc4d1c6b5bfc88b676c13276cba4352f31336cc3482191851e6064f
sha512: b299d257fb1689ecb1ecddf56207e5344a14a98552d72d18f3ee0c19a08f23c5ca22e60188ba168e1742e33e27cdee00be68d72ef2ab9b8d5232a88b6248979f
ssdeep: 1536:UQ7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIf8w9NOv:UuFfHgTWmCRkGbKGLeNTBf8N
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DF937D45F2E242F7E6F2053201A6716FE735A2388724D8DBC74C2D429953AD1A73D3E9
sha3_384: 85e85117ab9b269d9b20b44befc499cb8368132253d87eb76476120a290bbff736949a91e49d719683d5b52bc6f543e6
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2018-02-01 20:18:05

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.591.30DB91B7 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ALYacHeur.BZC.PZQ.Boxter.591.30DB91B7
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
BitDefenderHeur.BZC.PZQ.Boxter.591.30DB91B7
K7GWTrojan ( 0052419b1 )
CyrenW32/SchoolBoy.B.gen!Eldorado
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
MicroWorld-eScanHeur.BZC.PZQ.Boxter.591.30DB91B7
EmsisoftHeur.BZC.PZQ.Boxter.591.30DB91B7 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
FireEyeGeneric.mg.226c8bf00549a104
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
AviraTR/B2E.Dropper.Gen
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.N1K38E
AhnLab-V3Malware/Win32.RL_Generic.R364998
RisingTrojan.Kryptik!8.8 (RDMK:cmRtazqOePnJxDzFqjLKw5MjO5F3)
IkarusTrojan.PowerShell.Crypt
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.00549a
AvastWin32:Evo-gen [Susp]

How to remove Heur.BZC.PZQ.Boxter.591.30DB91B7?

Heur.BZC.PZQ.Boxter.591.30DB91B7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment