Boyka Ransomware (. Boyka File) — Removal Guide
What Is Known About the Boyka Virus? Boyka Appends Its Extra. Boyka Extension to Every File’s Name. for Example, an Image Entitled “Photo. Jpg” Will Be Renamed...
What is known about the BoYkA Virus?
Boyka appends its extra .BoYkA extension to every file’s name. For example, an image entitled “photo.jpg” will be renamed to “photo.jpg.BoYkA”. Likewise, the Excel table with the name “table.xlsx” will be changed to “table.xlsx.BoYkA”, and so forth.
The ransom note usually contains instructions on how to buy the decryption tool from the racketeers. That is it.
| Name | Boyka Virus |
| Extension | .BoYkA |
| Ransom | $1250 (0.06 Bitcoin) |
| Detection1 | Win32/FlyStudio.OGT, Trojan:Win32/Redline.UR!MTB, MSIL/Kryptik.AFSM |
| Symptoms | Your files (photos, videos, documents) get a .BoYkA extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Boyka virus |
The note accompanying the Boyka ransomware provides the following frustrating information:
ATTENTION!!! All your files have been encrypted! Files can only be decrypted with the keys that have been generated for your PC! The amount you have to pay to get the keys is 0.06 Bitcoin We do not accept another payment method! This is where you need to send bitcoin: bc1q6x4kev9pefay37uctaq9ggqmxrg7a6txn2tanf After sending, contact us at this email address: With this subject: ***************** Use the sites below to quickly buy bitcoin Another list of sites can be found here: After confirming the payment, you will receive a tutorial and the keys for decrypting the files. IF YOU DON\'T CONTACT ME OR PAY ME IN 5 DAYS, THE KEYS WILL BE DELETED.
In the screenshot below, you can see what a folder with files encrypted by the Boyka looks like. Each filename has the “.BoYkA” extension appended to it.
Must Read
How did Boyka ransomware end up on my PC?
Nowadays, there are three most popular ways for criminals to have the Boyka virus working in your system. These are email spam, Trojan infiltration and peer-to-peer file transfer.
If you open your inbox and see emails that look like familiar notifications from utility services providers, postal agencies like FedEx, web-access providers, and whatnot, but whose addresser is unknown to you, beware of opening those letters. They are very likely to have a harmful item attached to them. Therefore, it is even more dangerous to download any attachments that come with letters like these.
Another thing the hackers might try is a Trojan file scheme2. A Trojan is a program that infiltrates into your computer disguised as something legal. For instance, you download an installer of some program you need or an update for some program. But what is unboxed reveals itself a harmful program that compromises your data. As the installation file can have any title and any icon, you’d better be sure that you can trust the resource of the stuff you’re downloading. The optimal thing is to use the software companies’ official websites.
As for the peer networks like BitTorrent or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. So you’d better be using trustworthy resources. Also, it is reasonable to scan the directory containing the downloaded items with the anti-malware utility as soon as the downloading is done.