HAO.EXE – Trojan SuspiciousFile

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

HAO.EXE – Trojan SuspiciousFile removal

FileMD5Virus Alias
HAO.EXE 2170635291da73a000b25aefa74ccfa5 Trojan SuspiciousFile
HAO.EXE 2170635291da73a000b25aefa74ccfa5 Trojan Generic
HAO.EXE 2170635291da73a000b25aefa74ccfa5 Trojan Downloader

HAO.EXE size: 727575 bytes
HAO.EXE hash: 2170635291DA73A000B25AEFA74CCFA5

Created files:

%UserProfile%\My Documents\csrss\csrss.exe
%TEMP%\IXP000.TMP\hao.exe
%AppData%\Microsoft\Crypto\RSA\S-1-5-21-515967899-854245398-1708537768-1003\699c4b9cdebca7aaea5193cae8a50098_78de4566-a5cc-4192-bf8d-014e0d2bd235

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit: %WinDir%\System32\userinit.exe,%WinDir%\System32\config\Systemprofile\My Documents\csrss\csrss.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\csrss: %WinDir%\System32\config\Systemprofile\My Documents\csrss\csrss.exe

Detected by UnHackMe:

HAO.EXE
Default location: %TEMP%\IXP000.TMP\HAO.EXE

Dropper information:
MD5: 1a17e4f8bec3bed8e43d275df9690954
File size: 1109504 bytes

Leave a Reply