Malware

What is “Heur.BZC.PZQ.Boxter.591.30DB91B7 (B)”?

Malware Removal

The Heur.BZC.PZQ.Boxter.591.30DB91B7 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.591.30DB91B7 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments

How to determine Heur.BZC.PZQ.Boxter.591.30DB91B7 (B)?


File Info:

name: 335CDB4754FC039B719E.mlw
path: /opt/CAPEv2/storage/binaries/c0370ee11da9d274beb38cea2fe0930af030aa2a2e01b63f200b804e3b681ea7
crc32: 6FA4A0B3
md5: 335cdb4754fc039b719e42589273a40b
sha1: 7991635664df5caae285764d0ff403fd83fd77d6
sha256: c0370ee11da9d274beb38cea2fe0930af030aa2a2e01b63f200b804e3b681ea7
sha512: 60079f5a4e7791c1cec8483d3c40f22d0fa5afde99793ccb4cb6b5c7a110ef5097b40826b381dab1946b23842091f3dfd418a5b12ac3a9513e88f8f69cd9eb7a
ssdeep: 1536:UQ7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIfKwqOv:UuFfHgTWmCRkGbKGLeNTBfKM
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T143937D45F2E242F7EAF2053201A6716FA735A2388724D8DBC74C3D429953AD1A73D3E9
sha3_384: 3b76774f76759b92d5d5dd62848cec514e50796912a9b06c701e124c721792ba560ef7b6b551ba4f957cc460884c8d3d
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2018-02-01 20:18:05

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.591.30DB91B7 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ALYacHeur.BZC.PZQ.Boxter.591.30DB91B7
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
BitDefenderHeur.BZC.PZQ.Boxter.591.30DB91B7
K7GWTrojan ( 0052419b1 )
CyrenW32/SchoolBoy.B.gen!Eldorado
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
MicroWorld-eScanHeur.BZC.PZQ.Boxter.591.30DB91B7
RisingTrojan.Kryptik!8.8 (RDMK:cmRtazqOePnJxDzFqjLKw5MjO5F3)
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
FireEyeGeneric.mg.335cdb4754fc039b
EmsisoftHeur.BZC.PZQ.Boxter.591.30DB91B7 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/B2E.Dropper.Gen
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Backdoor.PowerShell.Agent.gen
GDataWin32.Trojan.PSE.N1K38E
AhnLab-V3Malware/Win32.RL_Generic.R364998
CylanceUnsafe
IkarusTrojan.PowerShell.Crypt
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.754fc0
AvastWin32:Evo-gen [Susp]

How to remove Heur.BZC.PZQ.Boxter.591.30DB91B7 (B)?

Heur.BZC.PZQ.Boxter.591.30DB91B7 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment