Home Malware Programs Browser Hijackers Palikan.com

Palikan.com

Posted: March 13, 2015

Threat Metric

Ranking: 2,241
Threat Level: 5/10
Infected PCs: 169,397
First Seen: March 13, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows


Palikan.com is a low-quality search engine that is associated with the promotion of a Potentially Unwanted Program (PUP) known as the Palikan Browser. The Palikan Browser may claim to be a great utility that can replace any modern Web browser, but we advise users to be careful if they plan to replace their current Web browser with the Palikan Browser. This change isn't recommended, because the Palikan Browser is classified as a Potentially Unwanted Program by reputable anti-virus companies, and the installation of this PUP may worsen your Web browsing experience immediately. The Palikan Browser may prevent you from using your favorite search engine and homepage, because this browser will replace them with Palikan.com automatically, therefore forcing you to use an unpopular search engine whose reliability is questionable. The Palikan Browser may be distributed with the help of unfair marketing tricks such as software bundles that may use misleading installation instructions. These bundles may offer users to install 3rd-party applications like the Palikan Browser by promoting them as useful utilities that can enhance a user's Web browsing experience. Since the Palikan Browser isn't threatening, there's no harm in using it, but our recommendation is to remove the program if it was installed on your computer without your knowledge.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttp_www.palikan.com_0.localstoragepalikan[1].xmlwww.palikan[1].xmlRegexp file mask%USERPROFILE%\AppData\LocalLow\Microsoft\Internet Explorer\Services\Palikan.ico%WINDIR%\System32\Tasks\[RANDOM CHARACTERS]Palikan[RANDOM CHARACTERS]%WINDIR%\System32\Tasks\{3990FBEE-7267-37AA-D9F0-3B866ECCB253}%WINDIR%\Tasks\[RANDOM CHARACTERS]Palikan[RANDOM CHARACTERS].jobHKEY..\..\..\..{RegistryKeys}Software\go_palikanSoftware\Microsoft\Internet Explorer\DOMStorage\palikan.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.palikan.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\palikan.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.palikan.comSoftware\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Go_Palikan.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Go_Palikan.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Go_PalikanSoftware\Microsoft\Windows\CurrentVersion\RunOnce\PalikanSoftware\palikanHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Go_PalikanPalikan{48DDA01D-185D-719D-A9DD-011D795DD29D}

Additional Information

The following directories were created:
%AppData%\Palikan%LOCALAPPDATA%\Palikan
The following URL's were detected:
Palikan NewPalikan~
Loading...