Malware

Should I remove “Heur.BZC.PZQ.Boxter.591.524D3220”?

Malware Removal

The Heur.BZC.PZQ.Boxter.591.524D3220 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.591.524D3220 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Heur.BZC.PZQ.Boxter.591.524D3220?


File Info:

name: F49BA3EB375F0233823F.mlw
path: /opt/CAPEv2/storage/binaries/952822f4992602fdedd839776173848c9f0cb6fad7797cfc956cbc54f2e5ca70
crc32: 03134038
md5: f49ba3eb375f0233823f41e954c73ad3
sha1: 7e8dab7620fd56b14160b5a308c441b6e9234aee
sha256: 952822f4992602fdedd839776173848c9f0cb6fad7797cfc956cbc54f2e5ca70
sha512: 380ad347ba48e6a7e5f036cddbd3e10c822ef5c0a273bd123dfc611caaac326519735b5c0cf1ccfabf73e65ab19f31089b1836503e71b78619ff4afd0ab11a0e
ssdeep: 1536:A7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfgwJHDwN7OI:+7DhdC6kzWypvaQ0FxyNTBfgo67
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A9937D41F3E102F7EAF1053100A6722F973663388764E8EBC75C2E529913AD5A63D3E9
sha3_384: 8a7db3b9a73afa462f2ec17d5d645a8b56c35e73b53f894ef0c5df236dc752995296a9c5d25a180694e0c600ca505c0d
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.591.524D3220 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanHeur.BZC.PZQ.Boxter.591.524D3220
FireEyeGeneric.mg.f49ba3eb375f0233
CAT-QuickHealTrojan.Generic
ALYacHeur.BZC.PZQ.Boxter.591.524D3220
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052796d1 )
AlibabaBackdoor:Win32/Kryptik.79a8f612
K7GWTrojan ( 0052796d1 )
Cybereasonmalicious.b375f0
SymantecML.Attribute.HighConfidence
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
KasperskyUDS:Trojan-Downloader.Win32.PsDownload
BitDefenderHeur.BZC.PZQ.Boxter.591.524D3220
AvastBV:Runner-CL [Drp]
TencentWin32.Backdoor.Agent.Eddr
Ad-AwareHeur.BZC.PZQ.Boxter.591.524D3220
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DB722
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
EmsisoftHeur.BZC.PZQ.Boxter.591.524D3220 (B)
IkarusTrojan.BAT.KillAV
GDataHeur.BZC.PZQ.Boxter.591.524D3220
Antiy-AVLTrojan/Generic.ASMalwS.2B9E7F9
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Tnega!ml
CynetMalicious (score: 100)
McAfeeRDN/Generic.grp
MAXmalware (ai score=82)
VBA32Trojan.Sabsik.FL
TrendMicro-HouseCallTROJ_GEN.R002C0DB722
RisingDownloader.Agent!8.B23 (RDMK:cmRtazo2kr5spbOZgMJd91q5FkKq)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_75%
FortinetPowerShell/Kryptik.H!tr
AVGBV:Runner-CL [Drp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Heur.BZC.PZQ.Boxter.591.524D3220?

Heur.BZC.PZQ.Boxter.591.524D3220 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment