Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Microsoft xiufu] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Microsoft xiufu] 'ImagePath' = '<Full path to file>'
- 'ja#####yjx.f3322.net':2018
- DNS ASK ja#####yjx.f3322.net
- '<Full path to file>'