Severity scale:  
  (97/100)

BOK ransomware virus. How to remove? (Uninstall guide)

removal by Julie Splinters - - | Type: Ransomware
12

Should you get terrified by BOK ransomware?

BOK virus attempts to intimidate the victims by declaring that all of their files have been encrypted. It happens to be just another file-encrypting malware. Though it employs the standard encryption method AES, virus researchers have doubts about whether the virus is going to evolve into such cyber threat as Cerber which already marked its fifth installment [1]. However, there are multiple cases when old viruses are revived again [2] causing a massive havoc in the international cyber space. Likewise, it is unwise to underestimate this virus. Remove BOK with the help of an anti-spyware program such as Reimage.

Such infamous cases of CryptoWall, TeslaCrypt, and Locky, has been inspiring international hackers to enter the market. Even the joint project of major cyber security companies did not ward off the bright minds to join such risky business [3]. Likewise, the developers of this malware weren’t alarmed enough and manifested their programming capabilities as well. In fact, BOK ransomware is an obvious rip-off of Locky virus. One of its previous versions appended .shit extension to corrupted files [4]. Likewise, the current malware attaches .bok file extension to every affected file. It is still unknown whether the developers of BOK malware have any relation to the cyber gang of Locky.

BOK ransomware mimics .shit ransomware

Following the style of the latter, the malware encodes all your personal files with AES encryption method. This method has been proven to lock out the data successfully as several cipher cycles are run to generate a unique public key. Only a matching private key unlocks the affected data. Alternatively, users who perform backups frequently do not need to worry as they can restore the data from them. Otherwise, if you happened to be one of those users who did not anticipate ransomware landing on their computers and did not back up your valuable documents, proceed to the last section of the article. You might consider paying the money to hackers, but there are no viable guarantees that you will receive the files even after remitting the payment. We urge you to start BOK removal process right away.

Does BOK also spread through spam?

Many new hackers walk already the trodden path by other cyber criminals, so few develop their own distribution techniques. Certainly, compiling several of them makes a threat more destructive. There are cases when ransomware is delivered to a victims’ computer via an insidious exploit kit. Unfortunately, the latter often disguise in fake Flash player updates [5]. Furthermore, you should not forget that spam and phishing still dominate the market when it comes to ransomware distributing. Surprisingly, many users still fall for invoice or tax report emails. Giving into a curiosity to extract the attachment leads to a rapid BOK hijack or the infiltration of another file-encrypting malware. In order to lower the risk of ransomware attack, do not rush to open the attachment. Otherwise, dealing with the outcomes becomes a nerve-wracking activity.

Eliminating the ransomware

When it comes to any file-encrypting malware, you should not waste your energy on meddling with the virtual infection manually. In this case, it would better to rely on a malware elimination tool, for example, Reimage or Malwarebytes Anti Malware. After BOK removal process is finished, you can proceed to data recovery guidelines. While IT professionals are working on a free decryption software, alternative programs might come in handy. More information is provided below. In case the malware has meddled with your system settings and you cannot remove BOK virus properly, go through the guidelines to regain the access.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove BOK ransomware virus you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall BOK ransomware virus. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.
More information about this program can be found in Reimage review.
Press mentions on Reimage

Manual BOK virus Removal Guide:

Remove BOK using Safe Mode with Networking

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove BOK

    Log in to your infected account and start the browser. Download Reimage or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete BOK removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove BOK using System Restore

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of BOK. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage and make sure that BOK removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove BOK from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by 2-spyware.com security experts.

If your files are encrypted by BOK, you can use several methods to restore them:

The pros of Data Recovery Pro

If you are lost finding a quick solution to get your files back, try using Data Recovery Pro. Though it was originally created for locating a missing and damaged files due to a system crash, the latest version might come in handy retrieving some of your files.

Windows Previous Versions Feature method

Keep in mind that this method works System Restore is enabled.

  • Find an encrypted file you need to restore and right-click on it;
  • Select “Properties” and go to “Previous versions” tab;
  • Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.

Will ShadowExplorer help me decrypt the files?

There are high chances that you will get your files back since the utility restores them using volume shadow copies. Only few ransomware are known to delete these copies. In the case of this virus, there are no reports yet that it accesses these copies.

  • Download Shadow Explorer (http://shadowexplorer.com/);
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from BOK and other ransomwares, use a reputable anti-spyware, such as Reimage, Plumbytes Anti-MalwareWebroot SecureAnywhere AntiVirus or Malwarebytes Anti Malware

About the author

Julie Splinters - Malware removal specialist

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Julie Splinters
About the company Esolutions

References


  • garciaM

    How original..other hackers come up with more amusing titles.

  • error404

    I hope this one will be soon taken down.

  • snowmaker

    Plenty of tools..what should I choose from?