Home Malware Programs Browser Hijackers Hao123 by Baidu

Hao123 by Baidu

Posted: April 9, 2013

Threat Metric

Ranking: 417
Threat Level: 1/10
Infected PCs: 595,502
First Seen: April 9, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows


Hao123 by Baidu is a site and service that is offered through the popular Chinese Baidu search engine site. Hao123 by Baidu may be loaded as a newly set default home page on your computer. This action may be due to you previously downloading and installing a freeware program downloaded from the internet. Loading of Hao123 by Baidu may take place during startup of windows causing a browser window to be opened. Unwanted actions performed by Hao123 by Baidu may lead you to questionable sites or redirects to pages that attempt to display advertisements or random links. Removal of the files associated with Hao123 by Baidu is required to stop Hao123 by Baidu from loading as your default home page. Performing removal of Hao123 by Baidu may be easiest through use of an antispyware application.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\OneDrive\Área de Trabalho\Backup - CCE\Windows7\Users\<username>\AppData\Local\Temp\is863293414\022E424D_stp\hao123inst-brazil.exe File name: hao123inst-brazil.exe
Size: 505.02 KB (505024 bytes)
MD5: 1fe05fae1c86c3380c8170b96926129e
Detection count: 227
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\OneDrive\Área de Trabalho\Backup - CCE\Windows7\Users\<username>\AppData\Local\Temp\is863293414\022E424D_stp\hao123inst-brazil.exe
Group: Malware file
Last Updated: June 5, 2023
hao123Inst.exe File name: hao123Inst.exe
Size: 904 KB (904008 bytes)
MD5: 9ba85a66f0900b143e8538db141e5a08
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 9, 2013
%APPDATA%\hao123inst.exe File name: hao123inst.exe
Size: 353.92 KB (353928 bytes)
MD5: ffd46e8471313a30b9f5c6bedec6afb2
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-ar\hao123.1.0.0.1111.exe File name: hao123.1.0.0.1111.exe
Size: 588.93 KB (588932 bytes)
MD5: 204f29a1611f18f0eab6b54048e5377b
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-ar
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-br\hao123.1.0.0.1111.exe File name: hao123.1.0.0.1111.exe
Size: 586.37 KB (586376 bytes)
MD5: 5c2b1869033a9a8989fbed54109b3839
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-br
Group: Malware file
Last Updated: March 23, 2016
%ALLUSERSPROFILE%\baidu\update\download\ALL_hao123_sys_2014_11_24\Hao123SysPop.exe File name: Hao123SysPop.exe
Size: 207.68 KB (207688 bytes)
MD5: 5e428c42fd57f72aa5fc23d7c5eda775
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\baidu\update\download\ALL_hao123_sys_2014_11_24
Group: Malware file
Last Updated: March 23, 2016
%SystemDrive%\Hao123_demo021214.exe File name: Hao123_demo021214.exe
Size: 333.55 KB (333554 bytes)
MD5: b08764dc151ac29ea9dae02c86a6387a
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%
Group: Malware file
Last Updated: March 23, 2016
%USERPROFILE%\Desktop\hao123_setup.exe File name: hao123_setup.exe
Size: 1.04 MB (1045448 bytes)
MD5: 138c344aac2f13497af504d81517ccec
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-id\hao123.1.0.0.1108.exe File name: hao123.1.0.0.1108.exe
Size: 665.04 KB (665040 bytes)
MD5: 6ef2095decd7e3d360c494b740578ee6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-id
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-ar\hao123.1.0.0.1101.exe File name: hao123.1.0.0.1101.exe
Size: 627.33 KB (627336 bytes)
MD5: 93366ca5b233420c9005d7a2614764db
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-ar
Group: Malware file
Last Updated: March 23, 2016
D:\madison_documents\hao123browserdownloader_tn-45045059_14.exe File name: hao123browserdownloader_tn-45045059_14.exe
Size: 1.09 MB (1090136 bytes)
MD5: 9eb7e3bc3c063395bef68b447bf4b9f2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: D:\madison_documents
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-ar\hao123.1.0.0.1108.exe File name: hao123.1.0.0.1108.exe
Size: 608.68 KB (608680 bytes)
MD5: 17d28637b6af825f3b1e10387cef1825
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-ar
Group: Malware file
Last Updated: March 23, 2016

Registry Modifications

The following newly produced Registry Values are:

CLSID{66C90826-4384-4020-AA28-D3A4FA5FD31F}{F552F265-6686-4422-84E5-C695E35D863A}File name without pathar.hao123[1].xmlbr.hao123[1].xmlCliponyu.lnkHao123.lnkhao123[1].htmhttp_ar.hao123.com_0.localstoragehttp_ar.hao123.com_0.localstorage-journalhttp_br.hao123.com_0.localstoragehttp_br.hao123.com_0.localstorage-journalhttp_id.hao123.com_0.localstoragehttp_id.hao123.com_0.localstorage-journalhttp_jp.hao123.com_0.localstoragehttp_jp.hao123.com_0.localstorage-journalhttp_tw.hao123.com_0.localstoragehttp_tw.hao123.com_0.localstorage-journalhttp_www.7654.com_0.localstoragehttp_www.9973.com_0.localstoragehttp_www.9973.com_0.localstorage-journalhttp_www.hao123.com_0.localstoragehttp_www.hao123.com_0.localstorage-journalhttps_ar.hao123.com_0.localstoragehttps_ar.hao123.com_0.localstorage-journalhttps_www.hao123.com_0.localstoragehttps_www.hao123.com_0.localstorage-journalInternet Hao123.lnkInternet Hao 123 .lnkjp.hao123[1].xmlnphao123DPS.dllnphao123DPS_x64.dllnpJuziPlugin.dllnpJuziPlugin_x64.dllsoft.123juzi[1].xmlsoft.hao123[1].xmlth.hao123[1].xmltw.hao123[1].xmlwww.hao123.com.icowww.hao123[1].xmlRegexp file mask%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\hao123[RANDOM CHARACTERS].lnk%ALLUSERSPROFILE%\Start Menu\hao123[RANDOM CHARACTERS].lnk%APPDATA%\Microsoft\Windows\Start Menu\hao123[RANDOM CHARACTERS].lnk%TEMP%\Hao123.ini%Temp%\hao123Config.xml%TEMP%\hao123inst[RANDOM CHARACTERS].exe%temp%\Toylocalize.ini%UserProfile%\Desktop\hao123[RANDOM CHARACTERS].lnk%WINDIR%\System32\drivers\LcScience64.sysHKEY..\..\..\..{RegistryKeys}SOFTWARE\Baidu\BaiduProtect\LockIEStartPageSOFTWARE\Baidu\Hao123Software\Baidu\Hao123-aeSoftware\Baidu\Hao123-arSOFTWARE\Baidu\Hao123-armeituSoftware\Baidu\Hao123-brSOFTWARE\Baidu\Hao123-brgamesSoftware\Baidu\Hao123-brmovieSoftware\Baidu\Hao123-idSoftware\Baidu\Hao123-internationalSoftware\Baidu\Hao123-jpSoftware\Baidu\Hao123-saSoftware\Baidu\Hao123-thSoftware\Baidu\Hao123-twSOFTWARE\Baidu\Hao123-vnSOFTWARE\Classes\hao123chprogidSoftware\Classes\hao123DPS.AgentSoftware\Classes\JuziAgent.AgentSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ar.hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\br.hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ar.hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\br.hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\hao123.comSOFTWARE\Clients\StartMenuInternet\hao123Juzi.exeSOFTWARE\Clients\StartMenuInternet\hao123JuziBrowser.exeSOFTWARE\Hao123Software\hao123JuziBrowserSoftware\hao123linkSoftware\HDwnldSOFTWARE\JuziPluginSoftware\Microsoft\Internet Explorer\DOMStorage\123juzi.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\7654.comSoftware\Microsoft\Internet Explorer\DOMStorage\br.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\cn.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\jp.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\sa.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\soft.123juzi.comSoftware\Microsoft\Internet Explorer\DOMStorage\th.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\v.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.hao123.comSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66C90826-4384-4020-AA28-D3A4FA5FD31F}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F552F265-6686-4422-84E5-C695E35D863A}SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ar.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\br.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cn.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\jp.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sa.hao123.comSoftware\Microsoft\Internet Explorer\LowRegistry\DOMStorage\th.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\tw.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.hao123.comSoftware\Microsoft\Windows\CurrentVersion\App Paths\hao123JuziBrowser.exeSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Jzbstall.exeSoftware\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_.HTMSoftware\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_.HTMLSoftware\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_.MHTMLSOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_httpSOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_httpsSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids\hao123chprogidSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithProgids\hao123chprogidSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\OpenWithProgids\hao123chprogidSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\OpenWithProgids\hao123chprogidSoftware\Microsoft\Windows\CurrentVersion\Ext\Stats\{F552F265-6686-4422-84E5-C695E35D863A}SOFTWARE\Microsoft\Windows\CurrentVersion\FileAssociations\ProgIds\hao123chprogid_.htmSOFTWARE\Microsoft\Windows\CurrentVersion\FileAssociations\ProgIds\hao123chprogid_.htmlSOFTWARE\Microsoft\Windows\CurrentVersion\FileAssociations\ProgIds\hao123chprogid_httpSoftware\Microsoft\Windows\CurrentVersion\RunOnce\hao123SettingSOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications\hao123Juzi.exeSoftware\MozillaPlugins\@123juzi.com/nphao123DPSSoftware\MozillaPlugins\@123juzi.com/npJuziAgentSOFTWARE\RegisteredApplications\hao123JuziBrowserSoftware\tsKdxSOFTWARE\Wow6432Node\Baidu\BaiduProtect\LockIEStartPageSOFTWARE\WOW6432Node\Clients\StartMenuInternet\hao123Juzi.exeSOFTWARE\Wow6432Node\Clients\StartMenuInternet\hao123JuziBrowser.exeSOFTWARE\Wow6432Node\hao123JuziBrowserSOFTWARE\Wow6432Node\Microsoft\Tracing\hao123_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\hao123_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\Jzbstall.exeSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\hao123SettingSOFTWARE\Wow6432Node\RegisteredApplications\hao123JuziBrowserSYSTEM\ControlSet001\Services\HSoftDoloExSYSTEM\ControlSet001\services\LcScienceSYSTEM\ControlSet001\services\WaNdFilterSYSTEM\ControlSet002\Services\HSoftDoloExSYSTEM\ControlSet002\services\LcScienceSYSTEM\ControlSet002\services\WaNdFilterSYSTEM\CurrentControlSet\Services\HSoftDoloExSYSTEM\CurrentControlSet\services\LcScienceSYSTEM\CurrentControlSet\services\WaNdFilterHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}hao123deskhao123desk-aehao123desk-arhao123desk-brhao123desk-brgameshao123desk-idhao123desk-internationalhao123desk-jphao123desk-sahao123desk-thhao123desk-vn{C5E2255C-66FA-4187-8EB6-5176247C4723}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\Hao123%ALLUSERSPROFILE%\Hao123%APPDATA%\HSoftDoloEx%APPDATA%\Hao123%APPDATA%\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#br.hao123.com%APPDATA%\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#s1.hao123img.com%APPDATA%\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#sa.hao123.com%APPDATA%\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.hao123.com%APPDATA%\Microsoft\Windows\Start Menu\Programs\Cliponyu-Indonesia%APPDATA%\Microsoft\Windows\Start Menu\Programs\Hao123-Brazil%APPDATA%\Microsoft\Windows\Start Menu\Programs\Hao123-Egypt%APPDATA%\Microsoft\Windows\Start Menu\Programs\Hao123-Saudi%APPDATA%\Microsoft\Windows\Start Menu\Programs\Hao123-Thailand%APPDATA%\Microsoft\Windows\Start Menu\Programs\Hao123-br%APPDATA%\baidu\Cliponyu%APPDATA%\baidu\hao123%APPDATA%\baidu\hao123-br%APPDATA%\baidu\hao123-brgames%APPDATA%\baidu\hao123-sa%AppData%\baidu\hao123-ar%AppData%\baidu\hao123-jp%AppData%\baidu\hao123-th%LOCALAPPDATA%\Hao123%ProgramFiles%\baidu\Hao123Desk%ProgramFiles(x86)%\baidu\Hao123Desk%ProgramFiles(x86)%\tbkset%TEMP%\hao123desksetup%TEMP%\hao123deskskinres%USERPROFILE%\AppData\LocalLow\JuziPlugin%USERPROFILE%\AppData\LocalLow\Microsoft\Windows\Start Menu\Programs\Hao123-br%USERPROFILE%\AppData\LocalLow\hao123DPS%USERPROFILE%\Application Data\JuziPlugin%UserProfile%\Local Settings\Application Data\Hao123%appdata%\hao123JuziBrowser
The following URL's were detected:
hao.169x.cn/hao.qquu8.com/hao643.com/http://br.hao123.com/http://hao.7654.com/http://hao.qq.com/http://id.hao123.com/http://jp.hao123.com/http://th.hao123.com/http://tw.hao123.com/http://us.hao123.com/http://vn.hao123.com/https://1111.tmall.com/https://ar.hao123.com/hao123www.9973.com/zhidaota.cn/
Loading...