Duuqu Group OU

Publisher Information

Duuqu Group OU is a software publisher located in Tallinn, Harju in Estonia*. The company is a primary distributor of unwanted software.
Remove Duuqu Group OU Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
8/9/2012 2:00:00 AM

Valid to:
8/10/2014 1:59:59 AM

Subject:
CN=Duuqu Group OU, O=Duuqu Group OU, L=Tallinn, S=Harju, C=EE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
162e253d4cb8942d57dc084a3456ba93

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.DuuquGroupOU.Q, PUP.Startup.DuuquGroupOU.I, PUP.Service.DuuquGroupOU.L, PUP.ChromePlugin.DuuquGroupOU.O, PUP.DuuquGroupOU.N, PUP.DuuquGroupOU.R, PUP.DuuquGroupOU.T, PUP.DuuquGroupOU.O, PUP.DuuquGroupOU.J, PUP.DuuquGroupOU.G, PUP.DuuquGroupOU.U, Threat.Installer.DuuquGroupOU, PUP.DuuquGroupOU (M)
100.00%

Dr.Web
Trojan.DownLoad3.25843
21.05%

Trend Micro House Call
TROJ_GEN.F47V0801
15.79%

Comodo Security
Heur.Suspicious
15.79%

Avira AntiVirus
APPL/Maxiget.P
10.53%

AVG
Generic
10.53%

herdProtect (fuzzy)
a variant of 75dc72a7bac94ad0317ff7f9a90fc13eac3488ed
10.53%

Rising Antivirus
PE:Trojan.GenericKDV!6.B5C
5.26%

AegisLab AV Signature
Troj.W32.Gen
5.26%

1 / 68      (Adware)
qwertybox.dll  (0a5d3f1d70a54b6d45619d5e0ea68e3d)

1 / 68      (Adware)
framefox.exe (FrameFox Extensions by Duuqu Group)  (dedd918c18d31163e2dae134a0538348)

1 / 68      (Adware)
33f467f3.msi  (33613105b8d8a51739488bfd18d8f67f)

1 / 68      (Adware)
setup.exe (Duuqu Update by Duuqu Group)  (eae0f0f1341e13d273a7aa100e9bd911)

5 / 68      (Adware)
framefox_1909-357c9206.exe (Duuqu Update by Duuqu Group)  (f69ab43eb987667d54518527148c5528)

5 / 68      (Adware)
framefoxsetup.exe (Duuqu Update by Duuqu Group)  (41c2b1dd99accd357faadca871c631e0)

1 / 68      (Adware)
duuquupdatehelper.msi  (c13388a1d0eb8a495c7014805ae236ef)

3 / 68      (Adware)
psuser.dll (Duuqu Update by Duuqu Group)  (b8907e95c973db23c21f7671f0fb969c)

3 / 68      (Adware)
psmachine.dll (Duuqu Update by Duuqu Group)  (2e50fafbd4c16bca2e48854777ab1fcc)

1 / 68      (Adware)
goopdateres_ru.dll (Duuqu Update by Duuqu Group)  (68b830d435229543af068e01f0f12472)

1 / 68      (Adware)
goopdateres_en.dll (Duuqu Update by Duuqu Group)  (4c0ba7bdc374eb100679a851c2b8f0bc)

2 / 68      (Adware)
duuquupdateondemand.exe (Duuqu Update by Duuqu Group)  (5791a5362e47198be5a3bd6c93fc06a2)

1 / 68      (Adware)
duuquupdatebroker.exe (Duuqu Update by Duuqu Group)  (b269d0d208241dac3a71501cd7e903b7)

1 / 68      (Adware)
goopdate.dllacc72 (Duuqu Update by Duuqu Group)  (7188f535d480b9bb8b5efac4e61e04a7)

2 / 68      (Adware)
DuuquUpdateSetup.exe (Duuqu Update by Duuqu Group)  (55f0045d54c3425e96335ebeffa29181)

1 / 68      (Adware)
npDuuquUpdate3.dll (Duuqu Update by Duuqu Group)  (bb6dcc53e503fc9e2469da8f046f186a)

2 / 68      (Adware)
DuuquUpdate.exe (Duuqu Update by Duuqu Group)  (136e913b1d3771b3535c3622c36b5e38)

1 / 68      (Adware)
framefox.exe (FrameFox Extensions by Duuqu Group)  (6017ca94be482bcb527d92c6d481b2cc)

4 / 68      (Adware)
DuuquUpdateSetup.exe (Duuqu Update by Duuqu Group)  (cfdfb01c8f4cc858dd098aaea145c5e1)

Downloads URLs for files signed by Duuqu Group OU.

2 / 68      (Adware)
http://secure.fastdlcache.com/.../DuuquUpdateSetup.exe  (55f0045d54c3425e96335ebeffa29181)

2 / 68      (Adware)
http://secured.cdnawbwest.us/.../duuqu.exe  (55f0045d54c3425e96335ebeffa29181)

2 / 68      (Adware)
http://secure.rocketdlgo.com/.../DuuquUpdateSetup.exe  (55f0045d54c3425e96335ebeffa29181)

2 / 68      (Adware)
http://secured.cdnpmmm.us/.../duuqu.exe  (55f0045d54c3425e96335ebeffa29181)

4 / 68      (Adware)
http://cdn3.recentdownload.com/.../FrameFoxSetup.exe  (cfdfb01c8f4cc858dd098aaea145c5e1)

The following websites host and distribute files published by Duuqu Group OU.

The following publishers (by Authenticode signature organization name) are related.

Remove Duuqu Group OU Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Duuqu Group OU by Thawte, Inc. on August 09, 2012 with the serial number '162e253d4cb8942d57dc084a3456ba93'.