Adware

Should I remove “Signed-Adware.Hao123.BaiduChinaCo”?

Malware Removal

The Signed-Adware.Hao123.BaiduChinaCo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Signed-Adware.Hao123.BaiduChinaCo virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
p.x.baidu.com
a.tomx.xyz

How to determine Signed-Adware.Hao123.BaiduChinaCo?


File Info:

crc32: AE712676
md5: 885eb0910c1f5a31ac3d6bebcf5bff58
name: xdagxk_70127.exe
sha1: 401be01c41d4c2a35dcb1840110414f1ed6a0016
sha256: 6010097f7e59dde7760fa281ce79a32ea767fe4ba334eb0f17925f95b171a218
sha512: 556cf0804b9c9e5a92e6831972a182ff0fedbc2bae404ed68502f02fa45ce5e12bfdc46519d379caa82b2ca21f6a57ad50c66804c91856bbdc687b0027c18c51
ssdeep: 49152:gBJcpI0UHYT7/au9iqx4VfaPj8XocsDVl:2JcpSHczR9h1Pj8Yf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 1.0.148.622
CompanyName:
LegalTrademarks:
ProductName:
ProductVersion: 1.0.148.622
FileDescription:
Translation: 0x0804 0x03a8

Signed-Adware.Hao123.BaiduChinaCo also known as:

VBA32Signed-Adware.Hao123.BaiduChinaCo

How to remove Signed-Adware.Hao123.BaiduChinaCo?

Signed-Adware.Hao123.BaiduChinaCo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment