Duuqu is a software usually installs without your knowledge vith the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 07/11/2013.


– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– Vendor : PUP.Optional


– It installs a plugin of the browser Google Chrome (G2)
– It installs a program of extension for browser Mozilla Firefox (M2)
– It installs a plugin of the browser Mozilla Firefox (P2)
– It changes the IP addresses of the file Hosts (O1),
– It installs as a process launched at startup of the system (RP),
– It starts a task planned in automatic (O39),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45).


P2 – FPN: [HKLM] [@www.duuqu.com/omaha/tools//Duuqu Update;version=3] – (.Duuqu Group – Duuqu Update.) — C:\Program Files\Duuqu\Update\\npDuuquUpdate3.dll
O1 – Hosts: 127.0. 0.1 www.duuqu.com
O23 – Service: Duuqu Update Service (dqupdate) (dqupdate) . (.Duuqu Group – Duuqu Installer.) – C:\Program Files\Duuqu\Update\DuuquUpdate.exe
O39 – APT:Automatic Planified Task – C:\Windows\Tasks\DuuquUpdateTaskMachineCore.job [878]
O39 – APT:Automatic Planified Task – C:\Windows\Tasks\DuuquUpdateTaskMachineUA.job [882]
[MD5.136E913B1D3771B3535C3622C36B5E38] [APT] [DuuquUpdateTaskMachineCore] (.Duuqu Group.) — C:\Program Files\Duuqu\Update\DuuquUpdate.exe [98360]
[MD5.136E913B1D3771B3535C3622C36B5E38] [APT] [DuuquUpdateTaskMachineUA] (.Duuqu Group.) — C:\Program Files\Duuqu\Update\DuuquUpdate.exe [98360]
O42 – Logiciel: Duuqu Update Helper – (.Duuqu Group.) [HKLM] — {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O43 – CFD: 26/11/2013 – 13:45:16 – [2,156] —-D C:\Program Files\Duuqu
O43 – CFD: 26/11/2013 – 13:45:16 – [0] —-D C:\Users\Coolman\AppData\Local\Duuqu
O45 – LFCP:[MD5.2DE360104A2DE0C69115753A5CD9BB85] – 27/11/2013 – 13:50:01 —A- – C:\Windows\Prefetch\DUUQUCRASHHANDLER.EXE-6DB52CCB.pf
O45 – LFCP:[MD5.6D0BD6C70002299A027FF597C25FBA52] – 06/12/2013 – 21:52:00 —A- – C:\Windows\Prefetch\DUUQUUPDATE.EXE-AAA01EF3.pf
SS – | Auto 26/11/2013 98360 | (dqupdate) . (.Duuqu Group.) – C:\Program Files\Duuqu\Update\DuuquUpdate.exe
SS – | Demand 26/11/2013 98360 | (dqupdatem) . (.Duuqu Group.) – C:\Program Files\Duuqu\Update\DuuquUpdate.exe
[MD5.6C550D2274DA0250A2CF19C36D87D29C] [WIS][19/08/2013] (.Duuqu Group – Duuqu Update Helper.) — C:\Windows\Installer\4944c9.msi [22016]
C:\Program Files (x86)\Duuqu
C:\Program Files\Duuqu
C:\Program Files\Duuqu\Update\DuuquUpdate.exe
[HKCR\CLSID\{024BA55C-DA05-4FA5-AD24-5EA6D3C7C153}] (DuuquUpdate Update3Web)
[HKCR\CLSID\{486E4A9A-50F4-4DA4-9F50-363FC9F72939}] (Duuqu Update Core Class)
[HKCR\CLSID\{7D79AC47-48F6-40F8-BA34-17677EAEA37C}] (Duuqu.OneClickProcessLauncher)
[HKCR\CLSID\{9EBB6A38-FB41-458F-AC93-B5B4AEEE2C41}] (Duuqu Update Broker Class Factory)
[HKCR\CLSID\{B03E3833-2BAE-439D-A3E6-1AC654BECEDB}] (DuuquUpdate Update3Web)
[HKCR\CLSID\{B6E89C52-A6C8-4839-A5D1-28A7A5EA46D9}] (Duuqu Update Core Class)
[HKCR\CLSID\{B8669E7E-2C40-42DC-8BA0-314D860F5200}] (Duuqu Update Legacy On Demand)
[HKCR\CLSID\{D4B7651E-076D-4BB2-A021-26F6E7A59A48}] (DuuquUpdate CredentialDialog)
[HKCR\CLSID\{D7BEC320-B746-4A47-B289-509214980E2B}] (Duuqu Update Legacy On Demand)
[HKCR\CLSID\{E555444B-4EA6-4B30-A314-49C2D1BE413D}] (Duuqu Update Process Launcher Class)
[HKCR\CLSID\{EF0AC81C-F34C-4B2E-B85D-91E4DB1E3E9D}] (Duuqu Update Broker Class Factory)


PUP.Optional.Duuqu.A [ Malwarebytes Antimalware ]


– Remove software in Windows Configuration Panel,
Remove with ZHPcleaner
Diagnose with ZHPDiag