Home Malware Programs Trojans Troj/BatDel-B

Troj/BatDel-B

Posted: December 18, 2012

Threat Metric

Ranking: 14,511
Threat Level: 9/10
Infected PCs: 6,649
First Seen: December 18, 2012
Last Seen: January 13, 2025
OS(es) Affected: Windows

Troj/BatDel-B is a technical identification for various components of the Batchwiper Trojan, including its Trojan dropper and an updated variant of Batchwiper that deletes files more regularly than previous versions. Even though Troj/BatDel-B isn't an especially advanced PC threat, Troj/BatDel-B does have a meaningfully dangerous payload: the ability to delete files automatically at pre-specified times. SpywareRemove.com malware research team especially recommends that PC users in the Middle East practice good anti-malware habits to protect their computers from Troj/BatDel-B, which has been confirmed primarily to target Windows systems in Iran. Like any Trojan that tries to conceal itself and its attacks, Troj/BatDel-B should be removed with anti-malware software as necessary.

Troj/BatDel-B: A Heaping Batch of File-Deleting Troubles

Troj/BatDel-B can be applied to any of the various components and PC threats that are associated directly with Batchwiper, such as its Trojan dropper (GrooveMonitor.exe), Juboot.exe (a batch file that's used to edit your Registry to allow Batchwiper to launch itself automatically), Jucheck.exe (the primary component of Batchwiper) or SLEEP.exe (a non-malicious utility that's used to delay the launch of related PC threats). If Batchwiper actually manages to launch, Batchwiper will erase all other components that would be detected as Troj/BatDel-B – along with large amounts of other files on your hard drive.

SpywareRemove.com malware analysts have noted that the primary file-deleting attack of Batchwiper restricts itself to desktop files and files stored on your hard drive partitions D through I. Therefore, PCs that only use C drive partitions are safe from Troj/BatDel-B-related attacks. The original versions of Batchwiper use attacks that are widely spaced apart, with the next dated attack being programmed for late January 2013. However, a new variant of Batchwiper, Wmiprv.exe (also detected by the label Troj/BatDel-B) has been found to conduct file-deleting attacks far more regularly: as often as every fifty minutes.

Shooing the Troj/BatDel-B Bat Out of Your PC Belfry

As long as you have partitions other than C (a very common setup for any Windows computers), any variant of Troj/BatDel-B should be considered a very direct danger to the files on your computer. Because Troj/BatDel-B must be downloaded and launched prior to its attack and doesn't possess any obvious self-distribution capabilities, SpywareRemove.com malware researchers recommend that you avoid suspicious file downloads, links and potentially infected USB devices as the most likely infection vectors for Troj/BatDel-B.

Although many of Troj/BatDel-B's components are deleted by the primary Batchwiper Trojan, this main component will remain on your PC and continue to delete files at arbitrary times. Deleting Troj/BatDel-B should entail the usage of appropriate anti-malware software, and, due to the primitive coding that's involved in all components of Troj/BatDel-B, SpywareRemove.com malware experts don't consider Troj/BatDel-B to be especially resistant to scans from competent security programs.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



017ec06739fd44a4d6d3526aecd9a155 File name: 017ec06739fd44a4d6d3526aecd9a155
Size: 155.2 KB (155208 bytes)
MD5: 017ec06739fd44a4d6d3526aecd9a155
Detection count: 82
Group: Malware file
Last Updated: January 7, 2013
1c8fc903268a29c5cf32e5f2285c7feb File name: 1c8fc903268a29c5cf32e5f2285c7feb
Size: 144.96 KB (144968 bytes)
MD5: 1c8fc903268a29c5cf32e5f2285c7feb
Detection count: 79
Group: Malware file
Last Updated: January 7, 2013
WmiPrv.exe File name: WmiPrv.exe
Size: 23.04 KB (23040 bytes)
MD5: b7117b5d8281acd56648c9d08fadf630
Detection count: 78
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 7, 2013
juboot.mod.bin File name: juboot.mod.bin
Size: 33.28 KB (33280 bytes)
MD5: 0c1161634d4f25e57a9e7bc560a1496d
Detection count: 73
File type: Binary File
Mime Type: unknown/bin
Group: Malware file
Last Updated: January 7, 2013
66022a804eccc02c6df3e0c83db1d2d8 File name: 66022a804eccc02c6df3e0c83db1d2d8
Size: 85.5 KB (85504 bytes)
MD5: 66022a804eccc02c6df3e0c83db1d2d8
Detection count: 68
Group: Malware file
Last Updated: January 7, 2013
GrooveMonitor.exe File name: GrooveMonitor.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
jucheck.exe File name: jucheck.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
juboot.exe File name: juboot.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
SLEEP.EXE File name: SLEEP.EXE
File type: Executable File
Mime Type: unknown/EXE
Group: Malware file
Wmiprv.exe File name: Wmiprv.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...