Troj/BatDel-B
Posted: December 18, 2012
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
| Ranking: | 14,511 |
|---|---|
| Threat Level: | 9/10 |
| Infected PCs: | 6,649 |
| First Seen: | December 18, 2012 |
|---|---|
| Last Seen: | January 13, 2025 |
| OS(es) Affected: | Windows |
Troj/BatDel-B is a technical identification for various components of the Batchwiper Trojan, including its Trojan dropper and an updated variant of Batchwiper that deletes files more regularly than previous versions. Even though Troj/BatDel-B isn't an especially advanced PC threat, Troj/BatDel-B does have a meaningfully dangerous payload: the ability to delete files automatically at pre-specified times. SpywareRemove.com malware research team especially recommends that PC users in the Middle East practice good anti-malware habits to protect their computers from Troj/BatDel-B, which has been confirmed primarily to target Windows systems in Iran. Like any Trojan that tries to conceal itself and its attacks, Troj/BatDel-B should be removed with anti-malware software as necessary.
Troj/BatDel-B: A Heaping Batch of File-Deleting Troubles
Troj/BatDel-B can be applied to any of the various components and PC threats that are associated directly with Batchwiper, such as its Trojan dropper (GrooveMonitor.exe), Juboot.exe (a batch file that's used to edit your Registry to allow Batchwiper to launch itself automatically), Jucheck.exe (the primary component of Batchwiper) or SLEEP.exe (a non-malicious utility that's used to delay the launch of related PC threats). If Batchwiper actually manages to launch, Batchwiper will erase all other components that would be detected as Troj/BatDel-B – along with large amounts of other files on your hard drive.
SpywareRemove.com malware analysts have noted that the primary file-deleting attack of Batchwiper restricts itself to desktop files and files stored on your hard drive partitions D through I. Therefore, PCs that only use C drive partitions are safe from Troj/BatDel-B-related attacks. The original versions of Batchwiper use attacks that are widely spaced apart, with the next dated attack being programmed for late January 2013. However, a new variant of Batchwiper, Wmiprv.exe (also detected by the label Troj/BatDel-B) has been found to conduct file-deleting attacks far more regularly: as often as every fifty minutes.
Shooing the Troj/BatDel-B Bat Out of Your PC Belfry
As long as you have partitions other than C (a very common setup for any Windows computers), any variant of Troj/BatDel-B should be considered a very direct danger to the files on your computer. Because Troj/BatDel-B must be downloaded and launched prior to its attack and doesn't possess any obvious self-distribution capabilities, SpywareRemove.com malware researchers recommend that you avoid suspicious file downloads, links and potentially infected USB devices as the most likely infection vectors for Troj/BatDel-B.
Although many of Troj/BatDel-B's components are deleted by the primary Batchwiper Trojan, this main component will remain on your PC and continue to delete files at arbitrary times. Deleting Troj/BatDel-B should entail the usage of appropriate anti-malware software, and, due to the primitive coding that's involved in all components of Troj/BatDel-B, SpywareRemove.com malware experts don't consider Troj/BatDel-B to be especially resistant to scans from competent security programs.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:017ec06739fd44a4d6d3526aecd9a155
File name: 017ec06739fd44a4d6d3526aecd9a155Size: 155.2 KB (155208 bytes)
MD5: 017ec06739fd44a4d6d3526aecd9a155
Detection count: 82
Group: Malware file
Last Updated: January 7, 2013
1c8fc903268a29c5cf32e5f2285c7feb
File name: 1c8fc903268a29c5cf32e5f2285c7febSize: 144.96 KB (144968 bytes)
MD5: 1c8fc903268a29c5cf32e5f2285c7feb
Detection count: 79
Group: Malware file
Last Updated: January 7, 2013
WmiPrv.exe
File name: WmiPrv.exeSize: 23.04 KB (23040 bytes)
MD5: b7117b5d8281acd56648c9d08fadf630
Detection count: 78
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 7, 2013
juboot.mod.bin
File name: juboot.mod.binSize: 33.28 KB (33280 bytes)
MD5: 0c1161634d4f25e57a9e7bc560a1496d
Detection count: 73
File type: Binary File
Mime Type: unknown/bin
Group: Malware file
Last Updated: January 7, 2013
66022a804eccc02c6df3e0c83db1d2d8
File name: 66022a804eccc02c6df3e0c83db1d2d8Size: 85.5 KB (85504 bytes)
MD5: 66022a804eccc02c6df3e0c83db1d2d8
Detection count: 68
Group: Malware file
Last Updated: January 7, 2013
GrooveMonitor.exe
File name: GrooveMonitor.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
jucheck.exe
File name: jucheck.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
juboot.exe
File name: juboot.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
SLEEP.EXE
File name: SLEEP.EXEFile type: Executable File
Mime Type: unknown/EXE
Group: Malware file
Wmiprv.exe
File name: Wmiprv.exeFile type: Executable File
Mime Type: unknown/exe
Group: Malware file
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.