BAT.Boohoo.Worm – a malicious program that spreads via weakly protected network shares

BAT.Boohoo.Worm is a self-spreading computer threat that is designed to infect Windows computers and perform malicious tasks on them. First discovered in 2003, this malware can attack private users as well as networks of corporations and businesses. The worm mainly spreads via weakly protected network shares after the attackers scan the internet with special tools.
| Name | BAT.Boohoo.Worm |
| Also known as | Mumu, IROffer12, NTScan |
| Type | Worm, malware |
| Distribution | Open or weakly protect network connections |
| Function | Steal sensitive information and deliver it to cybercriminals |
| Often installed with | Valla virus |
| Removal | Perform a full system scan with anti-malware software – SpyHunterCombo Cleaner |
| System fix | If a worm damaged Windows system files, it might malfunction. To remediate your OS and ensure its proper operation, scan it with FortectIntego |
Since its release in 2003, there have been several different Boohoo worm variants discovered in the wild, each of which slightly different. Some of the versions included more functionality and capabilities than its previous versions.
The virus consists of multitude of malicious utilities and tools, including batch files, nVIDIA and other legitimate utilities, text files, and more. It is important to keep in mind that different versions of the virus support and use different components, so not every variant will have all of these.
Here is an example of files that could be present on an infected device:
- starter.bat
- scan.bat
- ip.bat
- hacker.bat
- Xecuter.bat
- regkeyadd.REG, etc.
All these files are copied to Windows/System32 folder, where they begin to replicate and infect other files and folders located on the host machine.
The main goal of cybercriminals behind this strain is to steal sensitive information related to a computer user or corporate entity. BAT.Boohoo.Worm is capable of logging keystrokes and stealing passwords on the infected device or network. Hence, the damage can be significant.
Malware removal steps
In order to remove this parasite, you should perform a full system scan with a reliable anti-malware software – we recommend using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Do not forget to update security app to the latest version before performing this step. Also, due to severe level of compromise, you might not be able to use antivirus. In such case, access Safe Mode with networking as explained below and perform a full system scan from there.
Worm malware can infect various system and application files on the host computer, which might completely corrupt necessary files. As a result, programs might start crashing or Windows malfunctioning. If you have to deal with such problems, reinstall the operating system or use FortectIntego to fix damaged system files automatically.
Was this guide helpful?
Be the first to comment