Malware

Should I remove “Heur.BZC.PZQ.Boxter.762.4FB15C24”?

Malware Removal

The Heur.BZC.PZQ.Boxter.762.4FB15C24 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.762.4FB15C24 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • A script or command line contains a long continuous string indicative of obfuscation
  • Deletes executed files from disk
  • Attempts to execute suspicious powershell command arguments

How to determine Heur.BZC.PZQ.Boxter.762.4FB15C24?


File Info:

name: DC7CC2B443C53F83484D.mlw
path: /opt/CAPEv2/storage/binaries/47fbdd1809823a60740a33afe5d066be595f9762ccc5c31589846a6a496f0e1b
crc32: A383B413
md5: dc7cc2b443c53f83484dc724320585d1
sha1: 12b70869201f7004a0c818f61e4b48e26b6596a0
sha256: 47fbdd1809823a60740a33afe5d066be595f9762ccc5c31589846a6a496f0e1b
sha512: e50967e46581f585d4b4e82d69ab3790a72f0bfe9a845edf187e82834b8b0f87273009243eef3acc0d594313553af7f339db0c18f6626adb2f89108f8ec8fc95
ssdeep: 1536:MQ7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIf2wjvHOE:MuFfHgTWmCRkGbKGLeNTBf2wL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17C937C45F2E242F7EAF2053201A6716FE73562388724E8DBC74C2D429943AD5A73D3E9
sha3_384: 0f0cccf9e55b4bedf511f26eb687d6fc5f6c07937ab1a14fe83c9ab743048f8a70b64bf53d0dedcb30ef457a35db5f6f
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2018-02-01 20:18:05

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.762.4FB15C24 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanHeur.BZC.PZQ.Boxter.762.4FB15C24
FireEyeGeneric.mg.dc7cc2b443c53f83
MalwarebytesTrojan.PowerShell
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0052419b1 )
K7AntiVirusTrojan ( 0052419b1 )
CyrenW32/SchoolBoy.B.gen!Eldorado
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.PowerShell.Agent.gen
BitDefenderHeur.BZC.PZQ.Boxter.762.4FB15C24
AvastWin32:Evo-gen [Trj]
Ad-AwareHeur.BZC.PZQ.Boxter.762.4FB15C24
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/B2E.Dropper.Gen
VIPREHeur.BZC.PZQ.Boxter.762.4FB15C24
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
Trapminemalicious.high.ml.score
EmsisoftHeur.BZC.PZQ.Boxter.762.4FB15C24 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.N1K38E
AviraTR/B2E.Dropper.Gen
MAXmalware (ai score=89)
ArcabitHeur.BZC.PZQ.Boxter.762.4FB15C24
ZoneAlarmHEUR:Backdoor.PowerShell.Agent.gen
MicrosoftTrojan:Win32/Sabsik.TE.A!ml
GoogleDetected
AhnLab-V3Trojan/Win.RealProtect-LS.C5196685
Acronissuspicious
ALYacHeur.BZC.PZQ.Boxter.762.4FB15C24
CylanceUnsafe
RisingTrojan.Generic@AI.100 (RDML:ojtv/8b+0H6/gSmAyDlv6g)
IkarusTrojan.PowerShell.Crypt
MaxSecureTrojan.Malware.100465309.susgen
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.443c53

How to remove Heur.BZC.PZQ.Boxter.762.4FB15C24?

Heur.BZC.PZQ.Boxter.762.4FB15C24 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment