Malware

Heur.BZC.PZQ.Boxter.591.9CC2BD38 removal tips

Malware Removal

The Heur.BZC.PZQ.Boxter.591.9CC2BD38 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.591.9CC2BD38 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments

How to determine Heur.BZC.PZQ.Boxter.591.9CC2BD38?


File Info:

name: 5F19ADCAFFE6E63755A5.mlw
path: /opt/CAPEv2/storage/binaries/8c4f74b580352376ef4b1bef3fe5e0001d20ddf21b96ca33affae8497c4a85ba
crc32: EA3FA6DD
md5: 5f19adcaffe6e63755a5157dae9f509c
sha1: 78c2703482161aacf32196bbe0b4e475ed9854b2
sha256: 8c4f74b580352376ef4b1bef3fe5e0001d20ddf21b96ca33affae8497c4a85ba
sha512: 2deb3bfb2297147ea649fce04c9d80717a528a72d9787fcbd0d3f9cdff33a2bf40a577f3324c82fd2d8cc7f44f2656666f7036e5b6fb48c2e0aa3c3c60477d65
ssdeep: 1536:XM7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIfPw9hAOg:XCFfHgTWmCRkGbKGLeNTBfPQhs
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T101937D45F2E242F7EAF2053200A6716FE73562388724E8DBC74C2D529953AD1A73D3E9
sha3_384: bf922e4d8098d819e4113fa3c270c33520c45993fa4be062fc38b7f12175ee0967e367f3c836622e5727b4ac1ac6b698
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2018-02-01 20:18:05

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.591.9CC2BD38 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanHeur.BZC.PZQ.Boxter.591.9CC2BD38
ALYacHeur.BZC.PZQ.Boxter.591.9CC2BD38
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
K7GWTrojan ( 0052419b1 )
Cybereasonmalicious.affe6e
CyrenW32/SchoolBoy.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
KasperskyHEUR:Backdoor.PowerShell.Agent.gen
BitDefenderHeur.BZC.PZQ.Boxter.591.9CC2BD38
AvastScript:SNH-gen [Trj]
Ad-AwareHeur.BZC.PZQ.Boxter.591.9CC2BD38
TACHYONRansom/W32.FileCoder.92672
SophosMal/Generic-S
F-SecureTrojan.TR/B2E.Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.5f19adcaffe6e637
EmsisoftHeur.BZC.PZQ.Boxter.591.9CC2BD38 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/B2E.Dropper.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitHeur.BZC.PZQ.Boxter.591.9CC2BD38
ZoneAlarmHEUR:Backdoor.PowerShell.Agent.gen
GDataHeur.BZC.PZQ.Boxter.591.9CC2BD38
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Leivion.R416369
Acronissuspicious
McAfeeArtemis!5F19ADCAFFE6
MAXmalware (ai score=83)
RisingTrojan.Kryptik!8.8 (RDMK:cmRtazrafMMREuFAXIh5eIza+TOM)
IkarusTrojan.PowerShell.Crypt
MaxSecureTrojan.Malware.300983.susgen
AVGScript:SNH-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Heur.BZC.PZQ.Boxter.591.9CC2BD38?

Heur.BZC.PZQ.Boxter.591.9CC2BD38 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment