PUA

How to remove “PUP.Optional.Hao123”?

Malware Removal

The PUP.Optional.Hao123 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.Hao123 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Attempts to modify Internet Explorer’s start page
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup

Related domains:

ocsp.verisign.com
csc3-2010-crl.verisign.com
dl.client.baidu.com

How to determine PUP.Optional.Hao123?


File Info:

crc32: C919FB1C
md5: 324b775b0fba4b9ecc032f20d450de51
name: hao123inst-thailand-etype.exe
sha1: 8c874d77ed9c506acd76b87532a5bf851c61ab33
sha256: 26d9794bf4e9d647c28764e74afa4546335bf425d705dd32faf57af6f7b8a48e
sha512: 4a781c9794d00288ba7071cce8c5205913dd4b113684b7f94bad650bfbbb48b4412850c33b754ba83288c9ec2829098f518f4c6ff1b81a5cc086771bdb4c02af
ssdeep: 6144:yMOV3HpTrzeBrlhxzeYV3ivAecRVmZmQU2NpGZ50A:bUfze9heyyvmg+2rA
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: (C) 2011 Baidu.comx3002All Rights Reserved.
InternalName: hao123Inst.exe
FileVersion: 1.0.0.1106
CompanyName: Baidu.com
ProductName: hao123 Desktop Shortcut
ProductVersion: 1.0.0.1106
FileDescription: hao123 Desktop Shortcut
OriginalFilename: hao123Inst.exe
Translation: 0x0804 0x03a8

PUP.Optional.Hao123 also known as:

BkavW32.HfsAdware.39A3
McAfeeArtemis!324B775B0FBA
CylanceUnsafe
K7AntiVirusAdware ( 004c43921 )
K7GWAdware ( 004c43921 )
TotalDefenseWin32/PackedBaidu
APEXMalicious
KasperskyTrojan.Win32.StartPage.vhzu
AlibabaTrojan:Win32/StartPage.92b60341
NANO-AntivirusRiskware.Win32.Hao123.djagiv
ViRobotAdware.Hao123.292304
ComodoMalware@#1plhedvf3uwi6
DrWebTrojan.StartPage1.27027
EmsisoftApplication.Optional (A)
JiangminAdWare.Tahao.w
Antiy-AVLTrojan/Win32.BTSGeneric
SUPERAntiSpywarePUP.Hao123/Variant
ZoneAlarmTrojan.Win32.StartPage.vhzu
VBA32BScope.Trojan.StartPage
MalwarebytesPUP.Optional.Hao123
ESET-NOD32a variant of Win32/Hao123.D potentially unwanted
YandexRiskware.Agent!
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Hao123

How to remove PUP.Optional.Hao123?

PUP.Optional.Hao123 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment