Technical Information
- <SYSTEM32>\tasks\trojan remover
- %ALLUSERSPROFILE%\loaris\trojan remover\database\vs.c
- <SYSTEM32>\tasks\trojan remover
- 'oc##.thawte.com':80
- http://lo##is.com/check_ver.php?ve########
- http://lo##is.com/upd.php?ve###########################################
- http://lo##is.com/updates/upd10F.c
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- http://s1.##aris.com/?fo#########
- http://bi##.loaris.com/stats/?p=#############
- http://s1.##aris.com/?fo##############
- DNS ASK s1.##aris.com
- DNS ASK lo##is.com
- DNS ASK bi##.loaris.com
- DNS ASK microsoft.com
- DNS ASK oc##.thawte.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''