Home Malware Programs Browser Hijackers Duba.com

Duba.com

Posted: September 8, 2015

Threat Metric

Ranking: 1,362
Threat Level: 5/10
Infected PCs: 148,229
First Seen: September 8, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows


Duba.com is a Chinese search engine whose homepage also accommodates a large number of links that may lead users to news sites, social media pages, and other 3rd-party Web destinations that are considered to be safe and reliable. However, although Duba.com isn't associated with harmful activities, this page isn't faultless, and malware researchers have identified a browser hijacker whose sole purpose is to inject Duba.com in the configuration of the affected Web browser. The Duba.com browser hijacker isn't threatening, but users who install it may accept to allow this hijacker to modify their Web browser's settings unknowingly. The browser hijacker may then remove the user's current homepage, search engine, and new tab page and replace them with Duba.com. This is a simple technique that may be used to generate traffic and popularize low-quality websites like Duba.com. While these actions aren't threatening, they may have a negative impact on your Web browsing experience, and that's why we advise all users affected by the Duba.com browser hijacker to take action and eliminate this issue. The best way to deal with the Duba.com hijacker is to use an up-to-date and reliable anti-malware scanner that can help you remove all traces of the browser hijacker from your computer.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{30CCE6D9-A7B6-4020-B5DF-1C33CC41D8F2}{DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\DOMStorage\duba.comSOFTWARE\Microsoft\Internet Explorer\DOMStorage\hotnews.duba.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\duba.comSOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51}

Additional Information

The following URL's were detected:
https://www.duba.com/
Loading...