Posted: November 19, 2014

HDQ by Winston Project is promoted as a valuable addition to your video software. HDQ is a browser extension created with the Crossrider platform. HDQ may deliver what it promises, but it will do so along with the constant display of pop-ups, pop-unders and banners. This functionality classifies HDQ as a Potentially Unwanted Program (PUP). In most cases, it is delivered to computer users via freeware bundles, and it is available as a stand-alone installer too. HDQ aggressive advertisement techniques may not be to your liking. HDQ may gather non-personally identifiable information to facilitate better product placement. Users might want to remove HDQ with a trusted anti-spyware tool.

Technical Details

File System Modifications

The following files were created in the system:

%PROGRAMFILES(x86)%\hdqPlayer\hdqPlayerUpdaterService.exe File name: hdqPlayerUpdaterService.exe
Size: 11.77 KB (11776 bytes)
MD5: 26d539208663898e2626357bf7b2b554
Detection count: 69
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\hdqPlayer
Group: Malware file
Last Updated: July 15, 2015

Registry Modifications

The following newly produced Registry Values are:

File name without pathhdqPlayer.lnkwww.hdqplayer[1].xmlRegexp file mask%WINDIR%\System32\Tasks\HDQPlayer UpdaterHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Applications\hdqPlayer.exeSOFTWARE\hdqPlayerSOFTWARE\Microsoft\Tracing\hdqPlayer_RASAPI32SOFTWARE\Microsoft\Tracing\hdqPlayer_RASMANCSHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}hdqPlayer

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\hdqPlayer%LOCALAPPDATA%\hdqplayer%PROGRAMFILES%\hdqPlayer

