Trojan

Trojan:MSIL/Bobik.PTFJ!MTB (file analysis)

Malware Removal

The Trojan:MSIL/Bobik.PTFJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Bobik.PTFJ!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:MSIL/Bobik.PTFJ!MTB?


File Info:

name: A6997F6E91395AACA3DC.mlw
path: /opt/CAPEv2/storage/binaries/c42ee49c7096a82ab718646e9e080e593f6c0e569ab2cdce3f5780eb17454afa
crc32: D4CEF473
md5: a6997f6e91395aaca3dca646dfd2065f
sha1: c38daf14eafaed17c5deb41adff5558707ae875f
sha256: c42ee49c7096a82ab718646e9e080e593f6c0e569ab2cdce3f5780eb17454afa
sha512: 6ccd1e404975df021a37428620accf680ec92853d15db454909d2f3586fd667cd0fa150cd0f6d59d6f77811d057454513d443e1e188766e5d3d3f61d38a0ed2d
ssdeep: 6144:qSYx8cSRlbT3h+Zi4gIsc/ba9HHXN/9R:q5qRligcO9H3N/9R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17954AF2477E88667C22D573DE9E383301371F5422693CB4B6D887EAD3EB23925A036D5
sha3_384: 92f27690edc6a6bb32adbaad44dab6ffb8b030eb864aedbf96761fc6dad2e2ed39b6a3903c8e7d8da1ba8127777e4a5b
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-12-03 09:13:49

Version Info:

Translation: 0x0000 0x04b0
Comments: Macro Recorder
CompanyName: Jitbit Macro Recorder
FileDescription: MacroRecorder
FileVersion: 5.9.0.0
InternalName: ExeTemplate.exe
LegalCopyright: Copyright © Jitbit 2010-2021
LegalTrademarks:
OriginalFilename: ExeTemplate.exe
ProductName: MacroRecorder
ProductVersion: 5.9.0.0
Assembly Version: 5.9.0.0

Trojan:MSIL/Bobik.PTFJ!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Bobik.4!c
MicroWorld-eScanTrojan.GenericKD.71479612
FireEyeTrojan.GenericKD.71479612
CAT-QuickHealTrojan.GenericFC.S30156696
SkyhighRDN/Generic PWS.y
McAfeeRDN/Generic PWS.y
Cylanceunsafe
SangforTrojan.Msil.Bobik.Vshp
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:MSIL/Bobik.a571a9c4
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.e91395
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
TrendMicro-HouseCallTrojanSpy.MSIL.BOBIK.SM
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.71479612
EmsisoftTrojan.GenericKD.71479612 (B)
F-SecureTrojan.TR/Redcap.fccdn
VIPRETrojan.GenericKD.71479612
TrendMicroTrojanSpy.MSIL.BOBIK.SM
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
MAXmalware (ai score=88)
JiangminTrojan.Convagent.awd
GoogleDetected
AviraTR/Redcap.fccdn
VaristW32/MSIL_Agent.HJJ.gen!Eldorado
Antiy-AVLTrojan/MSIL.Bobik
MicrosoftTrojan:MSIL/Bobik.PTFJ!MTB
ArcabitTrojan.Generic.D442B13C
GDataTrojan.GenericKD.71479612
ALYacTrojan.GenericKD.71479612
MalwarebytesNeshta.Virus.FileInfector.DDS
PandaTrj/Chgt.AD
RisingTrojan.Bobik!8.124F2 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bobik.SM!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan:MSIL/Bobik.PTFJ!MTB?

Trojan:MSIL/Bobik.PTFJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment