Technical Information
- [<HKLM>\System\CurrentControlSet\Services\uMcg_x64] 'ImagePath' = '%TEMP%\DKVtUv.sys'
- 'uMcg_x64' %TEMP%\DKVtUv.sys
- %TEMP%\dkvtuv.sys
- %TEMP%\dkvtuv.sys
- %TEMP%\dkvtuv.sys
- 'go##2.vip':80
- '23##.com':80
- '23##.com':443
- 'cr#.#igicert.cn':80
- 'oc##.#igicert.cn':80
- 'microsoft.com':80
- http://www.go##2.vip/usamsg.txt
- http://www.go##2.vip/usaweb.txt
- http://oc##.#igicert.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQhnxEBNL9LgIhfSsTcHsrTt204QgQURNnISjOO01KNp5KUYR%2BayKW37MsCEAmXA3BU1Hq4%2BXERYZqPmak%3D
- http://cr#.#igicert.cn/DigiCertSecureSiteCNCAG3.crl
- DNS ASK go##2.vip
- DNS ASK 23##.com
- DNS ASK cr#.#igicert.cn
- DNS ASK oc##.#igicert.cn
- DNS ASK microsoft.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''