At the moment its not perticularly advanced and is easily removed, but will probably advance as time goes on just like they all do. All it appears to do is run internet explorer full screen with no navigation bars etc, divert you to a web address were they capture your details, disable task manager and windows explorer.

To remove just boot to safe mode of which seems to function as normal, load up ms config and strip the startup items which stops the file from running and reboot, the file is locate in a hidden folder located at c:\users\your user name\appdata\local\temp. Just delete the file once the computer has rebooted (no need for safe mode now). You will need to enable the viewing of hidden folders. Once removed i would do a few scans with AV software to check rest of the machine and clear all internet temp files, cookies etc.
I will post up tomorrow the file names that you will be looking for as i have them scribbled on a scrap piece of paper on my clip board at work, they may differ but will at least give you an idea of what you are looking for.
Although the grammer is not excellent at first glance its beleivable to those that do not understand this stuff, with 90% of people at some point having had counterfeit software put on their computer or browsed web sites they probably shouldnt have, and at a supposide fine of £100 is probably considered not to be exstortionate and rather reasonable as pointed out by colleagues at work.




