Black Worm ransomware is a dangerous file locking virus that appends .bworm extension

Black Worm ransomware is a crypto malware that derived from HiddenTear open source project. Once the virus infects the computer, it performs a scan to detect photos, videos, music, and other files. It then uses the AES[1] encryption algorithm to encode data and adds .bworm file extension. At this point, a personal ID is generated and is sent to the remote server controlled by hackers. Victims can also view a ransom note REAT_IT.txt that is placed in every single folder where altered files are located. Users are faced with the harsh truth: they are informed that all their personal files are inaccessible and the only way to get them back is by paying $200 worth of Bitcoin. Unfortunately, there is no Black Worm ransomware decryptor available yet, and users might not be able to ever return their files.
| Summary | |
| Name | Black Worm |
| Type | Ransomware |
| Cipher | AES |
| File extension | .bworm |
| Ransom demand | $200 in Bitcoin |
| Origination | HiddenTear |
| Infection source | Spam emails, unprotected RDP, malicious websites, fake updates, etc. |
| Elimination | Use security software like FortectIntego or SpyHunterCombo Cleaner |
Cyber blackmail is one of the most prevalent illegal money-making schemes, and hackers have been using ransomware viruses for over a decade now. Up till this day, file locking malware remains one of the most devastating cyber infections. Unfortunately, Black Worm ransomware removal will not return the access to the files. Nevertheless, such a process is necessary for a normal computer operation.
Black Worm virus makes several changes to the system, including:
- Alters/adds registry keys;
- Creates ADS file[2] to hide malicious files;
- Attempts to delete Shadow Volume Copies;
- Drops several executables;
- Launches svchost.exe string that runs the malware.
In order to revert these modifications, users need to remove Black Worm ransomware from their computers. While manual elimination is possible, it is not recommended, as only trained IT professionals can perform it. For regular users, we recommend using security software like FortectIntego, SpyHunterCombo Cleaner, or any other program that can detect Black Worm virus.
Many users might be considering the possibility of paying the ransom of $200, but experts[3] highly discourage victims from contacting crooks. Sure, it is one of the options available, but it increases the risk of losing nor only personal files, but also the paid money. Over the years, many victims ended up with nothing after transferring the money to criminals. Therefore, they cannot be trusted.
Those who keep backups are in luck – restoring files encrypted by Black Worm ransomware will be easy. Those who do not have such an option should try third-party software that might be able to help with at least partial data recovery. And, finally, security researchers are always working on creating free decryptors for malware victims, and projects like No More Ransom helped millions of users worldwide. Thus, if nothing works, make a copy of your files and wait.

Ransomware distribution techniques
In most cases, users do not know much about ransomware, let alone its distribution methods. Therefore, the vast majority of victims that gen infected are either less computer savvy or simply not attentive enough. Nevertheless, there are several precautionary measures that you can practice to avoid the dreadful infection. Here are some of the tips:
- Install reputable anti-malware software that is capable of stopping most of the malicious software from infecting the PC;
- Avoid visiting questionable sites, including file-sharing, torrent, porn, gambling, and similar;
- Beware of spam emails – that attachment or hyperlink might contain malware;
- Beware of bundled software, some installers might be modified and injected with a malicious script;
- Patch your software as soon as updates are released – they fix critical security vulnerabilities that can be exploited by malware authors;
- Use tools like VirusTotal to scan executable and other files before opening them;
- Use strong passwords for all your accounts (use password manager).
Additionally, because no security measures can prevent the malware infection completely, you should backup your files on a regular basis.
Black Worm virus removal steps
You should not listen to cybercrooks, even if your files are modified by .bworm extension. Instead, you should take care of Black Worm ransomware removal by using reputable security tools like FortectIntego or SpyHunterCombo Cleaner. Beware that not all security engines can detect each an every one of the malicious files, but some do better than the others. Because .bworm file virus might use evasion techniques, we advise you enter Safe Mode with Networking as explained below.
As soon as you remove Black Worm virus from your computer, proceed with the data recovery. If you have backups ready, make sure you do not connect the external or virtual device to your machine while it is infected by malware, or your backup data will be encrypted as well. If you do not keep backups, make use of our guide for alternative recovery options below.
Did this guide help?
Be the first to comment