When the Trojan is executed, it creates the following registry entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = "[CURRENT DIRECTORY]/[TROJAN]"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\"CleanShutdown" = "0"
The Trojan also creates the following registry entry so that it runs every time Windows starts:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "[CURRENT DIRECTORY]/[TROJAN]"
The Trojan then locks the desktop making the computer unusable.
Note: The image requests the user to text +79874418224, a Russian mobile number, for an unlock code.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":