Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Dec 2020

How to remove Booa ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Booa ransomware – a file-locking computer virus that tries to extort cryptocurrency for a decryption tool

Booa ransomware

Booa ransomware is a cryptovirus that encrypts all files on a victim's computer as soon as it infects it and demands a ransom for a tool that would supposedly unlock the data. This file-locking parasite derives from the Djvu ransomware family, and as all of its members, for instance, Nobu, Igdm, Weui, and others, it encrypts only personal data and leaves the system files untouched.

During the encryption, the virus appends all personal victim files, such as documents, archives, backups, pictures, etc., with .booa extension, thus making them inaccessible until some sort of a decryption tool is used to unlock them. All of the latest Djvu family members use a secure RSA-2048[1] coding algorithm to lock the files (despite this, a limited number of victims who have their data locked with an offline ID have a chance to decrypt it successfully with Emsisoft's decryption tool).

As soon as the virus is done with the first part of its bidding, it creates ransom notes, named _readme.txt, and places them in every folder that contains locked files so that the victim of the cyberattack would find the messages from the perpetrators literally wherever they look.

One more similarity between all of the cryptoviruses from this lineage is that the cybercriminals' contact emails rarely changes. The creators of the .Booa virus would like to be contacted via either of these two emails – helpmanager@mail.ch and restoremanager@airmail.cc.

Name Booa ransomware, .booa file virus
type Ransomware, cryptovirus
Family Djvu ransomware
Appended file extension .booa extension is appended to all non-system files on an infected computer
Ransom note _readme.txt are created and spread all over the infected device
Ransom amount The regular price for the decryption tool is $980, but if victims contact the criminals within 72 hours of the attack, a 50% discount is offered, lowering the price to $490
Criminal contact Details Cybercriminals provide two emails to reach them – helpmanager@mail.ch and restoremanager@airmail.cc.
Virus removal The elimination should be done with reliable anti-malware software to make sure that the virus and all its components are completely eliminated
System health Powerful system repair tools like the FortectIntego app should be used to correct any discrepancies that the cryptovirus might have done to the system settings

Practically all ransomware creates some sort of ransom notes. Some change the desktop wallpaper, some generate pop-up windows. Within these notes, the cybercriminals state their demands and instruction for the victims. The same goes for Booa ransomware virus ransom notes.

The perpetrators start by stating that all personal files on the infected computer were encrypted and that the only way to unlock them is by purchasing a decryption tool from the assailants. In most cases, that might be true, but keep reading to find out alternative decryption methods.

To convince the victims that the necessary tool really exists, the Booa virus creators offer to send them one encrypted file from the infected device, and they would decrypt it for free. Furthermore, they are providing a link to the victims so that they could see the decryption tool in action with their own eyes.

To put it in simple terms, the cybercriminals are trying their best to prove to their victims that their locked data decryption is possible, and they would really send the necessary tools, although it will cost them. The original ransom amount is $980, but if the victims are quick and contact the assailants within 72 hours of the cyberattack, then the criminals would apply a 50% discount to the ransom, lowering the price to $490.

Booa ransomware virus

Usually, the last part of ransom notes consists of threats not to rename the encrypted files or use any third-party description software because that could make the data irretrievable. Developers of this ransomware don't threaten their victims. They just provide them with an appointed unique user ID and two email addresses to establish contact.

We always advise our readers not to contact the criminals as that may lead to a lose-lose situation where the victims lose their data and their hard-earned money. Instead, victims of this cyber attack should concentrate on Booa ransomware removal and look for other ways to recover their files.

We recommend using trustworthy anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes to automatically remove Booa virus with all of its pieces from the infected devices. Reliable anti-virus application is a must these days because of thousands of various computer viruses are lurking on the internet.

As soon as the virus is eliminated, we suggest using a system repair tool like the FortectIntego app to perform a full system scan and restore any damage that the cryptovirus might have wreaked to the system settings, such as the system registry and its files.

Cybercriminals send this message to their victims with the Booa file virus ransom note:

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-EtT4dX8q3X
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
helpmanager@mail.ch

Reserve e-mail address to contact us:
restoremanager@airmail.cc

Your personal ID:

Most common method Djvu ransomware distribution method and how to avoid it

Ransomware is one of the most devastating computer infections in the wild, as its file encryption function might result in a complete personal file loss – it's a nightmare for the owners of the infected devices. While there are many different ways that cybercriminals can use to deliver malware to the victims, this strain is usually picking a single distribution method.

Our research suggests that Djvu family ransomware is mainly spread using file-sharing platforms, and to be even more specific – torrent websites that host pirated program installers and software cracks. Cybercriminals upload their creations named as popular game cracks[2], fake licensed software, and alike.

When a user decides to download such a torrent, the ransomware payload file is downloaded with it, and the encryption of the device starts within minutes. So please refrain from using such sites no matter how tempting some torrents might be. Support software developers by purchasing their products directly from them.

.booa virus files recovery is likely to be difficult without backups

Users are often shocked after realizing that all the data on their computer is inaccessible after a ransomware infection. Most of those infected never had to deal with crypto-malware before, so there are plenty of misconceptions about this threat, operation, and data recovery process. This is why many victims believe that they can recover .booa files as soon as they eliminate the malware from the system, although this couldn't be further from the truth – files will remain locked even after this process is performed successfully.

Your best chance to restore .booa virus files without any difficulties is by using backups. Unfortunately, not many regular users use this essential practice, putting themselves into a very difficult situation once ransomware manages to break into their computers. Luckily, there might be a few other methods that could help some victims to restore at least some of their data.

Once malware performs the encryption process, it attempts to contact a remote server, which would automatically assign a unique user ID, which can later be used for the decryption process. Djvu variants are known to fail this process due to C&C servers being offline. In such a case, the malware uses a static ID, otherwise known as an offline ID, to lock all files on the system, which means that it is identical for all the users affected by this positive failure.

Using this flaw, security experts from Emsisoft managed to create a decryption tool that could help victims whose files were locked with an offline key. Therefore, you should definitely check the tool out – we provide the download links and all the relevant information below.

Other methods to recover .booa virus files are:

  • Using third-party data recovery software;
  • Using built-in Windows recovery tools, if they were not deleted by malware.

Keep in mind that the above-mentioned options have a low chance of success, but you should try them regardless. Paying criminals is never a good choice, although some victims might nothing else left. Having backups would solve all the problems, so make sure you prepare those as often as possible. Note that you should copy all the .booa virus files before attempting the recovery.

Booa virus file

Guidelines for the Booa virus removal and system health check

All malware, including Booa virus, has to be deleted immediately. The best way to do it is with the help of dependable anti-malware software like MalwarebytesMalwarebytes or SpyHunterCombo Cleaner. That way, the users can be sure that the cryptovirus and all of its elements are really gone. Note that you should copy all the important files if no backups are available to you before you use anti-malware software.

Unfortunately, Booa ransomware removal won't decrypt your files. But in no way should that stop you from eliminating it. There are other data recovery options (read our suggestions at the bottom of this article), so if you didn't keep backups, then copy all essential encrypted files to offline storage and wait for a decryption tool to be made available to the public.

Djvu family ransomware is known for making changes in the system registry and other key system settings, that, for example, wouldn't let its victims visit any cybersecurity type websites. So once you remove Booa ransomware, experts[3] recommend performing a system tune-up with the FortectIntego or any other powerful system repair tool to undo all the changes.

Additionally, you should also navigate to the C:\Windows\System32\drivers\etc\ location on your machine and delete a file named “hosts,” as access to security-related websites will remain restricted otherwise. Windows will automatically recreate a new file, and you will be able to navigate to all the security-related websites once again.

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.