Download Dr.Web. Download by serial number If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow. Owner of serial number or license key file of Dr.Web for Windows also entitles to free Dr.Web anti-virus for Windows Mobile. The free Dr.Web license key file serial number giveaway is only limited to 5000 key, so do grab fast. Each account and each IP address only entitles to one, of course, there are plenty of workaround to this restriction.
Technical Information
- [<HKLM>SOFTWAREMicrosoftWindowsCurrentVersionRun] 'MKeuf' = '%WINDIR%spoolsv.exe'
- [<HKCU>SoftwareMicrosoftWindowsCurrentVersionRun] 'MKeuf' = '%WINDIR%spoolsv.exe'
- [<HKLM>SOFTWAREMicrosoftWindowsCurrentVersionRun] 'HNUGROXRnyc' = '%TEMP%csrss.exe'
- [<HKCU>SoftwareMicrosoftWindowsCurrentVersionRun] 'HNUGROXRmSc' = '%TEMP%avp32.exe'
- [<HKLM>SOFTWAREMicrosoftWindowsCurrentVersionRun] 'HNUGROXRnQc' = '%TEMP%fe8s2.exe'
- [<HKCU>SoftwareMicrosoftWindowsCurrentVersionRun] 'HNUGROXRnQc' = '%TEMP%fe8s2.exe'
- [<HKLM>SOFTWAREMicrosoftWindowsCurrentVersionRun] 'HNUGROXRmSc' = '%TEMP%avp32.exe'
- [<HKCU>SoftwareMicrosoftWindowsCurrentVersionRun] 'HNUGROXRnyc' = '%TEMP%csrss.exe'
- [<HKLM>SOFTWAREMicrosoftWindowsCurrentVersionRun] 'MKcZ' = '%WINDIR%mdm.exe'
- [<HKCU>SoftwareMicrosoftWindowsCurrentVersionRun] 'MKcZ' = '%WINDIR%mdm.exe'
- [<HKLM>SOFTWAREMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler] '{D2A123C3-A500-90BD-A820-04B53A2C8952}' = 'u3f5yhfghd5seuyhfj3jrih'
- [<HKCU>SoftwareMicrosoftWindowsCurrentVersionRun] 'MKexe' = '%WINDIR%system.exe'
- [<HKLM>SOFTWAREMicrosoftWindowsCurrentVersionRun] 'HNUGROXRpZ' = '%TEMP%mdm.exe'
- [<HKCU>SoftwareMicrosoftWindowsCurrentVersionRun] 'HNUGROXRpZ' = '%TEMP%mdm.exe'
- [<HKLM>SOFTWAREMicrosoftWindowsCurrentVersionRun] 'MKexe' = '%WINDIR%system.exe'
To complicate detection of its presence in the operating system,
- hidden files
- file extensions
blocks execution of the following system utilities:
blocks the following features:
Creates and executes the following:
- %WINDIR%spoolsv.exe
- %WINDIR%hexdump.exe
- %WINDIR%wininst.exe
- %WINDIR%drweb.exe
- %WINDIR%mdm.exe
- %WINDIR%system.exe
- %WINDIR%win16.exe
- <SYSTEM32>cmd.exe /c '<Current directory>p2hhr.bat' '<Full path to virus>'
- <SYSTEM32>regsvr32.exe /s <SYSTEM32>ozc0x.dll
- [<HKCU>SoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer] 'NoFolderOptions' = '00000001'
- [<HKCU>SoftwareMicrosoftWindowsCurrentVersionInternet Settings] 'ProxyServer' = '
- %WINDIR%spoolsv.exe
- %TEMP%user.exe
- %TEMP%spoolsv.exe
- %TEMP%csrss.exe
- %TEMP%services.exe
- %HOMEPATH%Local SettingsTemporary Internet FilesContent.IE50D6B6PI5dm[1].php
- <Current directory>p2hhr.bat
- %WINDIR%hexdump.exe
- %WINDIR%wininst.exe
- %WINDIR%drweb.exe
- %TEMP%hfpup2suh.exe
- %WINDIR%mdm.exe
- <SYSTEM32>ozc0x.dll
- %TEMP%fe8s2.exe
- %WINDIR%system.exe
- %TEMP%msmgm.exe
- %TEMP%avp32.exe
- %WINDIR%win16.exe
- %TEMP%mdm.exe
Sets the 'hidden' attribute to the following files:
- %WINDIR%spoolsv.exe
- %TEMP%csrss.exe
- %TEMP%spoolsv.exe
- %TEMP%user.exe
- %WINDIR%wininst.exe
- %WINDIR%hexdump.exe
- %TEMP%services.exe
- %WINDIR%win16.exe
- %WINDIR%system.exe
- %WINDIR%mdm.exe
- %TEMP%mdm.exe
- %WINDIR%drweb.exe
- %TEMP%avp32.exe
- %TEMP%msmgm.exe
- co###drun.com/dw/dm.php?id############################################################
Dr Web Serial Number 2020
- ClassName: 'Indicator' WindowName: '