The Trojan constantly searches for windows where the title contains the following strings:
OICQ QQ
If it detects such windows, it will scan them for text and password entry fields, and harvests information entered.
Harvested data is saved to a log file called robber.dll, which is located in the same folder as the Trojan. This file will be sent to the address specified by the remote malicious user.
The Trojan is configured using a Trojan spy construction program.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Use Task Manager to terminate the Trojan process.
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
- Delete the following files:
%System%\robber1.exe %System%\robber.dll
- Delete the following system registry key parameter:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Robber" = "%System%\robber1.exe" - Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).
This Trojan is designed to steal user passwords. It is a Windows PE EXE file. It is 70,144 bytes in size.
InstallationWhen launched, the Trojan copies its executable file to the Windows system directory:
%System%\robber1.exe
The Trojan also adds a link to its executable file in the system registry, ensuring that the Trojan will be launched when Windows is rebooted on the victim machine:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Robber" = "%System%\robber1.exe"
This ensures that the Trojan will be launched automatically each time Windows is restarted on the victim machine.
Payload
Subscribe
Hot Articles