When the Trojan is executed, it copies itself as the following file:
%System%\usrinit.exe
The Trojan modifies the following registry entry, so that it starts whenever Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "%System%\userinit.exe, %System%\usrinit.exe"
The Trojan attempts to lock the desktop making the computer unusable. It displays a gray background with the following message:
Translated from Russian:
Windows Blocked
For unlocking you need to
Send Text:#win1 t5680
To the number: 6008
The cost of communications is about 60 EUR.
In reply message you get a registration code, which should be put in the box.
To activate your copy of Microsoft Windows you have 3 hours from the time of the lock
Otherwise, the system with your computer will automatically be deleted, and all
data on it destroyed. Attempting to reinstall the system can lead to data loss.
It also disables Task Manager by ending the program whenever it is launched.
The key to disable the threat is 5748839. This key is hard-coded into the Trojan.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":