Threat Database Trojans Trojan: Win32/Hidebaid.B

Trojan: Win32/Hidebaid.B

By GoldSparrow in Trojans

Threat Scorecard

Ranking: 4,501
Threat Level: 80 % (High)
Infected Computers: 33,718
First Seen: March 7, 2016
Last Seen: May 2, 2024
OS(es) Affected: Windows

The Trojan: Win32/Hidebaid.B detection is used by security vendors to specify a backdoor Trojan from the HideBaid family of threats. Security alerts about Trojan: Win32/Hidebaid.B are a reason to suspect infection with a variant of the HideBaid Backdoor Trojan. The Trojan: Win32/Hidebaid.B may install its files in the Temp directory and make modifications to the Windows Registry values to run every time the users turn on their PCs. Most versions of the Hidebaid Backdoor Trojan are less than 80KB in size and may later the properties of your shortcuts on the desktop to enable additional program parameters. Security researchers speculate that the variants of Trojan: Win32/Hidebaid are made by Chinese coders and may be dispersed among PC users via spam mail and malvertising. There are samples of Trojan: Win32/Hidebaid.B that are made to look like readers for presentations and images that suggest an effort to spread the threat globally.

The Trojan: Win32/Hidebaid.B is written in the C++ programming language and may connect to the Internet to download and install external plug-ins that would allow it to hide its activities and expand its functionality. As stated above the Trojan: Win32/Hidebaid.B is a Backdoor Trojan that might open ports to your computer system and allow remote code execution and data manipulation. Trojan: Win32/Hidebaid is a severe threat that has many variants to avoid detection and is designed to bypass basic protection mechanisms. The Trojan: Win32/Hidebaid may use executable DLLs to maintain its operations and work under the radar of most AV engines. The Trojan: Win32/Hidebaid may hide itself as a separate thread under the Svchost.exe host process in Windows Task Manager. Computer users need to install a reliable anti-malware instrument to find and delete the files associated with the Trojan: Win32/Hidebaid.B malware.

SpyHunter Detects & Remove Trojan: Win32/Hidebaid.B

File System Details

Trojan: Win32/Hidebaid.B may create the following file(s):
# File Name MD5 Detections
1. uc.exe 136e86cbd5d24ce21791a444ce634024 566
2. uc.exe 056f367fe2499f934cc21bb3ac3e7a3d 131
3. uc.exe 9c4024e22583cf5eea25dc30a31dfd93 98
4. uc.exe c96a0f939b9e809d24d6149046b7eb72 95
5. uc.exe e8dd02af7c44245bc430170a361b96c5 25
6. uc.exe aa1bd917eab334838a0eba51aa8d537d 24
7. uc.exe 9e0db1c7993c58c7dfba2083fcfb53aa 24
8. uc.exe d9294a46d7f8f4dfd231baea176b40e8 23
9. uc.exe 2ac4b20ed54ec906f572829ca01528d1 19
10. uc.exe 095c31e3c61118d27ffe4aa80aebba2e 15
11. uc.exe 0e6106a015d10d031e8a49d36fe48609 12
12. Bind.exe d0b7db7b5da999f1db484183641ab1a7 10
13. uc.exe c60471c4bf6c89ce29273b563d8d88c2 9
14. uc.exe 4d5340f9027133ae6618aeca7ac1d688 7
15. uc.exe 4918ac094e5e71d97ccdbc9a552bd9b8 7
16. uc.exe 9fc71b01184059b193c8808b332acb8b 7
17. uc.exe 4332e679fee73a10383b08dade9567d4 6
18. uc.exe d132c91b232ec4197d3620dc9a42d663 6
19. Bind.exe db2911776fb87ba43a3f9d5bbe2555b0 4
20. uc.exe 93d48102ba6eae2dbbb5c13967e25555 4
21. uc.exe 523541ab89073afcd6cfeeab5f49ffef 4
22. uc.exe be267971d27a850d8405f161d777b0e6 3
23. uc.exe 3594a2b36d0e76881355f659863f82b3 3
24. uc.exe a6fe20fdbfd40bb7b8e1b4ba979418a2 2
25. uc.exe cfcb22571b24cce1f3721c5c01ea6658 2
26. uc.exe 29eb44eed97aaa6248e5df13c14d7ca5 2
27. uc.exe 4ef8da94bd00a972017d1154574a914a 1
28. uc.exe 870ebca17ecb2f191c6b5eb51e5ef164 1
More files

Registry Details

Trojan: Win32/Hidebaid.B may create the following registry entry or registry entries:
Regexp file mask
%PROGRAMFILES%\Badu\sys.exe
%PROGRAMFILES%\Badu\uc.exe
%PROGRAMFILES%\Baidu\BindEx.exe
%PROGRAMFILES%\eee\Bind.exe
%PROGRAMFILES%\eee\uc.exe
%PROGRAMFILES%\hhh\uc.exe
%PROGRAMFILES%\lll\bind.exe
%PROGRAMFILES%\rfv\uc.exe
%PROGRAMFILES%\ttt\Bind.exe
%PROGRAMFILES%\xxx\uc.exe
%PROGRAMFILES(x86)%\Badu\uc.exe
%PROGRAMFILES(x86)%\Baidu\BindEx.exe
%PROGRAMFILES(x86)%\eee\Bind.exe
%PROGRAMFILES(x86)%\eee\uc.exe
%PROGRAMFILES(x86)%\hhh\uc.exe
%PROGRAMFILES(x86)%\lll\bind.exe
%PROGRAMFILES(x86)%\lll\uc.exe
%PROGRAMFILES(x86)%\rfv\uc.exe
%PROGRAMFILES(x86)%\Tencent\app.exe
%PROGRAMFILES(x86)%\ttt\Bind.exe
%PROGRAMFILES(x86)%\ttt\uc.exe
%PROGRAMFILES(x86)%\xxx\uc.exe
%TEMP%\pps-qq-19.exe

Directories

Trojan: Win32/Hidebaid.B may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\wanttoxiamen
%APPDATA%\et\21
%APPDATA%\et\445
%PROGRAMFILES%\sbqh
%PROGRAMFILES%\sss
%PROGRAMFILES%\surranderu
%PROGRAMFILES%\wanttoxiamen
%PROGRAMFILES%\wanttoxiameng
%PROGRAMFILES(x86)%\sbqh
%PROGRAMFILES(x86)%\sss
%PROGRAMFILES(x86)%\surranderu
%PROGRAMFILES(x86)%\wanttoxiamen
%PROGRAMFILES(x86)%\wanttoxiameng

Trending

Most Viewed

Loading...