Malware

Should I remove “Heur.BZC.PZQ.Boxter.591.51F93619 (B)”?

Malware Removal

The Heur.BZC.PZQ.Boxter.591.51F93619 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.591.51F93619 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments

How to determine Heur.BZC.PZQ.Boxter.591.51F93619 (B)?


File Info:

name: 38A016DB01F71AD0DB31.mlw
path: /opt/CAPEv2/storage/binaries/6b34a9be4cf627b76262abe4b147a974d42fba255fafe596fdcde8f6cab15e99
crc32: 7E5B93FF
md5: 38a016db01f71ad0db312fe695912d33
sha1: 23afe105197a7ac47b30bc9e7d7076181a104569
sha256: 6b34a9be4cf627b76262abe4b147a974d42fba255fafe596fdcde8f6cab15e99
sha512: ec6388070d83abbc7eb20fe247377e3ec1e50a19559a8b94a722e8bcdcdaedb3b4b7fc5eb796ecb2121a57aad4eea29db68a507e8eab8710a61fe6aea5aec452
ssdeep: 1536:zM7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIfqwZVOK:zCFfHgTWmCRkGbKGLeNTBfqI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10F937C45F2E242F7E6F2053201A6716FE735A2388724E8DBC74C2D529943AD1A73D3E9
sha3_384: ed3e4148cc4f614a3c3ee31099e2e0e0d17fdc2544c5ade5c7dc162278ffee3ee26fdba6fa0230b08d3998bf0be62fb5
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2018-02-01 20:18:05

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.591.51F93619 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ALYacHeur.BZC.PZQ.Boxter.591.51F93619
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
BitDefenderHeur.BZC.PZQ.Boxter.591.51F93619
K7GWTrojan ( 0052419b1 )
CyrenW32/SchoolBoy.B.gen!Eldorado
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
AvastScript:SNH-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
MicroWorld-eScanHeur.BZC.PZQ.Boxter.591.51F93619
RisingTrojan.Kryptik!8.8 (RDMK:cmRtazq4bGHN4S6ig8QN9JBjLraj)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/B2E.Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.38a016db01f71ad0
EmsisoftHeur.BZC.PZQ.Boxter.591.51F93619 (B)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73799730.susgen
AviraTR/B2E.Dropper.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Backdoor.PowerShell.Agent.gen
GDataHeur.BZC.PZQ.Boxter.591.51F93619
TACHYONRansom/W32.FileCoder.92672
AhnLab-V3Malware/Win32.RL_Generic.R356355
MAXmalware (ai score=89)
CylanceUnsafe
IkarusTrojan.PowerShell.Crypt
eGambitUnsafe.AI_Score_89%
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.b01f71

How to remove Heur.BZC.PZQ.Boxter.591.51F93619 (B)?

Heur.BZC.PZQ.Boxter.591.51F93619 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment