HahoMedia

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 16,014
Threat Level: 20 % (Normal)
Infected Computers: 2,384
First Seen: September 3, 2014
Last Seen: December 28, 2025
OS(es) Affected: Windows

HahoMedia or Haho Media, is an adware application that may display several ads on your screen when you are attempting to surf the internet. The Hahomedia ads may be displayed as pop-ups, pop-unders or banners where they all attempt to offer various services or add-on components for your web browser. Some of those components are known to be media add-ons that claim to add functions for your computer in viewing media content over the internet. Use of the Hahomedia ads may cause redirects within your web browser landing you on sites that have questionable content or prove to be unwanted. In the task of stopping the Hahomedia ads from displaying, most computer users will find refuge in finding and removing each of the components related to Hahomedia loaded on their system.

SpyHunter Detects & Remove HahoMedia

File System Details

HahoMedia may create the following file(s):
# File Name MD5 Detections
1. VersionUpdaterService.exe 211eb4b123b7d8b8c621833864d06156 586
2. InjectorServiceProject.exe c6680e3c3cd5bb45a623ffeaac927c0d 535
3. Injector.exe 14477e1a023d5ff440f7043b00651235 210
4. license.exe 24a657d8c999849768b3d83936c5e323 16
5. DELA80F.tmp bf4c6bdc4a5d59c52225922337b854ce 14

Registry Details

HahoMedia may create the following registry entry or registry entries:
Regexp file mask
%WINDIR%\system32\policies\161011\policies.exe
%WINDIR%\syswow64\policies\161011\policies.exe
SOFTWARE\Classes\Installer\Dependencies\{87aec404-40de-4732-86ab-e9861ca5d01b}
SOFTWARE\Classes\Installer\Dependencies\{A36D9B44-D57A-4DC0-9D58-EEEC9757846F}
SOFTWARE\Hahomedia
SOFTWARE\Wow6432Node\Hahomedia
{746390A3-6C32-4253-ADDF-8F235AE19E7A}_is1
{87aec404-40de-4732-86ab-e9861ca5d01b}

Directories

HahoMedia may create the following directory or directories:

%ALLUSERSPROFILE%\Package Cache\{87aec404-40de-4732-86ab-e9861ca5d01b}
%PROGRAMFILES%\Hahomedia
%PROGRAMFILES(x86)%\Hahomedia

Analysis Report

General information

Family Name: Adware.HahoMedia
Signature status: Root Not Trusted

Known Samples

MD5: 7e485a2f5a762f9174581e97b8e7be3c
SHA1: 0315428bf2c4896cf633134103bdb1899b1851fb
SHA256: 018BA689E239A0BBBB3EDF93685781A5260675C49E4A21C03B1604BCAD0EE5C4
File Size: 661.98 KB, 661976 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name http://quickalarmclock.com/
File Description WinRarPasswordRemoverSetup Setup
File Version 1.0.0.0
Legal Copyright Copyright © FVDTube.
Product Name WinRarPasswordRemoverSetup
Product Version 1.1

Digital Signatures

Signer Root Status
ved priy pandey COMODO RSA Certification Authority Root Not Trusted

Trending

Most Viewed

Loading...