Home Malware Programs Browser Hijackers Ooov.net

Ooov.net

Posted: November 24, 2014

Ooov.net is a domain that currently is used to redirect all visitors to a Russian gaming website. Because Ooov.net has a substantial history of being involved in browser hijackings and recently was confirmed to host contact associated with threatening domains, unprotected contact with Ooov.net should be avoided whenever possible. Anti-malware scanners and associated security tools should be used to deal with all redirects to Ooov.net or any other browser misbehavior related to Ooov.net, as per usual for any potentially threatening site.

Ooov.net: a New Look for Windows Startup

Although domains that redirect to corrupted ones are a common sight on the Web, the majority load while you're already using your browser. Ooov.net has become part of a recent campaign to take that choice of the PC user's hands, with browser hijacking threats using standard exploits to force Ooov.net to load. The symptoms between recent attacks, dated late this year, may be consistent:

  • Threatening software launches the Windows Command Prompt, CMD.exe, when Windows starts. While different methods of doing so are viable, malware experts currently suspect that the attack in question is a modification of the Windows Registry.
  • A preset command forces Ooov.net to launch. Because this command uses a general Windows utility, rather than browser-specific formats (such as a BHO for Internet Explorer), Ooov.net may affect whatever your default Windows browser may be. Your browser's settings may have no effect on this attack.
  • Your browser redirects from Ooov.net to Gamezdoka.org, a Russian gaming website. However, along the way, their browsers also may load content from other domains that Oov.net has been confirmed to contact. These domains may include various sites known for threatening content.
  • The overall structure of these attacks and the domains related to them make it likely that these attacks are targeting Russian and European PC owners. However, as of late November 2014, some PC users in other regions also have been affected.

Keeping Ooov.net Hijacks from Spelling Game over for Your PC

As of malware researchers' last reports, Ooov.net and gamezdoka.org don't directly host any unsafe content. However, they have been verified for referencing threatening domains that may use them to harm your computer. Blocking scripts, using strong browser settings and having active anti-malware programs can keep potential harm to come to your computer through Ooov.net. After any contact with this site (or other sites with toxic content connections), scan your computer to identify any threats that may have been installed through Ooov.net and remove the threat responsible for the actual hijacking.

Although the Ooov.net browser hijacker campaign is a recent one, other browser hijackers have been in circulation for years. Most of these threats are distributed in freeware bundles or with browser add-ons, but others, such as those responsible for Ooov.net attacks, are modifications made by Trojans. The latter, while less visible than toolbars, are undeniably more of a threat to your PC than a Potentially Unwanted Program ever could be.

Loading...