Skip to content
  • Active
  • Severity: High
  • Worms
  • Windows
  • Verified · Apr 2021

How to remove BAT.Boohoo.Worm

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

BAT.Boohoo.Worm – a malicious program that spreads via weakly protected network shares

BAT.Boohoo.Worm

BAT.Boohoo.Worm is a self-spreading computer threat that is designed to infect Windows computers and perform malicious tasks on them. First discovered in 2003, this malware can attack private users as well as networks of corporations and businesses. The worm mainly spreads via weakly protected network shares after the attackers scan the internet with special tools.

Name BAT.Boohoo.Worm
Also known as Mumu, IROffer12, NTScan
Type Worm, malware
Distribution Open or weakly protect network connections
Function Steal sensitive information and deliver it to cybercriminals
Often installed with Valla virus
Removal Perform a full system scan with anti-malware software – SpyHunterCombo Cleaner
System fix If a worm damaged Windows system files, it might malfunction. To remediate your OS and ensure its proper operation, scan it with FortectIntego

Since its release in 2003, there have been several different Boohoo worm variants discovered in the wild, each of which slightly different. Some of the versions included more functionality and capabilities than its previous versions.

The virus consists of multitude of malicious utilities and tools, including batch files, nVIDIA  and other legitimate utilities, text files, and more. It is important to keep in mind that different versions of the virus support and use different components, so not every variant will have all of these.

Here is an example of files that could be present on an infected device:

  • starter.bat
  • scan.bat
  • ip.bat
  • hacker.bat
  • Xecuter.bat
  • regkeyadd.REG, etc.

All these files are copied to Windows/System32 folder, where they begin to replicate and infect other files and folders located on the host machine.

The main goal of cybercriminals behind this strain is to steal sensitive information related to a computer user or corporate entity. BAT.Boohoo.Worm is capable of logging keystrokes and stealing passwords on the infected device or network. Hence, the damage can be significant.

Malware removal steps

In order to remove this parasite, you should perform a full system scan with a reliable anti-malware software – we recommend using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Do not forget to update security app to the latest version before performing this step. Also, due to severe level of compromise, you might not be able to use antivirus. In such case, access Safe Mode with networking as explained below and perform a full system scan from there.

Worm malware can infect various system and application files on the host computer, which might completely corrupt necessary files. As a result, programs might start crashing or Windows malfunctioning. If you have to deal with such problems, reinstall the operating system or use FortectIntego to fix damaged system files automatically.

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.