Malware

Win32/Baidence.B removal guide

Malware Removal

The Win32/Baidence.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Baidence.B virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Baidence.B?


File Info:

name: 4D200D6B071A350F3861.mlw
path: /opt/CAPEv2/storage/binaries/ae796834083ba83a0575222a173b4ab126a53b5316243174d5b4f5d90ed57e8e
crc32: 66926BB7
md5: 4d200d6b071a350f38615f0ed205e776
sha1: 0076e6abbfc3a1a12ad1362e1020a0cd6fba7a2a
sha256: ae796834083ba83a0575222a173b4ab126a53b5316243174d5b4f5d90ed57e8e
sha512: a1f548fa1206ba6e6bba93a8c0ca20fb8836d8d97696b2e6b82e0d28922f81df9a09cfefb6bab30de9b2825198a281265d842641566cfa56b5aa4306de5352dd
ssdeep: 3072:hi5hGcl/XUcdMZUwn8PNNbBO5lnMnWRECPL8eirR3S5fg/OOqfEyS07mHKgajW6I:Uu0Uywn8PNNbBO5lnMnWRECPL8eirR3B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19EA3F9679F91C4D6DC080134F6BDA7BCEE8FFE341A90225522AAF80E58FF144875E45A
sha3_384: 88c3947cec259857e476c29c1f8eba11b7075d20a80ae43aee213c0efcc71c5b5825381871df04c8d5a0530989e80ff8
ep_bytes: 558bec6aff681881400068a269400064
timestamp: 2013-11-07 05:53:04

Version Info:

Comments:
CompanyName: 微软中国
FileDescription: Microsoft Office Word 97-2003 文档 (.doc)
FileVersion: 1, 0, 0, 1
InternalName: Microsoft Office Word 97-2003 文档 (.doc)
LegalCopyright: 版权所有 (C) 2013
LegalTrademarks:
OriginalFilename: Microsoft Office Word 97-2003 文档 (.doc)
PrivateBuild:
ProductName: Microsoft Office Word 97-2003 文档 (.doc)
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Win32/Baidence.B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Baidence.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.GC.gu3@ujSxeLkbf
FireEyeGeneric.mg.4d200d6b071a350f
CAT-QuickHealWin95.SK
SkyhighBehavesLike.Win32.Generic.ch
McAfeeGenericRXVT-TI!4D200D6B071A
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Vindor.2e7a8b88
K7GWTrojan ( 004996af1 )
K7AntiVirusTrojan ( 004996af1 )
BaiduWin32.Backdoor.Baidence.b
VirITTrojan.Win32.DownLoader10.DDPH
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Baidence.B
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DD524
ClamAVWin.Downloader.Zusy-10004224-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.GC.gu3@ujSxeLkbf
NANO-AntivirusTrojan.Win32.Dwn.cqxzxt
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Sdum.kf
EmsisoftGen:Trojan.Heur.GC.gu3@ujSxeLkbf (B)
GoogleDetected
F-SecureTrojan.TR/Crypt.FKM.Gen
DrWebTrojan.DownLoader10.55153
ZillyaTrojan.Baidence.Win32.5421
Trapminemalicious.high.ml.score
SophosMal/Baidence-A
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.anee
VaristW32/Trojan-disguised-based!Maxi
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Zbot!atmnm
XcitiumTrojWare.Win32.Spy.Agent@55ir62
ArcabitTrojan.Heur.GC.ED20CDD
ZoneAlarmUDS:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.10YXBYG
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5605799
Acronissuspicious
BitDefenderThetaAI:Packer.EDA7E7E520
ALYacGen:Trojan.Heur.GC.gu3@ujSxeLkbf
MAXmalware (ai score=86)
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingMalware.FakeDOC/ICON!1.9C3B (CLASSIC)
YandexTrojan.Agent!nV7uPII26PU
IkarusTrojan.Win32.Spy
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Baidence.B!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.b071a3
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Baidence.B

How to remove Win32/Baidence.B?

Win32/Baidence.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment