Technical Information
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\local.bin
- '<LOCALNET>.6.71':4562
- DNS ASK qk##aym.cn
- ClassName: '' WindowName: ''
- ClassName: 'CTXOPConntion_Class' WindowName: ''
- '%WINDIR%\syswow64\svchost.exe' -k LocalServiceNetworkRestricted