Home Malware Programs Trojans Trojan: Win32/Hidebaid.B

Trojan: Win32/Hidebaid.B

Posted: March 7, 2016

Threat Metric

Ranking: 3,849
Threat Level: 8/10
Infected PCs: 78,212
First Seen: March 7, 2016
Last Seen: October 17, 2023
OS(es) Affected: Windows

Trojan: Win32/Hidebaid.B is an advanced threat that may exploit various system vulnerabilities to enter undetected. Trojan: Win32/Hidebaid.B may open backdoors on infected machines. The parasite may connect the computers with distant hosts that work as Command and Control (C&C) servers. The hackers behind these attacks may use these hosts to transfer their instructions to the threat. They may use Trojan: Win32/Hidebaid.B to collect valuable files or obtain essential account credentials like the usernames and passwords for your bank accounts. If Trojan: Win32/Hidebaid.B reaches your PC, it may deteriorate its performance significantly due to the incoming and outgoing Internet traffic. Except for a possible slower operating speed of your machine, you may not notice too many additional clues unless you search for specific files and folders that it creates. This backdoor Trojan works in the background to prevent you from taking the proper measures in time. The consequences of the infection with this complex cyber threat may be detrimental, so it is advisable to make everything possible not to let Trojan: Win32/Hidebaid.B reach your PC in the first place. Trojan: Win32/Hidebaid.B travels across the cyberspace mainly as a corrupt email attachment. It may seem to be an invoice, a text file, a .pdf presentation, etc. If the sender of the message is unfamiliar to you, you should never open any attached files. Trojan: Win32/Hidebaid.B also may spread to your system if you connect compromised USB drives or download fake software updates. Trojan: Win32/Hidebaid.B may change an array of settings to remain hidden and functioning at all times. Trojan: Win32/Hidebaid.B may interfere with the Windows Registries to create an Autorun file. The parasite also may turn off automatic updates or disable the Windows Firewall to prevent detection. Once all preparatory actions are completed, Trojan: Win32/Hidebaid.B may initiate the connection to the remote hosts, which will put at risk all of your information. To prevent the significant issues that may follow, you should install credible security software that can delete Trojan: Win32/Hidebaid.B efficiently.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\fff\uc.exe File name: uc.exe
Size: 228.11 MB (228114518 bytes)
MD5: 056f367fe2499f934cc21bb3ac3e7a3d
Detection count: 307
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\fff
Group: Malware file
Last Updated: December 14, 2019
%PROGRAMFILES%\fff\uc.exe File name: uc.exe
Size: 228.08 MB (228081750 bytes)
MD5: 9c4024e22583cf5eea25dc30a31dfd93
Detection count: 230
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\fff
Group: Malware file
Last Updated: July 4, 2022
%PROGRAMFILES%\fff\uc.exe File name: uc.exe
Size: 44.29 MB (44290134 bytes)
MD5: c96a0f939b9e809d24d6149046b7eb72
Detection count: 222
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\fff
Group: Malware file
Last Updated: April 7, 2022
%PROGRAMFILES%\fff\uc.exe File name: uc.exe
Size: 190.14 MB (190140416 bytes)
MD5: 4ef8da94bd00a972017d1154574a914a
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\fff
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\sss\uc.exe File name: uc.exe
Size: 188.41 KB (188416 bytes)
MD5: aa1bd917eab334838a0eba51aa8d537d
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\sss
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\xxx\uc.exe File name: uc.exe
Size: 180.22 KB (180224 bytes)
MD5: 9e0db1c7993c58c7dfba2083fcfb53aa
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\xxx
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\baidu\uc.exe File name: uc.exe
Size: 3.47 MB (3475115 bytes)
MD5: 870ebca17ecb2f191c6b5eb51e5ef164
Detection count: 53
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\baidu
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES(x86)%\fff\uc.exe File name: uc.exe
Size: 190.11 MB (190111830 bytes)
MD5: 2ac4b20ed54ec906f572829ca01528d1
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\fff
Group: Malware file
Last Updated: March 11, 2017
%PROGRAMFILES%\lll\uc.exe File name: uc.exe
Size: 188.41 KB (188416 bytes)
MD5: 095c31e3c61118d27ffe4aa80aebba2e
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\lll
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\lll\uc.exe File name: uc.exe
Size: 221.18 KB (221184 bytes)
MD5: 0e6106a015d10d031e8a49d36fe48609
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\lll
Group: Malware file
Last Updated: May 10, 2017
C:\Program Files (x86)\ttt\Bind.exe File name: Bind.exe
Size: 49.15 KB (49152 bytes)
MD5: d0b7db7b5da999f1db484183641ab1a7
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\ttt\Bind.exe
Group: Malware file
Last Updated: August 9, 2022
%PROGRAMFILES%\baidu\uc.exe File name: uc.exe
Size: 188.41 KB (188416 bytes)
MD5: c60471c4bf6c89ce29273b563d8d88c2
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\baidu
Group: Malware file
Last Updated: March 17, 2017
%PROGRAMFILES%\ttt\uc.exe File name: uc.exe
Size: 450.98 KB (450981 bytes)
MD5: 4918ac094e5e71d97ccdbc9a552bd9b8
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ttt
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\ttt\uc.exe File name: uc.exe
Size: 631.17 KB (631174 bytes)
MD5: 9fc71b01184059b193c8808b332acb8b
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ttt
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\ttt\uc.exe File name: uc.exe
Size: 213.07 KB (213078 bytes)
MD5: 4332e679fee73a10383b08dade9567d4
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ttt
Group: Malware file
Last Updated: May 10, 2017
%SystemDrive%\Program Files\sss\uc.exe File name: uc.exe
Size: 159.74 KB (159744 bytes)
MD5: d132c91b232ec4197d3620dc9a42d663
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Program Files\sss
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\xxx\Bind.exe File name: Bind.exe
Size: 61.44 KB (61440 bytes)
MD5: db2911776fb87ba43a3f9d5bbe2555b0
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\xxx
Group: Malware file
Last Updated: March 3, 2017
%PROGRAMFILES%\ttt\uc.exe File name: uc.exe
Size: 217.62 KB (217629 bytes)
MD5: 93d48102ba6eae2dbbb5c13967e25555
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ttt
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\ttt\uc.exe File name: uc.exe
Size: 208.98 KB (208982 bytes)
MD5: 523541ab89073afcd6cfeeab5f49ffef
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ttt
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES(x86)%\lll\uc.exe File name: uc.exe
Size: 163.84 KB (163840 bytes)
MD5: be267971d27a850d8405f161d777b0e6
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\lll
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\rfv\uc.exe File name: uc.exe
Size: 172.03 KB (172032 bytes)
MD5: a6fe20fdbfd40bb7b8e1b4ba979418a2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\rfv
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES(x86)%\ttt\uc.exe File name: uc.exe
Size: 139.35 KB (139350 bytes)
MD5: cfcb22571b24cce1f3721c5c01ea6658
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ttt
Group: Malware file
Last Updated: May 10, 2017
%PROGRAMFILES%\sss\uc.exe File name: uc.exe
Size: 188.41 KB (188416 bytes)
MD5: 29eb44eed97aaa6248e5df13c14d7ca5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\sss
Group: Malware file
Last Updated: May 10, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%PROGRAMFILES%\Badu\sys.exe%PROGRAMFILES%\Badu\uc.exe%PROGRAMFILES%\Baidu\BindEx.exe%PROGRAMFILES%\eee\Bind.exe%PROGRAMFILES%\eee\uc.exe%PROGRAMFILES%\hhh\uc.exe%PROGRAMFILES%\lll\bind.exe%PROGRAMFILES%\rfv\uc.exe%PROGRAMFILES%\ttt\Bind.exe%PROGRAMFILES%\xxx\uc.exe%PROGRAMFILES(x86)%\Badu\uc.exe%PROGRAMFILES(x86)%\Baidu\BindEx.exe%PROGRAMFILES(x86)%\eee\Bind.exe%PROGRAMFILES(x86)%\eee\uc.exe%PROGRAMFILES(x86)%\hhh\uc.exe%PROGRAMFILES(x86)%\lll\bind.exe%PROGRAMFILES(x86)%\lll\uc.exe%PROGRAMFILES(x86)%\rfv\uc.exe%PROGRAMFILES(x86)%\Tencent\app.exe%PROGRAMFILES(x86)%\ttt\Bind.exe%PROGRAMFILES(x86)%\ttt\uc.exe%PROGRAMFILES(x86)%\xxx\uc.exe%TEMP%\pps-qq-19.exeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{B91BE9AB-DFAD-4406-8AC1-0F6D896D40CD}_is1

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\wanttoxiamen%APPDATA%\et\21%APPDATA%\et\445%PROGRAMFILES%\sbqh%PROGRAMFILES%\sss%PROGRAMFILES%\surranderu%PROGRAMFILES%\wanttoxiamen%PROGRAMFILES%\wanttoxiameng%PROGRAMFILES(x86)%\sbqh%PROGRAMFILES(x86)%\sss%PROGRAMFILES(x86)%\surranderu%PROGRAMFILES(x86)%\wanttoxiamen%PROGRAMFILES(x86)%\wanttoxiameng
Loading...