Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'ADSL DDiall' = '%WINDIR%\byhunter.exe'
- %WINDIR%\byhunter.exe
- '<SYSTEM32>\cmd.exe' /c cmd.exe /c SCHTASKS /Create /SC ONSTART /TN IipAdressConflict /TR %WINDIR%\byhunter.exe /F
- '<SYSTEM32>\cmd.exe' /c SCHTASKS /Create /SC ONSTART /TN IipAdressConflict /TR %WINDIR%\byhunter.exe /F
- '<SYSTEM32>\schtasks.exe' /Create /SC ONSTART /TN IipAdressConflict /TR %WINDIR%\byhunter.exe /F