Home Malware Programs Adware Fanhoosh

Fanhoosh

Posted: October 4, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 457
First Seen: October 4, 2013
Last Seen: October 1, 2022
OS(es) Affected: Windows

Fanhoosh Screenshot 1Fanhoosh is an adware that may display pop-up advertisements, coupons and sponsored links via a pop-up box on well-known online shopping websites that Internet users are visiting. Fanhoosh pop-up advertisements may be displayed as boxes, which carry numerous coupons that are available or as underlined keywords, which when clicked will show a pop-up advertisement that claims it is sent to the web by Fanhoosh. Fanhoosh is an extension for Internet Explorer, Mozilla Firefox and Google Chrome that is usually embedded when web users install other free programs, such as video recording/streaming, download-managers or PDF creators, that might had packed into their installation Fanhoosh. When PC users install these free software products, they may also install Fanhoosh. When installed, whenever the computer user will visit any popular online shopping or social networking website, Fanhoosh may display a 'See Similar' button on product images, which when clicked may display pop-up ads by Fanhoosh. Fanhoosh may also show advertising banners on the websites that PC users are visiting, and as they browse the web, Fanhoosh may display coupons and other deals available on a number of websites.

Fanhoosh Screenshot 2

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{8ef0781e-bf1a-4c9d-8315-c1cc1f148add}{E5A81F98-0AE1-42E4-BC62-FD6F5AF535CC}HKEY..\..\..\..{RegistryKeys}Software\fanhooshSoftware\Microsoft\Internet Explorer\Approved Extensions\{8EF0781E-BF1A-4C9D-8315-C1CC1F148ADD}SOFTWARE\Microsoft\Tracing\updatefanhoosh_RASAPI32SOFTWARE\Microsoft\Tracing\updatefanhoosh_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{8EF0781E-BF1A-4C9D-8315-C1CC1F148ADD}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8EF0781E-BF1A-4C9D-8315-C1CC1F148ADD}SOFTWARE\Wow6432Node\fanhooshSOFTWARE\Wow6432Node\Microsoft\Tracing\updatefanhoosh_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatefanhoosh_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8ef0781e-bf1a-4c9d-8315-c1cc1f148add}SYSTEM\ControlSet001\services\eventlog\Application\Update fanhooshSYSTEM\ControlSet001\services\Update fanhooshSYSTEM\ControlSet002\services\eventlog\Application\Update fanhooshSYSTEM\ControlSet002\services\Update fanhooshSYSTEM\CurrentControlSet\services\eventlog\Application\Update fanhooshSYSTEM\CurrentControlSet\services\Update fanhoosh

Additional Information

The following directories were created:
%ProgramFiles%\fanhoosh%ProgramFiles(x86)%\fanhoosh
The following URL's were detected:
fanhoosh
Loading...