Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'AVPMY' = '<SYSTEM32>\AVPMY.exe'
- ClassName: 'AVP.AlertDialog', WindowName: ''
- ClassName: 'AVP.Product_Notification', WindowName: ''
- ClassName: 'AVP.TrafficMonConnectionTerm', WindowName: ''
- %WINDIR%\syswow64\avpmy.exe
- %WINDIR%\syswow64\avpmy.exe
- ClassName: '#32770' WindowName: 'ÈðÐÇ×¢²á±ГВјГ ВїГГЊГЎГЉВѕ'
- ClassName: '#32770' WindowName: 'IE Ö´Ðб£»¤'
- ClassName: '#32770' WindowName: 'ÈðÐÇ¿¨¿¨ÉÏÍø°²È«ÖúÊÖ - IE·À©ǽ'
- '%WINDIR%\syswow64\avpmy.exe'
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del "%WINDIR%\SysWOW64\AVPMY.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file>"
- '%WINDIR%\syswow64\cmd.exe' /c del "%WINDIR%\SysWOW64\AVPMY.exe"