Home Malware Programs Browser Hijackers Fanli90.cn

Fanli90.cn

Posted: January 19, 2017

Threat Metric

Ranking: 17,342
Threat Level: 5/10
Infected PCs: 853
First Seen: January 19, 2017
Last Seen: September 3, 2023
OS(es) Affected: Windows


Fanli90.cn is a website that appears to be harmless since it's homepage only hosts a collection of short jokes and publications that are meant to entertain visitors. The website's name is 'Funny Collection,' and it does not appear to have any other pages which would be used to host additional content. Although it's purpose is to make people smile, some users might not be so happy when they visit Fanli90.cn, because they may end up doing this involuntarily. This is because some portion of the user's that visit Fanli90.cn may be brought there with the help of a browser hijacker – a small program that, once installed, may modify a Web browser's settings and shortcut so that it brings users to Fanli90.cn when they perform certain actions.

The browser hijacked linked to Fanli90.cn may change the Web browser's default homepage to Fanli90.cn. This way, whenever the users launch their Web clients or attempt to load their homepage, they'll be redirected to Fanli90.cn instead of to their usual homepage. This change is undesired and annoying, and it is safe to say that most users would prefer to use a homepage that hosts more relevant content than a collection of jokes. Often, these browser hijackers may be deployed to computers with the help of the installers of 3rd-party programs. However, the case with Fanli90.cn is a bit different, since the authors of this browser hijacker have opted to use a small VBScript that modifies the shortcuts of popular Web browsers so that they'll redirect users to Fanli90.cn. The folder in which the script is placed may vary, and that's why the best way to resolve the issue is to run a reputable anti-virus software suite that should identify and erase the intrusive script. Keep in mind that the shortcuts may need to be restored or recreated manually to reverse the changes that the Fanli90.cn VBScript had applied.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathfanli90[1].xmlhttp_fanli90.cn_0.localstoragehttp_fanli90.cn_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\DOMStorage\fanli90.cnSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\fanli90.cn

Additional Information

The following URL's were detected:
fanli90.cn
Loading...