Home Malware Programs Adware Hatchiho

Hatchiho

Posted: March 31, 2014

Threat Metric

Ranking: 17,037
Threat Level: 2/10
Infected PCs: 412
First Seen: March 31, 2014
Last Seen: September 7, 2023
OS(es) Affected: Windows


Hatchiho is considered to be adware that may state to make the PC user's Internet surfing activity more efficient and save time and money by delivering various offers, discount coupons, deals and sales. Hatchiho may display random pop-up box ads and messages on the computer system including discount coupons, sponsored links, deals and offers depending on the computer user's search queries and online surfing habits. Hatchiho may forcibly divert PC users to unreliable websites that may give computer users various deals and offers. Suspicious websites related to discounts may be produced with the aim to benefit from increased web traffic and clicks on ads. Upon installation, Hatchiho may embed a browser add-on, plug-in or extension into all the Web browsers such as Internet Explorer, Google Chrome and Mozilla Firefox installed on the PC. Hatchiho may spread and enter the computer system through bundled free software that computer users can download from questionable download websites.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{3E2E7CF5-4D58-4920-AB5C-1CA77559923A}{585B992F-0788-4E35-A8B2-BDA09D41ED59}HKEY..\..\..\..{RegistryKeys}SOFTWARE\HatchihoSoftware\Microsoft\Internet Explorer\Approved Extensions\{0569F0DF-CCE6-43E9-AECB-5C5CF431E3B4}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0569F0DF-CCE6-43E9-AECB-5C5CF431E3B4}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0569F0DF-CCE6-43E9-AECB-5C5CF431E3B4}SOFTWARE\Wow6432Node\HatchihoSOFTWARE\Wow6432Node\Microsoft\Tracing\updateHatchiho_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateHatchiho_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilHatchiho_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0569F0DF-CCE6-43E9-AECB-5C5CF431E3B4}SYSTEM\ControlSet001\services\eventlog\Application\Update HatchihoSYSTEM\ControlSet001\services\eventlog\Application\Util HatchihoSYSTEM\ControlSet002\services\eventlog\Application\Update HatchihoSYSTEM\ControlSet002\services\eventlog\Application\Util HatchihoSYSTEM\CurrentControlSet\services\eventlog\Application\Update Hatchiho

Additional Information

The following directories were created:
%PROGRAMFILES%\Hatchiho%PROGRAMFILES(x86)%\Hatchiho%temp%\Hatchiho
The following URL's were detected:
Hatchiho
Loading...