Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '*CryptoLocker' = '"<LS_APPDATA>\Fpivibovqxopnnv.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'CryptoLocker' = '"<LS_APPDATA>\Fpivibovqxopnnv.exe"'
- '<LS_APPDATA>\Fpivibovqxopnnv.exe' -wbc
- '<LS_APPDATA>\Fpivibovqxopnnv.exe' "-r<Full path to virus>"
- %TEMP%\GUV6C13.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\home[1].htm
- %TEMP%\PRK8A9B.tmp
- %TEMP%\QNQCB8F.tmp
- <LS_APPDATA>\Fpivibovqxopnnv.exe
- <LS_APPDATA>\Fpivibovqxopnnv.exe
- %TEMP%\GUV6C13.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\home[1].htm
- %TEMP%\QNQCB8F.tmp
- %TEMP%\PRK8A9B.tmp
- 'tm####kxkkmiiew.com':80
- 'ts#####vyvvhyvc.info':80
- 'uk####olxjvtici.net':80
- 'ue####jdyhibptu.ru':80
- 'hr####teweephfm.biz':80
- 'xd####kbqmycgae.biz':80
- 'wf####gndnpqpef.net':80
- 'xw####sdcbpdiit.ru':80
- 'su#####ilwmvihy.co.uk':80
- 'yu####wqpayoinb.org':80
- 'jm####gathjojps.org':80
- 'ql####mcargnpso.org':80
- 'pn####yixyhtpqo.ru':80
- 'ri#####eucmsrpm.co.uk':80
- 'ld####qdgieyiqr.com':80
- 'sg#####xwulmifu.info':80
- 'dh#####yfnbulyi.info':80
- 'wy#####yvknaius.co.uk':80
- 'qt####bxhqfgtgu.com':80
- 'so####ntetkftgj.biz':80
- 'fc####xucqgtuif.net':80
- 'yd####lbwynpqxp.com':80
- 'pk#####kgvmxvon.info':80
- 'yp#####qftcdaay.co.uk':80
- 'qg####hexdurvjr.com':80
- 'sb####mtrsiavba.biz':80
- 'rf####yaalagfsn.net':80
- 'bg####fvykoghwf.net':80
- 'cv####rfprixtf.com':80
- 'jk####nctimfyxa.biz':80
- 'lf####srnxanbuy.org':80
- 'wu####dbleouhmi.ru':80
- 'nt####wfmfauhwn.ru':80
- 'dn####tgopqkfpp.ru':80
- 'pb####nkbgwqwuq.biz':80
- 'ky####spkctjicg.org':80
- 'lq#####fjptvikm.info':80
- 'xl#####lxlndhdr.co.uk':80
- 'po#####ugundjie.co.uk':80
- 'op####kyemiohyn.org':80
- 'qk#####oxcvwaxm.info':80
- 'cv####hqpcqxdnb.net':80
- 'oj####bucsweeft.com':80
- DNS ASK uk####olxjvtici.net
- DNS ASK tm####kxkkmiiew.com
- DNS ASK hr####teweephfm.biz
- DNS ASK jm####gathjojps.org
- DNS ASK ue####jdyhibptu.ru
- DNS ASK ts#####vyvvhyvc.info
- DNS ASK xd####kbqmycgae.biz
- DNS ASK wf####gndnpqpef.net
- DNS ASK xw####sdcbpdiit.ru
- DNS ASK su#####ilwmvihy.co.uk
- DNS ASK yu####wqpayoinb.org
- DNS ASK ri#####eucmsrpm.co.uk
- DNS ASK ql####mcargnpso.org
- DNS ASK sg#####xwulmifu.info
- DNS ASK mb####ewibdsilv.net
- DNS ASK ld####qdgieyiqr.com
- DNS ASK pn####yixyhtpqo.ru
- DNS ASK dh#####yfnbulyi.info
- DNS ASK wy#####yvknaius.co.uk
- DNS ASK qt####bxhqfgtgu.com
- DNS ASK so####ntetkftgj.biz
- DNS ASK fc####xucqgtuif.net
- DNS ASK qg####hexdurvjr.com
- DNS ASK pk#####kgvmxvon.info
- DNS ASK rf####yaalagfsn.net
- DNS ASK nt####wfmfauhwn.ru
- DNS ASK sb####mtrsiavba.biz
- DNS ASK yp#####qftcdaay.co.uk
- DNS ASK bg####fvykoghwf.net
- DNS ASK cv####rfprixtf.com
- DNS ASK jk####nctimfyxa.biz
- DNS ASK lf####srnxanbuy.org
- DNS ASK wu####dbleouhmi.ru
- DNS ASK ky####spkctjicg.org
- DNS ASK dn####tgopqkfpp.ru
- DNS ASK xl#####lxlndhdr.co.uk
- DNS ASK yd####lbwynpqxp.com
- DNS ASK lq#####fjptvikm.info
- DNS ASK pb####nkbgwqwuq.biz
- DNS ASK po#####ugundjie.co.uk
- DNS ASK op####kyemiohyn.org
- DNS ASK qk#####oxcvwaxm.info
- DNS ASK cv####hqpcqxdnb.net
- DNS ASK oj####bucsweeft.com
- ClassName: 'Indicator' WindowName: '(null)'