Hao123 by Baidu
Posted: April 9, 2013
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 417 |
---|---|
Threat Level: | 1/10 |
Infected PCs: | 595,502 |
First Seen: | April 9, 2013 |
---|---|
Last Seen: | October 17, 2023 |
OS(es) Affected: | Windows |
Hao123 by Baidu is a site and service that is offered through the popular Chinese Baidu search engine site. Hao123 by Baidu may be loaded as a newly set default home page on your computer. This action may be due to you previously downloading and installing a freeware program downloaded from the internet. Loading of Hao123 by Baidu may take place during startup of windows causing a browser window to be opened. Unwanted actions performed by Hao123 by Baidu may lead you to questionable sites or redirects to pages that attempt to display advertisements or random links. Removal of the files associated with Hao123 by Baidu is required to stop Hao123 by Baidu from loading as your default home page. Performing removal of Hao123 by Baidu may be easiest through use of an antispyware application.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%SYSTEMDRIVE%\Users\<username>\OneDrive\Área de Trabalho\Backup - CCE\Windows7\Users\<username>\AppData\Local\Temp\is863293414\022E424D_stp\hao123inst-brazil.exe
File name: hao123inst-brazil.exeSize: 505.02 KB (505024 bytes)
MD5: 1fe05fae1c86c3380c8170b96926129e
Detection count: 227
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\OneDrive\Área de Trabalho\Backup - CCE\Windows7\Users\<username>\AppData\Local\Temp\is863293414\022E424D_stp\hao123inst-brazil.exe
Group: Malware file
Last Updated: June 5, 2023
hao123Inst.exe
File name: hao123Inst.exeSize: 904 KB (904008 bytes)
MD5: 9ba85a66f0900b143e8538db141e5a08
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 9, 2013
%APPDATA%\hao123inst.exe
File name: hao123inst.exeSize: 353.92 KB (353928 bytes)
MD5: ffd46e8471313a30b9f5c6bedec6afb2
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-ar\hao123.1.0.0.1111.exe
File name: hao123.1.0.0.1111.exeSize: 588.93 KB (588932 bytes)
MD5: 204f29a1611f18f0eab6b54048e5377b
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-ar
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-br\hao123.1.0.0.1111.exe
File name: hao123.1.0.0.1111.exeSize: 586.37 KB (586376 bytes)
MD5: 5c2b1869033a9a8989fbed54109b3839
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-br
Group: Malware file
Last Updated: March 23, 2016
%ALLUSERSPROFILE%\baidu\update\download\ALL_hao123_sys_2014_11_24\Hao123SysPop.exe
File name: Hao123SysPop.exeSize: 207.68 KB (207688 bytes)
MD5: 5e428c42fd57f72aa5fc23d7c5eda775
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\baidu\update\download\ALL_hao123_sys_2014_11_24
Group: Malware file
Last Updated: March 23, 2016
%SystemDrive%\Hao123_demo021214.exe
File name: Hao123_demo021214.exeSize: 333.55 KB (333554 bytes)
MD5: b08764dc151ac29ea9dae02c86a6387a
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%
Group: Malware file
Last Updated: March 23, 2016
%USERPROFILE%\Desktop\hao123_setup.exe
File name: hao123_setup.exeSize: 1.04 MB (1045448 bytes)
MD5: 138c344aac2f13497af504d81517ccec
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-id\hao123.1.0.0.1108.exe
File name: hao123.1.0.0.1108.exeSize: 665.04 KB (665040 bytes)
MD5: 6ef2095decd7e3d360c494b740578ee6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-id
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-ar\hao123.1.0.0.1101.exe
File name: hao123.1.0.0.1101.exeSize: 627.33 KB (627336 bytes)
MD5: 93366ca5b233420c9005d7a2614764db
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-ar
Group: Malware file
Last Updated: March 23, 2016
D:\madison_documents\hao123browserdownloader_tn-45045059_14.exe
File name: hao123browserdownloader_tn-45045059_14.exeSize: 1.09 MB (1090136 bytes)
MD5: 9eb7e3bc3c063395bef68b447bf4b9f2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: D:\madison_documents
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\baidu\hao123-ar\hao123.1.0.0.1108.exe
File name: hao123.1.0.0.1108.exeSize: 608.68 KB (608680 bytes)
MD5: 17d28637b6af825f3b1e10387cef1825
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\baidu\hao123-ar
Group: Malware file
Last Updated: March 23, 2016
Registry Modifications
CLSID{66C90826-4384-4020-AA28-D3A4FA5FD31F}{F552F265-6686-4422-84E5-C695E35D863A}File name without pathar.hao123[1].xmlbr.hao123[1].xmlCliponyu.lnkHao123.lnkhao123[1].htmhttp_ar.hao123.com_0.localstoragehttp_ar.hao123.com_0.localstorage-journalhttp_br.hao123.com_0.localstoragehttp_br.hao123.com_0.localstorage-journalhttp_id.hao123.com_0.localstoragehttp_id.hao123.com_0.localstorage-journalhttp_jp.hao123.com_0.localstoragehttp_jp.hao123.com_0.localstorage-journalhttp_tw.hao123.com_0.localstoragehttp_tw.hao123.com_0.localstorage-journalhttp_www.7654.com_0.localstoragehttp_www.9973.com_0.localstoragehttp_www.9973.com_0.localstorage-journalhttp_www.hao123.com_0.localstoragehttp_www.hao123.com_0.localstorage-journalhttps_ar.hao123.com_0.localstoragehttps_ar.hao123.com_0.localstorage-journalhttps_www.hao123.com_0.localstoragehttps_www.hao123.com_0.localstorage-journalInternet Hao123.lnkInternet Hao 123 .lnkjp.hao123[1].xmlnphao123DPS.dllnphao123DPS_x64.dllnpJuziPlugin.dllnpJuziPlugin_x64.dllsoft.123juzi[1].xmlsoft.hao123[1].xmlth.hao123[1].xmltw.hao123[1].xmlwww.hao123.com.icowww.hao123[1].xmlRegexp file mask%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\hao123[RANDOM CHARACTERS].lnk%ALLUSERSPROFILE%\Start Menu\hao123[RANDOM CHARACTERS].lnk%APPDATA%\Microsoft\Windows\Start Menu\hao123[RANDOM CHARACTERS].lnk%TEMP%\Hao123.ini%Temp%\hao123Config.xml%TEMP%\hao123inst[RANDOM CHARACTERS].exe%temp%\Toylocalize.ini%UserProfile%\Desktop\hao123[RANDOM CHARACTERS].lnk%WINDIR%\System32\drivers\LcScience64.sysHKEY..\..\..\..{RegistryKeys}SOFTWARE\Baidu\BaiduProtect\LockIEStartPageSOFTWARE\Baidu\Hao123Software\Baidu\Hao123-aeSoftware\Baidu\Hao123-arSOFTWARE\Baidu\Hao123-armeituSoftware\Baidu\Hao123-brSOFTWARE\Baidu\Hao123-brgamesSoftware\Baidu\Hao123-brmovieSoftware\Baidu\Hao123-idSoftware\Baidu\Hao123-internationalSoftware\Baidu\Hao123-jpSoftware\Baidu\Hao123-saSoftware\Baidu\Hao123-thSoftware\Baidu\Hao123-twSOFTWARE\Baidu\Hao123-vnSOFTWARE\Classes\hao123chprogidSoftware\Classes\hao123DPS.AgentSoftware\Classes\JuziAgent.AgentSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ar.hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\br.hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ar.hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\br.hao123.comSOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\hao123.comSOFTWARE\Clients\StartMenuInternet\hao123Juzi.exeSOFTWARE\Clients\StartMenuInternet\hao123JuziBrowser.exeSOFTWARE\Hao123Software\hao123JuziBrowserSoftware\hao123linkSoftware\HDwnldSOFTWARE\JuziPluginSoftware\Microsoft\Internet Explorer\DOMStorage\123juzi.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\7654.comSoftware\Microsoft\Internet Explorer\DOMStorage\br.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\cn.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\jp.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\sa.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\soft.123juzi.comSoftware\Microsoft\Internet Explorer\DOMStorage\th.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\v.hao123.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.hao123.comSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66C90826-4384-4020-AA28-D3A4FA5FD31F}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F552F265-6686-4422-84E5-C695E35D863A}SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ar.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\br.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cn.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\jp.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sa.hao123.comSoftware\Microsoft\Internet Explorer\LowRegistry\DOMStorage\th.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\tw.hao123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.hao123.comSoftware\Microsoft\Windows\CurrentVersion\App Paths\hao123JuziBrowser.exeSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Jzbstall.exeSoftware\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_.HTMSoftware\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_.HTMLSoftware\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_.MHTMLSOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_httpSOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\hao123chprogid_httpsSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids\hao123chprogidSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithProgids\hao123chprogidSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\OpenWithProgids\hao123chprogidSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\OpenWithProgids\hao123chprogidSoftware\Microsoft\Windows\CurrentVersion\Ext\Stats\{F552F265-6686-4422-84E5-C695E35D863A}SOFTWARE\Microsoft\Windows\CurrentVersion\FileAssociations\ProgIds\hao123chprogid_.htmSOFTWARE\Microsoft\Windows\CurrentVersion\FileAssociations\ProgIds\hao123chprogid_.htmlSOFTWARE\Microsoft\Windows\CurrentVersion\FileAssociations\ProgIds\hao123chprogid_httpSoftware\Microsoft\Windows\CurrentVersion\RunOnce\hao123SettingSOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications\hao123Juzi.exeSoftware\MozillaPlugins\@123juzi.com/nphao123DPSSoftware\MozillaPlugins\@123juzi.com/npJuziAgentSOFTWARE\RegisteredApplications\hao123JuziBrowserSoftware\tsKdxSOFTWARE\Wow6432Node\Baidu\BaiduProtect\LockIEStartPageSOFTWARE\WOW6432Node\Clients\StartMenuInternet\hao123Juzi.exeSOFTWARE\Wow6432Node\Clients\StartMenuInternet\hao123JuziBrowser.exeSOFTWARE\Wow6432Node\hao123JuziBrowserSOFTWARE\Wow6432Node\Microsoft\Tracing\hao123_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\hao123_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\Jzbstall.exeSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\hao123SettingSOFTWARE\Wow6432Node\RegisteredApplications\hao123JuziBrowserSYSTEM\ControlSet001\Services\HSoftDoloExSYSTEM\ControlSet001\services\LcScienceSYSTEM\ControlSet001\services\WaNdFilterSYSTEM\ControlSet002\Services\HSoftDoloExSYSTEM\ControlSet002\services\LcScienceSYSTEM\ControlSet002\services\WaNdFilterSYSTEM\CurrentControlSet\Services\HSoftDoloExSYSTEM\CurrentControlSet\services\LcScienceSYSTEM\CurrentControlSet\services\WaNdFilterHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}hao123deskhao123desk-aehao123desk-arhao123desk-brhao123desk-brgameshao123desk-idhao123desk-internationalhao123desk-jphao123desk-sahao123desk-thhao123desk-vn{C5E2255C-66FA-4187-8EB6-5176247C4723}
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.