Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Virus alerts

December 18th, 2012, 09:55 GMT · By

GrooveMonitor Data-Wiping Malware Not Sophisticated, but Enough to Cause Damage

SHARE:

Adjust text size:

Data-wiping malware targeting Iran analyzed
Enlarge picture
On Monday, we learned that Iran’s CERT issued a warning about a new piece of malware designed to wipe files from infected computers.

Experts from Kaspersky and Sophos have analyzed this new threat and they provide some interesting details.

It turns out that the malware is distributed as a self-extracting archive file called GrooveMonitor.exe which contains a number of three executable files: SLEEP.exe (which is not actually malicious), jucheck.exe and juboot.exe.

Basically, juboot.exe is a DOS BAT file that uses SLEEP.exe to wait for two seconds before it adds a registry entry, which ensures that jucheck.exe is executed each time the computer is started.

When executed, jucheck.exe erases GrooveMonitor.exe and juboot.exe and checks to see if the system date matches to one of the dates on which it must try to delete the files from the Desktop and the D, E, F, G, H and I partitions.

Once the data is deleted, chkdsk is run on the targeted partition, most likely to trick the victim into believing that the files have been removed because of a hardware or a software issue.

All those who have analyzed this piece of malware agree that it’s not sophisticated at all, but they also agree with the fact that it doesn’t necessarily need to be so in order to cause damage.

“Why Iran is drawing attention to this is anybody's guess. It does go to show that malware doesn't need to be sophisticated to cause trouble though. If you can execute arbitrary files, all it takes is a few lines in a batch file and some wrappers to cause serious damage,” Sophos’ Chester Wisniewski said.

“This is as basic as it gets. But if it was effective that doesn't matter. If it wasn't clear already - the era of cyber-sabotage has arrived. Be prepared,” Roel, a Kaspersky lab expert, explained.


1,199 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Iranian CERT Warns of Data-Wiping Malware

Cybercrime Investigators Help Russian Authorities Arrest DDOS Botnet Master

Cybercriminals Combine Ransomware with Survey Offers to Make a Profit

Carberp Banking Trojan Sold for $40,000 (€31,000)

Upclicker Uses Left Mouse Button to Execute Malicious Code When No One Is Looking

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM