Friday, December 28, 2012

A look into the Batch Wiper virus

The Iranian CERT reported the existence of a new targeted data wiping malware.
Although first thought as another serious  country level virus, further, deeper analysis show that it is relatively simple attack.

GrooveMonitor.exe is the main file.
Checking the file with a Hex Editor we notice something nice.

Basically its a self extracting RAR file.
Opening the archive we see 3 more files, jucheck.exe, juboot.exe and SLEEP.EXE.

If we look at juboot.exe in a hex editor we find the following signature

The header belongs to "the Ultimate Packer for eXecutables" (
I then opened the file with PE Explorer allowing me to see that the file is basically a Bat file with the following content:

@echo off & setlocal
sleep for 2
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v jucheck.exe /t REG_SZ /d "%systemroot%\system32\jucheck.exe" /f

start "" /D"%systemroot%\system32\" "jucheck.exe"

It looks like justboot.exe runs sleep for 2 and then adds registry keys ensuring that 'jucheck.exe' is executed each time the computer starts up.

In the same manner, checking jucheck.exe, it is also a batch file.
The batch file is longer this time so I'll summarize it for you. I made the source is available on pastebin, .

First sleep for 2 just like with the juboot.exe
then it deletes the juboot.exe file and the original GrooveMonitor.exe
The code then checks for specific dates to run. the dates are:
  • 10-12/Dec/2012
  • 21-23/Jan/2013
  • 6-8/May/2013
  • 22-24/Jul/2013
  • 11-13/Nov/2013
  • 3-5/Feb/2014
  • 5-7/May/2014
  • 11-13/Aug/2014
  • 2-4/Feb/2015
On these dates it attempts to wipe the data on the local drive using a simple "del /q /s /f" command on drives D, E, F, G, H and I.

The batch then moves on and attempts to erase the desktop in the same way.
Finally, the batch file runs "calc" (Where did this come from ?).

I haven't finished messing with the samples but as you've seen its not a sophisticated attack and will be easy to detect and stop before any damage is done.

If you want to look at the samples for yourselves, I've made them available at



  1. Warez sites seem to be distributing these attacks. Not sure why, but I had my windows xp wiped the other day.

    1. That is strange. Are you sure they are identical ? I would love to receive a sample if possible.

    2. I am doing a project for a malware class and choose batchwiper as my virus, I found a sample at It is a live sample so show caution.

  2. Infections are a standout amongst the most excruciating and baffling to manage, and get one of these can cost a great many dollars and botch your valuable PC. Utilizing some basic and powerful tips, you can extraordinarily diminish your odds of getting an infection and keep your PC running like new.
    zepto File Virus Removal

  3. Thanks for sharing the information! When I write MyAssignmentHelp testimonials I'm always afraid that my laptop shuts down from the virus and I lose all my data.

  4. Despite reading many blogs and articles, yours is the most useful. You did a very good job. Thank you so much for the information you shared. Additionally, I have a dedicated profile CPS Test where I provide more information. See it here Click Test and let me know what you think.

  5. Hello everyone! If some of you need professional help with essay or homework, you can ask this guys for help! They rally know how to do it, and you can just write to them thesis papers online and be ready for help! Good luck and have fun!

  6. This looks good is it windows only like on

  7. Order assignments safely at The service is DMCA protected. We never disclose information about customers and payments to any third party. We foster security and work to let the world know you’re the author.

  8. As an experienced CNC metal machining firm, Reading Plastic can ship precision parts from aluminum, brass, copper, stainless steel and titanium. Our metal parts are machined with the identical tight tolerances and quick turnarounds our plastic parts clients rely on, nicely as|in addition to} economical processes that streamline production and decrease costs. We make the most of one of the best machining practices – including constant slicing speeds, sharp tools and strategic processes – to make sure all of our Heated Blanket metal parts meet the strictest high quality requirements. At CNC Machining, Inc., we focus on manufacturing precision machined parts for the medical, automotive, analysis, and other industries.