Malware

Heur.BZC.PZQ.Boxter.762.2DE8324C (B) removal guide

Malware Removal

The Heur.BZC.PZQ.Boxter.762.2DE8324C (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.762.2DE8324C (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Collects and encrypts information about the computer likely to send to C2 server
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments

How to determine Heur.BZC.PZQ.Boxter.762.2DE8324C (B)?


File Info:

name: D86EB5B7B82EFB0ED416.mlw
path: /opt/CAPEv2/storage/binaries/5ba58549509a0d8e640f2b0b621892a6708b1fe507248fa4e0b9d58182a5a946
crc32: 8CA03602
md5: d86eb5b7b82efb0ed4164de103f7bfb3
sha1: 64170ee6ab583460a92ba5db2d0ba95b64dd010e
sha256: 5ba58549509a0d8e640f2b0b621892a6708b1fe507248fa4e0b9d58182a5a946
sha512: 98187bc98271afe8e4689b604648aa98154532fc8f095dbd02afd3de18de5fad26ca560fa3def9a0a6a9d223bd2fea020745e60a35ce753d64254029ae544a0c
ssdeep: 1536:bG7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIfiw7ROT:b8FfHgTWmCRkGbKGLeNTBfin
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T178937C45F2E242F7E6F2053201A6716FA735A2388724E8DBC74C3D429943AD5A73D3E9
sha3_384: ecee0852deae6583bfab6d1532e40d4257c64dcd4ccc656a8d1898cabb1bf0b1c3ac3b9bebb67f7dbc732ca380ead302
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2018-02-01 20:18:05

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.762.2DE8324C (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.d86eb5b7b82efb0e
CAT-QuickHealTrojan.GenericPMF.S15065801
Cybereasonmalicious.7b82ef
CyrenW32/SchoolBoy.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
KasperskyHEUR:Backdoor.PowerShell.Agent.gen
BitDefenderHeur.BZC.PZQ.Boxter.762.2DE8324C
MicroWorld-eScanHeur.BZC.PZQ.Boxter.762.2DE8324C
AvastWin32:Evo-gen [Susp]
Ad-AwareHeur.BZC.PZQ.Boxter.762.2DE8324C
EmsisoftHeur.BZC.PZQ.Boxter.762.2DE8324C (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
SophosGeneric ML PUA (PUA)
AviraTR/B2E.Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitHeur.BZC.PZQ.Boxter.762.2DE8324C
GDataHeur.BZC.PZQ.Boxter.762.2DE8324C
TACHYONTrojan/W32.SchoolBoy.92160
Acronissuspicious
ALYacHeur.BZC.PZQ.Boxter.762.2DE8324C
MAXmalware (ai score=89)
RisingTrojan.Generic@ML.99 (RDML:JsYyOg46Xzh6iLyPF44HJQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Susp]

How to remove Heur.BZC.PZQ.Boxter.762.2DE8324C (B)?

Heur.BZC.PZQ.Boxter.762.2DE8324C (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment