This Trojan must be manually installed.
When the Trojan is executed, it creates the following files:
- %UserProfile%\Start Menu\Programs\Startup\ctfmon.lnk
- %UserProfile%\Application Data\nur-xcp-sabb.pad
It also drops a clean version of %System%\rundll32.dll to the following location:
%UserProfile%\Application Data\lsass.exe
Next, the Trojan creates the following registry entry:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"NoProtectedModeBanner" = "1"
The Trojan then creates the following registry entries in order to lower the ratings for certain zones on the compromised computer, thereby increasing the chance to establish a remote connection:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\"2500" = "3"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"2500" = "3"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\"2500" = "3"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\"2500" = "3"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\"2500" = "3"
It also modifies the following registry entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\"1609" = "0"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\"1609" = "0"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\"1609" = "0"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\"1609" = "0"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\"1609" = "0"
Next, the Trojan locks the computer and displays a fraudulent message on the screen informing the user that they are in breach of copyright law and requests a money transfer of $200 to a MoneyPak account.

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":