Malware

Should I remove “Heur.BZC.PZQ.Boxter.841.462D47A1”?

Malware Removal

The Heur.BZC.PZQ.Boxter.841.462D47A1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.841.462D47A1 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • CAPE extracted potentially suspicious content
  • A HTTP/S link was seen in a script or command line
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Appears to use command line obfuscation
  • A script or command line contains a long continuous string indicative of obfuscation
  • Deletes executed files from disk

How to determine Heur.BZC.PZQ.Boxter.841.462D47A1?


File Info:

name: E622313DD96B59BFC29B.mlw
path: /opt/CAPEv2/storage/binaries/b435b11f1e0298e3eace6519b343d406694c84106cda99021b8d6692ec0075a4
crc32: 00E20BAF
md5: e622313dd96b59bfc29be837b5945916
sha1: ba1ec2fd51cdf857ca96851b4727df223e419d48
sha256: b435b11f1e0298e3eace6519b343d406694c84106cda99021b8d6692ec0075a4
sha512: 44da9e45af3b9397439e5ae321cf812f13033b1d2a03fe300747f441878a94797a4d7f7ca35a13f37e5dc3b2a80829eef8bea1caa8a3aeb876ed3ade819b804c
ssdeep: 1536:77fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIf1xZDOF:Xq6+ouCpk2mpcWJ0r+QNTBf1O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA937C41F3E241F7E9E10A3100A6712FE73966249724E8DBC34C3D829953AD5AA7D3F9
sha3_384: ec221ff90da3e81d97ad53dbbc7079ebddb2b46e55e75cc367f7c148b47f14acf97155467f1a601f252441a1ff4efe73
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Heur.BZC.PZQ.Boxter.841.462D47A1 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e622313dd96b59bf
CylanceUnsafe
ZillyaTool.Lazagne.Win32.102
SangforTrojan.Win32.Save.a
Cybereasonmalicious.dd96b5
VirITTrojan.Win32.Genus.IHW
CyrenW32/Trojan.VFBA-8001
APEXMalicious
BitDefenderHeur.BZC.PZQ.Boxter.841.462D47A1
MicroWorld-eScanHeur.BZC.PZQ.Boxter.841.462D47A1
Ad-AwareHeur.BZC.PZQ.Boxter.841.462D47A1
TACHYONTrojan/W32.KillFiles.89600
EmsisoftHeur.BZC.PZQ.Boxter.841.462D47A1 (B)
VIPREHeur.BZC.PZQ.Boxter.841.462D47A1
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataHeur.BZC.PZQ.Boxter.841.3FF2AD86
Antiy-AVLTrojan/Generic.ASMalwS.50F5
ArcabitHeur.BZC.PZQ.Boxter.841.462D47A1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
ALYacHeur.BZC.PZQ.Boxter.841.3FF2AD86
MAXmalware (ai score=85)
MalwarebytesMalware.AI.392946571
RisingTrojan.Generic@AI.100 (RDMK:c0jaYtwyuF50pjTK0+vt2A)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.11973.susgen

How to remove Heur.BZC.PZQ.Boxter.841.462D47A1?

Heur.BZC.PZQ.Boxter.841.462D47A1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment