Trojan

How to remove “Trojan:MSIL/Bokytuda.B!rfn”?

Malware Removal

The Trojan:MSIL/Bokytuda.B!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Bokytuda.B!rfn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:MSIL/Bokytuda.B!rfn?


File Info:

crc32: 7D74D1DC
md5: dbb523b53c282613b55a7b843a26556f
name: DBB523B53C282613B55A7B843A26556F.mlw
sha1: 433e191ba75b630709b1cda87546f757c9370463
sha256: b5cfec22c86d2a3475eda38938c2f3fe2be75d5dd2f7e062e9150f57b8d5fbf1
sha512: 99997676612defeae40c7c09db605c6485e1e145bcbfd535c553453bee0ff4f0527dc55bc1c972154f0b63bdfffcee20c26df4721b92c842b9085f32539bbd7d
ssdeep: 12288:1185RFuLWHClG8DPkh/MCUDPQNOu35GFUa:8NClG+okCUDPQl3AG
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010 Valve Corporation
InternalName: x64launcher.exe
FileVersion: 3, 0, 0, 1
CompanyName: Valve Corporation
ProductName: Steam
ProductVersion: 3, 0, 0, 1
FileDescription: x64launcher.exe
OriginalFilename: x64launcher.exe
Translation: 0x0409 0x04b0

Trojan:MSIL/Bokytuda.B!rfn also known as:

K7AntiVirusTrojan ( 005017fa1 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.39822
MicroWorld-eScanGen:Variant.MSILPerseus.65117
ALYacGen:Variant.MSILPerseus.65117
MalwarebytesMachineLearning/Anomalous.100%
ZillyaTrojan.Blocker.Win32.61701
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Blocker.65477f74
K7GWTrojan ( 005017fa1 )
Cybereasonmalicious.53c282
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.QZP
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 85)
KasperskyTrojan-Ransom.Win32.Blocker.kluh
BitDefenderGen:Variant.MSILPerseus.65117
NANO-AntivirusTrojan.Win32.Blocker.evgend
TencentMalware.Win32.Gencirc.114953b6
Ad-AwareGen:Variant.MSILPerseus.65117
SophosML/PE-A + Troj/MSIL-JKN
ComodoMalware@#boxyy98a0fw0
BitDefenderThetaGen:NN.ZemsilF.34608.1m0@a8Bvs9b
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.dbb523b53c282613
EmsisoftGen:Variant.MSILPerseus.65117 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1127724
eGambitUnsafe.AI_Score_92%
MicrosoftTrojan:MSIL/Bokytuda.B!rfn
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.MSILPerseus.65117
AhnLab-V3Trojan/Win32.RL_Generic.C4092780
McAfeeArtemis!DBB523B53C28
MAXmalware (ai score=96)
VBA32Trojan-Ransom.Blocker
PandaTrj/GdSda.A
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.Blocker!NmxkrFag/Yk
IkarusTrojan.MSIL.Krypt
FortinetMSIL/GenKryptik.RIH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOoA

How to remove Trojan:MSIL/Bokytuda.B!rfn?

Trojan:MSIL/Bokytuda.B!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment